Malware
Curated coverage and analysis in this editorial area.

Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection
SentinelOne researchers have documented Gaslight, a previously unknown Rust-based macOS implant that embeds a prompt-injection payload…

Edgecution: Malicious Edge Extension Bypasses Sandbox via Native Messaging
Zscaler ThreatLabz documents a campaign where the Edgecution extension abuses Chrome's Native Messaging API to escape the browser sand…

Linux Process Masquerading Tricks ps and top
On Linux, malicious processes mask their name and command line by abusing prctl and argv memory overwrites. Standard tools like ps and…

Mistic: KongTuke's In-Memory Backdoor Challenges EDR Defenses
Operational since April 2026, the stealthy Mistic backdoor leverages DLL sideloading and in-memory BOF execution for long-term persist…

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries
Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

The Fake kworker: How APTs Masquerade Linux Processes
Ps and top become unreliable: APTs overwrite argv[0] and use prctl to impersonate kworker. eBPF tools like Kunai detect the real binar…

ClickFix macOS: When Users Bypass Gatekeeper Themselves
Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

OXLOADER: Malicious Google Ads Deliver Infostealer
Elastic Security Labs uncovers OXLOADER, a previously undocumented Windows loader distributed via malicious Google Ads impersonating N…

WhatsApp Weaponized: VBS and RMM Delivered via DMs from Compromised Contacts
An active campaign since June 2026 uses WhatsApp Desktop to distribute malicious VBScript files, install legitimate RMM software, and…

CSIS Secures First Threat-Reduction Warrant to Disinfect Domestic Botnet
Canada's spy agency obtains the first judicial warrant for active cyber threat-reduction operations on infected routers and IoT device…

Malware on Steam Workshop: Malicious Wallpapers Steal Accounts
Dozens of malicious wallpapers on Steam Workshop have racked up thousands of downloads. Kaspersky analysis reveals DarkKomet backdoor,…

AryStinger Botnet Compromises Over 4,000 End-of-Life D-Link Routers Worldwide
Qianxin XLab researchers have uncovered AryStinger, a previously undocumented botnet that has hijacked more than 4,000 obsolete D-Link…