macOS.Gaslight: North Korea-Linked Rust Backdoor Exfiltrates Data via Telegram and Poisons AI Analysis Tools
A Rust-written macOS backdoor attributed to North Korean threat actors steals browser credentials, keychain files, and terminal history, exfiltrating everything via Telegram. The malware also embeds 38 prompt...
WhatsApp Disrupts Fresh NSO Group Pegasus Campaign, Seeks Court Contempt Order
Meta's WhatsApp has disrupted a new NSO Group-linked Pegasus spyware campaign targeting users in Jordan and Lebanon, and is now petitioning a U.S. federal court to hold NSO...
FSB Claims Foreign Spyware Found on Russian Officials’ Phones in Targeted Espionage Campaign
Russia's FSB announced the disruption of a foreign intelligence campaign implanting advanced spyware on senior officials' mobile phones, enabling silent surveillance, communication interception, and data exfiltration consistent with...
KidsProtect: New Rebrandable Android Stalkerware Platform Lets Anyone Resell Covert Surveillance Malware
A new Android spyware tool called KidsProtect is being sold on hacking forums with a white-label reseller model that lets buyers rebrand and resell it under their own...
The Sophisticated ClickFix Sting: How Calisto Disguises Itself to Steal Credentials
Calisto, a cyberespionage campaign attributed to the Russian FSB’s Center 18 for Information Security (military unit 64829), has been making waves in the cybersecurity community. This group has...
ClayRat: A New Breed of Android Spyware with Unprecedented Control
A closer look at the sophisticated threat and its tactics. The mobile device landscape is under a constant barrage of new threats, with cybercriminals becoming increasingly adept at...
Arkanix: A Sneaky New Malware Stealing from Homes and Small Offices
New malware is emerging with a distinct focus on stealing sensitive information from home users and small businesses: the Arkanix stealer. This advanced tool leverages common vulnerabilities to...
ShadyPanda’s Seven-Year Heist: How a Simple Extension Became a Mass Spy Tool
A sophisticated threat group, dubbed ShadyPanda, has quietly exploited millions of users across the world by weaponizing popular Chrome and Edge extensions. This stealthy campaign, spanning seven years...