Malware
Curated coverage and analysis in this editorial area.

CVE-2026-48558: Djinn Stealer Exploited In-the-Wild on SimpleHelp
Threat actors exploit CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver. The new infostealer targets AI and cloud credentials. Rou…

Gamaredon 2025: 35 Spear-Phishing Campaigns and 6 PowerShell Tools Target Ukraine
The Gamaredon APT group, attributed by Ukraine's SSU to the FSB's 18th Center for Information Security, launched 35 distinct spear-phi…

Microsoft Removes 119 Edge Extensions Hiding Malware in Images and Fonts
Microsoft purged 119 Edge extensions that concealed StegoAd malware inside PNG, WebP, and WOFF2 font files, reaching a combined instal…

Amadey/StealC: 27M Credentials Recovered, $47M in Crypto Seized
Operation Endgame dismantled two malware-as-a-service networks. Here's why the RICO legal theory changes the game and what it means fo…

SBU and FBI Expose Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts
Ukraine's SBU and the FBI disclosed a long-running Russian operation that uses morning-timed SMS phishing to steal verification codes…

Masquerading Linux: When ps Lies and eBPF Exposes the Truth
A SANS ISC post demonstrates how prctl and argv overwriting make ps and top unreliable on Linux, and why only eBPF tools like Kunai ca…

Miasma: The Malware Turning npm Into a Developer Trap
Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

SharkLoader: The Malware That Bypasses Loader Lock to Hide Cobalt Strike
Kaspersky has identified SharkLoader, a new loader that exploits Perfect DLL Hijacking to bypass Windows Loader Lock and deploy Cobalt…

CL-STA-1062: From Taiwanese Web Hosting to Power Plants with TinyRCT Backdoor
Unit 42 reveals CL-STA-1062's escalation: from web hosting to state energy infrastructure in Southeast Asia with a custom .NET backdoo…

Turla's STOCKSTAY Backdoor Has Targeted Ukraine Since 2022
Google Threat Intelligence Group disclosed STOCKSTAY, a multi-component backdoor from the Turla APT active since December 2022 against…

Burnyard: Local Malware Analysis Beats Cloud on Speed, But Accuracy Remains Unverified
Ohio State University's Burnyard project challenges VirusTotal and Sophos Intelix with user-space emulation on local hardware, deliver…

ThreatsDay June 2026: Miasma Toolkit Leaked, Claude Code Patched, AI Agent Phishing
The June 2026 ThreatsDay Bulletin, published June 11 by Rescana, is an aggregated cyber threat digest. This analysis relies primarily…