Malware
Curated coverage and analysis in this editorial area.

HollowGraph: APT Malware Turns M365 Calendars into Covert C2 Channel
HollowGraph exploits the Microsoft Graph API to transform compromised account calendars into bidirectional command-and-control channel…

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams
Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

Android Malware in Car Head Units: Vehicles Become Gig-Economy Nodes
Kaspersky discovered in June 2026 a new Android malware family that infects DoFun automotive head units through their built-in TWCore…

Lumma Stealer Hides in Pirated 'The Odyssey' Downloads: The Hidden Extension Trick
Cybercriminals are distributing Lumma Stealer via Windows executables disguised as pirated copies of The Odyssey (2026) on torrent tra…

Mustang Panda Arms CoolClient with Signed Rootkit: EDR in the Kernel Crosshairs
HoneyMyte deploys msagent.sys, a kernel-mode rootkit driver signed with an expired 2013 certificate. It hides processes, files, and C2…

AmnesiaStealer: The macOS Malware That Hijacks Victim Browser Sessions in Real Time
Jamf Threat Labs has documented AmnesiaStealer, a Rust-based macOS infostealer that clones the victim's Chromium profile, launches it…

WindRelay Turns Android Phones into NFC Relays to Drain Contactless Cards
Group-IB discovered WindRelay, Android malware that captures and relays contactless payment card NFC data in real time during social-e…

Pirated 'The Odyssey' Downloads Hide Lumma Stealer: Windows Users Tricked by Fake Video Files
Cybercriminals are recycling a proven attack pattern to distribute Lumma Stealer through fake pirated copies of Christopher Nolan's Th…

VoidLink: The Cloud-Native Malware Turning Linux into an Attack SaaS
Check Point Research discovered VoidLink in December 2025, a cloud-native Linux malware framework written in Zig with 30-plus plugins,…

QLNX: The Linux RAT Targeting Software Supply Chain Keys
Trend Micro discovered QLNX, a previously undocumented Linux RAT that combines a dual-tier rootkit, PAM backdoor, and P2P network to s…

SourTrade: The Browser Becomes an In-Memory Malware Factory
The SourTrade malvertising campaign assembles malware directly in the victim's browser memory using legitimate web APIs. The technique…

BRICKSTORM: Chinese Backdoor Targets US and Canadian Critical Infrastructure
CISA, NSA, and the Canadian Centre for Cyber Security disclosed BRICKSTORM, Chinese state-sponsored malware with 17-month persistence…