Malware
Curated coverage and analysis in this editorial area.

Lorem Ipsum Pivots to ClickFix After Fox Tempest Takedown
BlueVoyant reports the Lorem Ipsum malware abandoned signed Microsoft Teams installers for ClickFix tactics on compromised WordPress s…

DragonForce Weaponizes Microsoft Teams TURN Relays for Stealth C2
The DragonForce ransomware group deployed Backdoor.Turn, the first documented in-the-wild malware to abuse Microsoft Teams' legitimate…

SprySOCKS Returns to Windows: Kernel Rootkit and Government Targeting
ESET discovered Windows variants of the SprySOCKS backdoor—previously Linux-only—equipped with a kernel rootkit and used against gover…

C0XMO: Gafgyt Variant Targets DD-WRT Routers with Modular Scanner and Competitor-Killing Routine
The C0XMO variant of the Gafgyt botnet exploits CVE-2021-27137 in DD-WRT firmware, utilizing a modular architecture with a standalone…

TA4922 Targets Europe with New Atlas RAT and AI-Assisted Malware Development
Proofpoint tracks the European expansion of TA4922, a Chinese-speaking cybercrime group deploying the new Atlas RAT, RomulusLoader, an…

JINX-0164: Potential macOS Malware Campaigns Targeting Crypto Developers via LinkedIn
Threat actor JINX-0164 may be targeting cryptocurrency developers through LinkedIn social engineering, potentially utilizing the AUDIO…

BTMOB: The Malware-as-a-Service Erasing Technical Barriers to Android Takeover
ESET researchers have detailed BTMOB, an Android RAT sold as a service featuring a no-code builder. For a $5,000 lifetime fee, even lo…

NGate Malware Trojanizes HandyPay App to Steal Contactless PINs in Brazil
ESET Research has uncovered a new NGate variant that trojanizes the legitimate HandyPay Android app to relay NFC data and intercept PI…

18 Malicious AI Extensions Exposed: Unit 42 Details Email Spying and RAT Risks
Palo Alto Networks Unit 42 has uncovered 18 AI browser extensions that masquerade as productivity tools while deploying RATs and spyin…

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere
Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…