DeepLoad Malware Employs ClickFix and WMI for Credential Theft

A new malware loader, DeepLoad, utilizes social engineering and advanced evasion techniques to steal browser credentials and maintain persistence on infected systems.

A new malware loader, DeepLoad, utilizes social engineering and advanced evasion techniques to steal browser credentials and maintain persistence on infected systems.

A recent email campaign attributed to the Russian threat group TA446 has leveraged the DarkSword exploit kit to target iOS devices, raising concerns about the evolving landscape of mobile security threats.

A recent supply chain attack on Trivy has led to the distribution of malicious Docker images, impacting developer environments and exposing sensitive data.

Microsoft has reported a significant phishing campaign exploiting the U.S. tax season, affecting approximately 29,000 users across various industries.

A new malware named Speagle has been identified, which hijacks the Cobra DocGuard software to extract sensitive data from infected systems.

A malicious npm package posing as an OpenClaw installer has been identified, capable of deploying a remote access trojan (RAT) and stealing sensitive data from macOS systems.

A new multi-stage malware campaign, dubbed VOID#GEIST, has been identified, utilizing batch scripts to deliver various remote access trojans, including XWorm, AsyncRAT, and Xeno RAT.

The hacking group Transparent Tribe has adopted AI tools to enhance its malware production, primarily targeting Indian government entities and private businesses.

Fake installers for the AI agent OpenClaw have emerged, delivering malware to unsuspecting users searching on Bing.

Microsoft has issued a warning regarding ongoing OAuth abuse scams that exploit phishing tactics to deliver malware, particularly targeting government and public-sector organizations.