Decade-Old Noodle RAT Resurfaces, Now Hunting Both Windows and Linux Systems Across Asia
Check Point researchers have tracked renewed activity from Noodle RAT, a cross-platform backdoor linked to Chinese-speaking threat actors and shared across multiple APT and cybercrime groups. Victims span...
Toy Ghouls Hide New Windows Backdoors Behind MQTT and Matrix Traffic
The Toy Ghouls group has deployed two custom Windows backdoors that use MQTT and Matrix-based services for command traffic. The malware adds durable remote control to compromises previously...
Rogue ScreenConnect Clients Turn Remote Support Sessions Into a Worm-Like Infection Chain
Attackers are abusing unauthorized ScreenConnect installations to push staged malware into newly connected Windows systems. The campaign begins with social engineering, then uses trusted remote-support functions for persistence,...
Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign
A Silver Fox-linked campaign is distributing counterfeit installers for brands like Razer, Microsoft Edge, and Kaspersky that use SYSTEM-level scheduled tasks to strip Microsoft Defender protections and delete...
Payload Ransomware Deploys ChaCha20 + Curve25519 ECDH to Lock Files — 50+ Victims Across Five Countries
A new ransomware operation called Payload has emerged using military-grade ChaCha20 encryption paired with Curve25519 ECDH key exchange, making file recovery without the operator key impossible. Active since...
DEEP#DOOR: New Python Backdoor Silently Harvests Browser Passwords, Cloud Tokens, SSH Keys, and Wi-Fi Credentials
Securonix researchers have documented DEEP#DOOR, a self-contained Python backdoor delivered via obfuscated batch files that systematically disables Windows defenses before establishing persistent remote access. Its credential-harvesting engine simultaneously...