North Korea-Linked Hackers Hide OtterCookie Malware Inside 14 Fake Mac Apps
Researchers have identified fourteen trojanized macOS installers impersonating popular utilities like The Unarchiver and Sketch, all delivering the OtterCookie credential-stealing malware. The campaign, tied to North Korea's long-running...
Over 14,000 Dahua Cameras Compromised With Backdoors That Survive Factory Resets
Researchers at Hunt.io say a 35-day campaign compromised more than 14,000 internet-connected Dahua cameras, planting hidden administrator accounts and abusing cloud recovery codes that persist even through password...
Toy Ghouls Hide New Windows Backdoors Behind MQTT and Matrix Traffic
The Toy Ghouls group has deployed two custom Windows backdoors that use MQTT and Matrix-based services for command traffic. The malware adds durable remote control to compromises previously...
Rogue ScreenConnect Clients Turn Remote Support Sessions Into a Worm-Like Infection Chain
Attackers are abusing unauthorized ScreenConnect installations to push staged malware into newly connected Windows systems. The campaign begins with social engineering, then uses trusted remote-support functions for persistence,...
Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign
A Silver Fox-linked campaign is distributing counterfeit installers for brands like Razer, Microsoft Edge, and Kaspersky that use SYSTEM-level scheduled tasks to strip Microsoft Defender protections and delete...
ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor
A ValleyRAT campaign is disguising its infection chain as adware and familiar software installers, with most observed victims in China and India. The backdoor uses DLL sideloading and...
Malvertising Has Moved Past the Ad Itself: Why the Real Threat Now Lives in the Redirect Chain
New moderation data shows malicious advertising is increasingly indistinguishable from a legitimate ad at first glance, with the real payload hidden several redirects deep behind cloaking, disposable domains,...
Infostealers Target Claude Sessions, Letting Attackers Bypass MFA and Drain Paid Accounts
Attackers are stealing authenticated Claude browser sessions and abusing malicious ads and files to compromise users. Anthropic has invalidated affected sessions and refunded confirmed charges, but victims must...