❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 23 July 2026GBHackers

New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control

23 July 2026 at 02:59

A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a […]

The post New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayGBHackers

AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware

21 July 2026 at 03:34

AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent‑readable READMEs, public AI registries, and GitHub trust signals into a weaponized β€œAI capability supply chain,” attackers now […]

The post AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images

20 July 2026 at 01:39

A sophisticated North Korean threat campaign dubbed β€œContagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking DPRK-linked activity note that the campaign continues to impersonate recruiters and job interview workflows, luring […]

The post North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload

17 July 2026 at 01:02

An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed […]

The post Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware

16 July 2026 at 01:10

The China-linked Daxin backdoor has resurfaced in an active intrusion targeting a Taiwan-based subsidiary of a multinational high-tech manufacturer, exposing the enduring reach of an espionage operation first publicly detailed in 2022. Daxin’s return is significant because the malware was already regarded as an unusually sophisticated implant built for stealthy, long-term access to hardened networks. […]

The post China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases

15 July 2026 at 08:46

A newly documented malware framework dubbed OkoBot is targeting cryptocurrency users with a multi-stage intrusion chain designed to capture Ledger and Trezor recovery phrases, browser credentials, wallet files, keystrokes, screenshots, and application video recordings. Researchers first observed the activity in January 2026, although the campaign’s TookPS downloader component has been active since March 2025. The […]

The post OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems

15 July 2026 at 07:41

A previously undocumented Rust-based remote access trojan, dubbed LabubaRAT, which masquerades as legitimate NVIDIA software to establish persistent access on Windows systems. The malware was identified by the company’s Adversary Pursuit Group (APG) and appears designed as a reusable, panel-managed framework rather than a single-purpose payload. The observed sample, named nvidia-sysruntime.exe, impersonates an NVIDIA Container […]

The post LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware

15 July 2026 at 06:03

11 malicious NuGet packages masquerading as game cheats, automation bots, and management β€œpanels” that deploy a Windows payload called pepesoft.exe. The packages were published as .NET command-line tools, enabling users to install them through the dotnet tool install workflow and execute bundled commands such as throne-run. The affected packages target communities around Albion Online, GTA5RP, […]

The post 11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Artlist ClickFix Campaign Uses Infostealer-Stolen WordPress Credentials to Deploy RAT Malware

15 July 2026 at 01:25

A threat campaign discovered in mid-July 2026 abused the compromised Artlist subdomain new-blog. artlist[.]io to distribute a Remote Access Trojan through a fake CAPTCHA prompt. The operation combined stolen WordPress credentials, blockchain-based EtherHiding infrastructure, ClickFix social engineering, DLL side-loading, and a Tor-backed command-and-control fallback. The incident affected a high-value web property. Similarweb data indicates that […]

The post Artlist ClickFix Campaign Uses Infostealer-Stolen WordPress Credentials to Deploy RAT Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities

13 July 2026 at 09:06

Adaptive, AI-driven malware could challenge a foundational assumption in enterprise defense: that a malicious program’s exploitation logic remains fixed after deployment. New research on adaptive computer worms argues that a self-replicating agent paired with an onboard reasoning loop could assess different environments, select target-specific attack paths, and regenerate capabilities as older methods become less effective. […]

The post Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs

9 July 2026 at 04:40

A coordinated supply-chain campaign that pushed 17 malicious packages across npm and PyPI, masquerading as SDKs for well-known payment services including PaySafe, Skrill and Neteller. The campaign’s packages 17 npm modules published with four rapid versions each and four PyPI packages access with single malicious releases presented as convenient payment SDK facades but contained logic […]

The post npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions

9 July 2026 at 03:15

Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with […]

The post SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Umbrij Malware Lets ToddyCat Hackers Hijack Gmail Accounts Through Google API Abuse

9 July 2026 at 02:04

A targeted campaign in which the ToddyCat (aka APT-style) group leverages a previously observed loader family, Umbrij, to hijack Gmail accounts by abusing Google APIs. Chaining that capability to broad remote access achieved through a malicious MSI installer masquerading as the Kuailian/LetsVPN client. The operation blends social engineering with a sophisticated in-memory loader and a […]

The post Umbrij Malware Lets ToddyCat Hackers Hijack Gmail Accounts Through Google API Abuse appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities

8 July 2026 at 01:40

A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH, a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell, multi-protocol proxying, and intermediate command-and-control (C2) forwarding capabilities. LONGLEASH retains SHORTLEASH’s ff-agent codebase but expands its operational scope. The implant, internally named β€œnz1.0,” splits into Base, Executor, and Core modules. The Base module […]

The post LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌