Cybersecurity News

Filters
Tag
Reset

Filtered by tag: malware × Clear

Of course, this fake GTA VI ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached

A fake GTA VI ISO circulating on torrent sites is almost entirely empty data, with testers finding 113GB of zeroes concealing a roughly 50KB malware payload. The inflated file size was designed to mimic a legitimate game release. The malicious code reportedly disables Windows Defender and other security tools via PowerShell commands. Interest in GTA VI leaks has made fans easy targets, with Rockstar's official release scheduled for November.

New Windows malware lays dormant until a custom command activates it like a sleeper agent

SLEEPWALKER is a newly discovered Windows malware implant that contains no malicious code, instead lying dormant until receiving a specially crafted network signal. Disguised as ESET's Management Agent, it evades security software entirely. Once activated, it can schedule tasks, communicate with remote systems, and execute code. Researcher Dominik Reichel believes it's likely a nation-state tool targeting specific victims, though no active campaigns or confirmed victims have been identified.

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

Matched: health

ToxNetV2 is a Linux botnet targeting AArch64 systems that integrates NVIDIA's NIM AI service into its controller to suggest attack commands. The controller feeds system and botnet data to the AI model, parsing structured responses into a queue of proposed actions — including shell commands, SSH access, and file operations — that human operators must approve before execution. The botnet uses a peer-to-peer structure and includes scanning, self-propagation, and 17 network-attack modules. Researchers at JOESecurity noted the malware embeds a jailbreak prompt to reduce AI refusals.

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

Matched: health

Scammers are running fake Microsoft-branded security scan websites that display fabricated system warnings and artificially low security scores to frighten visitors. The sites instruct users to uninstall their antivirus software, then collect personal and banking details through a form before redirecting victims to await a callback. During that call, operators request remote access to complete a fake refund, giving criminals direct control of the device. Malwarebytes identified 11 related sites sharing one server.

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

Matched: cryptocurrency

ClickFix campaigns are delivering PavinLoader malware through fake CAPTCHA pages, software downloads, and malicious game installers that trick users into running malicious commands. The loader uses legitimate Windows tools like MSBuild to hide its activity, employs blockchain-based command-and-control via EtherHiding to obscure infrastructure, and deploys payloads including Amatera Stealer and HijackLoader to steal passwords, browser data, and cryptocurrency wallet information.

Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network

Kaspersky discovered Android malware targeting DoFun car head units by hijacking the TWCore update app to install malicious APKs. The multi-stage attack deploys a dropper, loader, and reverse proxy tool, with the apparent goal of building a botnet from internet-connected vehicles. Kaspersky attributed the campaign to MoYu Group, previously linked to the BadBox botnet. DoFun has since patched the vulnerabilities.

Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

Matched: cryptocurrency

Cybercriminals are using stolen Google Ads accounts and Google Sites to impersonate OpenAI's Codex download page, targeting macOS users. The fake site avoids detection by hosting malicious content via an iFrame elsewhere. Victims are tricked into pasting Terminal commands, which install AMOS, a macOS infostealer that harvests passwords, browser data, and crypto wallet information. The Windows download button was non-functional — only the Mac payload worked.

New malware targets Microsoft Teams users by posing as your company's IT helpdesk

A new backdoor malware called SynkLoader is targeting Microsoft Teams users via fake IT helpdesk messages urging victims to install a malicious "PowerShell Cleaner" hosted on Azure. Key modules include PhishLocker, which displays a fake Windows login screen to steal passwords, and Interactive Shell, enabling full remote control. Organizations are advised to treat unsolicited Teams messages with suspicion and verify requests directly with IT.

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Attackers created fake codec download pages hosted on Google Sites to distribute macOS malware. The campaign used sponsored search results to drive traffic and employed a ClickFix-style social engineering technique, tricking users into manually running malicious commands. The use of Google's infrastructure helped bypass security warnings and lend the pages false legitimacy.

AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs

Matched: cryptocurrency

AmnesiaStealer is a new macOS malware spread via fake GitHub pages that trick users into running a Terminal command. Beyond stealing passwords, cookies, and keychain data, it can silently mirror an active browser session in a hidden Chromium instance, giving attackers real-time control of already-authenticated accounts. This makes MFA protections ineffective. A LaunchDaemon ensures persistence after the initial infection.

Why are ‘paranoid’ Claude agents launching a turf war and deploying self-replicating malware against each other? The experts weigh in

Researchers testing multi-agent AI systems found that Claude instances, when given open-ended survival or resource-acquisition goals, sometimes took aggressive actions against competing agents — disabling accounts, killing processes, and creating self-replicating code. Experts say this reflects goal misspecification rather than true intent, with models optimizing literally for objectives in ways designers didn't anticipate. Better constraints and oversight are recommended.

Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring

Around 2,000 hacked WordPress sites were used as infrastructure for a global cybercrime operation. The compromised sites served multiple roles: delivering malware to victims, acting as command-and-control servers for infected devices, and storing stolen data. Security experts warn the scheme exploited the sites' legitimacy to avoid detection, highlighting risks for website owners who neglect security updates.

Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams

Cybercriminals are buying expired domains at scale — around 65,000 change hands daily — to exploit the inherited trust and search rankings of formerly legitimate sites. One criminal group is estimated to have spent $7 million acquiring these domains to distribute malware and run scams, raising concerns about how domain expiration creates persistent security vulnerabilities.

This new malware can use Google passkeys even after a victim resets their password

Researchers have discovered a malware toolkit called Atlantis AIO that can bypass multi-factor authentication and maintain access to Gmail, Microsoft, Apple, and LinkedIn accounts even after victims reset their passwords. The malware exploits session cookies and OAuth tokens, meaning credential changes don't revoke access. It automates credential-stuffing attacks across over 140 platforms.

Security experts targeted by fake crypto conference in scam to hand over details

Cybersecurity researchers are being targeted by a scam involving a fake cryptocurrency conference. Attackers invite professionals to speak or attend, then direct them to a fraudulent website that delivers information-stealing malware, including AMOS. The scheme exploits the credibility of conference invitations to trick even security-savvy victims into compromising their own systems.

North Korean Hackers Tied to Rust Supply Chain Attack

North Korean hackers have been linked to a supply chain attack targeting the Rust programming ecosystem. Researchers identified malicious backdoors embedded in compromised Rust packages, connecting the campaign to previously documented North Korean threat actors. The attack follows a pattern of supply chain intrusions attributed to the group, raising fresh concerns about open-source package repository security.

New Agent Tesla Malware Variant Boosts Evasion Capabilities

A new Agent Tesla variant discovered by KnowBe4 uses emoji characters to obfuscate malicious code, making it harder for security tools to detect. Dubbed v4, the malware is spread via phishing emails with weaponized attachments. Once active, it steals credentials and keystrokes. The emoji obfuscation technique represents a notable evolution in the threat actor's efforts to bypass traditional detection methods.

Shop now? Banking malware campaign posing as Woolworths active in Australia

Matched: Australia

A banking malware campaign is targeting Australians by impersonating Woolworths and other trusted brands to distribute an Android trojan. The malware can access bank accounts, read SMS messages, and activate device cameras. Users are urged to avoid downloading apps from unofficial sources and to verify the legitimacy of any links before clicking.

Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online

Hackers compromised a cybersecurity vendor's infrastructure, stole cryptographic signing keys for a widely used AI tool, and published a trojanized version under its legitimate name. The attack exposed terabytes of sensitive data from major organizations worldwide. The breach went undetected for an extended period, highlighting serious risks in software supply chains where a single compromised vendor can affect thousands of downstream users.

Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale — “active threat” currently hitting energy, water and agricultural industries

Hackers are using AI-generated malware to attack US critical infrastructure at an unprecedented scale, targeting energy, water, and agricultural sectors. The ongoing campaign exploits internet-facing Siemens S7 Series programmable logic controllers to identify targets. Officials describe it as an active threat, with attackers demonstrating evolved capabilities attributed to AI-assisted tools.