home.social

#malwareasaservice — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malwareasaservice, aggregated by home.social.

fetched live
  1. MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

    MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

    Pulse ID: 6a9fff8d4e576223ee6f9b4e
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:29:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault

  2. MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

    MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

    Pulse ID: 6a9fff8d4e576223ee6f9b4e
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:29:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault

  3. MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

    MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

    Pulse ID: 6a9fff8d4e576223ee6f9b4e
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:29:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault

  4. MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

    MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

    Pulse ID: 6a9fff8d4e576223ee6f9b4e
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:29:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault

  5. MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

    MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

    Pulse ID: 6a9fff8d4e576223ee6f9b4e
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:29:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault

  6. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  7. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  8. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  9. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  10. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  11. هجوم RedWing على أجهزة Android

    تفاصيل الهجوم في يوليو 2026، كشفت شركة الأمن السيبراني Zimperium عن برمجية خبيثة لنظام Android أطلقت عليها اسم RedWing. البرمجية لا تُباع كبرنامج عادي، وإنما تُقدم للمجرمين كنموذج Malware-as-a-Service (MaaS) عبرتطبيق Telegram، أي أن المهاجم يستطيع استئجار البنية والأدوات الجاهزة بدلًا من تطوير […]

    cybercases8.wordpress.com/2026

  12. Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes

    Indicators extracted from public reporting. Source: esentire.com/blog/malware-as-a

    Pulse ID: 6a87077b82a77bd532367445
    Pulse Link: otx.alienvault.com/pulse/6a870
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 13:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL

  13. Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes

    Indicators extracted from public reporting. Source: esentire.com/blog/malware-as-a

    Pulse ID: 6a87077b82a77bd532367445
    Pulse Link: otx.alienvault.com/pulse/6a870
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 13:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL

  14. Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes

    Indicators extracted from public reporting. Source: esentire.com/blog/malware-as-a

    Pulse ID: 6a87077b82a77bd532367445
    Pulse Link: otx.alienvault.com/pulse/6a870
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 13:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL

  15. Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes

    Indicators extracted from public reporting. Source: esentire.com/blog/malware-as-a

    Pulse ID: 6a87077b82a77bd532367445
    Pulse Link: otx.alienvault.com/pulse/6a870
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 13:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL

  16. Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes

    Indicators extracted from public reporting. Source: esentire.com/blog/malware-as-a

    Pulse ID: 6a87077b82a77bd532367445
    Pulse Link: otx.alienvault.com/pulse/6a870
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 13:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL

  17. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  18. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  19. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  20. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  21. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  22. Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

    In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...

    Pulse ID: 6a8474eb4f130dfa41887e40
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:06:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault

  23. Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

    In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...

    Pulse ID: 6a8474eb4f130dfa41887e40
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:06:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault

  24. Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

    In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...

    Pulse ID: 6a8474eb4f130dfa41887e40
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:06:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault

  25. Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

    In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...

    Pulse ID: 6a8474eb4f130dfa41887e40
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:06:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault

  26. Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

    In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...

    Pulse ID: 6a8474eb4f130dfa41887e40
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:06:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault

  27. Malware Campaigns Target Gamers, 86K Infected by CountLoader

    A shocking 86,000 gamers have fallen victim to CountLoader, a sneaky malware campaign that's been targeting players since January 2026, and the masterminds behind it are making it easy for others to join the malicious party with their free, user-friendly malware service.

    osintsights.com/malware-campai

    #MalwareAsAService #Maas #Weedhack #Minecraft #Countloader

  28. ESET Exposes BTMOB Android Malware Service

    Meet BTMOB, a sneaky Android malware that's being sold as a subscription service - think $700/month or a one-time $5,000 fee for a lifetime license - making it easy for anyone to become a cyber threat actor. This malware-as-a-service platform even comes with a user-friendly APK builder, requiring zero coding skills.

    osintsights.com/eset-exposes-b

    #AndroidMalware #Malwareasaservice #RemoteAccessTrojan #Maas #Rat

  29. Mirax RAT Exploits Meta Apps to Infiltrate Android Devices

    Beware of fake ads on Meta apps - a sneaky new malware called Mirax RAT is using them to secretly take control of Android devices, with a focus on Spanish-speaking nations. This remote access Trojan is part of a growing Malware-as-a-Service economy that's putting unsuspecting users at risk.

    osintsights.com/mirax-rat-expl

    #MiraxRat #Malwareasaservice #MetaApps #AndroidMalware #RemoteAccessTrojan

  30. Mirax Trojan Hijacks Android Devices for Proxy Network

    Meet Mirax, a sneaky new Android banking trojan that's not only stealing credentials, but also hijacking devices to create a powerful proxy network - putting European users at risk. This emerging malware is a triple threat, combining a malware-as-a-service model, remote access capabilities, and residential proxies to wreak havoc…

    osintsights.com/mirax-trojan-h

    #AndroidBankingTrojan #EmergingThreats #Malwareasaservice #ResidentialProxies #Maas

  31. Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.

    thedefendopsdiaries.com/the-ri

    #meduzastealer
    #malwareanalysis
    #cybercrime
    #infosec
    #malwareasaservice

  32. Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.

    thedefendopsdiaries.com/the-ri

    #meduzastealer
    #malwareanalysis
    #cybercrime
    #infosec
    #malwareasaservice

  33. Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.

    thedefendopsdiaries.com/the-ri

    #meduzastealer
    #malwareanalysis
    #cybercrime
    #infosec
    #malwareasaservice

  34. Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.

    thedefendopsdiaries.com/the-ri

    #meduzastealer
    #malwareanalysis
    #cybercrime
    #infosec
    #malwareasaservice

  35. Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?

    thedefendopsdiaries.com/atropo

    #atroposia
    #malwareasaservice
    #cybercrime
    #remotetrojan
    #credentialtheft

  36. Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?

    thedefendopsdiaries.com/atropo

    #atroposia
    #malwareasaservice
    #cybercrime
    #remotetrojan
    #credentialtheft