Malware
Curated coverage and analysis in this editorial area.

Security Vendor Jscrambler Becomes Supply-Chain Vector: 5 Malicious npm Versions
Threat actors compromised Jscrambler's npm publishing credentials and released five malicious versions of the jscrambler package conta…

RedHook RAT: Android Malware Gains Shell Access Without Root or PC
The RedHook trojan upgrades its arsenal by abusing Wireless ADB, Shizuku, and Accessibility Service to obtain shell privileges on non-…

The Gentlemen Climbs RaaS Rankings: 90% Payout and 580 Victims in One Year
The Gentlemen, tracked as Storm-2697, has become the second most active RaaS operation of 2026 with over 6x growth and a 90% affiliate…

GodDamn Ransomware Uses Microsoft-Signed Driver to Disable EDR
The GodDamn ransomware, a rebrand of the Hyadina family, leverages the PoisonX driver — signed with a valid Microsoft Windows Hardware…

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

Operation Muck and Load: 222 GitHub Repositories Weaponized to Distribute Windows Malware
A threat actor built a network of 222 GitHub repositories across 190 accounts to distribute Windows malware via malicious Go modules.…

GigaWiper: The Post-Compromise Malware Masking Three Destructive Intents
GigaWiper is a modular Go backdoor that unifies wiper, fake ransomware, and spyware capabilities. Linked to BLUERABBIT, the platform c…

AI-Generated Malware Maps Active Directory: How It Was Caught
On June 3, 2026, Huntress detected an attack using an AI-generated PowerShell script created via vibe coding. Behavioral detection suc…

Hyadina Strikes with GodDamn: Microsoft-Signed Driver Disables EDR in 24 Hours
The Hyadina ransomware-as-a-service group deploys a new locker, GodDamn, using the Microsoft-signed PoisonX kernel driver to neutraliz…

Verified X Ads Spread Mac Malware and Steal Microsoft 365 Accounts
Active campaigns exploit X's blue verification badge to distribute Mac malware via ClickFix and steal Microsoft 365 OAuth tokens using…

HalluSquatting Turns AI Assistants' Predictable Hallucinations into a Botnet Installation Vector
Researchers from Tel Aviv University, Technion, and Intuit demonstrated that nine AI coding tools install botnet malware when asked fo…

Malicious AI Skills: 3,000 Evade Scanning, Enterprises Exposed
ESET detected over 3,000 malicious skills among nearly 900,000 analyzed. The SkillCloak technique bypasses static scanners in more tha…