A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
Introduction
Introduction
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. […]
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. […]
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. […]
Victims have been identified in Africa, including in Kenya and Uganda.
The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek.
Dominican Republic Leak, Celestial Malware, Money Network Sale, CVV Auction, and US VPN Access SOCRadar Dark Web Team identified several new underground posts, including an alleged Dominican Republic citizen data leak ,
An ongoing npm malware campaign involving the ‚indexed-btree‘ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. […]
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. […]
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. […]