Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY MalwareThe Hacker News·Jul 24, 05:33 UTC · Jul 24, 2024MalwareCVE-2024-2369247
Vollgar botnet has managed to infect around 3k MSSQL DB servers dailySecurity Affairs·Apr 1, 15:50 UTC · Apr 1, 2020Malware42
WARNING: Hackers Install Secret Backdoor on Thousands of Microsoft SQL ServersThe Hacker News·Apr 1, 13:02 UTC · Apr 1, 2020Malware42
Chinese-Backed Silver Fox Plants Backdoors in Healthcare NetworksInfosecurity Magazine·Feb 25, 13:40 UTC · Feb 25, 2025Malware42
Russian Hackers Deploy HATVIBE and CHERRYSPY Malware Across Europe and AsiaThe Hacker News·Nov 22, 16:59 UTC · Nov 22, 2024Malware55
China-Linked ValleyRAT Malware Resurfaces with Advanced Data Theft TacticsThe Hacker News·Jun 11, 08:47 UTC · Jun 11, 2024MalwareCVE-2017-0199CVE-2017-1188235
New Lucifer DDoS botnet targets Windows systems with multiple exploitsSecurity Affairs·Jun 26, 06:42 UTC · Jun 26, 2020MalwareCVE-2019-9081CVE-2014-6287CVE-2018-1000861+7 CVEs60
TwoFace Webshell: Persistent Access Point for Lateral MovementPalo Alto Unit 42·Nov 1, 10:54 UTC · Nov 1, 2018Malware30
Stealth Falcon's undocumented backdoor uses Windows BITS to exfiltrate dataSecurity Affairs·Sep 24, 16:29 UTC · Sep 24, 2023Malware42
Critical shim bug impacts every Linux boot loader signed in the past decadeSecurity Affairs·Feb 7, 14:46 UTC · Feb 7, 2024MalwareCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
CRAT wants to plunder your endpointsCisco Talos·Nov 12, 13:18 UTC · Nov 12, 2020MalwareCVE-2017-829147
The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefactKaspersky Securelist·Jun 30, 08:00 UTC · Jun 30, 2022Malware42
OilRig Malware Campaign Updates Toolset and Expands TargetsPalo Alto Unit 42·Nov 1, 10:23 UTC · Nov 1, 2018Malware42
Python-Based PWOBot Targets European OrganizationsPalo Alto Unit 42·Jan 28, 20:32 UTC · Jan 28, 2022Malware130
SilentCryptoMiner distributed as a bypass toolKaspersky Securelist·Mar 5, 10:22 UTC · Mar 5, 2025Malware30
Cloud Atlas using a new backdoor, VBCloud, to steal dataKaspersky Securelist·Dec 23, 10:00 UTC · Dec 23, 2024MalwareCVE-2018-080247
GoPix banking Trojan targeting Brazilian financial institutionsKaspersky Securelist·Mar 16, 09:36 UTC · Mar 16, 2026Malware42
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
Efimer Trojan delivered via email and hacked WordPress websitesKaspersky Securelist·Aug 8, 09:00 UTC · Aug 8, 2025Malware30
OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat GroupPalo Alto Unit 42·Jan 10, 16:52 UTC · Jan 10, 2020Malware30
South Korean ERP Vendor's Server Hacked to Spread Xctdoor MalwareThe Hacker News·Jul 3, 06:52 UTC · Jul 3, 2024Malware42
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
Transparent Tribe Launches New RAT Attacks Against Indian Government and AcademiaThe Hacker News·Jan 6, 05:33 UTC · Jan 6, 2026Malware42
Two never-before-seen tools, from same group, infect airArs Technica · Security·Oct 9, 12:26 UTC · Oct 9, 2024Malware42
Chafer used Remexi malware to spy on IranKaspersky Securelist·Jan 30, 10:00 UTC · Jan 30, 2019Malware42
New KONNI Malware attacking Eurasia and Southeast AsiaPalo Alto Unit 42·Nov 2, 11:25 UTC · Nov 2, 2018Malware30
New MATA Multi-platform malware framework linked to NK Lazarus APTSecurity Affairs·Jul 23, 14:47 UTC · Jul 23, 2020Malware42
PlugX malware delivered by exploiting flaws in Chinese programsSecurity Affairs·Mar 11, 19:40 UTC · Mar 11, 2023Malware42
North Korea-linked Lazarus APT uses first Mac malware in cryptocurrency exchange attackSecurity Affairs·Aug 24, 15:17 UTC · Aug 24, 2018Malware42
New Tomiris tools and techniques: multiple reverse shells, Havoc, AdaptixC2Kaspersky Securelist·Nov 28, 07:00 UTC · Nov 28, 2025Malware142
Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX MalwareThe Hacker News·Mar 10, 06:46 UTC · Mar 10, 2023Malware42
Prometei botnet improves modules and exhibits new capabilities in recent updatesCisco Talos·Mar 9, 13:02 UTC · Mar 9, 2023MalwareCVE-2019-0708147
Prilex: Brazilian PoS malware evolutionKaspersky Securelist·Sep 29, 12:56 UTC · Sep 29, 2022Malware42
Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese TargetsPalo Alto Unit 42·Nov 1, 09:41 UTC · Nov 1, 2018Malware42
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News·Jul 28, 11:55 UTC · Jul 28, 2026Malware42
YiSpecter: First iOS Malware That Attacks Non-jailbroken Apple iOS Devices by Abusing Private APIsPalo Alto Unit 42·Jul 3, 00:01 UTC · Jul 3, 2020Malware30
Researchers Uncover RAT-Dropping npm Package Targeting Gulp UsersThe Hacker News·Jun 4, 06:13 UTC · Jun 4, 2024Malware42