Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Windows Malware
#Windows Malware

Decade-Old Noodle RAT Resurfaces, Now Hunting Both Windows and Linux Systems Across Asia

17 September 2026  |  dark6  |  Malware

Check Point researchers have tracked renewed activity from Noodle RAT, a cross-platform backdoor linked to Chinese-speaking threat actors and shared across multiple APT and cybercrime groups. Victims span...

>> read more

Toy Ghouls Hide New Windows Backdoors Behind MQTT and Matrix Traffic

5 September 2026  |  dark6  |  Malware

The Toy Ghouls group has deployed two custom Windows backdoors that use MQTT and Matrix-based services for command traffic. The malware adds durable remote control to compromises previously...

>> read more

Rogue ScreenConnect Clients Turn Remote Support Sessions Into a Worm-Like Infection Chain

4 September 2026  |  dark6  |  Malware

Attackers are abusing unauthorized ScreenConnect installations to push staged malware into newly connected Windows systems. The campaign begins with social engineering, then uses trusted remote-support functions for persistence,...

>> read more

Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign

3 September 2026  |  dark6  |  Malware

A Silver Fox-linked campaign is distributing counterfeit installers for brands like Razer, Microsoft Edge, and Kaspersky that use SYSTEM-level scheduled tasks to strip Microsoft Defender protections and delete...

>> read more

Payload Ransomware Deploys ChaCha20 + Curve25519 ECDH to Lock Files — 50+ Victims Across Five Countries

26 May 2026  |  dark6  |  Ransomware

A new ransomware operation called Payload has emerged using military-grade ChaCha20 encryption paired with Curve25519 ECDH key exchange, making file recovery without the operator key impossible. Active since...

>> read more

DEEP#DOOR: New Python Backdoor Silently Harvests Browser Passwords, Cloud Tokens, SSH Keys, and Wi-Fi Credentials

2 May 2026  |  dark6  |  Malware

Securonix researchers have documented DEEP#DOOR, a self-contained Python backdoor delivered via obfuscated batch files that systematically disables Windows defenses before establishing persistent remote access. Its credential-harvesting engine simultaneously...

>> read more