Tag: Malware Campaign

Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
News

Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

Details of a Windows-based cryptocurrency clipper operation that has been targeting victims since February 2026 with clipboard-intercepting malware that may distribute itself and conceal communication over the Tor anonymity network have been revealed by Microsoft. According to a research released on Tuesday by the Microsoft Defender Security Research Team, the clipper in this campaign uses Windows Script Host and ActiveX-driven logic to start a packaged Tor proxy and poll a hidden-service C2 [command-and-control] server. It does wallet-address substitution, screenshot exfiltration, and high-frequency clipboard stealing. This clipper's execution is noteworthy because it doesn't rely on exposed IP-based C2 infrastructure or a conventional installation. Rather, it turns a financially m...
New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack
News

New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack

Cybersecurity experts have revealed information on a new campaign called SHADOW#REACTOR, which uses an evasive multi-stage attack chain to create persistent, covert remote access and deliver Remcos RAT, a commercial remote administration tool. According to a technical report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, the infection chain follows a carefully planned execution path: an obfuscated VBS launcher run via wscript.exe triggers a PowerShell downloader, which retrieves fragmented, text-based payloads from a remote host. A.NET Reactor-protected assembly reconstructs these pieces into encoded loaders, decodes them in memory, and uses them to retrieve and apply a distant Remcos configuration. The Remcos RAT backdoor i...
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
News

Hacker arrested for KMSAuto malware campaign with 2.8 million downloads

A Lithuanian national has been detained on suspicion of using the KMSAuto tool to unlawfully activate Windows and Office applications in order to infect 2.8 million devices with clipboard-stealing malware. After a corresponding request was coordinated by Interpol, the 29-year-old male was extradited from Georgia to South Korea. The Korean National Police Agency claims that the suspect used KMSAuto to trick victims into downloading "clipper malware," a malicious application that searched the clipboard for bitcoin addresses and substituted them with ones under the attacker's control. The Korean National Police Agency claims that the suspect infected the KMSAuto tool, which looked for bitcoin addresses in clipboard contents and altered the destination address read more about Hacker ...
APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign
News

APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign

A threat actor with ties to Pakistan has been seen launching spear-phishing operations against Indian government organizations in an attempt to spread DeskRAT, a Golang-based malware. Sekoia saw the activity in August and September of 2025, and it has been linked to Transparent Tribe (also known as APT36), a state-sponsored hacker collective that has been active since at least 2013. Additionally, it expands on a previous campaign that CYFIRMA revealed in August 2025. Phishing emails with a ZIP file attachment or, occasionally, a link to an archive stored on reputable cloud services like Google Drive are part of the attack chains. The ZIP package contains malicious desktop file embedding commands that, when run alongside the main payload, cause Mozilla Firefox to display a phony PDF ...
Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures
News

Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures

The Noodlophile malware's threat actors are using spear-phishing emails and new delivery methods to spread the information stealer in assaults against businesses in the Asia-Pacific (APAC), Europe, the Baltic states, and the United States. According to a report shared with The Hacker News, Morphisec researcher Shmuel Uzan stated that the Noodlophile campaign, which has been in operation for more than a year, now uses sophisticated spear-phishing emails that mimic copyright infringement notices and are customized with information gleaned from reconnaissance, such as particular Facebook Page IDs and company ownership details. The antivirus vendor previously described Noodlophile in May 2025, revealing that the attackers used phony artificial intelligence (AI)-powered gadgets as lures ...
ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections
News

ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections

According to new research from Guardio Labs, the social engineering approach known as ClickFix was able to gain the traction it did over the course of the last year by utilizing a combination of evasion strategies, narrative complexity, and propagation mechanisms. "This new 'ClickFix' strain swiftly outpaced and eventually eradicated the notorious fake browser update scam that afflicted the internet just last year," security researcher Shaked Chen stated in a study published with The Hacker News, similar to a real-world viral variation. It accomplished this by spreading via reliable infrastructure, eliminating the need for file downloads, and employing more clever social engineering techniques. The outcome was a surge of infections that included hyper-targeted spear-phishing lures a...
New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains
News

New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains

Cloudflare Tunnel subdomains are being used by a new campaign to host malicious payloads, which are then distributed through malicious attachments included in phishing emails. Securonix has given the ongoing campaign the codename SERPENTINE#CLOUD. "The Cloudflare Tunnel infrastructure and Python-based loaders are utilized to deliver memory-injected payloads through a chain of shortcut files and obfuscated scripts," according to a report that security researcher Tim Peck provided with The Hacker News. Phishing emails with an invoice or payment theme and a link to a zipped document containing a Windows shortcut (LNK) file are the first step in the attack. By posing as papers, these shortcuts deceive victims into opening them, so starting the infection chain. A Python-based shellcod...
Water Curse Employs 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign
News

Water Curse Employs 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign

Water Curse is a hitherto unidentified threat actor that uses weaponized GitHub repositories to spread multi-stage malware, according to cybersecurity analysts. According to an investigation released this week by Trend Micro researchers Jovit Samaniego, Aira Marcelo, Mohamed Fahmy, and Gabriel Nicoleta, the virus permits remote access, long-term persistence on compromised devices, and data exfiltration (including credentials, browser data, and session tokens). First discovered last month, the extensive and persistent campaign installed repositories that appeared to be harmless penetration testing tools but actually contained malicious payloads including Sakura-RAT and SMTP email bomber in their Visual Studio project configuration files. A variety of technologies and programming l...
Node.js Malware Campaign Targets Crypto Users with Fake Binance and TradingView Installers
News

Node.js Malware Campaign Targets Crypto Users with Fake Binance and TradingView Installers

Microsoft is drawing attention to a persistent malvertising effort that uses Node.js to distribute malicious payloads that can steal and exfiltrate data. The behavior, which was initially discovered in October 2024, involves luring users into installing a malicious installer from phony websites that pose as trustworthy applications, such as Binance or TradingView, using lures associated with bitcoin trading. A dynamic-link library ("CustomActions.dll") is included in the downloaded installer and is in charge of leveraging Windows Management Instrumentation (WMI) to gather basic system information and scheduling a job to establish persistence on the host. The DLL uses "msedge_proxy.exe" to open a browser window that shows the authentic cryptocurrency trading website in an effort t...
Malware campaign ‘DollyWay’ breached 20,000 WordPress sites
News

Malware campaign ‘DollyWay’ breached 20,000 WordPress sites

Since 2016, a malware operation known as "DollyWay" has more than 20,000 WordPress websites worldwide in order to reroute users to malicious websites. Over the last eight years, the campaign has undergone tremendous change, utilizing sophisticated evasion, re-infection, and monetization techniques. In its most recent version (v3), DollyWay has been operating as a widespread scam redirection system, according to GoDaddy researcher Denis Sinegubko. It has, however, previously disseminated more dangerous payloads, such as banking trojans and ransomware. According to a recent study by Godaddy, GoDaddy Security researchers have found evidence that connects several malware attacks into a single read more about Malware campaign 'DollyWay' breached 20000 WordPress sites.