New ‘Pass-ta-key’ Attacks Show How Malware Can Silently Hijack Google’s Synced Passkeys
Unit 42 researchers have detailed three escalating attack techniques that let malware already on a Windows PC take over Google-synced passkeys without ever triggering a password, PIN, or...
BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server
China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the victim's own proxy infrastructure....
Fake macOS Update Screens Are Tricking Mac Users Into Handing Over Crypto Wallets
A North Korea-linked campaign is using fake 'Installing System Update' overlays to trick victims into pasting malicious commands into Terminal, deploying a backdoor that raids 157 cryptocurrency wallets...
Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware
Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords,...
Fake Claude Desktop Ads on Bing Are Delivering SectopRAT to Corporate Networks
A campaign dubbed FakeAgent used paid Bing search ads and a malicious public Claude Artifact to trick corporate employees into installing a disguised remote access trojan. At least...
Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...
Fake Game Downloads Are Quietly Installing Amatera Stealer Through a Disguised RenPy Loader
A malware campaign is hiding behind fake games, cracks, and mods to install Amatera Stealer, a multi-stage infostealer that harvests browser credentials, messaging data, and cryptocurrency wallets. The...
PhantomEnigma: How a Malware Crew Turned Brazilian Government Sites Into Trusted Malware Hubs
A campaign tracked as PhantomEnigma has compromised more than 20 official Brazilian government websites, using them to host and deliver malware that passes email authentication checks and slips...