There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware FamiliesPalo Alto Unit 42·Jun 5, 20:23 UTC · Jun 5, 2024Malware42
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike BeaconKaspersky Securelist·Jun 24, 14:23 UTC · Jun 24, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs47
OpenAI Assistants API Exploited in 'SesameOp' BackdoorInfosecurity Magazine·Nov 4, 15:00 UTC · Nov 4, 2025Malware42
Experts spotted a Skype backdoor for Mac, it could be a coding bugSecurity Affairs·Dec 14, 15:29 UTC · Dec 14, 2016Malware42
Microsoft Detects "SesameOp" Backdoor Using OpenAI's API as a Stealth Command ChannelThe Hacker News·Nov 4, 14:16 UTC · Nov 4, 2025Malware42
SesameOp: New backdoor exploits OpenAI API for covert C2Security Affairs·Nov 4, 17:06 UTC · Nov 4, 2025Malware42
Compromised Cloud Compute Credentials: Case Studies From the WildPalo Alto Unit 42·Jun 5, 17:10 UTC · Jun 5, 2024Malware42
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google APIThe Hacker News·Jul 2, 15:49 UTC · Jul 2, 2026Malware42
Microsoft Sues Hacking Group Exploiting Azure AI for Harmful Content CreationThe Hacker News·Jan 11, 07:54 UTC · Jan 11, 2025Malware42
Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware CommunicationsThe Hacker News·May 4, 08:18 UTC · May 4, 2024Malware142
Crooks exploit exposed Docker APIs to build AESDDoS botnetSecurity Affairs·Jun 15, 22:27 UTC · Jun 15, 2019MalwareCVE-2019-5736147
Microsoft Graph API misused by new GoGra Linux malware for hidden communicationSecurity Affairs·Apr 25, 22:00 UTC · Apr 25, 2026Malware142
Dero miner spreads inside containerized Linux environmentsKaspersky Securelist·May 21, 10:00 UTC · May 21, 2025Malware42
Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User AccountsThe Hacker News·May 20, 05:49 UTC · May 20, 2025Malware142
New Cryptojacking Attack Targets Docker API to Create Malicious Swarm BotnetThe Hacker News·Oct 1, 06:22 UTC · Oct 1, 2024Malware142
Iranian State-Sponsored OilRig Group Deploys 3 New Malware DownloadersThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Malware142
Mobile Malware Evolution: An Overview, Part 1Kaspersky Securelist·Sep 29, 13:09 UTC · Sep 29, 2006Malware42
F5 Distributed Cloud Services improves modern application securityHelp Net Security·Feb 16, 00:00 UTC · Feb 16, 2022Malware42
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API TokensThe Hacker News·Feb 23, 10:20 UTC · Feb 23, 2026Malware142
NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows SystemsThe Hacker News·Dec 12, 13:12 UTC · Dec 12, 2025Malware142
FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and LinuxThe Hacker News·Feb 28, 04:32 UTC · Feb 28, 2025Malware142
Python Malware Poses DDoS Threat Via Docker API MisconfigurationInfosecurity Magazine·Nov 13, 16:30 UTC · Nov 13, 2023Malware142
TeamTNT botnet now steals Docker API and AWS credentialsSecurity Affairs·Jan 10, 10:22 UTC · Jan 10, 2021Malware142
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPIKaspersky Securelist·May 5, 14:33 UTC · May 5, 2026Malware42
Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux SystemsThe Hacker News·Apr 19, 15:13 UTC · Apr 19, 2025Malware42
CloudSorcerer APT uses cloud services and GitHub as C2Kaspersky Securelist·Jul 8, 07:00 UTC · Jul 8, 2024Malware142
CRAT wants to plunder your endpointsCisco Talos·Nov 12, 13:18 UTC · Nov 12, 2020MalwareCVE-2017-829147
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph APIThe Hacker News·May 21, 10:41 UTC · May 21, 2026Malware142
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph APIThe Hacker News·Apr 22, 15:28 UTC · Apr 22, 2026Malware142
New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions GloballyThe Hacker News·Jun 9, 16:37 UTC · Jun 9, 2025Malware42
New Golang-Based Backdoor Uses Telegram Bot API for Evasive C2 OperationsThe Hacker News·Feb 17, 09:04 UTC · Feb 17, 2025Malware42
TeleRAT, a new Android Trojan that uses Telegram for data exfiltrationSecurity Affairs·Mar 22, 08:52 UTC · Mar 22, 2018Malware42
Week in review: PowerPoint malware delivery, dark web fraud guides, security through APIsHelp Net Security·Jun 11, 00:00 UTC · Jun 11, 2017Malware42
PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and LinuxThe Hacker News·May 7, 09:20 UTC · May 7, 2026Malware42
GoPix banking Trojan targeting Brazilian financial institutionsKaspersky Securelist·Mar 16, 09:36 UTC · Mar 16, 2026Malware42
Elastic detects stealthy NANOREMOTE malware using Google Drive as C2Security Affairs·Dec 12, 11:11 UTC · Dec 12, 2025Malware42
Arid Viper disguising mobile spyware as updates for nonCisco Talos·Oct 31, 11:00 UTC · Oct 31, 2023Malware42