T9000: Advanced Modular Backdoor Uses Complex AntiPalo Alto Unit 42·Nov 1, 10:04 UTC · Nov 1, 2018MalwareCVE-2012-1856CVE-2015-164160
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike BeaconKaspersky Securelist·Jun 24, 14:23 UTC · Jun 24, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs47
Kaspersky analysis of the backdoor in XZKaspersky Securelist·Apr 12, 08:00 UTC · Apr 12, 2024Malware42
TimbreStealer campaign targets Mexican users with financial luresCisco Talos·Feb 27, 13:00 UTC · Feb 27, 2024Malware30
New Malware with Ties to SunOrcal DiscoveredPalo Alto Unit 42·Nov 1, 10:57 UTC · Nov 1, 2018Malware130
How RainyDay, Turian and a new PlugX variant abuse DLL search order hijackingCisco Talos·Sep 23, 18:00 UTC · Sep 23, 2025Malware42
Experts analyzed how Ursnif evolves to keep threatening ItalySecurity Affairs·Jun 11, 13:48 UTC · Jun 11, 2019Malware30
OctLurk and SilkLurk: new Backdoors in Central AsiaKaspersky Securelist·Jul 31, 09:44 UTC · Jul 31, 2026Malware42
Analyzing the Various Layers of AgentTesla’s PackingPalo Alto Unit 42·Sep 25, 17:00 UTC · Sep 25, 2017Malware30
OysterLoader Evolves With New C2 Infrastructure and ObfuscationInfosecurity Magazine·Feb 16, 16:15 UTC · Feb 16, 2026Malware42
Android Malware Konfety evolves with ZIP manipulation and dynamic loadingSecurity Affairs·Jul 15, 17:18 UTC · Jul 15, 2025Malware30
Outlaw botnet detected in an incident contained by KasperskyKaspersky Securelist·Apr 29, 10:00 UTC · Apr 29, 2025Malware42
How Kaspersky obtained all stages of Operation TriangulationKaspersky Securelist·Oct 26, 10:30 UTC · Oct 26, 2023Malware30
Threat Spotlight: AsyncRAT campaigns feature new version of 3LOSH crypterCisco Talos·Apr 5, 12:00 UTC · Apr 5, 2022Malware30
StegBaus: Because Sometimes XOR Just Isn’t EnoughPalo Alto Unit 42·Jan 28, 20:35 UTC · Jan 28, 2022Malware30
Looking for sophisticated malware in IoT devicesKaspersky Securelist·Sep 23, 10:00 UTC · Sep 23, 2020Malware in the wild57
COMpfun authors spoof visa application with HTTP statusKaspersky Securelist·May 14, 10:00 UTC · May 14, 2020Malware42
Downeks and Quasar RAT Used in Recent Targeted Attacks Against GovernmentsPalo Alto Unit 42·Nov 1, 10:43 UTC · Nov 1, 2018Malware30
FIN7 Group Uses JavaScript and Stealer DLL Variant in New AttacksCisco Talos·Sep 27, 17:38 UTC · Sep 27, 2017Malware30
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksThe Hacker News·Jun 27, 12:06 UTC · Jun 27, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs60
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPIKaspersky Securelist·May 5, 14:33 UTC · May 5, 2026Malware42
UAT-9244 targets South American telecommunication providers with three new malware implantsCisco Talos·Mar 5, 11:00 UTC · Mar 5, 2026Malware55
Keenadu the tablet conqueror and the links between major Android botnetsKaspersky Securelist·Feb 17, 09:00 UTC · Feb 17, 2026Malware55
Eagerbee backdoor targets govt entities and ISPs in Middle EastSecurity Affairs·Jan 7, 06:23 UTC · Jan 7, 2025MalwareCVE-2021-2685547
GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update AttacksRecorded Future·Jul 4, 00:00 UTC · Jul 4, 2024Malware55
Docker Honeypot Reveals Cryptojacking as Most Common Cloud ThreatPalo Alto Unit 42·Jun 6, 12:40 UTC · Jun 6, 2024Malware30
Lazarus targets blockchain engineers with new KandyKorn macOS MalwareSecurity Affairs·Nov 5, 12:14 UTC · Nov 5, 2023Malware42
Signed MSI files, Raccoon and Amadey are used for installing ServHelper RATCisco Talos·Aug 12, 12:00 UTC · Aug 12, 2021Malware42
Raindrop, a fourth malware employed in SolarWinds attacksSecurity Affairs·Jan 19, 22:31 UTC · Jan 19, 2021Malware42
Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU MediaPalo Alto Unit 42·Nov 1, 09:52 UTC · Nov 1, 2018MalwareCVE-2012-015835
“Red October”. Detailed Malware Description 4. Second Stage of AttackKaspersky Securelist·Jan 17, 16:06 UTC · Jan 17, 2013Malware42
Botnet Shutdown Success Story – again: Disabling the new Hlux/Kelihos BotnetKaspersky Securelist·Mar 28, 17:27 UTC · Mar 28, 2012Malware30