ZeroHour
Vendor

Malwarebytes

6 mentions in 7 days · 25 in 30 days · 26 total · first seen · last

Timeline

Crypto customers targeted by scammers after email marketing provider breach

Attackers exploited a Brevo SAML SSO flaw to access 138 accounts and phish crypto customers of Trezor, CoinTracking, and BitBox.

An attacker exploited a flaw in Brevo's SAML SSO handling to access 138 customer accounts on September 10; six accounts were used to send phishing emails and contacts were exported from 43 accounts. Crypto firms Trezor, CoinTracking, and BitBox confirmed customers received phishing emails, with Trezor warning roughly 347,000 newsletter subscribers. The Trezor-themed email cited a fabricated STM32 microcontroller entropy bug and urged recipients to enter wallet backups through a malicious link. Exported contact lists could fuel future targeted phishing attacks.

Malwarebytes Labs · 4d agoData breach in the wild 6 sources

Android malware creates a hidden copy of your banking app

Group-IB found the Gigabud Android banking trojan clones banking apps into a hidden work profile to conduct fraud undetected.

Group-IB researchers found the Gigabud Android banking trojan installs Vwork, a trojanized version of the open-source Shelter app, to create a separate Android work profile and clone the victim's banking app into it. The operator then performs fraudulent transactions from the cloned app, separating risky activity from malware detections in the personal profile and potentially bypassing bank-side anti-fraud checks. Victims are lured into sideloading fake airline, tax, or government apps via phishing sites and messages, then grant Accessibility, overlay, and battery-optimization permissions that enable remote control and credential-theft overlays. Malwarebytes detects Gigabud components under multiple Android.Trojan.Banker signatures.

Malwarebytes Labs · 4d agoMalware 6 sources

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Proofpoint documents BlueMoon exploit kit used by four espionage groups to chain Chrome V8 and Windows flaws via phishing, all now in CISA's KEV.

Proofpoint identified a shared Chrome and Windows exploit kit, BlueMoon, used by four espionage groups against Chrome on Windows within days of one another. Attacks began with phishing emails leading to web pages that exploited two Chrome V8 vulnerabilities, followed by a Windows flaw to escape browser protections and gain higher privileges. The Chrome flaws were patched in Stable on September 3 and 8, 2026, the Windows flaw was fixed in September Patch Tuesday, and all three were actively exploited and added to CISA's KEV catalog. Researchers found clues, but no conclusive evidence, that the kit was developed with AI assistance.

Malwarebytes Labsupdated · 11h agofirst · 5d agoExploit / PoC in the wild 20 sources1

Top 10 Best Ransomware Protection Solutions in 2026

A 2026 buyer's guide ranks ten ransomware protection tools by kill-chain role as extortion shifts from encryption to data theft.

The roundup organizes defenses across the ransomware kill chain: prevention-grade EPP/EDR platforms, containment layers, rollback specialists, and immutable recovery. Recommended products include CrowdStrike, Microsoft Defender, Sophos, SentinelOne, Bitdefender, Trend Micro, Halcyon, Huntress, and Malwarebytes. It stresses that many crews now extort on stolen data without encrypting, making exfiltration detection and response speed as important as rollback.

Cyber Security News · 5d agoIndustry1

More than 100,000 fake stores are out to steal your card details

Researchers uncovered DoppelCart, a network of roughly 119,000 cloned fake shops that harvest card details and one-time bank codes during checkout.

Researchers at German firm Nebty identified 118,787 .shop domains tied to cloned online stores, representing 2.72% of the TLD population examined and described as the largest publicly documented fake-shop network by domain count. The shops mimic more than 44,000 brands, advertise discounts up to 65%, and 96% of confirmed shops reportedly share identical build files using just 27 ecommerce backends. Fraudulent checkout pages send card numbers, CVVs, billing data and bank one-time confirmation codes to attacker-controlled servers in real time over WebSockets, allowing criminals to complete payments while victims are still checking out.

Malwarebytes Labs · 6d agoPhishing & fraud

The 12 Best Antivirus Software for Mac, Compared and Priced

GBHackers ranks 12 Mac antivirus products, naming Bitdefender best overall and noting Gen Digital owns Norton, Avast, and Avira.

GBHackers scored twelve Mac antivirus products, ranking Bitdefender first at 8.8/10, followed by Intego, Malwarebytes, and ESET. The piece highlights that Gen Digital owns Norton, Avast, and Avira following the NortonLifeLock-Avast merger, so three of the twelve options share one corporate owner. It advises comparing year-two renewal prices rather than discounted first-year pricing and notes macOS already ships XProtect, Gatekeeper, and automatic malware removal. The 2026 Mac threat model described is infostealers harvesting passwords, cookies, and wallets via cracked software, fake installers, and malicious search ads.

GBHackersupdated · 4d agofirst · 6d agoIndustry 10 sources

The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced

GBHackers compares 12 business antivirus products on detection, EDR depth, pricing, and platform coverage, ranking CrowdStrike and Bitdefender joint top at 8.8.

The roundup scores 12 enterprise endpoint protection vendors across detection, EDR depth, management, pricing transparency, and platform coverage. CrowdStrike and Bitdefender tie at 8.8, with Microsoft Defender for Endpoint scoring 8.5 and noted as effectively free for Microsoft 365 E5 licensees. The piece also flags that Kaspersky cannot legally be sold in the US and that Panda and Webroot now sit under WatchGuard and OpenText respectively.

GBHackers · 7d agoIndustry 2 sources1

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Malwarebytes' Lock and Code podcast examines loyalty-points theft, with LexisNexis' Kim Sutherland explaining why stolen airline and hotel points are lucrative for fraudsters.

LexisNexis Risk Solutions' Kim Sutherland says loyalty currency is worth roughly one cent per point, making 100,000 airline points worth about $1,000 in the US. Cited incidents include a Chicago teacher who lost 240,000 airline points, discovered only via a confirmation email, and a man whose miles were used to book rental cars in New York and Memphis. The episode discusses how points theft happens and what companies and consumers can do.

Malwarebytes Labs · 8d agoPhishing & fraud

LG TV flaws could let attackers listen in, even in standby mode

Researchers found LG smart TVs collect network data and ACR viewing profiles, and demonstrated microphone audio capture plus undisclosed RCE vulnerabilities.

An investigation by Gamers Nexus with Level1Techs and independent researchers found LG TVs performing network discovery, collecting nearby Wi-Fi names and device identifiers, and conducting Automated Content Recognition (ACR) tracking. They demonstrated microphone audio capture even when the TV appeared off, and audio buffering while the TV was unplugged from the internet. Remote-code-execution vulnerabilities were reported to LG under ongoing responsible disclosure, with full details not yet public.

Malwarebytes Labs · 8d agoVulnerability

Flirty OnlyFans promoters on X may be using AI to appear human

Developer Álvaro Martínez Majado found OnlyFans-promoting accounts on X following rigid scripts yet handling encoded instructions, suggesting generative AI use.

Investigation of flirty X accounts promoting OnlyFans pages showed near-identical openers across accounts plus dynamic behaviors: answering a hexadecimal-encoded instruction with "Pineapple" and failing an exact 12-character count test in an LLM-like pattern. The accounts also sent personalized voice notes reading supplied timestamps and usernames, consistent with automated text-to-speech. Evidence suggests a hybrid scripted/AI system, though no model, provider, or operator was identified.

Malwarebytes Labs · 8d agoAI safety & security

A week in security (August 31 – September 6)

Malwarebytes publishes its weekly security recap covering cyber news from August 31 through September 6.

Malwarebytes Labs' recurring 'A week in security' digest aggregates the past week's cybersecurity stories. The published text contains only newsletter boilerplate without specific incident, vulnerability, or threat-actor details.

Malwarebytes Labs · 8d agoIndustry

The hidden work of modernizing Malwarebytes

Malwarebytes details its migration of Windows product managed components to .NET 10, citing security, supportability, diagnostics, and performance benefits.

Malwarebytes says it migrated the managed portions of Malwarebytes for Windows to .NET 10 while leaving native drivers and the detection engine untouched. The vendor cites a supported runtime, safer defaults, stronger cryptography, better diagnostics, and JIT/GC performance improvements as benefits. The migration also deprecated Windows 7 support, and the company applies staged rollouts and automated validation because its code runs with elevated privileges on millions of endpoints. No vulnerabilities or incidents are described.

Malwarebytes Labs · 11d agoIndustry1

X Money rollout linked to password-reset attacks

X is investigating bulk unsolicited password-reset emails as its X Money payments service expands, with no confirmed breaches or account takeovers yet.

X users began reporting unexpected password-reset emails and codes on September 1, and product engineer Mridul Singhai said attackers appear to believe newly widespread X Money access makes accounts worth targeting. X says it has found no evidence of any breach or successful account takeover, and completing a reset still requires access to the account's email or phone number. X Money offers eligible US users interest-bearing accounts, a Visa debit card, and P2P payments, with Cross River Bank providing banking infrastructure. Malwarebytes warns the reset flood can serve as cover for phishing and urges reset protection, 2FA, and unique passwords.

Malwarebytes Labs · 11d agoPhishing & fraud in the wild

Free streaming boxes may be routing criminal traffic through your home

Researchers found SuperBox streaming boxes and the CyberFlix TV app enroll home connections into the Popanet residential proxy network, routing criminal traffic.

Researchers found that SuperBox devices and the CyberFlix TV app, distributed through SuperBox's custom app store, contain Popanet proxy functionality that registers the device with servers controlled by the proxy operator, enrolling household connections into residential proxy networks. The reported configuration weakens Android safeguards with exposed ADB access, root-level privileges without authentication, and removal of app-install protections. Plume's research warns these proxy networks can also function as malware-delivery platforms, and the FBI notes foreign entities use residential proxies to conceal activity such as credential stuffing and account abuse. Malwarebytes advises disconnecting and replacing affected SuperBox/CyberFlix devices rather than factory-resetting them.

Malwarebytes Labs · 11d agoMalware in the wild

Scammers have figured out the best time to text you

Malwarebytes threat data shows scammers tailor platforms per scam, with the web as top channel, Friday midday peaks, and MrBeast the most impersonated person.

Malwarebytes analyzed its threat data from April 15 to July 14, 2026 across more than 20 scam categories, finding scammers match platforms to scam types: job scams via email, romance scams via social media, and tech support scams via phone. The web is the top delivery channel ahead of email and SMS, and Malwarebytes says it blocks about 500,000 phishing sites a day. Scam texts peak at 12:00 pm ET, roughly 874% above the quietest hour, with volume peaking on Fridays about 50% higher than the start of the week. MrBeast (Jimmy Donaldson) appears in about 30% of impersonation scams, and the most impersonated brands are Google, Microsoft, Apple, Roblox and Amazon.

Help Net Security · 11d agoPhishing & fraud in the wild

StreamRat Android malware spreads through Meta and TikTok ads

Malwarebytes reports StreamRat Android banking trojan spread via Meta and TikTok ads reaching roughly 570,000 users, mostly in Spain.

Malwarebytes researchers uncovered a malicious advertising campaign on Meta and TikTok promoting a fake free TV-streaming service that delivered the StreamRat Android banking trojan and infostealer. The ads, aimed at Spanish-speaking users with most victims in Spain, reached approximately 570,000 Meta users in a campaign running June 11 through July 3, 2026. The download site detected Android devices and the referral source, then coached users through sideloading steps including enabling installs from unknown sources. StreamRat can monitor the screen, capture typed credentials, display fake login screens, and give attackers remote control, including black-screen and fake Android update overlays.

Malwarebytes Labs · 12d agoMalware in the wild

Tech support scams look different now. Here’s what to watch for

Malwarebytes warns tech support scammers now abuse sponsored search results, fake listings, calendar invites, and Apple Pay notifications, and shares red flags for impersonation scams.

Malwarebytes describes how tech support scams have expanded beyond browser locks and fake virus warnings to sponsored search results, hijacked on-site searches, fake platform listings, renewal scams, fake calendar invites, and Apple Pay notifications. Scammers impersonate trusted security companies including Malwarebytes, seeking payment, personal information, or remote access to victims' computers. Malwarebytes notes it does not outsource support, never makes unsolicited calls, and works with the FTC and the Global Anti-Scam Alliance to combat these scams.

Malwarebytes Labs · 13d agoPhishing & fraud1

Scammers are getting smarter about where they target you

Malwarebytes data shows scammers tailor fraud by platform: 90% of toll scams arrive via email/SMS and MrBeast is now the most impersonated person.

Malwarebytes threat research analyzed global scam data from April 15 to July 14, 2026, across more than 20 scam types, finding each type favors a specific channel such as email, SMS, phone, or social media. Roughly nine in ten toll scams arrive by email or text, about half of IRS scams come by phone, and MrBeast is impersonated in about 30% of impersonation scams. The most impersonated brands are Google, Microsoft, Apple, Roblox, and Amazon, and Malwarebytes blocks around 500,000 phishing websites daily. Gaming scams on Roblox, Steam, Discord, and Minecraft increasingly carry losses of $1,000 or more, with 15-19% activity spikes in mid-2026.

Malwarebytes Labs · 13d agoPhishing & fraud

Your AI chats could be used in court

AI chatbot conversations from ChatGPT and Claude are increasingly obtained by prosecutors and litigants, with OpenAI disclosures quadrupling in 2025.

A Washington Post report found chatbot logs cited in 12 court cases over the past two years, and OpenAI disclosed the content of more than 80 user accounts in the second half of 2025, more than four times the figure for the second half of 2024. In The New York Times' copyright lawsuit against OpenAI, a judge ordered the company to preserve chat logs, including ones users had asked to delete, despite GDPR and California privacy commitments. Chatbot conversations lack attorney-client or medical privilege, and OpenAI's policy allows reviewers to refer conversations to law enforcement when there is an imminent, credible risk of harm.

Malwarebytes Labs · 13d agoAI policy

TerminalFix looks like ClickFix, but delivers a very different payload

Malwarebytes warns TerminalFix mimics the ClickFix fake CAPTCHA social engineering trick but delivers a payload granting attackers access to victims' wider network.

Malwarebytes identified TerminalFix, a variant of the familiar ClickFix fake CAPTCHA social engineering trick. The adapted chain delivers a very different payload, one that can give attackers access to the victim's wider network beyond the initially infected host.

Malwarebytes Labs · 14d agoMalware in the wild

Infostealers are hijacking Claude accounts at users’ expense

Malwarebytes reports infostealers are stealing Claude session cookies to hijack Anthropic accounts and consume victims' usage at their expense.

Anthropic warned that infostealer malware operators are harvesting Claude session cookies from infected machines. Attackers replay the stolen cookies to take over users' accounts and consume their usage quotas, affecting the victims' own access. The activity involves observed account hijacking rather than a flaw in Claude itself.

Malwarebytes Labs · 14d agoMalware in the wild

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare giant McKesson confirmed a cyber incident after ShinyHunters claimed theft of hundreds of millions of patient records.

McKesson acknowledged a data breach following public claims by the threat actor group ShinyHunters that it stole hundreds of millions of records containing patient data. The company confirmed a cyber incident occurred but the full scope of the theft has not yet been independently verified. ShinyHunters is known for large-scale data theft and extortion against major organizations. The healthcare sector remains a frequent target for data-theft extortion groups.

Malwarebytes Labs · 15d agoData breach

ChatGPT’s new feature could give infostealers a map of your Mac activity

OpenAI's Computer History feature for macOS ChatGPT logs app and website activity into memories, raising prompt injection and infostealer privacy risks.

OpenAI's Computer History builds timelines of Mac activity from interaction events and macOS accessibility data, turning them into memories for ChatGPT and Codex. The feature is opt-in, requires Memories, runs only in the ChatGPT macOS desktop app, and is unavailable in the EEA, Switzerland, and the UK. Raw event files stay on-device and are deleted after 48 hours, but generated Markdown memory files are unencrypted and persist until manually deleted. OpenAI itself flagged unencrypted files and prompt injection risks, and security experts warned infostealers could use the logs as a ready-made map of someone's workday.

Help Net Security · 27d agoAI safety & security

Analysis of Smoke Loader in New Tsunami Campaign

Fake Japanese Meteorological Agency tsunami warning emails delivered Smoke Loader and AzoRult malware to steal credentials from targets in Japan.

A fake tsunami warning email impersonating Japan's Meteorological Agency asked recipients to click a link on a registered fake agency domain, delivering the commodity loader Smoke Loader to targets in Japan. Smoke Loader, active since 2011, is modular, and its payloads have included banking trojans, ransomware, cryptominers, password stealers, and PoS malware; the campaign later also deployed AzoRult. New samples add junk-jump obfuscation, encrypted network traffic and payload files, a unique machine ID used for tracking and encryption, and PROPagate injection into explorer.exe, with persistence via a Startup folder shortcut and RC4-encrypted C2 communication.

Palo Alto Unit 42 · 29d agoMalware in the wild

How the EITest Campaign's Path to Angler EK Evolved Over Time

Unit 42 documents how the EITest campaign's gate URLs and infrastructure evolved since 2014 while still routing victims to Angler EK and diverse malware.

Unit 42 traced network traffic changes in the EITest campaign, which Malwarebytes identified in October 2014 across thousands of compromised websites. The campaign's injected script patterns have remained consistent, but its gate URLs changed repeatedly, and since January 2016 gates used the 85.93.0.0/24 IP block, often with .tk domains. The gate returns a Flash file that redirects victims to Angler EK, which delivered malware including Vawtrak, Tinba, TeslaCrypt, Bedep, Kovter, Ursnif, and Zeus variants from 2014 through 2016.

Palo Alto Unit 42 · 29d agoThreat actor in the wild

Ready-made $500 kit puts a crypto scam within anyone's reach

A $500 ready-made scam kit sold on a cybercrime forum builds fake Tesla $TSLA presale pages that harvest wallet recovery phrases and cryptocurrency deposits.

Malwarebytes found a $500 scam-in-a-box kit by seller xrep on a cybercrime forum, bundling a fake Tesla-style $TSLA presale site, a victim-tracking admin panel, and controls to inflate fake balances. The kit harvests 12-word wallet recovery phrases via wallet-connection prompts or accepts direct transfers in Bitcoin, Ethereum, USDT, or Dogecoin. The admin panel lets operators check stolen wallets' value before draining them, raise displayed balances to encourage further deposits, and send follow-up messages demanding fake network fees.

Help Net Security · Aug 12, 2026Phishing & fraud