##malware
Malware uses HashHiding: hiding IPs and ports in Ethereum addresses. #BlockchainThreat #Ethereum #Malware #Security #HashHiding #CyberDefense thedailytechfeed.com/malware-uses...
September 29, 2026 at 2:18 PM
SilverFox clones software sites and uses signed launchers with malware—common apps masking hidden threats. #SecurityNews #ThreatIntelligence #Malware #SilverFox #WindowsSecurity thedailytechfeed.com/silverfox-ma...
September 29, 2026 at 1:46 PM
The Carbonato Botnet: Orchestrating Post-Compromise Chaos with AI Agents

Analysis of the Carbonato botnet, which exploits exposed Docker daemons to deploy the Hermes AI framework for autonomous credential theft and host control.

#Malware #Docker

Read more →
The Carbonato Botnet: Orchestrating Post-Compromise Chaos with AI Agents
Analysis of the Carbonato botnet, which exploits exposed Docker daemons to deploy the Hermes AI framework for autonomous credential theft and host control.
calmvibez.com
September 29, 2026 at 12:55 PM
@huntress.com
Attackers abuse ChatGPT Custom GPTs and Google Sites to deliver a RAT via PowerShell and DLL sideloading.
-
IOCs: 96[.]62[.]224[.]81, chatgpt[.]com, sites[.]google[.]com
-
#ClickFix #Malware #ThreatIntel
Custom GPT ClickFix RAT
www.huntress.com
September 29, 2026 at 12:50 PM
~Anyrun~
CSuite, N0va, Wazza, TerminalFix and IronToll used session theft, remote access, evasive phishing and payment fraud against US/EU targets.
-
IOCs: CSuite, N0va, IronToll
-
#Malware #Phishing #ThreatIntel
September Cyberattacks Target Identity and Payments
any.run
September 29, 2026 at 12:39 PM
Microsoft found NeedyMantis in targeted attacks on organizations, but hasn’t confirmed whether it’s still in use.

The DAEMON Tools Lite installer ta…

https://en.hacks.gr/tilepikoinonies-panepistimia-kai-foreis-ygeias-sto-stochastro-epitheseon-me-needymantis/

#NeedyMantis #DAEMONToolsLite #Malware
September 29, 2026 at 10:47 AM
AgtaBackup RAT hijacks Windows via fake Store pages and RMM abuse for credential theft and hidden SYSTEM-access. #AgtaBackup #RAT #WindowsSecurity #Malware #RMM #CyberThreat https://thedailytechfeed.com/agtabackup-rat-masquerades-as-microsoft-store-to-hijack-windows-systems/
September 29, 2026 at 10:44 AM
⚠️ ALERTA DE SEGURIDAD en el #Gaming : Análisis del Incidente de #Malware en #Steam ("Beyond The Dark") (+DETALLES) www.newstecnicas.com/2026/05/aler...
⚠️ ALERTA DE SEGURIDAD en el Gaming : Análisis del Incidente de Malware en Steam ("Beyond The Dark") (+DETALLES)
¿Instalaste Beyond The Dark en Steam? Aprende cómo detectar este malware en tu PC, auditar tus archivos y proteger tus billeteras tras el hackeo
www.newstecnicas.com
September 29, 2026 at 10:33 AM
BotHelper RAT spies live on users’ screens and evades antivirus with encrypted payloads. #Security #Malware #RAT #BotHelper #Cybersecurity #Windows https://thedailytechfeed.com/bothelper-rat-windows-malware-that-watches-you-in-real-time/
September 29, 2026 at 9:16 AM
特別定額給付金を装ったAndroidマルウェア
hxxps://gzmingan.com/transtioncash/
hxxps://jzqixing.com/transtioncash/
www.virustotal.com/gui/file/4cc...
#Phishing #フィッシング詐欺 #malware
September 29, 2026 at 8:28 AM
📰 Apple Perbaiki Zero-Day CoreGraphics yang Dieksploitasi dalam Serangan Bertarget

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/29/apple-perbaiki-coregraphics-zero-day-cve-2026-20700/

#apple #cybersecurity #ipad #iphone #keamanan #macos #malware #zero-day
September 29, 2026 at 7:41 AM
nebulaai-sdk v1.0.0 (npm) is CRITICAL: Installs a RAT on Windows, opening C2 access with user privileges. Remove the package & conhost.exe if installed. Monitor for suspicious connections. https://radar.offseq.com/threat/malicious-code-in-nebulaai-sdk-npm-cf83f4133db4c1ba #OffSeq #npm #malware
Malicious code in nebulaai-sdk (npm)
The nebulaai-sdk npm package version 1.0.0 includes a preinstall script that decodes a base64 and zlib compressed 257 KB Windows PE executable. Upon npm install on Windows, this executable is written to %LOCALAPPDATA%\Microsoft\Conhost\conh
radar.offseq.com
September 29, 2026 at 6:00 AM
The latest update for #Cyberint includes "SalatStealer #Malware: Inside a Credential Stealer Built for Repeat Use" and "MovieReaper Malware: From Movie Download to Malware Infection".

#Cybersecurity #ThreatActors #ThreatIntelligence https://opsmtrs.com/33G8R11
Cyberint
Best-in-class managed intelligence suite. We help you identify emerging threats, verify your security posture, and respond effectively to reduce their impact.
opsmtrs.com
September 29, 2026 at 4:26 AM
hxxps://puwaiosd.com/transtioncash/
hxxps://tver.gopuwas.com/transtioncash/
hxxps://tver.gouwas.com/transtioncash/
hxxps://wuaiosdsad.com/transtioncash/
hxxps://wusdhiads.com/transtioncash/
#Phishing #フィッシング詐欺 #malware
September 28, 2026 at 11:22 PM
特別定額給付金を装ったAndroidマルウェア
hxxps://hasoadwaznqps.com/transtioncash/
hxxps://hhmjjdfwzx.com/transtioncash/
hxxps://poiwaldsas.com/transtioncash/
hxxps://posidwaksd.com/transtioncash/
www.virustotal.com/gui/file/7c7...
#Phishing #フィッシング詐欺 #malware
September 28, 2026 at 11:22 PM
e-Taxを装ったAndroidマルウェア
hxxps://worldprimenew-jp.com/
www.virustotal.com/gui/file/1f6...
#Phishing #フィッシング詐欺 #malware
September 28, 2026 at 11:15 PM
A new ransomware strain named 'Altair' has been discovered targeting Windows. It uses a double-extortion model, exfiltrates data, and leverages WMI for stealth. Victims are given a 72-hour deadline. #Ransomware #Altair #CyberSecurity #Malware

🌐 cyber[.]netsecops[.]io
New
Security firm CYFIRMA has identified a new double-extortion ransomware strain called Altair that targets Windows systems and uses WMI for stealthy...
cyber.netsecops.io
September 28, 2026 at 10:34 PM
231589 malicious packages caught and counting. Every one was read statically, never executed.

#supplychain #malware
PkgRadar coverage
What we're seeing across the ecosystems, from our own scan data.
pkgradar.com
September 28, 2026 at 8:25 PM
📈 Our week: 67 malicious packages flagged across the ecosystems, npm the hottest, typically 0 days before the advisory landed.

#malware #supplychainsecurity #opensource
This week in supply-chain malware
PkgRadar's live view of malicious-package activity across nine ecosystems.
pkgradar.com
September 28, 2026 at 8:25 PM
⏱ 2 days of lead time on npm eslint-plugin-skywagon-web@100.0.0: we flagged it, then MAL-2026-17215 confirmed it.

#flaggedfirst #npm #malware #supplychainsecurity
Flagged first: npm eslint-plugin-skywagon-web@100.0.0
PkgRadar flagged this 2 days before MAL-2026-17215 was published. See the dated receipt and static evidence.
pkgradar.com
September 28, 2026 at 8:24 PM