PyInstaller is a tool tracked across 7 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed January 5, 2026; most recent activity June 5, 2026.
In 2024, Iranian APT group BladedFeline launched a cyber campaign against Kurdish and Iraqi government officials, utilizing advanced malware tools including the Shahmaran backdoor and the Whisper backdoor. The attacks…
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
Trendmicro's TrendAI™ Research has identified two AI-augmented threat campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, targeting government and financial organizations in Latin America. These campaigns began in late…
BlankGrabber's operators are utilizing a fake certificate loader to conceal a sophisticated multi-stage infection chain involving Rust and Python. This method leverages built-in Windows tools like certutil.exe and…
Between October and December 2025, Ukrainian Defense Forces were targeted by a cyberattack disguised as a charitable foundation. The attack, attributed to the Russian group Void Blizzard (Laundry Bear), installed…
VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…
A new variant of the PDFly malware has been identified, utilizing a modified PyInstaller executable to obscure its payload and complicate analysis efforts. This advanced technique hinders security teams from effectively…