Latest news

Gremlin Stealer Evolves: New Variant Hides C2 URLs in Encrypted Resources and Adds Discord Token Theft
Malware

Gremlin Stealer Evolves: New Variant Hides C2 URLs in Encrypted Resources and Adds Discord Token Theft

21 May 2026 dark6

A newly analyzed Gremlin stealer variant hides C2 URLs inside XOR-encrypted .NET resource sections, making it invisible to static scanners....
Four Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets in Coordinated Supply Chain Attack
Malware

Four Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets in Coordinated Supply Chain Attack

19 May 2026 dark6

Four malicious npm packages have been discovered stealing SSH keys, cloud credentials, cryptocurrency wallets, and environment variables, with one variant...
InstallFix: Hackers Use Fake Claude AI Installer Pages and Google Ads to Deploy RedLine Stealer Malware
Malware

InstallFix: Hackers Use Fake Claude AI Installer Pages and Google Ads to Deploy RedLine Stealer Malware

10 May 2026 dark6

A malware campaign called InstallFix is using paid Google Ads to push fake Claude AI installation pages to the top...
DEEP#DOOR: New Python Backdoor Silently Harvests Browser Passwords, Cloud Tokens, SSH Keys, and Wi-Fi Credentials
Malware

DEEP#DOOR: New Python Backdoor Silently Harvests Browser Passwords, Cloud Tokens, SSH Keys, and Wi-Fi Credentials

2 May 2026 dark6

Securonix researchers have documented DEEP#DOOR, a self-contained Python backdoor delivered via obfuscated batch files that systematically disables Windows defenses before...
Hackers Weaponize Fake Claude Code Leak to Distribute Vidar Infostealer and GhostSocks Proxy Malware
Malware

Hackers Weaponize Fake Claude Code Leak to Distribute Vidar Infostealer and GhostSocks Proxy Malware

28 April 2026 dark6

Threat actors are using fake GitHub repositories impersonating the leaked Anthropic Claude Code source to deliver a Rust dropper that...
Omnistealer Malware Uses Blockchain Permanence to Host Unremovable Payloads, Compromising 300,000 Credentials
Malware

Omnistealer Malware Uses Blockchain Permanence to Host Unremovable Payloads, Compromising 300,000 Credentials

20 April 2026 dark6

A sophisticated new infostealer dubbed Omnistealer embeds its payloads directly into public blockchain transactions on TRON, Aptos, and Binance Smart...
CERT-UA Exposes APT Malware Campaign Targeting Eastern European Governments and Municipal Hospitals
Malware

CERT-UA Exposes APT Malware Campaign Targeting Eastern European Governments and Municipal Hospitals

17 April 2026 dark6

Ukraine's CERT-UA has disclosed a sophisticated infostealer campaign targeting government bodies and municipal healthcare institutions across Eastern Europe. The malware...
The Sophisticated ClickFix Sting: How Calisto Disguises Itself to Steal Credentials
Spyware

The Sophisticated ClickFix Sting: How Calisto Disguises Itself to Steal Credentials

5 December 2025 dark6

Calisto, a cyberespionage campaign attributed to the Russian FSB’s Center 18 for Information Security (military unit 64829), has been making...
Arkanix: A Sneaky New Malware Stealing from Homes and Small Offices
Spyware

Arkanix: A Sneaky New Malware Stealing from Homes and Small Offices

2 December 2025 dark6

New malware is emerging with a distinct focus on stealing sensitive information from home users and small businesses: the Arkanix...
Katz Stealer: infostealers targets 78+ Chromium and Gecko-based browsers
Spyware

Katz Stealer: infostealers targets 78+ Chromium and Gecko-based browsers

15 May 2025 securebulletin.com

A newly uncovered information stealer, dubbed Katz Stealer, has rapidly emerged as a formidable threat to both enterprise and individual...
Oh Ship! Steam game “PirateFi” caught red-handed dropping password-stealing malware
Malware

Oh Ship! Steam game “PirateFi” caught red-handed dropping password-stealing malware

16 February 2025 dark6

Ahoy, gamers! Hope you weren’t sailing the high seas of Steam with a recently released free-to-play game called PirateFi. Turns...
North Korean threat actors adopt infostealer spreading tactics
Spyware

North Korean threat actors adopt infostealer spreading tactics

28 December 2024 securebulletin.com

In a recent development, North Korean hackers have adopted advanced malware distribution techniques reminiscent of the notorious Clickfix campaigns, marking...