Malware
Curated coverage and analysis in this editorial area.

OctagonPanel Spyware Hides Behind Fake Bahrain Civil Defense Alert App
A counterfeit "BH Alert" app impersonating Bahrain's civil defense system delivers the OctagonPanel surveillance malware via a four-st…

RedHook RAT: Android Malware Gains Shell Access Without Root or PC
The RedHook trojan upgrades its arsenal by abusing Wireless ADB, Shizuku, and Accessibility Service to obtain shell privileges on non-…

Operation Muck and Load: 222 GitHub Repositories Weaponized to Distribute Windows Malware
A threat actor built a network of 222 GitHub repositories across 190 accounts to distribute Windows malware via malicious Go modules.…

GigaWiper: The Post-Compromise Malware Masking Three Destructive Intents
GigaWiper is a modular Go backdoor that unifies wiper, fake ransomware, and spyware capabilities. Linked to BLUERABBIT, the platform c…

RedWing: Android Banking Malware Turns into a Telegram Rental Service
Zimperium zLabs uncovered RedWing, a Malware-as-a-Service platform that commercializes Android banking fraud with Telegram bots and su…

CAI Worm Kills Rival Cloud Malware, Steals Credentials
The CAI cloud-native worm eliminates TeamPCP and PCPJack processes to monopolize compromised hosts, marking an escalation in criminal…

Avalon: The Malware Framework Merging AI and Multi-Evasion to Strike
The Avalon framework combines credential harvesting, multi-EDR evasion, and the CrownX ransomware into a single attack chain. Blackpoi…

BusySnake Stealer: The APT That Generates Malware With AI
Armored Likho uses LLMs to write first-stage payloads and PyArmor Pro to obfuscate them. Kaspersky's report reveals an infostealer tar…

ToddyCat's Umbrij Malware Steals Gmail OAuth Tokens by Abusing Enterprise Browsers
The Umbrij malware automates OAuth 2.0 token theft via the Chrome DevTools Protocol, bypassing passwords and MFA on corporate Gmail ac…

ClickFix Evolves Into a Platform: Analysis of 3,000 Payloads Reveals API-Driven Delivery
A researcher analyzed 3,000 live ClickFix payloads, uncovering an API-driven architecture, rotating cryptographic wrappers, and adopti…

ScreenConnect Abused to Deliver AsyncRAT via 90+ Spoofed Freeware Domains
Kaspersky MDR uncovered a large-scale campaign that weaponizes the legitimate remote-access tool ScreenConnect to deploy AsyncRAT thro…

RustDuck: The IoT Botnet Rewritten in Rust Challenges Researchers
QiAnXin XLab has tracked RustDuck since February 2026: a two-stage malware rewritten in Rust with enterprise-grade encryption and anti…