Robuta

Sponsor of the Day: Jerkmate
https://hackread.com/openssf-malware-slack-linux-foundation-figures/ OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures Apr 13, 2026 - OpenSSF warns hackers impersonate Linux Foundation leaders on Slack, tricking developers into installing malware that can compromise entire systems. malware campaignlinux foundationopenssfflagsslack https://securityonline.info/brushworm-brushlogger-malware-financial-sector-usb-airgap/ Inside the BRUSHWORM Malware Campaign Bridging Air-Gaps with USB "Sleeper" Cells Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER: AI-aided malware using USB drives to steal data from air-gapped financial networks. Update your... malware campaignsleeper cellsinsidebridgingair https://www.infosecurity-magazine.com/news/github-covert-multi-stage-malware/ GitHub Used as Covert Channel in Multi-Stage Malware Campaign - Infosecurity Magazine Apr 3, 2026 - LNK files use GitHub C2, embedded decoders and PowerShell for persistence and data exfiltration multi stagemalware campaigninfosecurity magazinegithubused https://gbhackers.com/open-directory-malware/ Obfuscated VBS and PNG Loaders Power New Open Directory Malware Campaign with RAT Payloads Mar 25, 2026 - A sophisticated, multi-stage delivery framework leveraging obfuscated Visual Basic Script (VBS) files, fileless PowerShell loaders, and payloads hidden within... power newopen directorymalware campaignobfuscatedvbs https://www.heise.de/en/news/WhatsApp-malware-campaign-installs-backdoors-11244368.html WhatsApp malware campaign installs backdoors | heise online Apr 2, 2026 - Microsoft warns of a malware campaign that delivers malicious software via WhatsApp messages and compromises systems. whatsapp malwareheise onlinecampaigninstallsbackdoors https://hashnode.com/posts/nailproxy-space-github-malware-campaign/69e8aa485d1c1071052a3dab Discussion on "nailproxy.space: A Multi-Repository GitHub Malware Campaign" | Hashnode malware campaigndiscussionspacemultirepository https://thehackernews.com/2025/08/clickfix-malware-campaign-exploits.html ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections ClickFix malware replaced ClearFake in 2024, infecting users via fake CAPTCHAs and trusted platforms. clickfix malwarecross platformcampaignexploitscaptchas https://thehackernews.com/2026/04/uac-0247-targets-ukrainian-clinics-and.html UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign CERT-UA reports UAC-0247 targeted clinics in March–April 2026, stealing browser and WhatsApp data, enabling lateral movement. data theftmalware campaignuac0247targets https://deriv.com/derivtech/feed/brewing-trouble-dissecting-a-macos-malware-campaign Brewing Trouble — Dissecting a macOS Malware Campaign How a single alert led our team down a rabbit hole of sophisticated deception —and what we learned about the evolving threat landscape macos malwarebrewingtroubledissectingcampaign https://www.cyberdaily.au/security/13514-twisted-firestarter-aussie-us-and-uk-cyber-agencies-warn-of-cisco-malware-campaign Twisted Firestarter! Aussie, US, UK cyber agencies warn of Cisco malware campaign - Cyber Daily Firestarter backdoor found targeting Cisco Firepower and Secure Firewall devices despite upgrades. us ukcyber agenciesmalware campaigntwistedfirestarter https://cyble.com/blog/miningdropper-global-modular-android-malware/ MiningDropper: A Global Android Malware Campaign Apr 15, 2026 - Cyble analyzes a surge in an ongoing campaign to deliver MiningDropper — a modular Android malware framework - at scale. global androidmalware campaign https://www.csoonline.com/article/4153092/whatsapp-malware-campaign-uses-malicious-vbs-files-to-gain-persistent-access.html WhatsApp malware campaign uses malicious VBS files to gain persistent access | CSO Online Apr 1, 2026 - The attack chain relies on delayed execution, trusted Windows utilities, and legitimate hosting services to maintain persistence and evade detection. whatsapp malwarecampaign usescso onlinemaliciousvbs https://www.infosecurity-magazine.com/news/malware-campaign-targets-facebook/ Malware Campaign Targets Facebook - Infosecurity Magazine Mar 22, 2025 - The fake Facebook messages deliver Nivdort, a trojan that interferes with internet connections and allows the installation of ransomware. malware campaigninfosecurity magazinetargetsfacebook https://www.mimecast.com/threat-intelligence-hub/strategic-xred-malware-campaign/ XRed Malware Campaign Impersonates Indian Ministry of Finance to Target Multinational Organizations... A sophisticated XRed malware campaign is targeting multinational organizations by impersonating the Indian Ministry of Finance and Income Tax Department. Using... malware campaignxredimpersonatesindianministry https://vpncentral.com/microsoft-teams-phishing-campaign-deploys-new-snow-malware-suite/ Microsoft Teams Phishing Campaign Deploys New “Snow” Malware Suite Apr 26, 2026 - A newly tracked threat group called UNC6692 is using Microsoft Teams chats to trick employees into installing a custom malware suite named Snow. The campaign... microsoft teamsphishing campaigndeploys newmalwaresuite https://thehackernews.com/2024/10/malvertising-campaign-hijacks-facebook.html Malvertising Campaign Hijacks Facebook Accounts to Spread SYS01stealer Malware Uncover the latest on SYS01stealer malware and phishing scams abusing platforms like Meta and Eventbrite. facebook accountsmalvertisingcampaignhijacksspread https://thecybersecurity.news/general-cyber-security-news/atmzow-js-sniffer-campaign-linked-to-hancitor-malware-21124/ ATMZOW JS Sniffer Campaign Linked to Hancitor Malware | The Cyber Security News The same menace actors could be guiding both of those the ATMZOW JS sniffer campaign and the Hancitor malware downloader. The link was manufactured early this... cyber security newsjssniffercampaignlinked https://www.infosecurity-magazine.com/news/npm-ghost-campaign-fake-install/ New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware - Infosecurity Magazine Apr 7, 2026 - Ghost npm campaign fakes install logs to steal sudo passwords and drop RATs that loot crypto and data campaign useshide malwareinfosecurity magazinenewnpm