Console Pipe Injection Shows Why EDR Cannot Rely on Classic Memory-Write Signals
A newly disclosed Windows injection method delivers payload bytes through a child console process’s redirected input, avoiding two APIs commonly associated with remote code injection. The technique still...
Samsung MagicINFO Exploit Leads to Persistent Access and On-Host Cryptominer Build
Attackers exploited a known Samsung MagicINFO file-write flaw, installed AnyDesk, created an administrator account and disabled Microsoft Defender before building a Monero miner on the victim. The case...
CARBONATO Botnet Embeds an AI Agent in Compromised Docker Hosts
The CARBONATO botnet abuses unauthenticated Docker services, escapes privileged containers and installs an AI agent controlled through Telegram. Separate automated scripts spread across nearby networks while the agent...
TWEAKOS Doesn’t Just Steal Your Discord and Telegram Accounts — It Puts Them Up for Sale
A newly uncovered malware operation called TWEAKOS pairs a lightweight Windows stealer with a Telegram-based storefront, letting operators harvest Discord tokens and hijack Telegram sessions, then sell the...
RemControl: The Android Banking Trojan Hiding Behind Fake Streaming Apps and AI-Written Code
A new Android banking trojan called RemControl is spreading through fake streaming-app download pages, using convincing overlay screens to steal PINs and card details from more than 30...
RemControl Android Trojan Uses Fake Banking Screens to Steal PINs
RemControl spreads through fake streaming-app pages and overlays convincing phishing screens on top of banking apps. The Android trojan targets more than 30 financial institutions and combines credential...
New PamStealer Variant Poses as a Crypto Wallet App to Raid Mac Keychains
Jamf Threat Labs has identified a third-generation PamStealer campaign distributed through a fake multichain crypto-wallet installer called Wavel. The malware has been rewritten in Swift and now relies...
105 Minutes of Stolen Access Turned a Trusted npm Package Into a Multi-Stage Malware Loader
Attackers hijacked a maintainer account for just 105 minutes to slip a hidden loader into a popular npm package, abusing legitimate publishing infrastructure so the poisoned release carried...