Cybersecurity News
Filters
Filtered by tag: malware × Clear
15 Malicious Firefox Extensions Abuse Cloudflare Workers to Exfiltrate Crypto Wallet Secrets
Matched: cryptocurrency
Fifteen malicious Firefox extensions posing as crypto wallets, themes, and browser tools have been stealing recovery phrases, private keys, login credentials, and clipboard data since at least March 2026. The campaign uses Cloudflare Workers to exfiltrate stolen information and spans 77 extensions total, putting users' digital assets and online accounts at serious risk.
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Matched: cryptocurrency
Researchers found 40 malicious Firefox extensions disguised as Web3 products like OKX and Rabby Wallet that steal cryptocurrency wallet credentials. Dubbed "Offside Wallet Theft Factory" by Socket Threat Research, the extensions are part of a broader group of 77 add-ons sharing code and infrastructure. Users are advised to verify extensions carefully before installing.
Microsoft smothers malware by tracking behavior instead of blocking domains
Microsoft has shifted its malware defense strategy from blocking malicious domains to tracking behavioral patterns. Because attackers can rapidly automate new domains to replace blocked ones, domain-blocking proves ineffective. By monitoring how malware behaves rather than where it connects, Microsoft aims to identify and neutralize threats more reliably, staying ahead of attackers who exploit the limitations of domain-based defenses.
Geekom reveals multiple mini-PCs may be infected with malware hidden in a network driver — but it's now down to you to fix your PC
Geekom has confirmed that several of its mini-PC models shipped with malware embedded in a network driver. The malicious executable can log keystrokes, intercept data, and steal passwords. The company has acknowledged the issue but is placing responsibility on users to manually remove the malware themselves, rather than issuing an automatic fix or patch.
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Researchers at Check Point identified a ransomware operation called StopAndProtect in May 2026. The campaign uses the ClickFix social-engineering technique to trick victims into running a PowerShell command, triggering a multi-stage downloader chain. Thousands of hacked WordPress sites serve as infrastructure for the operation, which researchers have now partially unmasked through analysis of its infection chain and supporting infrastructure.
Ransomware gang crashes own attack — with no-one to blame but themselves
Ransomware group Akira accidentally sabotaged its own attack after using a driver exploit to disable endpoint detection software — the same technique also killed their encryption tool. Researchers noted the self-inflicted failure but warned the tactic of using vulnerable drivers to bypass security is increasingly common and remains a serious threat even when, as here, it backfires on the attackers.
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Matched: cryptocurrency
Attackers posing as Web3 recruiters on LinkedIn lured cryptocurrency professionals into fake job interviews, ultimately tricking Windows users into installing malware via a signed ClickOnce application. The infection deployed NeedleStealer, which harvested private keys and browser data, alongside an hVNC remote access trojan. The campaign used Calendly scheduling and technical assessments to appear legitimate.
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
Matched: cryptocurrency
China-linked threat actor Jewelbug conducts cyber espionage against governments and militaries while also running cryptocurrency fraud operations. Both activities are managed through a single control panel called XG-Web, a browser-based framework that converts victims' browsers into remote-control tools for data theft and access.
Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes
Cybercriminals are targeting Android users with malware called WindRelay, which can clone contactless payment cards in around 13 minutes. Attackers phone victims, trick them into installing the malicious app, then use it to capture card data via the phone's NFC chip. The stolen information is relayed to a criminal-controlled device to make fraudulent payments.
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Matched: cryptocurrency
Phantom Stealer is a credential-stealing malware that conceals malicious code inside PNG image files to avoid detection. Once executed on Windows systems, it harvests passwords, browser cookies, cryptocurrency wallet data, and other sensitive information. The malware has been used in campaigns targeting users across multiple countries.
Akira Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate attempted to bypass endpoint detection by rebooting a victim's system into Safe Mode, which prevents most security tools from loading. The tactic backfired when Safe Mode also blocked their own ransomware from executing properly. Researchers documented the full attack chain, highlighting how threat actors are adapting techniques against modern EDR solutions, sometimes with self-defeating results.
Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram
Matched: cryptocurrency
A malicious VS Code extension called Solidity Pro has been discovered stealing cryptocurrency wallet data, API keys, and SSH keys from developers. Disguised as a legitimate Solidity development tool with polished documentation, the extension exfiltrates stolen data via Telegram. The attack highlights how convincing branding and familiar tooling can lower developers' guard against supply chain threats.
Aussies looking for pirated versions of the Odyssey could be walking into a cyber-trap
Matched: Australia
Australians searching for pirated copies of Christopher Nolan's film *Odyssey* risk downloading malware that steals personal data. Cybersecurity experts warn that files posing as the movie may contain malicious software designed to harvest sensitive information from users' devices.
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Matched: cryptocurrency
A ClickFix-style attack campaign is targeting macOS users with Go-based malware that steals cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script to profile the host before delivering a CPU-compatible payload, allowing attackers to drain crypto wallets and harvest sensitive data from compromised machines.
One Fake Movie Download Can Expose Passwords, Payments and Crypto Assets
Matched: cryptocurrency
Cybercriminals are distributing fake downloads of the 2026 film "The Odyssey" to spread Lumma Stealer malware. Once executed, it silently harvests saved browser passwords, payment card details, and cryptocurrency wallets from infected systems. Researchers identified the campaign within days of the film's release, exploiting its popularity to lure victims seeking pirated copies.
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A Mac user was tricked by a fake CAPTCHA prompt into running a Terminal command that installed Go-based malware. The attack, a variant of the ClickFix scam, gave attackers access to macOS Keychain passwords and cryptocurrency wallets. Security researchers warn the technique is growing more common and targets users across platforms.
Bank of America Phishing Email Delivers ScreenConnect Malware
A phishing campaign impersonating Bank of America delivers ScreenConnect remote access malware through a multi-stage infection chain. The convincing fake emails trick recipients into actions that ultimately install the legitimate remote access tool, which attackers abuse to control victims' systems. The campaign highlights how cybercriminals exploit trusted brand names and repurpose legitimate software to evade detection.
North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
Matched: cryptocurrency
North Korean hackers are using fake macOS update screens to deploy malware targeting cryptocurrency wallets, browser data, and developer credentials. The campaign uses a ClickFix-style lure that makes browser pages appear broken, prompting users to run malicious commands. Entry points include routine web searches, making the attack difficult to detect.
Every Ransomware Attack Has a Backstory
Ransomware attacks don't begin with encryption — they start long before, often with access brokers selling stolen credentials or network entry points to attackers. Criminals then use legitimate tools already present in the environment to move quietly through systems, avoiding detection. By the time ransomware deploys, attackers may have been inside for weeks. Stopping them requires catching intrusions early, before the final stage.
Threat Actors Achieve Persistence After SQL Injection
Attackers exploited SQL injection vulnerabilities to compromise IIS servers, deploying the BadIIS malware to gain persistence. Once inside, they disabled Windows Defender to avoid detection, then silently installed a cryptominer to hijack system resources. The attack highlights how unpatched web application vulnerabilities can serve as entry points for multi-stage intrusions with lasting impact.
