Blinder Tunnel: Fake Dubai Airports Job Test Runs Malware on Project Open
Unit 42 traced a fake Dubai Airports job test that ran malware…
BPFDoor and AVERAT Hide Linux Access in Mail-Gateway Traffic
Rapid7 found Linux implants using deleted executables, daemon disguises and SMTP control…
RedFlick Turns a Phishing Invitation Into Scheduled Windows Tasks
Microsoft traces Star Blizzard’s RedFlick chain: document-looking shortcuts, remote applets and scheduled…
Crypto Address Changes When You Paste It? Check for Clipboard Malware
Crypto address changes when pasted? Separate normal wallet rotation from clipboard malware,…
Browser Closes When Searching for Antivirus? What to Do
Browser closes when you search for antivirus, or installers disappear? Scan Windows…
NeedyMantis Hides Its Next Stage Behind Familiar DLL Names
Microsoft traces NeedyMantis through planted DLLs, an extensionless archive and a fake…
Kothamine Carries Hostile Commands Through a Legitimate Tunnel
Kothamine uses tailcat for encrypted remote control. The research shows why localhost…
RemotePanel and BoundSiphon Split a ClickFix Attack in Two
A ClickFix command installs persistent RemotePanel access and the BoundSiphon stealer. Why…
Storm-2570 Uses Four Ransomware Brands—and the Same Access Tools
Microsoft links Storm-2570 to four ransomware families. Repeated remote access, credential theft…
CLOSEDQUORUM: Windows Malware Puts Its Next Move to a Vote
Talos found a Windows implant designed to take votes from four AI…
GigCluster.exe: Is It a Virus? Check and Remove It Safely
GigCluster.exe using high CPU or GPU? Check a suspected miner, verify the…
WaterPlum Fake Job Interviews Infect 30,000 Devices
A joint advisory links WaterPlum fake interviews to 30,000 infected devices. How…
