Decade-Old Noodle RAT Resurfaces, Now Hunting Both Windows and Linux Systems Across Asia
Check Point researchers have tracked renewed activity from Noodle RAT, a cross-platform backdoor linked to Chinese-speaking threat actors and shared across multiple APT and cybercrime groups. Victims span...
For $250 a Month, Anyone Can Rent a Fully Featured Windows Spy Tool Called VectraRAT
Researchers have uncovered VectraRAT, a subscription-based remote access trojan renting for as little as $250 a month that gives buyers keylogging, hidden-desktop control, and credential theft on infected...
Malicious Twitch Extension Leaks OAuth Tokens From 30,000 Browser Users
A Twitch helper extension installed by about 30,000 Chrome and Firefox users was found sending active account tokens through operator-controlled servers. The incident shows how a seemingly convenient...
ClearFake CAPTCHA Campaign Disables EDR to Deploy Crypto Stealer
ClearFake has expanded its fake CAPTCHA operation with a vulnerable-driver technique that terminates endpoint defenses before deploying a cryptocurrency stealer. The campaign combines compromised sites, blockchain-hosted instructions, WebDAV...
Fake Job Interviews Deliver NodeRabbit and PollCat Malware to Software Developers
An Iran-linked group tracked as Mirage Kitten (UNC1549) is posing as recruiters on LinkedIn to trick developers into running malicious take-home coding tests. The booby-trapped projects deploy two...
FortiGate Exploitation Campaign Plants PivotC2 Malware and Steals Network Credentials
Attackers are exploiting a critical Fortinet vulnerability to install a custom Node.js remote-access framework on exposed appliances. The campaign has reportedly compromised 178 devices and can harvest credentials,...
Stealth Linux Rootkit Hides Fileless Web Shells Inside F5 BIG-IP Memory
Researchers have uncovered a Linux rootkit that alters PHP code only in memory on compromised F5 BIG-IP APM appliances. Its fileless web shell, local socket backdoor and upgrade...
North Korean Hackers Hide ‘Ted’ Backdoor Inside Trojanized HAProxy to Spy on South Korean Firms
Rapid7 researchers have uncovered a DPRK-linked Linux intrusion toolkit — built around a modified HAProxy binary dubbed Ted and a companion remote access tool called CurlRAT — that...