Sponsor of the Day:
Jerkmate
https://hackread.com/openssf-malware-slack-linux-foundation-figures/
OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures
Apr 13, 2026 - OpenSSF warns hackers impersonate Linux Foundation leaders on Slack, tricking developers into installing malware that can compromise entire systems.
malware campaignlinux foundationopenssfflagsslack
https://securityonline.info/brushworm-brushlogger-malware-financial-sector-usb-airgap/
Inside the BRUSHWORM Malware Campaign Bridging Air-Gaps with USB "Sleeper" Cells
Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER: AI-aided malware using USB drives to steal data from air-gapped financial networks. Update your...
malware campaignsleeper cellsinsidebridgingair
https://www.infosecurity-magazine.com/news/github-covert-multi-stage-malware/
GitHub Used as Covert Channel in Multi-Stage Malware Campaign - Infosecurity Magazine
Apr 3, 2026 - LNK files use GitHub C2, embedded decoders and PowerShell for persistence and data exfiltration
multi stagemalware campaigninfosecurity magazinegithubused
https://gbhackers.com/open-directory-malware/
Obfuscated VBS and PNG Loaders Power New Open Directory Malware Campaign with RAT Payloads
Mar 25, 2026 - A sophisticated, multi-stage delivery framework leveraging obfuscated Visual Basic Script (VBS) files, fileless PowerShell loaders, and payloads hidden within...
power newopen directorymalware campaignobfuscatedvbs
https://www.heise.de/en/news/WhatsApp-malware-campaign-installs-backdoors-11244368.html
WhatsApp malware campaign installs backdoors | heise online
Apr 2, 2026 - Microsoft warns of a malware campaign that delivers malicious software via WhatsApp messages and compromises systems.
whatsapp malwareheise onlinecampaigninstallsbackdoors
https://hashnode.com/posts/nailproxy-space-github-malware-campaign/69e8aa485d1c1071052a3dab
Discussion on "nailproxy.space: A Multi-Repository GitHub Malware Campaign" | Hashnode
malware campaigndiscussionspacemultirepository
https://thehackernews.com/2025/08/clickfix-malware-campaign-exploits.html
ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections
ClickFix malware replaced ClearFake in 2024, infecting users via fake CAPTCHAs and trusted platforms.
clickfix malwarecross platformcampaignexploitscaptchas
https://thehackernews.com/2026/04/uac-0247-targets-ukrainian-clinics-and.html
UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
CERT-UA reports UAC-0247 targeted clinics in March–April 2026, stealing browser and WhatsApp data, enabling lateral movement.
data theftmalware campaignuac0247targets
https://deriv.com/derivtech/feed/brewing-trouble-dissecting-a-macos-malware-campaign
Brewing Trouble — Dissecting a macOS Malware Campaign
How a single alert led our team down a rabbit hole of sophisticated deception —and what we learned about the evolving threat landscape
macos malwarebrewingtroubledissectingcampaign
https://www.cyberdaily.au/security/13514-twisted-firestarter-aussie-us-and-uk-cyber-agencies-warn-of-cisco-malware-campaign
Twisted Firestarter! Aussie, US, UK cyber agencies warn of Cisco malware campaign - Cyber Daily
Firestarter backdoor found targeting Cisco Firepower and Secure Firewall devices despite upgrades.
us ukcyber agenciesmalware campaigntwistedfirestarter
https://cyble.com/blog/miningdropper-global-modular-android-malware/
MiningDropper: A Global Android Malware Campaign
Apr 15, 2026 - Cyble analyzes a surge in an ongoing campaign to deliver MiningDropper — a modular Android malware framework - at scale.
global androidmalware campaign
https://www.csoonline.com/article/4153092/whatsapp-malware-campaign-uses-malicious-vbs-files-to-gain-persistent-access.html
WhatsApp malware campaign uses malicious VBS files to gain persistent access | CSO Online
Apr 1, 2026 - The attack chain relies on delayed execution, trusted Windows utilities, and legitimate hosting services to maintain persistence and evade detection.
whatsapp malwarecampaign usescso onlinemaliciousvbs
https://www.infosecurity-magazine.com/news/malware-campaign-targets-facebook/
Malware Campaign Targets Facebook - Infosecurity Magazine
Mar 22, 2025 - The fake Facebook messages deliver Nivdort, a trojan that interferes with internet connections and allows the installation of ransomware.
malware campaigninfosecurity magazinetargetsfacebook
https://www.mimecast.com/threat-intelligence-hub/strategic-xred-malware-campaign/
XRed Malware Campaign Impersonates Indian Ministry of Finance to Target Multinational Organizations...
A sophisticated XRed malware campaign is targeting multinational organizations by impersonating the Indian Ministry of Finance and Income Tax Department. Using...
malware campaignxredimpersonatesindianministry
https://vpncentral.com/microsoft-teams-phishing-campaign-deploys-new-snow-malware-suite/
Microsoft Teams Phishing Campaign Deploys New “Snow” Malware Suite
Apr 26, 2026 - A newly tracked threat group called UNC6692 is using Microsoft Teams chats to trick employees into installing a custom malware suite named Snow. The campaign...
microsoft teamsphishing campaigndeploys newmalwaresuite
https://thehackernews.com/2024/10/malvertising-campaign-hijacks-facebook.html
Malvertising Campaign Hijacks Facebook Accounts to Spread SYS01stealer Malware
Uncover the latest on SYS01stealer malware and phishing scams abusing platforms like Meta and Eventbrite.
facebook accountsmalvertisingcampaignhijacksspread
https://thecybersecurity.news/general-cyber-security-news/atmzow-js-sniffer-campaign-linked-to-hancitor-malware-21124/
ATMZOW JS Sniffer Campaign Linked to Hancitor Malware | The Cyber Security News
The same menace actors could be guiding both of those the ATMZOW JS sniffer campaign and the Hancitor malware downloader. The link was manufactured early this...
cyber security newsjssniffercampaignlinked
https://www.infosecurity-magazine.com/news/npm-ghost-campaign-fake-install/
New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware - Infosecurity Magazine
Apr 7, 2026 - Ghost npm campaign fakes install logs to steal sudo passwords and drop RATs that loot crypto and data
campaign useshide malwareinfosecurity magazinenewnpm