HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel
Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical overlap...
Inside NadMesh: The Shodan-Powered Botnet Hunting Exposed AI Servers
Researchers at XLab have identified NadMesh, a Go-based botnet that uses Shodan to hunt down exposed AI and MCP infrastructure before hijacking it with more than 20 exploitation...
Cavern Manticore: Iranian-Linked APT Abuses SysAid RMM and DLL Sideloading to Deploy Modular C2 Framework
A newly identified Iranian-linked group, Cavern Manticore, is abusing the SysAid RMM platform and DLL sideloading via WinDirStat to deploy a modular C2 framework against Israeli organizations. Check...
PamStealer: New macOS Infostealer Disguises Itself as the Maccy Clipboard Manager
PamStealer is a newly discovered macOS infostealer that impersonates the Maccy clipboard manager, using a two-stage AppleScript-to-Rust infection chain to steal Keychain data, browser credentials, and clipboard contents...
Ousaban Banking Trojan Resurfaces With Steganographic PDF Lures Targeting Spain and Portugal
Fortinet's FortiGuard Labs has documented a fresh wave of the Ousaban banking trojan hitting Windows users in Spain and Portugal through fake corrupted PDFs and a spoofed tax...
AsyncRAT Trojan Hidden in 90+ Fake Software Download Sites via DLL Sideloading and ScreenConnect
A stealthy campaign is hiding the AsyncRAT trojan inside fake installers for popular free software, using DLL sideloading and the legitimate ScreenConnect remote-access tool to slip past security...
Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen
Researchers scanning 50,000 ClawHub skills — the official marketplace for the OpenClaw AI agent platform — found working remote control backdoors, credential stealers, and autonomous malware that installs...
LokiBot Returns: Multi-Stage JScript Campaign Uses Process Injection to Steal Credentials
LokiBot, the decade-old credential stealer, has resurfaced with a sophisticated multi-stage attack chain: a JScript email dropper, in-memory .NET injection, and process hollowing inside aspnet_compiler.exe to silently harvest...