Atomic macOS (AMOS) Stealer Activity

This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August Read More …

Iranian Cyber Targeting of Dissidents, Activists and Journalists

CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a Read More …

A new Android attack combines malware and ransomware in a cocktail of cybercrime

Unique malware variant spotted targeting Android users. When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. Rarely do we see all Read More …

Dissecting a PHP web server rootkit

SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while Read More …

Angry Birds: Toy Ghouls’ new toys

Kaspersky continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along Read More …

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

While monitoring Mirage Kitten activity, Kaspersky researchers uncovered a previously undocumented malware family that we dubbed NodeRabbit. The researchers identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a Read More …

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell Read More …

The invisible passenger in your car

While monitoring Android threats in June 2026, Kaspersky discovered a new piece of Android malware. What struck the researchers as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: Read More …

ChainDrop worm crawls into npm supply chain, evades standard defenses

A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave little trace in the corresponding source repositories. In Frank Herbert’s Dune, Shai-Hulud was the name of the giant self-sustaining desert Read More …

APT group HoneyMyte upgrades CoolClient

CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, Read More …