Tag: Backdoor

node-ipc npm Package Compromised With Credential Stealer

Malicious node-ipc versions 9.1.6, 9.2.3, and 12.0.1 were published to npm with…

Stephanie Adlam

cPanel CVE-2026-41940 Exploited to Drop Filemanager Backdoor

Attackers are exploiting cPanel & WHM CVE-2026-41940 to deploy a Filemanager backdoor,…

Stephanie Adlam

PamDOORa Linux PAM Backdoor Turns SSH Login Into a Trap

PamDOORa is a Linux PAM-based backdoor marketed for persistent OpenSSH access and…

Stephanie Adlam

Is JDownloader Safe?

JDownloader says attackers changed several official website download links on May 6-7,…

Stephanie Adlam

QLNX RAT Targets Linux Developer and Cloud Credentials

Trend Micro reports QLNX, a Linux-focused Quasar RAT variant that combines persistence,…

Stephanie Adlam

PyPI ZiChatBot Packages Linked to Suspected OceanLotus Campaign

Kaspersky reports a suspected OceanLotus campaign that used malicious PyPI packages to…

Stephanie Adlam

Fake Claude AI Malware: SectopRAT and Beagle

Fake Claude downloads can lead to SectopRAT or Beagle malware. Check the…

Brendan Smith

Backdoor:Win64/RogueDaemon.LTSN!MTB: DAEMON Tools Alert and Cleanup

Backdoor:Win64/RogueDaemon.LTSN!MTB is a Microsoft Defender alert linked by users to the DAEMON…

Brendan Smith

FakeUpdate Campaign Spreads WarmCookie Virus in France

FakeUpdate, a campaign of fake browser updates that pops up during regular…

Stephanie Adlam

Trojan:Win32/LsassDump.A: False Positive or Credential Dump?

Defender found LSASS dumping behavior? Check false positive risk, clean persistence, and…

Brendan Smith

Trojan:Win32/Malgent: Remove !MSR/!MTB or False Positive?

Defender found Trojan:Win32/Malgent or a Malgent suffix such as !MSR or !MTB?…

Brendan Smith

Trojan:Win32/Znyonm

Trojan:Win32/Znyonm is a detection often seen during the backdoor malware activity in…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?