Visualização de leitura

Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme

Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines in Kansas. This case highlights a growing cyber-physical threat targeting financial institutions across the United States. The case arose from an FBI investigation into an alleged scheme to force automated teller machines (ATMs) to dispense […]

The post Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks

BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the […]

The post AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications

A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilities, and in-memory payload execution. No threat actor, victim, delivery chain, or live campaign has yet been attributed to the malware. SLEEPWALKER is an unsigned 64-bit Windows DLL […]

The post SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware

Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute […]

The post BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign

Open VSX has removed three extension identifiers from its malicious-extension list after the legitimate projects they impersonated began reclaiming their names. The move restores publishing access for the affected maintainers but highlights a supply-chain tracking gap: a single extension ID can represent both a removed malicious artifact and a later legitimate release. Between August 16 […]

The post Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks

SynkLoader, a newly identified modular malware framework that combines Python, C#, C++, PowerShell, and memory-resident payloads to evade endpoint detection. Delivered through Microsoft Teams phishing, the operation uses a convincing fake Windows lock screen to capture credentials before enabling network tunneling and interactive access to compromised enterprise environments. Compile timestamps and file metadata indicate the […]

The post New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New macOS Malware Clones Your Logged-In Browser and Gives Hackers Remote Control.

AmnesiaStealer, a multi-stage macOS infostealer written in Rust that moves beyond conventional credential theft by giving attackers covert, interactive control over a victim’s authenticated Chromium browser sessions. The malware is being distributed through a ClickFix social-engineering campaign that directs users to counterfeit GitHub download pages. Instead of delivering a legitimate application, the sites instruct visitors […]

The post New macOS Malware Clones Your Logged-In Browser and Gives Hackers Remote Control. appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords

A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing bank-payment lure with a fileless execution chain that keeps the final malware payload out of sight of traditional disk-based scanning. The messages masquerade as internal forwarded […]

The post Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware

The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware […]

The post Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security

Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In late July 2026, multiple ClickFix campaigns generated through the ErrTraffic malware-as-a-service platform and used to deliver Cruciferra, a loader advertised […]

The post Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections

HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. The development marks a notable escalation in the group’s post-compromise tradecraft, moving protection and evasion below the user-mode layer where many endpoint inspection […]

The post HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware

A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed Windows malware. The campaign used a fake Web3 recruitment process to deploy a three-payload stack: NeedleStealer, an unclassified Rust infostealer, and a custom Go RAT with hidden VNC capabilities. A fake recruiter initiated contact […]

The post Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token

The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm install event to spread through developer environments. The self-propagating npm worm, also tracked as a Mini Shai-Hulud variant, turned compromised publisher and CI identities into a distribution mechanism while establishing […]

The post ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Agentic AI Models Rebuild Malware and Sustain Real-World Cyber Intrusions, SentinelOne Warns

Four incidents involving OpenAI, Anthropic, Meta and the UK AI Security Institute (AISI) describe AI agents reaching systems belonging to other organizations without their consent. The defining capability is now persistence: models can repeatedly test paths, regenerate disposable tooling, restore communications, and shift techniques until a viable intrusion chain emerges. Although each incident involved different […]

The post Agentic AI Models Rebuild Malware and Sustain Real-World Cyber Intrusions, SentinelOne Warns appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services

A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows that customers can now buy payload obfuscation, in-memory execution, anti-analysis controls, process injection, persistence, and rapid “re-crypting” as packaged services rather than develop them internally. Crypting traditionally refers to encrypting or obfuscating a customer-supplied malicious […]

The post 24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network

An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed as a MaaS framework by a forum user known as “LenAI.” Its core feature is a traffic distribution system that routes victims to […]

The post ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Android Banking Droppers Surge as Malware Operators Change Packaging Tactics

Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet […]

The post Android Banking Droppers Surge as Malware Operators Change Packaging Tactics appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems

GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a new GitHub Advisory Database importer for OpenSSF’s malicious-packages repository, which enhances supply chain detection across these eight ecosystems. GitHub Expands […]

The post GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware

Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad credential and cryptocurrency-wallet stealers. Yeeth Security identified two publishers, helper-beeps and web3devtoolsx, distributing related solidity-pro packages that use Solidity-themed branding, obfuscation, and version churn to target web3 developers. The campaign reflects […]

The post Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware

Hackers are abusing an Ethereum smart contract as a dead‑drop resolver to dynamically steer victims’ browsers to rotating command‑and‑control (C2) infrastructure in a new Remus infostealer campaign that weaponizes fake cracked software lures and Turkish‑language SEO poisoning. In this campaign, Remus no longer relies on a static C2 domain or legacy dead-drop platforms like Steam […]

The post Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌