A deeper insight into the CloudWizard APT's activity revealed a longSecurity Affairs·May 23, 09:46 UTC · May 23, 2023Malware42
Iranian State-Sponsored OilRig Group Deploys 3 New Malware DownloadersThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Malware142
Analysis of the CloudWizard APT frameworkKaspersky Securelist·May 19, 10:30 UTC · May 19, 2023Malware42
APT28 relies on PowerPoint Mouseover to deliver Graphite malwareSecurity Affairs·Sep 28, 13:47 UTC · Sep 28, 2022Malware42
AI platform n8n abused for stealthy phishing and malware deliverySecurity Affairs·Apr 16, 13:57 UTC · Apr 16, 2026Malware42
Earth Kurma Targets Southeast Asia With Rootkits and CloudThe Hacker News·Apr 29, 03:34 UTC · Apr 29, 2025Malware42
New Go-based Backdoor GoGra Targets South Asian Media OrganizationThe Hacker News·Aug 7, 11:50 UTC · Aug 7, 2024Malware42
Russian APT BlueBravo targets diplomatic entities with GraphicalProton backdoorSecurity Affairs·Jul 28, 22:15 UTC · Jul 28, 2023Malware42
Chinese Hacker Group 'Flea' Targets American Ministries with Graphican BackdoorThe Hacker News·Jun 21, 11:29 UTC · Jun 21, 2023Malware42
Bad magic: new APT found in the area of RussoKaspersky Securelist·Mar 21, 08:00 UTC · Mar 21, 2023Malware42
Researchers Uncover Custom Backdoors and Spying Tools Used by Polonium HackersThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2022Malware42
POLONIUM targets Israel with a new backdoor dubbed PapaCreepSecurity Affairs·Oct 13, 10:14 UTC · Oct 13, 2022Malware42
HollowFrame Loader Uses Fake Python DLL to Evade DefenderInfosecurity Magazine·Aug 3, 11:26 UTC · Aug 3, 2026Malware42
ScarCruft Uses Zoho WorkDrive and USB Malware to Breach AirThe Hacker News·Feb 27, 12:43 UTC · Feb 27, 2026Malware42
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage MalwareThe Hacker News·Dec 20, 12:12 UTC · Dec 20, 2025Malware42
Over 80,000 Microsoft Entra ID Accounts Targeted Using OpenThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025Malware42
CeranaKeeper Emerges as New Threat to Thai Government NetworksInfosecurity Magazine·Oct 3, 16:30 UTC · Oct 3, 2024Malware42
China-Linked CeranaKeeper Targeting Southeast Asia with Data ExfiltrationThe Hacker News·Oct 2, 15:21 UTC · Oct 2, 2024Malware42
Chinese Daggerfly uses a new version of Macma macOS backdoorSecurity Affairs·Jul 24, 10:09 UTC · Jul 24, 2024MalwareCVE-2021-3086947
Chinese Espionage Group Upgrades Malware to Target All Major OSInfosecurity Magazine·Jul 23, 16:00 UTC · Jul 23, 2024Malware42
Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware CommunicationsThe Hacker News·May 4, 08:18 UTC · May 4, 2024Malware142
BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic EntitiesThe Hacker News·Jul 29, 04:06 UTC · Jul 29, 2023Malware42
NAPLISTENER: New Malware in REF2924 Group's Arsenal for Bypassing DetectionThe Hacker News·Mar 22, 09:25 UTC · Mar 22, 2023Malware42
New Bad Magic APT used CommonMagic framework in the area of RussoSecurity Affairs·Mar 21, 21:49 UTC · Mar 21, 2023Malware42
Report: Lebanon-based hacking group attacked Israeli targets with custom backdoorsThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Malware42
Hackers Using PowerPoint Mouseover Trick to Infect Systems with MalwareThe Hacker News·Oct 2, 05:18 UTC · Oct 2, 2022MalwareCVE-2021-40444147
Microsoft took down 18 Azure AD apps used by Chinese Gadolinium APTSecurity Affairs·Sep 27, 09:28 UTC · Sep 27, 2020Malware42
Even With The Best Email Spoofing Defences in The World, HMRC is SpoofedSecurity Affairs·Oct 17, 07:27 UTC · Oct 17, 2017Malware42
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050The Hacker News·Jul 20, 14:33 UTC · Jul 20, 2026Malware42
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for EspionageThe Hacker News·Jul 17, 08:46 UTC · Jul 17, 2026Malware42
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python InfostealerThe Hacker News·Jul 1, 10:25 UTC · Jul 1, 2026Malware142
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike BeaconKaspersky Securelist·Jun 24, 14:23 UTC · Jun 24, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs47
145 Mastra npm Packages Compromised via Hijacked Contributor AccountThe Hacker News·Jun 22, 05:41 UTC · Jun 22, 2026Malware42
Fake Gemini and Claude Code Sites Spread InfostealersInfosecurity Magazine·May 22, 11:30 UTC · May 22, 2026Malware42
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph APIThe Hacker News·May 21, 10:41 UTC · May 21, 2026Malware142
Webworm APT targets European government organizations with new backdoorsHelp Net Security·May 20, 00:00 UTC · May 20, 2026Malware142
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian MilitaryThe Hacker News·Mar 10, 14:28 UTC · Mar 10, 2026Malware42