PackClient RAT: A Tax Notice Can Leave Persistent Access
PackClient tax lures deliver a Windows RAT with a restart guard. Check…
StreamRat Android Trojan: Stop the Fake Streaming Install
StreamRat installers can block Internet access while seeking phone control. Check which…
RedC2 npm Packages: Importing Can Infect a Linux Host
RedC2 starts a Linux backdoor when a poisoned npm package is imported.…
Post-DEF CON Google Doc Phishing Delivers AMOS and NetSupport
A real Google Doc sidebar and fake DocSend installer delivered AMOS and…
Fake Exodus Installer Hides a RAT Behind a Wallet That Never Opens
A fake Exodus installer runs the wallet invisibly while a RAT steals…
SynkLoader Malware Uses a Fake Windows Lock Screen to Steal Passwords
SynkLoader arrives through fake Teams help-desk chats, steals Windows passwords with PhishLocker,…
E4del and PINHOLE RATs Hide Commands in FTP Banners
E4del and PINHOLE use FTP server banners to deliver Windows malware. Check…
Sable Squirrel Uses Expired Domains for Streaming and Malware
Infoblox says Sable Squirrel bought more than 10,000 expired domains for illegal…
How Malware Abused Paste.tc: XWorm, LimeRAT, and AsyncRAT Cases
A cross-case investigation of how AsyncRAT, LimeRAT, and XWorm used Paste.tc raw…
Golden Gh0st RAT: Loader, Risks, and Recovery
Golden Gh0st uses a separate loader to launch a modular remote-access Trojan.…
Heisenberg RAT: Claims, Hidden Desktop Risk, and Removal
See what is verified about Heisenberg RAT, how hidden desktops can expose…
Joyfill npm Packages Compromised: Six Malicious Versions
Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and…
