How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline
Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...
North Korean Hackers Hide Malware Instructions Inside Ethereum Smart Contracts to Drain Crypto Wallets
A North Korean-linked campaign is using fake macOS update screens to trick victims into pasting a malicious command into Terminal, kicking off an infection chain that hunts for...
New ‘Pass-ta-key’ Attacks Show How Malware Can Silently Hijack Google’s Synced Passkeys
Unit 42 researchers have detailed three escalating attack techniques that let malware already on a Windows PC take over Google-synced passkeys without ever triggering a password, PIN, or...
BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server
China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the victim's own proxy infrastructure....
Fake macOS Update Screens Are Tricking Mac Users Into Handing Over Crypto Wallets
A North Korea-linked campaign is using fake 'Installing System Update' overlays to trick victims into pasting malicious commands into Terminal, deploying a backdoor that raids 157 cryptocurrency wallets...
Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware
Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords,...
Fake Claude Desktop Ads on Bing Are Delivering SectopRAT to Corporate Networks
A campaign dubbed FakeAgent used paid Bing search ads and a malicious public Claude Artifact to trick corporate employees into installing a disguised remote access trojan. At least...
Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...