Výsledky hledání

téma: malware× typ: varování× v celém archivu zrušit filtry

93 karet z 94 položek · strana 1 z 2 CZ · EN/orig

3

Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

Executive Summary Following disclosure of the TraderTraitor attack against LayerZero in April 2026, SentinelOne identified an additional victim with the same macOS backdoors. Our analysis explores the mechanics of these backdoors and the expanded targeting against a victim in the IT services sector with no relationship to cryptocurrency trading. We also identified more weaponized GitHub repositories from the social engineering schemes used to target job seekers in these campaigns. This report…

Apple Terraform GitHub US

tg: incident tg: varování tg: rozbor tp: malware tp: phishing tp: dodavatelský řetězec tp: špionáž

· SentinelLabs · Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

SPOJENO PŘES CVE TSUBAME Report Overflow (Apr-Jun 2026)

This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the JPCERT/CC Quarterly Report. This article covers monitoring results from April to June 2026. Note: Starting in FY2026, the JPCERT/CC Internet Threat Monitoring Report has been integrated into the JPCERT/CC Quarterly Report. Sharp Increase in Mirai-like Packets Targeting 23/TCP Observed in Early May 2026 In early May 2026, TSUBAME observed a…

KEV ✓ · ransomware EPSS 0.99 CVSS 9.8 CVE-2026-41940 cPanel JP HR

tg: varování tg: rozbor tp: malware

· JPCERT/CC – blog · TSUBAME Report Overflow (Apr-Jun 2026) · CERT.hr · Upozorenje: Kritična ranjivost u cPanel i WHM (CVE-2026-41940)

2

The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

Introduction Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. Installation guides for pirated software routinely instruct users to disable their antivirus, conditioning them to ignore potential threats they are inviting onto their…

RU

tg: varování tg: rozbor tp: malware

· Securelist (Kaspersky) · The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

3

NightEagle targets Russian companies

Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign. Initial access In most incidents, the attackers used compromised valid…

KEV ✓ · ransomware EPSS 1.00 CVE-2019-0708 CVE-2020-0688 Microsoft RU

tg: varování tg: rozbor tp: malware tp: špionáž

· Securelist (Kaspersky) · NightEagle targets Russian companies

3

HBO Max’s verified Reddit account hijacked to spread malware

Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used HBO Max’s trusted corporate account to promote fake AI tools, developer software, and macOS utilities, lowering potential victims’ guards. Some ads directed users to convincing HBO lookalike sites that claimed to offer a native HBO Max app for macOS or a promotional download. But instead of providing an installer, the sites…

Reddit HBO média US

tg: incident tg: varování tp: malware tp: phishing tp: identita

· Malwarebytes Labs · HBO Max’s verified Reddit account hijacked to spread malware

4

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Over 15 months and seven campaigns, they built a malicious browser extension that installs…

Google Microsoft finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

1

4

Artifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

KEV ✓ EPSS 0.08 CVE-2026-42016 CVE-2026-42018 CVE-2026-82329 JFrog US

tg: varování tg: zneužíváno tp: malware

· BleepingComputer · Artifactory flaws chained in attacks deploying backdoor malware

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]

US

tg: varování tg: rozbor tp: malware tp: phishing tp: AI

· BleepingComputer · How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

4

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod tp: identita

· Microsoft Security Blog · Detect and disrupt AI-themed attacks with Microsoft Defender

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless. But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running…

Google Microsoft US

tg: varování tg: zneužíváno tg: rozbor tg: propagace tp: malware tp: phishing tp: špionáž

· Malwarebytes Labs · BlueMoon exploit kit turns Chrome and Windows flaws into attacks

SPOJENO PŘES CVE New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

KEV ✓ EPSS 0.01 CVE-2026-85046 CVE-2026-85880 CVE-2026-87491 Microsoft Google US

tg: varování tg: zneužíváno tg: rozbor tp: malware tp: phishing tp: špionáž

· BleepingComputer · New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws · Volexity · Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

1

4

SPOJENO PŘES CVE Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

KEV ✓ EPSS 0.02 CVE-2025-53521 F5 US FR

tg: varování tg: rozbor tp: malware

· BleepingComputer · Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit · CERT-FR – alerty · Vulnérabilité dans F5 BIG-IP Access Policy Manager (31 mars 2026)

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan,…

PyPI npm Docker GitHub zdravotnictví veřejná správa média US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI tp: identita

· Mandiant / Google TI · GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery…

Google Cloudflare NetSupport veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the…

Google Tampermonkey US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

1

2

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and…

HAProxy média výroba a průmysl US

tg: varování tg: rozbor tp: malware tp: špionáž

· Rapid7 · DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Angry Birds: Toy Ghouls’ new toys

Introduction We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In early July 2026, we observed the group using a custom backdoor for the first time. We…

Microsoft RU

tg: varování tg: rozbor tp: malware tp: ransomware

· Securelist (Kaspersky) · Angry Birds: Toy Ghouls’ new toys

4

StreamRat Android malware spreads through Meta and TikTok ads

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections, but…

Meta TikTok US

tg: varování tg: rozbor tp: malware tp: podvod

· Malwarebytes Labs · StreamRat Android malware spreads through Meta and TikTok ads

RIASZTÁS Magyarország Ügyészségének nevével visszaélő ransomware támadásokkal kapcsolatban

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki Magyarország Ügyészségének nevével és arculati elemeivel visszaélő, zsarolóvírus fertőzéshez vezető adathalász üzenetekről. A bejelentések alapján a támadók hamis, hivatalos megkeresés látszatát keltő leveleket küldenek, amelyekben ügyészségi alkalmazottak nevével élnek vissza. A kampány célja az, hogy a felhasználó a levélben szereplő hivatkozásra kattintson, majd a […]

veřejná správa HU

tg: varování tg: zranitelnost tp: malware tp: phishing tp: ransomware

· NKI Maďarsko · RIASZTÁS Magyarország Ügyészségének nevével visszaélő ransomware támadásokkal kapcsolatban

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

In this article Risk to enterprise environmentsAttack chain overviewMitigation and response recommendationsLearn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI…

Microsoft US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

6

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Research by: Amit Yardeni Key Points A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. We dubbed this group Gambling Goblin: a Chinese-speaking cybercrime cluster connected to a previously documented group, Earth Berberoka, that targeted gambling sites across Asia. It marks a shift from Brazil’s usual home-grown banking-trojan threats to a…

Apache veřejná správa školství IL

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Check Point Research · Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on…

US

tg: varování tg: rozbor tp: malware tp: podvod tp: identita

· Elastic Security · REVSTEALER ramps up: analysis of up-and-coming infostealer

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

In this article Attack chain overviewCampaign scope and targetingMitigation and protection guidanceReferencesLearn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of…

zdravotnictví výroba a průmysl veřejná správa školství US

tg: varování tg: rozbor tp: malware

· Microsoft Security Blog · Counterfeit installers to system compromise: Tracking a deceptive software download campaign

6

Fake GTA 6 leaked copy drains your crypto wallet

We’ve seen scam sites built around Grand Theft Auto VI (GTA 6) targeting visitors in three different ways this year. In June, we looked at sites selling GTA 6 “early access” for hundreds of dollars in cryptocurrency. You paid, got nothing, and could not reverse the payment. In August, we found fake Extended Look and demo sites delivering an infostealer instead of a game. The site we examined this week looks like a GTA 6 fan countdown site but offers to sell a leaked copy of the game. It loads a…

US

tg: varování tg: rozbor tp: malware tp: podvod

· Malwarebytes Labs · Fake GTA 6 leaked copy drains your crypto wallet

TerminalFix looks like ClickFix, but delivers a very different payload

Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A website visitor is presented with a fake Cloudflare CAPTCHA which, when clicked, secretly copies a malicious command to their clipboard. Then they receive instructions on what they need to do to “prove they are human,” when in reality they are being instructed to execute the malicious command. After…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing

· Malwarebytes Labs · TerminalFix looks like ClickFix, but delivers a very different payload

Infostealers are hijacking Claude accounts at users’ expense

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…

Anthropic US

tg: incident tg: varování tg: zranitelnost tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · Infostealers are hijacking Claude accounts at users’ expense

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on…

doprava finance RU

tg: varování tg: rozbor tp: malware tp: phishing tp: špionáž

· Securelist (Kaspersky) · Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In…

finance obchod US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod tp: AI

· Mandiant / Google TI · Financially Motivated Threat Actor BREEZE COMET Targets Brazil

3

1

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

In this article Attack chain overviewMitigation and protection guidanceLearn more Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns…

Microsoft Cloudflare US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · TerminalFix campaign deploys a reverse tunnel through multistage intrusion

1

@7nohe/openapi-react-query-codegen Compromised in Supply Chain Attack (Campaign)

On August 28, starting at approximately 2000 UTC eight malicious versions of the @7nohe/openapi-react-query-codegen package were published on npm and were available for approximately three hours. These malicious versions were trojanized with an updated version of the miasma ma...

@7nohe/openapi-react-query-codegen US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec

· Wiz Research · @7nohe/openapi-react-query-codegen Compromised in Supply Chain Attack (Campaign)

1

SPOJENO PŘES CVE Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995)

CISA added CVE-2022-0995 to the Known Exploited Vulnerabilities catalog. Affected product: Linux Kernel. Remediation due date: 2026-09-09.

KEV ✓ EPSS 0.10 CVE-2022-0995 Linux Microsoft veřejná správa školství média US

tg: varování tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

· CISA KEV · Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995) · Cisco Talos · UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

1

1

BengalSEO Part 1: Anatomy of the Operation

Key Takeaways The DFIR Report Offerings Check out our Products here and our Services here. Want a demo, more information on our services, pricing or just want to chat? Get in Touch Contact us today for pricing or a demo! Case Summary In March 2026, our team identified an SEO poisoning campaign leading to malware deployment […] The post BengalSEO Part 1: Anatomy of the Operation appeared first on The DFIR Report.

US

tg: varování tg: rozbor tg: propagace tp: malware

· The DFIR Report · BengalSEO Part 1: Anatomy of the Operation

2

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques. The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis…

US

tg: varování tg: rozbor tp: malware tp: podvod tp: AI

· Cisco Talos · UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)

On August 20, 2026, malicious versions of three Rust crates were published to crates.io from the account of their maintainer, droundy: arrayref@0.3.10, internment@0.8.7 and append-only-vec@0.1.9. The Rust Security Response Team does not believe the maintainer published them, a...

arrayref internment append-only-vec US

tg: incident tg: varování tp: malware tp: dodavatelský řetězec

· Wiz Research · arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)

2