❌

Reading view

There are new articles available, click to refresh the page.

Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions

Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator mark a clear architectural evolution in the group’s malware-as-a-service (MaaS) ecosystem, signaling a shift […]

The post Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design

SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors in 12 geographies across APAC, LATAM, Africa, and Western markets, including Japan, Thailand, South Korea, […]

The post SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload

A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on Portuguese-speaking victims rather than domestic Brazilian targets. In the latest campaign, attackers leverage convincing financial-themed phishing emails masquerading as routine […]

The post Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails

Russian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education, […]

The post Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems

CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer 2026, introduces two newly identified tools, LUNCHPOKE and BURNYBEAR, along with an updated MATCHBOIL.V2 loader. This activity highlights […]

The post Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control

A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a […]

The post New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware

AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent‑readable READMEs, public AI registries, and GitHub trust signals into a weaponized β€œAI capability supply chain,” attackers now […]

The post AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images

A sophisticated North Korean threat campaign dubbed β€œContagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking DPRK-linked activity note that the campaign continues to impersonate recruiters and job interview workflows, luring […]

The post North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload

An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed […]

The post Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware

The China-linked Daxin backdoor has resurfaced in an active intrusion targeting a Taiwan-based subsidiary of a multinational high-tech manufacturer, exposing the enduring reach of an espionage operation first publicly detailed in 2022. Daxin’s return is significant because the malware was already regarded as an unusually sophisticated implant built for stealthy, long-term access to hardened networks. […]

The post China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases

A newly documented malware framework dubbed OkoBot is targeting cryptocurrency users with a multi-stage intrusion chain designed to capture Ledger and Trezor recovery phrases, browser credentials, wallet files, keystrokes, screenshots, and application video recordings. Researchers first observed the activity in January 2026, although the campaign’s TookPS downloader component has been active since March 2025. The […]

The post OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems

A previously undocumented Rust-based remote access trojan, dubbed LabubaRAT, which masquerades as legitimate NVIDIA software to establish persistent access on Windows systems. The malware was identified by the company’s Adversary Pursuit Group (APG) and appears designed as a reusable, panel-managed framework rather than a single-purpose payload. The observed sample, named nvidia-sysruntime.exe, impersonates an NVIDIA Container […]

The post LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware

11 malicious NuGet packages masquerading as game cheats, automation bots, and management β€œpanels” that deploy a Windows payload called pepesoft.exe. The packages were published as .NET command-line tools, enabling users to install them through the dotnet tool install workflow and execute bundled commands such as throne-run. The affected packages target communities around Albion Online, GTA5RP, […]

The post 11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Artlist ClickFix Campaign Uses Infostealer-Stolen WordPress Credentials to Deploy RAT Malware

A threat campaign discovered in mid-July 2026 abused the compromised Artlist subdomain new-blog. artlist[.]io to distribute a Remote Access Trojan through a fake CAPTCHA prompt. The operation combined stolen WordPress credentials, blockchain-based EtherHiding infrastructure, ClickFix social engineering, DLL side-loading, and a Tor-backed command-and-control fallback. The incident affected a high-value web property. Similarweb data indicates that […]

The post Artlist ClickFix Campaign Uses Infostealer-Stolen WordPress Credentials to Deploy RAT Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities

Adaptive, AI-driven malware could challenge a foundational assumption in enterprise defense: that a malicious program’s exploitation logic remains fixed after deployment. New research on adaptive computer worms argues that a self-replicating agent paired with an onboard reasoning loop could assess different environments, select target-specific attack paths, and regenerate capabilities as older methods become less effective. […]

The post Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs

A coordinated supply-chain campaign that pushed 17 malicious packages across npm and PyPI, masquerading as SDKs for well-known payment services including PaySafe, Skrill and Neteller. The campaign’s packages 17 npm modules published with four rapid versions each and four PyPI packages access with single malicious releases presented as convenient payment SDK facades but contained logic […]

The post npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions

Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with […]

The post SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Umbrij Malware Lets ToddyCat Hackers Hijack Gmail Accounts Through Google API Abuse

A targeted campaign in which the ToddyCat (aka APT-style) group leverages a previously observed loader family, Umbrij, to hijack Gmail accounts by abusing Google APIs. Chaining that capability to broad remote access achieved through a malicious MSI installer masquerading as the Kuailian/LetsVPN client. The operation blends social engineering with a sophisticated in-memory loader and a […]

The post Umbrij Malware Lets ToddyCat Hackers Hijack Gmail Accounts Through Google API Abuse appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities

A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH, a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell, multi-protocol proxying, and intermediate command-and-control (C2) forwarding capabilities. LONGLEASH retains SHORTLEASH’s ff-agent codebase but expands its operational scope. The implant, internally named β€œnz1.0,” splits into Base, Executor, and Core modules. The Base module […]

The post LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌