Go to HELL, PowersHELL : Powerdown the PowerShell AttacksSecurity Affairs·Nov 15, 07:20 UTC · Nov 15, 2017Malware in the wild157
MintsLoader Malware Analysis: Multi-Stage Loader Used by TAGRecorded Future·Apr 20, 00:00 UTC · Apr 20, 2025Malware42
Covert Channels and Poor Decisions: The Tale of DNSMessengerCisco Talos·Mar 2, 17:11 UTC · Mar 2, 2017Malware30
Suspected CoralRaider continues to expand victimology using three information stealersCisco Talos·Apr 23, 12:42 UTC · Apr 23, 2024Malware30
Cybercriminals target graphic designers with GPU minersCisco Talos·Sep 7, 12:00 UTC · Sep 7, 2023Malware42
Signed MSI files, Raccoon and Amadey are used for installing ServHelper RATCisco Talos·Aug 12, 12:00 UTC · Aug 12, 2021Malware42
GoPix banking Trojan targeting Brazilian financial institutionsKaspersky Securelist·Mar 16, 09:36 UTC · Mar 16, 2026Malware42
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignCisco Talos·Jul 16, 10:00 UTC · Jul 16, 2026Malware30
Threat actor abuses Gophish to deliver new PowerRAT and DCRATCisco Talos·Oct 22, 10:00 UTC · Oct 22, 2024Malware30
JasperLoader Emerges, Targets Italy with Gootkit Banking TrojanCisco Talos·Apr 25, 15:00 UTC · Apr 25, 2019Malware30
MaaS operation using Emmenhtal and Amadey linked to threats against Ukrainian entitiesCisco Talos·Jul 17, 10:00 UTC · Jul 17, 2025Malware30
Walmart Discovers New PowerShell Backdoor Linked to Zloader MalwareInfosecurity Magazine·Jul 29, 15:00 UTC · Jul 29, 2024Malware42
New SolarMarker (Jupyter) Campaign Demonstrates the Malware’s Changing Attack PatternsPalo Alto Unit 42·Jun 5, 23:24 UTC · Jun 5, 2024Malware42
ModernLoader delivers multiple stealers, cryptominers and RATsCisco Talos·Sep 1, 17:35 UTC · Sep 1, 2022Malware30
FIN7 Group Uses JavaScript and Stealer DLL Variant in New AttacksCisco Talos·Sep 27, 17:38 UTC · Sep 27, 2017Malware30
OctLurk and SilkLurk: new Backdoors in Central AsiaKaspersky Securelist·Jul 31, 09:44 UTC · Jul 31, 2026Malware42
Detecting evolving threats: NetSupport RAT campaignCisco Talos·Aug 1, 10:00 UTC · Aug 1, 2024Malware30
The Curious Case of Notepad and Chthonic: Exposing a Malicious InfrastructurePalo Alto Unit 42·Aug 15, 12:00 UTC · Aug 15, 2017Malware30
New Fileless Malware Uses DNS Queries To Receive PowerShell CommandsThe Hacker News·Mar 6, 10:03 UTC · Mar 6, 2017Malware42
Divergent: "Fileless" NodeJS Malware Burrows Deep Within the HostCisco Talos·Sep 26, 20:07 UTC · Sep 26, 2019Malware30
New Tomiris tools and techniques: multiple reverse shells, Havoc, AdaptixC2Kaspersky Securelist·Nov 28, 07:00 UTC · Nov 28, 2025Malware142
Threat Spotlight: AsyncRAT campaigns feature new version of 3LOSH crypterCisco Talos·Apr 5, 12:00 UTC · Apr 5, 2022Malware30
Ursnif: Long Live the Steganography and AtomBombing!Security Affairs·Feb 7, 11:00 UTC · Feb 7, 2019Malware30
Experts spotted a new undetectable PowerShell BackdoorSecurity Affairs·Oct 20, 18:09 UTC · Oct 20, 2022Malware42
Alleged MuddyWater attack downloads a PowerShell script from GitHubSecurity Affairs·Jan 4, 08:49 UTC · Jan 4, 2021Malware142
Talos team spotted a PowerShell malware that uses DNS queries to contact the C2Security Affairs·Mar 3, 14:14 UTC · Mar 3, 2017Malware42
The rise of .NET and Powershell malwareKaspersky Securelist·Oct 12, 10:08 UTC · Oct 12, 2015Malware142
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain DevelopersThe Hacker News·Jan 26, 08:54 UTC · Jan 26, 2026Malware42
PowerShell-Based Loader Deploys Remcos RAT in New Fileless AttackInfosecurity Magazine·May 15, 16:00 UTC · May 15, 2025Malware42
Public report on attacks in Middle East we attribute to WIRTE APTKaspersky Securelist·Nov 29, 08:00 UTC · Nov 29, 2021Malware42
What did DeathStalker hide between two ferns?Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2020Malware42
Combing Through Brushaloader Amid Massive Detection UptickCisco Talos·Feb 20, 16:27 UTC · Feb 20, 2019Malware30
Sofacy Creates New ‘Go’ Variant of Zebrocy ToolPalo Alto Unit 42·Jan 15, 12:31 UTC · Jan 15, 2019Malware30