LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT companyKaspersky Securelist·Sep 10, 10:00 UTC · Sep 10, 2018Malware30
LuckyMouse APT has been using a digitally signed network filtering driverSecurity Affairs·Sep 10, 18:59 UTC · Sep 10, 2018Malware42
UAT-10027 campaign hits U.S. education and healthcare with stealthy Dohdoor backdoorSecurity Affairs·Feb 26, 19:11 UTC · Feb 26, 2026Malware42
FatalRAT Phishing Attacks Target APAC Industries Using Chinese Cloud ServicesThe Hacker News·Mar 5, 08:58 UTC · Mar 5, 2025Malware42
Experts warn of a new stealthy loader tracked as BLISTERSecurity Affairs·Dec 24, 10:26 UTC · Dec 24, 2021Malware30
Hackers Target Middle East Governments with Evasive "CR4T" BackdoorThe Hacker News·Apr 19, 06:16 UTC · Apr 19, 2024Malware42
Latin American Javali trojan weaponizing Avira antivirus legitimate injector to implant malwareSecurity Affairs·Feb 17, 07:39 UTC · Feb 17, 2021Malware30
Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military SystemsThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Malware42
Chinese Lotus Blossom APT targets multiple sectors with Sagerunex backdoorSecurity Affairs·Mar 6, 08:17 UTC · Mar 6, 2025Malware42
HollowFrame Loader Deploys Matryoshka Backdoor in SpearThe Hacker News·Jul 31, 16:39 UTC · Jul 31, 2026Malware42
New VPNFilter malware targets at least 500K networking devices worldwideCisco Talos·May 23, 13:00 UTC · May 23, 2018Malware55
GoSerpent backdoor attacks in Southeast AsiaKaspersky Securelist·Jul 17, 09:23 UTC · Jul 17, 2026Malware42
Miniduke is back: Nemesis Gemina and the Botgen StudioKaspersky Securelist·Jul 3, 08:46 UTC · Jul 3, 2014Malware42
SkillSpector: NVIDIA's open-source security scanner for AI agent skillsHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2026Malware55
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RATThe Hacker News·Jun 2, 09:05 UTC · Jun 2, 2026Malware30
New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain PersistenceInfosecurity Magazine·Oct 16, 16:00 UTC · Oct 16, 2025MalwareCVE-2025-20352CVE-2017-388147
China-Linked ValleyRAT Malware Resurfaces with Advanced Data Theft TacticsThe Hacker News·Jun 11, 08:47 UTC · Jun 11, 2024MalwareCVE-2017-0199CVE-2017-1188235
Pakistan-linked hackers targeted Indian power company with ReverseRatThe Hacker News·Jun 24, 06:26 UTC · Jun 24, 2021Malware42
CosmicStrand: the discovery of a sophisticated UEFI firmware rootkitKaspersky Securelist·Jul 25, 10:00 UTC · Jul 25, 2022Malware42
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malwareHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2026Malware130
Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and PersistenceSecurity Affairs·May 9, 13:11 UTC · May 9, 2026Malware42
Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 TrafficThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Malware55
UNC2565 threat actors continue to improve the GOOTLOADER malwareSecurity Affairs·Jan 30, 05:48 UTC · Jan 30, 2023Malware42
Attackers abuse ConnectWise ScreenConnect to drop AsyncRATSecurity Affairs·Sep 11, 09:32 UTC · Sep 11, 2025Malware30
Threat Spotlight: PoSeidon, A Deep Dive Into Point of Sale MalwareCisco Talos·Mar 20, 11:57 UTC · Mar 20, 2015Malware30
HollowFrame Loader Uses Fake Python DLL to Evade DefenderInfosecurity Magazine·Aug 3, 11:26 UTC · Aug 3, 2026Malware42
STX RAT Targets Finance Sector With Advanced Stealth TacticsInfosecurity Magazine·Apr 9, 15:00 UTC · Apr 9, 2026Malware30
New "Raptor Train" IoT Botnet Compromises Over 200,000 Devices WorldwideThe Hacker News·Sep 19, 06:35 UTC · Sep 19, 2024Malware in the wild57
Threat actors target law firms with GootLoader and SocGholishSecurity Affairs·Mar 2, 08:53 UTC · Mar 2, 2023Malware42
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutesHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2026Malware30
New PS1Bot Malware Campaign Uses Malvertising to Deploy Multi-Stage InThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Malware42
Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in 'Zero Disco' AttacksThe Hacker News·Oct 17, 04:35 UTC · Oct 17, 2025MalwareCVE-2025-20352CVE-2017-388160
Muhstik Botnet Exploiting Apache RocketMQ Flaw to Expand DDoS AttacksThe Hacker News·Jun 8, 17:28 UTC · Jun 8, 2024MalwareCVE-2023-3324660
Thousands of Linux systems infected by stealthy malware since 2021Ars Technica · Security·Oct 3, 23:42 UTC · Oct 3, 2024MalwareCVE-2023-33246CVE-2021-404347
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareThe Hacker News·Aug 1, 06:29 UTC · Aug 1, 2026Malware30
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 TrafficThe Hacker News·Jul 10, 13:45 UTC · Jul 10, 2026Malware30