New malware works only in memory, leaves no traceCyberScoop·Feb 9, 23:29 UTC · Feb 9, 2017Malware in the wild60
Experts spotted a new stealthy Linux malware dubbed ShikitegaSecurity Affairs·Mar 26, 23:11 UTC · Mar 26, 2026MalwareCVE-2021-4034CVE-2021-349335
NSA Exploit EternalBlue is becoming even common in hacking tools and malwareSecurity Affairs·Oct 24, 21:08 UTC · Oct 24, 2017Malware42
Banks around the world hit with fileless malwareHelp Net Security·May 28, 10:00 UTC · May 28, 2020Malware30
Duqu Malware Techniques Used by CybercriminalsSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Malware55
TrickBot developers have spun up a new backdoor for highCyberScoop·Jan 9, 20:14 UTC · Jan 9, 2020Malware in the wild60
Hackers Planted Backdoor in Webmin, Popular Utility for Linux/Unix ServersThe Hacker News·Aug 20, 09:00 UTC · Aug 20, 2019MalwareCVE-2019-1510760
Gallmaker APT group eschews malware in cyber espionage campaignsSecurity Affairs·Oct 11, 06:25 UTC · Oct 11, 2018Malware42
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During InstallThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Malware30
Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malwareSecurity Affairs·Apr 18, 15:20 UTC · Apr 18, 2026MalwareCVE-2025-2639947
Google uncovers malware using LLMs to operate and evade detectionHelp Net Security·Nov 5, 00:00 UTC · Nov 5, 2025Malware142
Flax Typhoon APT exploited ArcGIS server for over a year as a backdoorSecurity Affairs·Oct 15, 07:11 UTC · Oct 15, 2025Malware55
Iranian Hackers Deploy New Android Spyware VersionInfosecurity Magazine·Jul 21, 17:30 UTC · Jul 21, 2025Malware42
TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware CampaignsThe Hacker News·Jul 3, 09:00 UTC · Jul 3, 2025Malware55
New LightSpy spyware variant comes with enhanced data collection features targeting social media platformsSecurity Affairs·Feb 26, 09:49 UTC · Feb 26, 2025MalwareCVE-2018-4233CVE-2018-440435
New LightSpy spyware version targets iPhonesSecurity Affairs·Nov 1, 19:51 UTC · Nov 1, 2024MalwareCVE-2018-4233CVE-2018-4404CVE-2020-9802+1 CVEs35
New APT CloudSorcerer Malware Hits Russian TargetsInfosecurity Magazine·Jul 8, 17:00 UTC · Jul 8, 2024Malware142
ExCobalt Cyber Gang Targets Russian Sectors with New GoRed BackdoorThe Hacker News·Jun 23, 18:07 UTC · Jun 23, 2024MalwareCVE-2019-13272CVE-2021-3156CVE-2021-4034+1 CVEs47
LightSpy Spyware's macOS Variant Found with Advanced Surveillance CapabilitiesThe Hacker News·Jun 10, 04:34 UTC · Jun 10, 2024MalwareCVE-2018-4233CVE-2018-440435
Experts found a macOS version of the sophisticated LightSpy spywareSecurity Affairs·May 30, 18:36 UTC · May 30, 2024MalwareCVE-2018-4233CVE-2018-440460
Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing MalwareInfosecurity Magazine·Nov 22, 17:00 UTC · Nov 22, 2023Malware in the wildCVE-2023-46604CVE-2023-491160
North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance MalwareThe Hacker News·May 24, 06:59 UTC · May 24, 2023Malware42
Tomiris called, they want their Turla malware backKaspersky Securelist·Apr 26, 07:40 UTC · Apr 26, 2023Malware42
CobaltSpam tool can flood Cobalt Strike malware serversThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Malware42
Hackers Sign Android Malware Apps with Compromised Platform CertificatesThe Hacker News·Dec 2, 13:56 UTC · Dec 2, 2022Malware30
New Stealthy Shikitega Malware Targeting Linux Systems and IoT DevicesThe Hacker News·Sep 8, 06:00 UTC · Sep 8, 2022MalwareCVE-2021-4034CVE-2021-349347
Researchers Detail Evasive DarkTortilla Crypter Used to Deliver MalwareThe Hacker News·Aug 19, 04:55 UTC · Aug 19, 2022Malware42
Manjusaka: A Chinese sibling of Sliver and Cobalt StrikeCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2022Malware55
Researchers Disclose Undocumented Chinese Malware Used in Recent AttacksThe Hacker News·Jan 22, 10:21 UTC · Jan 22, 2021Malware42
New release of Lampion trojan spreads in Portugal with some improvements on the VBS downloaderSecurity Affairs·Jul 7, 20:09 UTC · Jul 7, 2020Malware in the wild157
TrickBot gangs developed the PowerTrick backdoor for highSecurity Affairs·Jan 9, 19:36 UTC · Jan 9, 2020Malware42
Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet CampaignsPalo Alto Unit 42·Mar 8, 18:14 UTC · Mar 8, 2019MalwareCVE-2018-10561CVE-2018-1562CVE-2018-10562+2 CVEs47
Threat actors using FrameworkPOS malware in POS attacksSecurity Affairs·Mar 4, 07:40 UTC · Mar 4, 2019Malware42
Multi-exploit IoT/Linux Botnets Mirai and Gafgyt Target Apache Struts, SonicWallPalo Alto Unit 42·Sep 17, 09:02 UTC · Sep 17, 2018MalwareCVE-2018-9866CVE-2017-5638CVE-2017-17215+1 CVEs47
LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT companyKaspersky Securelist·Sep 10, 10:00 UTC · Sep 10, 2018Malware30
Who planted the Juniper ScreenOS Backdoor?Security Affairs·Feb 14, 09:51 UTC · Feb 14, 2018MalwareCVE-2015-7755CVE-2015-775647