Malware
Curated coverage and analysis in this editorial area.

Amadey/StealC: 27M Credentials Recovered, $47M in Crypto Seized
Operation Endgame dismantled two malware-as-a-service networks. Here's why the RICO legal theory changes the game and what it means fo…

Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection
SentinelOne researchers have documented Gaslight, a previously unknown Rust-based macOS implant that embeds a prompt-injection payload…

Edgecution: Malicious Edge Extension Bypasses Sandbox via Native Messaging
Zscaler ThreatLabz documents a campaign where the Edgecution extension abuses Chrome's Native Messaging API to escape the browser sand…

Mistic: KongTuke's In-Memory Backdoor Challenges EDR Defenses
Operational since April 2026, the stealthy Mistic backdoor leverages DLL sideloading and in-memory BOF execution for long-term persist…

ClickFix macOS: When Users Bypass Gatekeeper Themselves
Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

OXLOADER: Malicious Google Ads Deliver Infostealer
Elastic Security Labs uncovers OXLOADER, a previously undocumented Windows loader distributed via malicious Google Ads impersonating N…

WhatsApp Weaponized: VBS and RMM Delivered via DMs from Compromised Contacts
An active campaign since June 2026 uses WhatsApp Desktop to distribute malicious VBScript files, install legitimate RMM software, and…

Malware on Steam Workshop: Malicious Wallpapers Steal Accounts
Dozens of malicious wallpapers on Steam Workshop have racked up thousands of downloads. Kaspersky analysis reveals DarkKomet backdoor,…

Operation Endgame Dismantles SocGholish: Nearly 15,000 Sites Cleaned
On June 18, 2026, the international Operation Endgame coalition took down 106 servers and domains linked to SocGholish and cleaned 14,…

CryptoBandits: The USB Clipper-Worm That Adds RCE via Tor
Microsoft disclosed an active Windows clipper malware campaign running since February 2026 that uses malicious LNK files distributed v…

Rust Crypto Clipper Campaign Weaponizes Fake Reputation on VirusTotal and GitHub
A threat actor distributed a Rust-based crypto clipper for Windows and macOS by fabricating trust signals across GitHub, SourceForge,…

Rokarolla: The Android Trojan That Turns Your Phone Into a Digital Prison
Discovered by Zimperium zLabs, the Rokarolla trojan deploys 137 commands and fake overlays to isolate victims, steal banking credentia…