Threat Research

    ClickLock Stealer is a newly discovered macOS malware that likely spreads through ClickFix phishing pages using compromised WordPress sites and Telegram infrastructure. It steals browser credentials, macOS Keychain data, password manager information, cryptocurrency wallet data, FTP credentials, and shell history, while using a modified GSocket backdoor for persistence....
    Security Labs identified a new Contagious Interview campaign, tracked as REF9403, that hides malware inside SVG image files using steganography. The infection chain appears to be previously undocumented. The campaign was uncovered after a DPRK-linked threat actor targeted the team's Slack workspace with a fake job posting and a malicious coding challenge....
    Researchers uncovered Spirals, a previously unseen Rust-based ransomware that compromised an IT services company in South Asia, progressing from initial access to data theft and network-wide encryption in less than 24 hours....
    UAT-11795 is a Russian-speaking, financially motivated threat actor targeting users primarily in the United States, with additional victims observed in Germany, Romania, and Venezuela....
    Since late March 2026, researchers have observed large-scale phishing campaigns that use fileless techniques and Lua-based loaders with low detection rates to deliver malware such as Agent Tesla, Remcos, XWorm, and Best Private LOGGER. The attackers impersonate well-known companies and pose as potential business partners to trick victims into opening malicious files....
    This campaign highlights the continued evolution of phishing attacks through the use of malicious VHDX images, DLL sideloading, in-memory shellcode execution, and layered anti-analysis techniques to evade traditional detection....
    Threat actors compromised multiple AsyncAPI npm packages by injecting a malicious import-time loader that executed automatically when affected packages were imported, bypassing mitigations such as npm install --ignore-scripts....
    Researchers analyzed TelePuz, a modular Malware-as-a-Service (MaaS) framework distributed through ClickFix social engineering campaigns that trick users into executing malicious commands. The malware employs a multi-stage infection chain with obfuscated loaders, dynamic payload delivery, and anti-analysis techniques to deploy additional malware modules....
    In January 2026, multiple attacks were detected using unknown malware to steal cryptocurrency wallet data. Investigators reconstructed a complex, four-stage infection chain linked to a malicious PowerShell script. This campaign stands out by using a new framework to deliver and orchestrate all malicious modules....
    Scammers are selling fake Celine Dion Paris concert tickets across social media. They exploit Ticketmaster’s official transfer feature to resell the same tickets indefinitely. Fraudsters are creating lookalike websites that mimic legitimate ticket distributors. These fake sites abuse Shopify’s payment infrastructure via a recycled scam kit....
    Researchers identified an infostealer infection led to the theft of WordPress credentials, enabling attackers to launch a sophisticated ClickFix campaign. The attack leveraged EtherHiding, PowerShell, DLL sideloading, and in-memory execution to deploy a multi-stage RAT....
    A suspected China-linked threat actor used the TencShell backdoor alongside Claude Code and DeepSeek-v4-pro to automate cyberespionage operations targeting government and financial systems....
    Our investigation began with a malicious Go module masquerading as a DNS/subdomain scanner. The module exposed a Windows malware chain using hidden PowerShell and dead-drop resolution. Pivoting revealed a larger GitHub lure network of 222 repositories across 190 accounts. We track this campaign as "Operation Muck and Load" based on its infrastructure and behavior....
    Threat actors compromised legitimate WordPress websites to inject ClickFix JavaScript that delivers malware to unsuspecting visitors. Rather than hardcoding command-and-control infrastructure, the script dynamically retrieves its configuration from a Polygon blockchain smart contract, allowing attackers to rotate infrastructure without modifying compromised sites....
    Researchers identified a malicious NuGet supply-chain campaign using Braintree.Net, a typosquat of the legitimate Braintree payment SDK. The package silently intercepts live payment-card data, steals Braintree merchant API credentials, and harvests environment, configuration, and cloud-related secrets while allowing normal payment operations to continue....
    Looking for Something?
    Threat Research Categories:
    Tags