❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayGBHackers

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

11 September 2026 at 08:24

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a […]

The post Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

11 September 2026 at 05:07

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed […]

The post New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware

9 September 2026 at 09:27

A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain smart contracts to deploy the Amatera information stealer. The activity was first identified in April 2026 after a Ukrainian government organization executed a disguised DLL named β€œverification.google” from a WebDAV path using the 32-bit rundll32.exe […]

The post Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

9 September 2026 at 06:49

GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter application. The companion tool abuses Android Work Profile isolation to clone banking apps into a separate managed environment, weakening the link between malware signals detected in a victim’s personal profile and fraudulent activity […]

The post GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

7 September 2026 at 09:14

A sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation of CVE-2025-53521, an unauthenticated remote code execution flaw affecting BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the vulnerability and links the related compromise activity […]

The post PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems

3 September 2026 at 09:15

A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is […]

The post Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning

3 September 2026 at 02:28

A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct large-scale SEO poisoning and online-gambling fraud. The operation has been active since mid-2025 and represents a notable shift in Brazil’s threat landscape. Rather than deploying the country’s more familiar banking malware, the attackers are […]

The post Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme

By: Divya
1 September 2026 at 08:49

Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines in Kansas. This case highlights a growing cyber-physical threat targeting financial institutions across the United States. The case arose from an FBI investigation into an alleged scheme to force automated teller machines (ATMs) to dispense […]

The post Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks

1 September 2026 at 05:39

BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the […]

The post AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌