Malware
Curated coverage and analysis in this editorial area.

Interpol Ransomware: Small Businesses Targeted via Social Engineering
Threat actors are impersonating Interpol in a ransomware campaign hitting small businesses across pharmaceutical, food, agriculture, t…

ToddyCat's Umbrij Malware Steals Gmail OAuth Tokens by Abusing Enterprise Browsers
The Umbrij malware automates OAuth 2.0 token theft via the Chrome DevTools Protocol, bypassing passwords and MFA on corporate Gmail ac…

FortiBleed, the Missing Link: From 430,000 Targeted Firewalls to INC and Lynx Ransomware
SOCRadar ties the FortiBleed credential theft campaign to the INC and Lynx ransomware groups, revealing a single operator managing bot…

ChocoPoC RAT: How Fake PoCs on PyPI Infected Vulnerability Researchers
ChocoPoC, a Python RAT, spreads via GitHub repositories posing as proof-of-concept exploits that hide the payload in transitive PyPI d…

VEIL#DROP: How Blogger Became an Infostealer Armorer
Securonix uncovers VEIL#DROP, a multi-stage malware chain that weaponizes Google Blogger to deliver the PureLogs Stealer filelessly, b…

AI-Generated Ransomware Attacks via Browser: No Payload, Just Chrome Permissions
Check Point analyzed a DeepSeek-generated sample that encrypts local files by abusing Chrome's File System Access API. No exploit, no…

ClickFix Evolves Into a Platform: Analysis of 3,000 Payloads Reveals API-Driven Delivery
A researcher analyzed 3,000 live ClickFix payloads, uncovering an API-driven architecture, rotating cryptographic wrappers, and adopti…

ScreenConnect Abused to Deliver AsyncRAT via 90+ Spoofed Freeware Domains
Kaspersky MDR uncovered a large-scale campaign that weaponizes the legitimate remote-access tool ScreenConnect to deploy AsyncRAT thro…

RustDuck: The IoT Botnet Rewritten in Rust Challenges Researchers
QiAnXin XLab has tracked RustDuck since February 2026: a two-stage malware rewritten in Rust with enterprise-grade encryption and anti…

Langflow RCE Exploited for Miner Worm: 19-Day Campaign
CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Health Card Phishing: €6.39 to Steal Your Identity
CERT-AGID exposes the funnel of an active phishing campaign impersonating the Italian Ministry of Health, using a fake mandatory healt…

Mustang Panda Turns Zoho WorkDrive Into Covert C2 Channel Against Indian Government
The Mustang Panda APT group ran two espionage campaigns in June 2026 targeting the Indian government and hydroelectric infrastructure,…