Threat Research

    DarkMe malware was observed in two separate incidents targeting different organizations on August 31, 2026. DarkMe is a VB6-based spy-RAT previously linked to the financially motivated Water Hydra and Operation DarkCasino. The samples were identified through their command set, VB6 loader chain, and a modified RC4 routine that produces a single-byte XOR payload....
    Researcher details a malicious Firefox extension masquerading as a PDF identity-verification utility that fetches its malicious payload only after installation to evade detection. The extension targets Google accounts, injecting an account-takeover script into legitimate accounts.google.com pages to automate authentication flows and capture Google OAuth session cookies....
    RemControl is a previously undocumented Android banking trojan targeting retail banking customers across Western Europe, the Middle East, and Canada. It abuses Android Accessibility Services to display fake banking overlays, capture PINs and keystrokes, stream screens, and provide attackers with full remote control....
    The team identified an active campaign where threat actors hide indirect prompt injection payloads within legitimate-looking advertiser landing pages to manipulate AI-based ad review systems. At least 10 domains have been identified, with AI-generated, unique, and convincing content that allows attackers to quickly create and abandon domains....
    PolinRider campaign, which compromises GitHub developer accounts and repositories to spread malware through software development workflows and package ecosystems. The campaign uses (Supply Chain Attack) Git history rewriting, malicious configuration files, VS Code auto-execution, payload concealment, and EtherHiding/NullReceiver for staged C2 delivery....
    CSuite is a multi-stage phishing and remote-access operation targeting organizations across the US and Europe, with 60% of identified victims based in the US. Attackers use trusted lures such as Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 voicemail to steal credentials and hijack Microsoft 365 sessions through device-code authentication....
    In April 2026, a threat actor compromised a Middle Eastern manufacturing organization and gained domain administrator-level control of its Active Directory environment. The attacker created a malicious Group Policy Object (GPO) named PAYLOAD and linked it to the domain root to affect all domain-joined Windows systems....
    AsyncRAT uses a multi-stage malware delivery mechanism in which the AutoIT component serves as the initial loader, while PowerShell facilitates execution of the subsequent stage. The final AsyncRAT payload provides attackers with remote access, including system information collection, command execution, Stealing, Screen Capture, and C2 communication....
    BigBear 2.0 is a rebranded Evilginx2-based Phishing-as-a-Service (PhaaS) framework targeting Microsoft 365 accounts and using AiTM phishing, automated cookie replay, residential proxies, and Telegram-based credential exfiltration to bypass MFA....
    P2PInfect activity targeting internet-exposed and exploiting misconfigured Redis instances, with attackers abusing Redis replication and module-loading capabilities to achieve remote code execution. The campaign exploits CVE-2022-0543 and deploys ELF-based malware, establishes reverse shells, and uses mechanisms such as cron jobs and SSH authorized keys for persistence....
    Torrent trackers are frequently abused to distribute malware disguised as popular movies, games, and pirated software. Attackers use cracked software and malicious installers to infect large numbers of users. During the analysis, researchers discovered a new modular, multi-stage malware framework called MovieReaper....
    Chinese threat actors UTA0560 and JungleBamboo (APT31) exploited a Chrome patch-gap vulnerability, CVE-2026-85046, in targeted spear-phishing campaigns against NGOs. The exploit chain combined CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (V8 sandbox escape), and CVE-2026-85880 (Windows kernel LPE) to escape browser and OS security boundaries....
    SideCopy has expanded its cyber operations beyond its traditional focus on government officials and high-ranking personnel to include academic institutions. The group typically uses spear-phishing campaigns to gain initial access and deliver malicious payloads....
    HEAVYGRAM is a Windows backdoor attributed with moderate confidence to Handala Hack, used since 2023 to target Iranian dissidents, journalists, and individuals opposing the Iranian government....
    Researcher details SparroWocky, a modular C++ backdoor deployed by the China-aligned FamousSparrow APT against governmental organizations across Latin America. The malware uses DLL sideloading, RC4-encrypted payloads, reflective code loading,...
    Looking for Something?
    Threat Research Categories:
    Tags