Core Werewolf Deploys Custom CoreRAT Against Russian Defense Targets
The Core Werewolf threat group is using a newly documented Windows remote access trojan in campaigns aimed at Russian public-sector and defense organizations. Telegram lures and forged official...
ToxNetV2 Botnet Adds AI-Guided Commands to Linux Attack Operations
Researchers have analyzed a peer-to-peer Linux botnet whose controller consults an NVIDIA-hosted AI model to propose operational actions. Human approval still gates the most consequential commands, but the...
Fake Adobe Reader Site Powers a New Malware-as-a-Service Platform Targeting Windows Users
Researchers have uncovered a live malware-as-a-service operation hiding behind a convincing fake Adobe Acrobat Reader site, using a WebDAV trick and a disguised batch file to install information-stealing...
New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools
Researchers have uncovered SilkParasite, a cyberespionage operation using spear-phishing and five previously unseen malware families to target government bodies across Central Asia. The campaign favors cloud-based command channels...
Hijacked Rust Crates With 244 Million Downloads Turned Into Malware Delivery Pipeline
A typosquatted Rust package quietly hijacked two popular crates, arrayref and append-only-vec, to run an infostealer during ordinary builds. The attack hid inside an automatically-executed build script, leaving...
Fake CAPTCHA Prompts on Hacked WordPress Sites Fuel Global StopAndProtect Malware Botnet
Researchers have uncovered a sprawling campaign, dubbed StopAndProtect, that has hijacked thousands of poorly maintained WordPress sites to serve as rotating command-and-control infrastructure. Fake CAPTCHA prompts trick visitors...
Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks
Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has...
‘Bring Your Own EDR’ Trick Turns SentinelOne Into a Bodyguard for Malware
DEF CON 34 research shows how trusted SentinelOne components could be abused to dump memory from Windows' most protected processes, ultimately shielding malicious payloads behind the endpoint agent's...