Analysis of the CloudWizard APT frameworkKaspersky Securelist·May 19, 10:30 UTC · May 19, 2023Malware42
NullMixer drops Redline Stealer, SmokeLoader and other malwareKaspersky Securelist·Sep 26, 08:00 UTC · Sep 26, 2022Malware42
Operation AppleJeus: Lazarus hits cryptocurrency exchange with fake installer and macOS malwareKaspersky Securelist·Aug 23, 08:00 UTC · Aug 23, 2018Malware42
PipeMagic in 2025: How the backdoor operators’ tactics have changedKaspersky Securelist·Aug 18, 09:00 UTC · Aug 18, 2025MalwareCVE-2025-29824CVE-2017-014447
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2Infosecurity Magazine·Jul 20, 12:30 UTC · Jul 20, 2026Malware142
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux SystemsThe Hacker News·Sep 10, 13:04 UTC · Sep 10, 2025Malware142
LuminousMoth APT: Sweeping attacks for the chosen fewKaspersky Securelist·Jul 14, 10:00 UTC · Jul 14, 2021Malware42
AI-Generated Malware Powers New Armored Likho APT CampaignSecurity Affairs·Jul 7, 08:28 UTC · Jul 7, 2026Malware42
GhostContainer backdoor for Exchange serversKaspersky Securelist·Jul 17, 08:00 UTC · Jul 17, 2025MalwareCVE-2020-068847
OilRig Group Steps Up Attacks with New Delivery Documents and New Injector TrojanPalo Alto Unit 42·Dec 17, 08:59 UTC · Dec 17, 2018MalwareCVE-2017-019947
The HoneyMyte APT now protects malware with a kernelKaspersky Securelist·Dec 29, 11:28 UTC · Dec 29, 2025Malware42
SockDetour – a Silent, Fileless, Socketless BackdoorPalo Alto Unit 42·Jun 5, 23:28 UTC · Jun 5, 2024MalwareCVE-2021-40539CVE-2021-44077CVE-2021-2879947
Recent InPage Exploits Lead to Multiple Malware FamiliesPalo Alto Unit 42·Nov 1, 10:56 UTC · Nov 1, 2018Malware42
New Dohdoor malware campaign targets education and health careCisco Talos·Feb 26, 11:00 UTC · Feb 26, 2026Malware42
Experts discovered a SYSCON Backdoor using FTP Server as C&CSecurity Affairs·Oct 5, 20:36 UTC · Oct 5, 2017Malware42
FlawedAmmyy Leveraging Undetected XLM Macros as an Infection VehicleSecurity Affairs·Mar 2, 18:46 UTC · Mar 2, 2019Malware in the wild157
Threat Actors Target Government of Belarus Using CMSTAR TrojanPalo Alto Unit 42·Nov 1, 10:55 UTC · Nov 1, 2018MalwareCVE-2015-164147
OctLurk and SilkLurk: new Backdoors in Central AsiaKaspersky Securelist·Jul 31, 09:44 UTC · Jul 31, 2026Malware42
“Red October”. Detailed Malware Description 2. Second Stage of AttackKaspersky Securelist·Jan 17, 16:08 UTC · Jan 17, 2013Malware42
Magnat malvertising campaigns spreads malicious Chrome extensions, backdoors and info stealersSecurity Affairs·Dec 6, 07:25 UTC · Dec 6, 2021Malware42
TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machinesCisco Talos·Sep 21, 12:11 UTC · Sep 21, 2021Malware42
Signed MSI files, Raccoon and Amadey are used for installing ServHelper RATCisco Talos·Aug 12, 12:00 UTC · Aug 12, 2021Malware42
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPIKaspersky Securelist·May 5, 14:33 UTC · May 5, 2026Malware42
Technical analysis of the QakBot banking TrojanKaspersky Securelist·Sep 2, 10:00 UTC · Sep 2, 2021Malware42
Hidden between the tags: Insights into spammers’ evasion techniques in HTML SmugglingCisco Talos·Jul 10, 12:00 UTC · Jul 10, 2024Malware42
Analysis of TAG-140 Campaign and DRAT V2 Development Targeting Indian Government OrganizationsRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Malware42
Kaspersky discovers C++ version of BellaCiao malwareKaspersky Securelist·Dec 19, 15:33 UTC · Dec 19, 2024Malware42
menuPass Returns with New Malware and New Attacks Against Japanese Academics and OrganizationsPalo Alto Unit 42·Nov 1, 10:44 UTC · Nov 1, 2018Malware42
Doki, an undetectable Linux backdoor targets Docker ServersSecurity Affairs·Jul 29, 12:21 UTC · Jul 29, 2020Malware142
Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling toolsKaspersky Securelist·Jul 28, 09:18 UTC · Jul 28, 2026Malware42
VPNFilter EXIF to C2 mechanism analysedKaspersky Securelist·May 24, 18:00 UTC · May 24, 2018Malware42