Malware
Curated coverage and analysis in this editorial area.

Prinz Eugen: The Ransomware That Encrypts the Newest Files First
Threatdown researchers have documented Prinz Eugen, a Go-based ransomware that prioritizes recently modified files, leaves no ransom n…

Microsoft Attributes Mastra Supply-Chain Attack to North Korean Sapphire Sleet
Microsoft assesses with high confidence that the supply-chain compromise of more than 140 @mastra npm packages was carried out by the…

GentleKiller: The EDR-Killer Framework Built Into the Gentlemen RaaS
The Gentlemen ransomware-as-a-service operation equips affiliates with GentleKiller, an in-house BYOVD framework spanning eight-plus v…

Crypto-Clipper: The Fake Reputation Economy Becomes a Weapon
Cybercriminals have weaponized stars, downloads, and reviews to distribute a Rust-based clipper across GitHub, YouTube, and even legit…

June 2026 ThreatsDay Bulletin: When Claude’s Shared Chat Becomes a Malware Vector
The June 2026 ThreatsDay Bulletin documents the abuse of Anthropic Claude’s shared chat feature to distribute the MacSync credential s…

Mackay Sugar Ransomware Attack Halts Mills, 1,300 Farms Frozen at Harvest Start
The Gentlemen ransomware group struck Australia's second-largest sugar producer on June 10, 2026, idling two of three mills and forcin…

Operation Endgame Dismantles SocGholish: Nearly 15,000 Sites Cleaned
On June 18, 2026, the international Operation Endgame coalition took down 106 servers and domains linked to SocGholish and cleaned 14,…

CryptoBandits: The USB Clipper-Worm That Adds RCE via Tor
Microsoft disclosed an active Windows clipper malware campaign running since February 2026 that uses malicious LNK files distributed v…

The 'robase' Malware Empties Entire Roblox Games: From Hat Theft to Digital Business Seizure
A malware campaign using the Python package 'robase' steals authenticated session tokens from Roblox developers via Discord social eng…

INC Ransomware: 800 Victims, Not a Single Zero-Day
INC ranks among the world's most active ransomware groups despite relying exclusively on known techniques. The Acronis report reveals…

Rust Crypto Clipper Campaign Weaponizes Fake Reputation on VirusTotal and GitHub
A threat actor distributed a Rust-based crypto clipper for Windows and macOS by fabricating trust signals across GitHub, SourceForge,…

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads
A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…