home.social

#malwareoperations — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malwareoperations, aggregated by home.social.

fetched live
  1. macOS Stealer Uses Coercion Loop to Force Password Entry

    A new macOS stealer malware has hit over 100 victims across 33 countries in just two months, with a clever coercion loop trick that forces users to enter their passwords. The attack starts with a simple paste-and-run lure, where victims unknowingly paste a command into Terminal after visiting a malicious webpage.

    osintsights.com/macos-stealer-

    #MacosStealer #MalwareOperations #EmergingThreats #SocialEngineering #Europe

  2. PamStealer Targets Mac Users with Fake Maccy Sites and PAM Checks

    Researchers have uncovered PamStealer, a sneaky macOS information stealer that tricks users into downloading it from fake Maccy sites, and it can even slip past Apple's security measures. This clever malware uses a two-stage delivery method to steal sensitive info from unsuspecting Mac users.

    osintsights.com/pamstealer-tar

    #MacosInformationStealer #Pamstealer #EmergingThreats #MalwareOperations #Apple

  3. GitHub Disrupts Microsoft Repos Hosting Password-Stealing Malware

    In a lightning-fast response, GitHub and Microsoft swiftly contained a malware incident on June 5, removing 73 repositories and restoring disrupted developer workflows in a mere 105 seconds. The quick takedown prevented password-stealing malware from causing further harm, showcasing the companies' commitment to protecting their…

    osintsights.com/github-disrupt

    #Github #Microsoft #MalwareOperations #SupplyChain #EmergingThreats

  4. Hackers Exploit Everest Forms Pro Flaw to Hijack WordPress Sites

    More than 29,300 attempted hacks have been blocked by Wordfence, revealing a surge in automated attacks exploiting a critical flaw in the Everest Forms Pro plugin, tracked as CVE-2026-3300. This alarming number highlights the urgent need for WordPress site owners to safeguard against this vulnerability.

    osintsights.com/hackers-exploi

    #Cve20263300 #Wordpress #EverestFormsPro #PluginVulnerability #MalwareOperations

  5. Malware Worms Infect npm Ecosystem in Dual Supply Chain Attacks

    Meet IronWorm, a sneaky Rust-based malware that's infecting the npm ecosystem by scraping sensitive secrets from developers' machines and spreading through poisoned packages. This stealthy threat hides behind an eBPF kernel rootkit and communicates with its operators over Tor.

    osintsights.com/malware-worms-

    #MalwareOperations #SupplyChain #Npm #Ironworm #Rust

  6. Chinese APT Exploits New Malware to Prolong Network Access

    A Chinese-linked espionage group, tracked as UNC5221 or VerdantBamboo, exploited new malware to secretly maintain access to US networks for over 18 months, evading detection by blending in with legitimate traffic. The attackers used a sophisticated backdoor called Brickstorm to prolong their stay undetected.

    osintsights.com/chinese-apt-ex

    #ChineseApt #MalwareOperations #NationState #Unc5221 #Verdantbamboo

  7. Researchers Prototype Self-Contained AI Worm

    Imagine a computer worm that's not just a malicious piece of code, but a self-contained AI entity that can spread and operate on its own - researchers have just prototyped one, and it's as fascinating as it is unsettling. This AI-powered worm is equipped with its own Large Language Model (LLM), making it a reality that's eerily close to sci-fi concepts.

    osintsights.com/researchers-pr

    #AiWorm #ArtificialIntelligence #EmergingThreats #Llm #MalwareOperations

  8. Hola Browser Compromised to Deliver Cryptominer in Supply Chain Attack

    Hola's CEO, Avi Raz Cohen, assured users that the company has taken swift action to prevent future breaches, rebuilding its distribution pipeline and implementing robust security measures. The move comes after a supply chain attack compromised the Hola Browser, secretly delivering a cryptominer to unsuspecting users.

    osintsights.com/hola-browser-c

    #SupplyChainAttack #Cryptominer #HolaBrowser #MalwareOperations #EmergingThreats

  9. Microsoft Warns AI Adoption Exposes Organizations to New Malware Threats

    Microsoft's senior security researcher warns that the AI tools making our jobs easier can also be exploited by threat actors, highlighting a new and urgent risk for organizations to manage. As AI adoption grows, companies must recognize it as both a valuable asset and a potential attack surface that requires careful…

    osintsights.com/microsoft-warn

    #AiAdoption #EmergingThreats #MalwareOperations #SocialEngineering #Microsoft

  10. Hackers Exploit Gaps in Vulnerability Programs with Simplified Playbook

    Meet Hercules, the mastermind behind a notorious underground tutorial that spills the beans on how to turn vulnerability exploitation into cold, hard cash. With a refreshingly blunt approach, Hercules breaks down the process into simple, actionable steps that even novice attackers can follow.

    osintsights.com/hackers-exploi

    #VulnerabilityExploitation #ExploitKits #UndergroundEconomy #MalwareOperations #EmergingThreats

  11. Malware Sites Exploit Open-Source Tools in Google Search Results

    Malicious websites are masquerading as legitimate open-source and freeware projects, expertly designed to deceive users into downloading malware. With fake portals that mimic trusted sites, complete with real GitHub links and references to upstream resources, it's easy to get caught off guard - until you…

    osintsights.com/malware-sites-

    #MalwareDistributionPaths #OpensourceTools #GoogleSearchResults #MalwareOperations #ThreatActors

  12. Malware Sites Exploit Open-Source Tools in Google Search Results

    Malicious websites are masquerading as legitimate open-source and freeware projects, expertly designed to deceive users into downloading malware. With fake portals that mimic trusted sites, complete with real GitHub links and references to upstream resources, it's easy to get caught off guard - until you…

    osintsights.com/malware-sites-

    #MalwareDistributionPaths #OpensourceTools #GoogleSearchResults #MalwareOperations #ThreatActors

  13. Malware Hidden in Hentai Games Exposes Users to Full System Compromise

    Beware of hentai games that seem too good to be true - a new malware campaign has been discovered that hides in these games and can fully compromise your system. Hundreds of users, mainly in Russia, Brazil, Germany, and Vietnam, have already fallen victim to this threat, dubbed Argamal.

    osintsights.com/malware-hidden

    #MalwareOperations #SupplyChain #EmergingThreats #Russia #Brazil

  14. WeedHack Malware Targets 116,000 Minecraft Systems Worldwide

    Over 116,000 Minecraft systems worldwide have fallen victim to the WeedHack malware campaign since January, with an alarming rate of 2,000 to 3,000 infections daily. This massive operation has spread its reach across the US, Germany, India, and the UK, affecting a staggering number of users.

    osintsights.com/weedhack-malwa

    #WeedhackMalware #Minecraft #EmergingThreats #MalwareOperations #GamingIndustry

  15. WeedHack Malware Infects 116,000 Minecraft Systems Worldwide

    A massive malware campaign, dubbed WeedHack, has infected a staggering 116,464 Minecraft systems worldwide since January, with a whopping 2,000 to 3,000 new infections occurring daily. The widespread attack has hit the US, Germany, India, and the UK the hardest.

    osintsights.com/weedhack-malwa

    #WeedhackMalware #Minecraft #Infostealer #EmergingThreats #MalwareOperations

  16. Malware Worms Red Hat npm Packages, Targets Cloud Credentials

    A single compromised Red Hat employee's GitHub account was used to seed dozens of Red Hat npm package releases with a self-propagating credential-stealer, putting cloud credentials at risk. The malicious packages, downloaded around 80,000 times a week, are still considered a live threat.

    osintsights.com/malware-worms-

    #MalwareOperations #SupplyChain #CloudCredentials #NpmPackages #RedHat

  17. WordPress Sites Targeted in Steam Profile Malware Campaign

    A massive malware campaign has infected nearly 2,000 WordPress websites, using a sneaky tactic of hiding command-and-control data within Steam Community profile comments. The attack, first detected in July 2025, has left security experts scrambling to uncover its entry point.

    osintsights.com/wordpress-site

    #Wordpress #MalwareOperations #SteamProfile #EmergingThreats #WebsiteInfection

  18. Russia-Linked GREYVIBE Exploits AI in Ukraine Cyberattacks

    Discover how the Russia-linked group GREYVIBE is using AI to launch sophisticated cyberattacks on Ukraine, leveraging tactics like spear-phishing emails and fake websites to spread malware. WithSecure researchers have tracked GREYVIBE's activities back to August 2025, revealing a pattern of attacks targeting Ukraine's…

    osintsights.com/russia-linked-

    #RussialinkedGreyvibe #UkraineCyberattacks #NationState #MalwareOperations #Spearphishing

  19. AI-Generated Malware Exposes Operator's GitHub Token

    A malicious npm package, disguised as a harmless sync utility called "mouse5212-super-formatter", was downloaded 676 times before it was caught stealing sensitive data and exposing its creator's GitHub token. This AI-generated malware cleverly hid its true intentions, uploading stolen files to a fake repository and covering its tracks.

    osintsights.com/ai-generated-m

    #AigeneratedMalware #Github #Infostealer #MalwareOperations #Npm

  20. Kimsuky Expands Malware Arsenal with HTTPSpy, HelloDoor

    Kimsuky, a notorious North Korean hacking group, has upgraded its malware arsenal with HTTPSpy and HelloDoor, using clever tactics like fake installation pages and a spoofed Webex meeting to infiltrate targets. The group's latest attacks involve highly tailored social engineering and real-time infection verification to maximize success.

    osintsights.com/kimsuky-expand

    #Kimsuky #NorthKorea #Statesponsored #MalwareOperations #SocialEngineering

  21. Cybercrime Gang Targets Fans with Miner Malware via Pirated Media Sites

    Millions of fans are unwittingly getting hacked when they visit popular pirated media sites, with a staggering 40 million visits to infected sites in April alone. A sneaky malware campaign is using fake video player updates to infect devices with cryptomining and remote-access malware.

    osintsights.com/cybercrime-gan

    #MalwareOperations #MinerMalware #PiratedMedia #Cryptomining #RemoteaccessCampaign

  22. GPU mining malware spreads via SEO poisoning and AI chatbot manipulation

    Beware of a sneaky malware that's spreading through manipulated AI chatbot responses and search engine poisoning, tricking users into downloading GPU mining malware. Victims unknowingly stumble upon malicious links while searching for popular software or getting recommendations from AI assistants.

    osintsights.com/gpu-mining-mal

    #SeoPoisoning #GpuMiningMalware #AiChatbotManipulation #MalwareOperations #EmergingThreats

  23. CrowdStrike Disrupts GlassWorm Malware's Global Supply Chain Attack Infrastructure

    In a major win for cybersecurity, CrowdStrike teamed up with Google and the Shadowserver Foundation to dismantle the global infrastructure behind the GlassWorm malware attack, crippling its ability to issue commands or deliver new payloads to infected machines. This coordinated operation targeted and neutralized…

    osintsights.com/crowdstrike-di

    #Glassworm #MalwareOperations #SupplyChain #EmergingThreats #CicdPipeline

  24. KnowledgeDeliver LMS Flaw Exploited to Deploy Malware

    A security flaw in the KnowledgeDeliver LMS, known as CVE-2026-5426, was exploited by a threat actor to inject malicious code and infect users visiting the site. This vulnerability was caused by a predictable secret in the system's web.config file, allowing attackers to execute remote code.

    osintsights.com/knowledgedeliv

    #RemoteCodeExecution #LmsSecurity #Cve20265426 #MalwareOperations #EmergingThreats

  25. TrapDoor Attack Spreads Credential-Stealing Malware Across Software Ecosystems

    A massive supply chain attack, dubbed TrapDoor, has been spreading credential-stealing malware across three major language ecosystems, infecting over 34 malicious packages and 384 versions. The coordinated campaign began on May 22, 2026, and continues to target developers with cleverly named packages…

    osintsights.com/trapdoor-attac

    #SupplyChain #CredentialstealingMalware #Trapdoor #MalwareOperations #EmergingThreats

  26. GitHub Tags Exploited to Deploy Credential-Stealing Malware

    Malicious actors have manipulated hundreds of GitHub tags to spread credential-stealing malware through popular Laravel Lang localization packages, putting countless users at risk. By rewriting historical tags, attackers tricked Composer installations into downloading the malicious payload.

    osintsights.com/github-tags-ex

    #MalwareOperations #CredentialStealing #Github #Composer #Laravel

  27. Malicious Laravel-Lang Packages Deliver Cross-Platform Credential Stealer

    A massive wave of malicious Laravel-Lang packages, with over 700 versions released in just two days, has been used to spread a sneaky cross-platform credential stealer. Security researchers warn that multiple PHP packages from the Laravel-Lang organization were compromised, hinting at a large-scale breach of the organization's…

    osintsights.com/malicious-lara

    #MalwareOperations #Laravel #CredentialStealer #Php #SupplyChain

  28. Cyber Thieves Exploit SEO to Spread Infostealers via Fake AI Sites

    Cyber thieves are using clever SEO tricks to spread infostealers through fake AI sites, targeting enterprise users and developer workstations with a potent mix of imitation and in-memory malware. This brief but potent campaign has been meticulously planned, with malicious domains deployed as early as March 2026.

    osintsights.com/cyber-thieves-

    #Infostealers #SeoManipulation #EnterpriseSecurity #MalwareOperations #InmemoryMalware

  29. Chinese hackers infiltrate telcos with Showboat, JFMBackdoor malware

    Chinese-aligned hackers have been secretly infiltrating telecommunications providers across Asia Pacific and the Middle East since mid-2022, using sneaky malware like Showboat and JFMBackdoor to stay under the radar. They even used a clever "hide" command to conceal their digital footprints on infected machines.

    osintsights.com/chinese-hacker

    #ChineseHackers #MalwareOperations #Telecommunications #AsiaPacific #MiddleEast

  30. Ukraine Cracks Down on Infostealer Operator Linked to 28,000 Stolen Accounts

    Ukrainian cyberpolice, in collaboration with US law enforcement, have cracked down on an 18-year-old suspect behind a massive infostealer malware campaign that compromised 28,000 accounts, with over 5,800 used for fraudulent activities. The suspect allegedly ran the operation, selling stolen session data from a California…

    osintsights.com/ukraine-cracks

    #Infostealer #Ukraine #EmergingThreats #MalwareOperations #NationState

  31. Microsoft Disrupts Malware-Signing Service Used in Ransomware Attacks

    Microsoft swooped in to shut down a notorious malware-signing service, seizing the website signspace.cloud and taking down hundreds of virtual machines used to fuel ransomware attacks. This bold move, dubbed OpFauxSign, crippled a key operation run by the threat actor Fox Tempest, which had been using Microsoft's own system against…

    osintsights.com/microsoft-disr

    #MalwareOperations #Ransomware #Microsoft #FoxTempest #Opfauxsign

  32. Malvertisers Exploit Code Signing in TamperedChef Malware Campaigns

    Meet the sneaky malware campaign that's been flying under the radar, leveraging polished marketing tactics and code signing to spread its malicious reach - with over 4,000 samples and 100 unique variants uncovered across three distinct clusters of activity.

    osintsights.com/malvertisers-e

    #TamperedchefMalware #CodeSigning #MalwareOperations #Malvertising #PaloAltoNetworks