malware

Live Updates: Sha1-Hulud, The Second Coming

TLDR: Major resurgence of Shai-Hulud malware, now called “Sha1-Hulud: The Second Coming,” compromises over 800 npm packages and tens of thousands of GitHub repos. It embeds credential-stealing payloads and can delete users' home directories if unsuccessful. It exploits GitHub Actions for remote code execution, allowing attackers to run commands through victim accounts. Organizations should scan endpoints, remove affected packages, rotate credentials, and audit workflows to mitigate risks.

https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised

Matrix Push C2 Abuses Browser Notifications to Deliver Phishing and Malware

Cybercriminals exploit browser push notifications via the Matrix Push C2 platform to deliver malware and phishing attacks. Users are deceived into granting permission through misleading prompts, allowing attackers to send fake alerts and gather personal data. The platform enables detailed monitoring of victims and custom URL management for malicious campaigns, often resulting in data theft or financial loss. Users are advised to manage notification permissions across their browsers to mitigate these risks.

https://www.malwarebytes.com/blog/news/2025/11/matrix-push-c2-abuses-browser-notifications-to-deliver-phishing-and-malware

ClickFix Gets Creative: Malware Buried in Images

ClickFix malware is a multi-stage attack using steganography to conceal infostealing malware within images. It begins with social engineering tactics, tricking users into executing malicious commands. Huntress identified two main ClickFix lures—one using a “Human Verification” tactic and the other mimicking a Windows Update interface. The process involves JavaScript to copy commands to the clipboard, PowerShell for loading .NET assemblies, and a complex steganographic algorithm to hide and extract shellcode from PNG images. This shellcode is then injected into target processes, ultimately delivering LummaC2 malware for data theft. The campaign has evolved with increasingly convincing user interfaces to deceive targets effectively.

https://www.huntress.com/blog/clickfix-malware-buried-in-images

Sturnus: Mobile Banking Malware Bypassing WhatsApp, Telegram and Signal Encryption

Sturnus is a newly identified Android banking trojan capable of bypassing encrypted messaging apps like WhatsApp, Telegram, and Signal. It monitors communications by capturing screen content, harvests banking credentials via fake login screens, and allows extensive remote control of infected devices, including real-time screen viewing and activity injections. Currently in a pre-deployment phase, it primarily targets users in Southern and Central Europe, focusing on high-value applications. The malware's architecture incorporates advanced evasion techniques, including code obfuscation and complex communication protocols, posing significant threats to financial security and privacy.

https://www.threatfabric.com/blogs/sturnus-banking-trojan-bypassing-whatsapp-telegram-and-signal

DanaBot Malware Is Back to Infecting Windows After 6-month Break

DanaBot malware returns after 6-month hiatus, with version 669 using Tor for command-and-control. It's a banking trojan evolved into an info stealer, disrupted by law enforcement in May but now active again. It targets credentials and cryptocurrency data via nefarious emails and malvertising. Organizations can mitigate risks by updating security tools and blocking new threats identified by Zscaler.

https://www.bleepingcomputer.com/news/security/danabot-malware-is-back-to-infecting-windows-after-6-month-break/

GootLoader Is Back, Using a New Font Trick to Hide Malware on WordPress Sites

GootLoader malware has resurfaced, utilizing custom fonts to obscure filenames on WordPress sites, complicating detection. It exploits SEO tactics and comment endpoints to deliver encrypted payloads, often leading to domain controller compromises. The malware has evolved to disguise its true nature, using deceptive techniques to evade automated analysis and remains tied to a broader cybercriminal ecosystem involving various threat actors.

https://thehackernews.com/2025/11/gootloader-is-back-using-new-font-trick.html

GlassWorm Malware Discovered in Three VS Code Extensions With Thousands of Installs

GlassWorm Malware targets VS Code via three malicious extensions, harvesting credentials and using invisible code to spread. Despite attempts to remove it, the campaign persists, affecting various regions, including government entities. The malware showcases evolving attack techniques, such as utilizing blockchain for command/control. Security researchers identified a Russian-speaking attacker behind it, indicating significant risks to organizations using affected tools.

https://thehackernews.com/2025/11/glassworm-malware-discovered-in-three.html

Gootloader Malware Is Back With New Tricks After 7-month Break

Gootloader malware has returned after a 7-month hiatus, using SEO tricks to promote fake websites that distribute malicious files. It tricks users into downloading harmful documents, often disguised as legal templates, to install additional malware like ransomware. Researchers have discovered new techniques to evade detection, including obfuscating filenames and using malformed ZIP archives. Users are cautioned to avoid suspicious sites when searching for legal documents.

https://www.bleepingcomputer.com/news/security/gootloader-malware-is-back-with-new-tricks-after-7-month-break/

Malicious Infrastructure Finds Stability With Aurologic GmbH

TLDR: aurologic GmbH is a key German hosting provider supporting high-risk networks linked to cybercrime. Established in 2023, it provides services to many threat activity enablers like Aeza Group and Global-Data System, despite increasing scrutiny and sanctions. The company’s operational neutrality raises concerns about accountability in the internet hosting ecosystem, as it facilitates malicious activities while complying legally. Notable downstream customers have been linked to various malware and cybercrime infrastructures, indicating aurologic's significant role in the ongoing challenges of managing malicious online activities.

https://www.recordedfuture.com/research/malicious-infrastructure-finds-stability-with-aurologic-gmbh

Malicious Android Apps on Google Play Downloaded 42 Million Times

Malicious Android apps on Google Play were downloaded over 42 million times between June 2024 and May 2025, with a 67% rise in mobile malware, especially spyware and banking trojans. Shift in cybercriminal tactics towards social engineering-based attacks is noted. The report highlights three significant malware families affecting users: Anatsa (banking trojan), Android Void (backdoor for Android TV boxes), and Xnotice (RAT targeting job seekers). Key advice for users includes applying security updates and using reputable app sources.

https://www.bleepingcomputer.com/news/security/malicious-android-apps-on-google-play-downloaded-42-million-times/

Massive Surge of NFC Relay Malware Steals Europeans’ Credit Cards

NFC relay malware significantly increased in Eastern Europe, with over 760 malicious Android apps identified stealing credit card data. This malware utilizes Android’s Host Card Emulation to capture payment information and perform unauthorized transactions without the card present. It first appeared in Poland and has spread to several countries. Security experts advise Android users to avoid installing risky apps, check permissions, and utilize built-in anti-malware tools.

https://www.bleepingcomputer.com/news/security/massive-surge-of-nfc-relay-malware-steals-europeans-credit-cards/

Compromised YouTube Accounts Distribute Infostealer Malware

A large-scale malware campaign called the “YouTube Ghost Network” exploited over 3,000 malicious YouTube videos, hosted on fake or compromised accounts, to distribute infostealers targeting users seeking pirated software or game hacks. The top targets were Adobe and FL Studio products, with videos guiding users to download files from third-party sites and often to disable Windows Defender. The operation relied on a structure that quickly replaced banned accounts and faked user trust with positive comments. Main infostealers included Lumma, Rhadamanthys, StealC, and Redline. The report highlights the risks of using cracked software and notes the increasing sophistication of such attacks on popular platforms.

https://thecyberexpress.com/compromised-youtube-accounts-infostealer-malware/

Large-Scale Attack Targeting Macs Via GitHub Pages Impersonating Companies to Attempt to Deliver Stealer Malware

TLDR: A large-scale cyberattack targets Mac users through fake GitHub pages impersonating companies, promoting the installation of an infostealer malware called Atomic. The malicious sites use SEO tactics to appear high in search results, redirecting users to download malware after entering commands. LastPass has taken down some fraudulent sites and continues to monitor the situation.

https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages

Lumma Stealer: Breaking Down the Delivery Techniques and Capabilities of a Prolific Infostealer

Lumma Stealer Overview: Lumma Stealer is a sophisticated infostealer malware targeting various industries, utilizing diverse delivery methods including phishing, malvertising, and exploiting legitimate services. Operated as Malware-as-a-Service (MaaS) by threat actor Storm-2477, it facilitates credential theft from browsers and applications, particularly cryptocurrency wallets. Unlike previous variants, it employs multi-vector strategies and adaptive infrastructure to evade detection. Microsoft is actively working to disrupt Lumma's operations, having recently taken down around 2,300 associated domains and providing recommendations for mitigation against this evolving cyber threat.

https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/

Scroll to Top