Targeted mobile implants in the age of cyberKaspersky Securelist·Jan 18, 10:57 UTC · Jan 18, 2016Malware30
New Zardoor backdoor used in long-term cyber espionage operation targeting an Islamic organizationCisco Talos·Feb 8, 14:10 UTC · Feb 8, 2024Malware42
MoonPeak malware from North Korean actors unveils new details on attacker infrastructureCisco Talos·Aug 21, 10:00 UTC · Aug 21, 2024Malware42
Tria stealer targets Android users for SMS exfiltration and financial gainKaspersky Securelist·Jan 30, 08:00 UTC · Jan 30, 2025Malware30
DeathStalker targets legal entities with new Janicab variantKaspersky Securelist·Dec 9, 09:30 UTC · Dec 9, 2022Malware30
Attack Campaign on the Government of Thailand Delivers Bookworm TrojanPalo Alto Unit 42·Nov 1, 09:57 UTC · Nov 1, 2018Malware30
GrayBravo’s CastleLoader Activity Clusters Target Multiple IndustriesRecorded Future·Oct 9, 00:00 UTC · Oct 9, 2025Malware30
SapphireStealer: Open-source information stealer enables credential and data theftCisco Talos·Aug 31, 12:00 UTC · Aug 31, 2023Malware42
Highlighting TA866/Asylum Ambuscade Activity Since 2021Cisco Talos·Oct 23, 10:02 UTC · Oct 23, 2024Malware42
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignCisco Talos·Jul 16, 10:00 UTC · Jul 16, 2026Malware30
Operation Gamework: Infrastructure Overlaps Found Between BlueAlpha and Iranian APTsRecorded Future·Jul 31, 00:00 UTC · Jul 31, 2025Malware42
Malware report for Q3 2024: threat overviewKaspersky Securelist·Nov 29, 10:45 UTC · Nov 29, 2024Malware42
Uncovering Hidden Malware with No Distribute ScannersRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Malware30
EtherRAT Distribution Spoofing Administrative Tools via GitHub FacadesThe Hacker News·Jun 7, 15:47 UTC · Jun 7, 2026Malware155
Common TTPs of attacks against industrial organizationsKaspersky Securelist·Aug 10, 08:00 UTC · Aug 10, 2023Malware42
Kaspersky report on APT trends in Q1 2024Kaspersky Securelist·May 7, 13:19 UTC · May 7, 2024Malware42
Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor OperationsThe Hacker News·Jan 19, 06:53 UTC · Jan 19, 2026Malware30
Threat actors exploit Ivanti VPN bugs to deploy KrustyLoader MalwareSecurity Affairs·Jan 31, 11:45 UTC · Jan 31, 2024MalwareCVE-2023-46805CVE-2024-2188760
Public report on attacks in Middle East we attribute to WIRTE APTKaspersky Securelist·Nov 29, 08:00 UTC · Nov 29, 2021Malware42
TwoFace Webshell: Persistent Access Point for Lateral MovementPalo Alto Unit 42·Nov 1, 10:54 UTC · Nov 1, 2018Malware30
Threat actor abuses Gophish to deliver new PowerRAT and DCRATCisco Talos·Oct 22, 10:00 UTC · Oct 22, 2024Malware30
Suspected CoralRaider continues to expand victimology using three information stealersCisco Talos·Apr 23, 12:42 UTC · Apr 23, 2024Malware30
High-profile malware and targeted attacks in Q1 2023Kaspersky Securelist·Jun 7, 08:00 UTC · Jun 7, 2023Malware42
Threat actors use copyright infringement phishing lure to deploy infostealersCisco Talos·Oct 31, 13:37 UTC · Oct 31, 2024Malware30
Chinese threat actors use Quad7 botnet in passwordSecurity Affairs·Nov 3, 10:09 UTC · Nov 3, 2024Malware42
Threat actors use Quantum Builder to deliver Agent Tesla malwareSecurity Affairs·Sep 28, 15:43 UTC · Sep 28, 2022Malware42
Dissecting UAT-8099: New persistence mechanisms and regional focusCisco Talos·Jan 29, 11:00 UTC · Jan 29, 2026Malware55
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential StealerThe Hacker News·May 31, 12:13 UTC · May 31, 2026MalwareCVE-2026-3561660
Hidden between the tags: Insights into spammers’ evasion techniques in HTML SmugglingCisco Talos·Jul 10, 12:00 UTC · Jul 10, 2024Malware42
Tusk campaign uses infostealers and clippers for financial gainKaspersky Securelist·Aug 15, 12:00 UTC · Aug 15, 2024Malware30
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
Bumblebee, a new loader used by multiple crimeware threat actorsSecurity Affairs·Apr 28, 14:49 UTC · Apr 28, 2022Malware42