Malware
Curated coverage and analysis in this editorial area.

HalluSquatting Turns AI Assistants' Predictable Hallucinations into a Botnet Installation Vector
Researchers from Tel Aviv University, Technion, and Intuit demonstrated that nine AI coding tools install botnet malware when asked fo…

Malicious AI Skills: 3,000 Evade Scanning, Enterprises Exposed
ESET detected over 3,000 malicious skills among nearly 900,000 analyzed. The SkillCloak technique bypasses static scanners in more tha…

RedWing: Android Banking Malware Turns into a Telegram Rental Service
Zimperium zLabs uncovered RedWing, a Malware-as-a-Service platform that commercializes Android banking fraud with Telegram bots and su…

CAI Worm Kills Rival Cloud Malware, Steals Credentials
The CAI cloud-native worm eliminates TeamPCP and PCPJack processes to monopolize compromised hosts, marking an escalation in criminal…

UAT-7810 Expands ORB Network: New LONGLEASH, DOGLEASH, and JARLEASH Backdoors
Cisco Talos reveals the China-nexus APT UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network with new malwar…

Vishing 2.0 Hits Teams: Fake IT Support Calls Deploy EtherRAT
Palo Alto Networks Unit 42 uncovered a campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support and trick…

Cavern: The .NET Framework That Challenges Analysts With Three Distinct Compilation Formats
Check Point Research has unveiled Cavern, a modular .NET C2 framework used by the Iranian threat actor Cavern Manticore. The framework…

Armored Likho Targets Governments and Power Operators with BusySnake Stealer
The Armored Likho APT group, uncovered by Kaspersky, is conducting cyber-espionage and financially motivated attacks against governmen…

The Gentlemen: Go Backdoor and BYOVD in New RaaS That Spies on EDR
Kaspersky analyzes The Gentlemen, a ransomware-as-a-service group active since early 2026. Custom Go backdoor with persistent C2, five…

Researcher Documents Real-Time Shared Access Between FortiBleed Operator and INC Ransom, Lynx Panels for First Time
SOCRadar documented that an operator with access to the FortiBleed infrastructure was simultaneously logged into the negotiation panel…

Avalon: The Malware Framework Merging AI and Multi-Evasion to Strike
The Avalon framework combines credential harvesting, multi-EDR evasion, and the CrownX ransomware into a single attack chain. Blackpoi…

BusySnake Stealer: The APT That Generates Malware With AI
Armored Likho uses LLMs to write first-stage payloads and PyArmor Pro to obfuscate them. Kaspersky's report reveals an infostealer tar…