Malware 2026    2026()  2025()  2024()  2023()  2022()  OTHER() 2020  2019  2018  2017  2016  2015  2014  2013  2012  2011  2010  2009  2008
Viry znalosti  MALWARE DATABAZE  Programy  MALWARE TRAFFIC | PODLE ROKŮ | PODLE MĚSÍCŮ | PODLE ABECEDY | PODLE SUBKATEGORIE


January(0) February(0) March(0) April(0) May(0) June(0) July(0) August(0) September(0) October(0) November(0) December(0) YEARS


DATE

NAME

INFO

CATEGORY

SUBCATE

3.10.26

CloudSyncD CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode MALWARE MACOS

3.10.26

SmokeLoader This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of SmokeLoader malware. This is a modular program used by a variety of criminal and APT groups to gain a foothold on a system. It has vigorous anti-VM, anti-AV, and anti-analysis checks and capabilities. SmokeLoader can be used with RATs, ransomware, backdoors or botnets and uses both file and fileless methods of persistence. MALWARE LOADER

3.10.26

VioletRAT v6.5 Recently, the SonicWall Capture Labs Threat Research Team discovered a sophisticated multi-stage .NET malware campaign that delivers VioletRAT v6.5 through a heavily obfuscated infection chain. The malware uses multiple .NET loader stages, an obfuscated batch script, in-memory assembly loading, and process injection into Msbuild.exe before executing the final VioletRAT payload. MALWARE RAT

2.10.26

SC WordPress Malware SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor MALWARE LOADER

30.9.26

JSCEAL JSCEAL is malware that operates using the Node.Js environment. Threat actors entice users to click by advertising that installing the official program of a cryptocurrency exchange will result in rewards such as cryptocurrency. This malware attack is not limited to a specific time frame but has continued to target users in Korea up until recently. MALWARE JS

30.9.26

TOPHIT Part 2 CloudSEK found an attacker's control panel targeting vast.ai, a GPU rental marketplace. It rents containers beside victims to scan their networks. It reached one unprotected notebook and planted no miners. The panel exposed its own source code. MALWARE PYTHON

30.9.26

TOPHIT Part 1 CloudSEK found 85 malicious npm packages, published in three minutes, likely named to surface in search when developers mistype popular libraries. They give attackers remote command access. The same server hosts a GPU-hijacking panel. No victims confirmed. MALWARE PYTHON

30.9.26

MALFEX CloudSEK uncovered MALFEX, a long-running npm supply-chain campaign linked to a single operator, using malicious packages to deploy RATs and credential stealers. Two packages remain installable, including one malicious postinstall that evaded advisories for 14 months. MALWARE PYTHON

30.9.26

PhantomSub PhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels MALWARE PYTHON

29.9.26

NeedyMantis NeedyMantis: Unpacking a post-compromise malware family used in targeted operations MALWARE MALWARE

27.9.26

Lunex Lunex Unmasked: A New Information Stealer Deployed Through BYOVD MALWARE STEALER

26.9.26

ZionSiphon Inside ZionSiphon: Darktrace’s Analysis of OT Malware Targeting Israeli Water Systems MALWARE OT

26.9.26

Rokarolla The Rokarolla Android banking trojan combines fake login screens, message collection, and remote device interaction. With the required permissions, it can steal credentials and manipulate legitimate app interfaces. MALWARE ANDROID

26.9.26

SLEEPWALKER Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my “TODO” pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. MALWARE BACKDOOR

26.9.26

GHAPPIER CloudSEK researchers uncovered GHAPPIER, a previously unreported loader operation spanning at least 65 public repositories, 73 infected files and 22 accounts. The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted publishing. MALWARE LOADER

26.9.26

SleepyDuck In November 2025, we analyzed a small backdoor loose on Open VSX. SleepyDuck was unremarkable in every way but one: its header was an ASCII-art duck, and its C2 was a Solana smart contract the loader polled for tasking. It was a JavaScript file, a few kilobytes, executing fetched code in memory — a toy with a mascot. MALWARE BACKDOOR

26.9.26

AvisLoader Varonis Threat Labs discovered AvisLoader, a new Windows malware loader built to keep its command-and-control (C2) channel beyond the reach of traditional domain takedowns. MALWARE LOADER

25.9.26

PamStealer PamStealer adapts again: a move to Swift with a server-side decryption chain MALWARE INFOSTEALER

25.9.26

Psychedelic Stealer The Psychedelic Stealer: When a CAPTCHA Becomes an Installer MALWARE STEALER

24.9.26

sckit sckit, also known as the “supplychain.local worm”, is a Go implant framework that we found in two MemTensor packages on September 23, 2026. It runs on Linux, macOS, and Windows. MALWARE GO

24.9.26

RemControl Group-IB researchers have discovered a previously undocumented Android banking trojan, internally named RemControl by its operator, targeting retail banking customers across Western Europe, the Middle East, and Canada. MALWARE ANDROID AI

23.9.26

DarkMe RAT Huntress spotted the DarkMe malware in two separate incidents affecting different organizations on August 31, 2026. MALWARE RAT

23.9.26

ClosedQuorum CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025. MALWARE AI

22.9.26

TASK#STOMP TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access MALWARE BACKDOOR

21.9.26

ChainScript ChainScript: Tracing a Node.js RAT Through the Blockchain MALWARE RAT

19.9.26

SpiceRAT Disclosure note: ahead of publishing this research on September 9, 2026, we notified the affected organizations and the relevant national CERTs, sharing a TLP:AMBER advance copy and holding publication to allow review. MALWARE RAT

19.9.26

LabubaRAT LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan (RAT) identified by the Blackpoint Adversary Pursuit Group (APG), designed to masquerade as legitimate NVIDIA software while providing a full remote access feature set including command execution, file operations, screen capture, and SOCKS5 proxying. MALWARE RAT

19.9.26

SpiceRAT Disclosure note: ahead of publishing this research on September 9, 2026, we notified the affected organizations and the relevant national CERTs, sharing a TLP:AMBER advance copy and holding publication to allow review. MALWARE RAT

19.9.26

PhantomRaven CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software. MALWARE JS

19.9.26

TeleClip SonicWall Capture Labs threat researchers have been tracking a Telegram bot malware capable of silently stealing cryptocurrency. The malware is a cryptocurrency clipboard hijacker and keylogger written in C (GCC/MinGW, native 64-bit PE). MALWARE BOT

19.9.26

Atomic macOS This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. MALWARE MACOS

18.9.26

WeaselBiscuit WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials MALWARE INFOSTEALER

18.9.26

RatHat The zLabs team has uncovered RatHat, a novel Android malware strain linked to threat actors that appear to be operating in China. RatHat incorporates novel techniques for persistence and leverage generative AI for operational control. MALWARE ANDROID AI

17.9.26

CHOSEN BRICK Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves. MALWARE BOT

17.9.26

HEAVYGRAM HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack MALWARE BACKDOOR

17.9.26

MovieReaper Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. MALWARE TROJAN

16.9.26

KREMLIN The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions MALWARE BANKING

15.9.26

VectraRAT SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt. MALWARE RAT

12.9.26

Casbaneiro In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. MALWARE BANKING

12.9.26

SloppyRAT In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. MALWARE RAT

12.9.26

MacSync Executive Summary MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines.... MALWARE MACOS

12.9.26

Gray Rabbits One click. Three critical failures. One backdoor. MALWARE BACKDOOR

12.9.26

GuardBreaker LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor MALWARE AI

12.9.26

Casbaneiro In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. MALWARE BANKING

12.9.26

SloppyRAT In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. MALWARE RAT

12.9.26

MacSync Executive Summary MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines.... MALWARE MACOS

12.9.26

Gray Rabbits One click. Three critical failures. One backdoor. MALWARE BACKDOOR

12.9.26

GuardBreaker LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor MALWARE AI

11.9.26

Hagaseca Hagaseca: Inside a Packed Android RAT Loader MALWARE RAT

10.9.26

Gigabud Vwork: Weaponized Open-source Software as an Addon for Gigabud MALWARE ANDROID

8.9.26

Syslogk Rootkit Detection and Removal of the Syslogk Rootkit in a Linux Environment MALWARE ROOTKIT

8.9.26

HVNC Backdoor HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures MALWARE BACKDOOR

8.9.26

WeWorm The first zero-click worm to spread through WeChat calls across iOS and Android. MALWARE WORM

7.9.26

JSCeal Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode MALWARE JAVASCRIPT

6.9.26

REVSTEALER Elastic Security Labs deep dives into REVSTEALER, an emerging infostealer targeting browsers, wallets, and gaming accounts. MALWARE STEALER

4.9.26

ted backdoor DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors MALWARE BACKDOOR

3.9.26

BraZetsu Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets. MALWARE PYTHON

2.9.26

Mirax Mirax: a new Android RAT turning infected devices into potential residential proxy nodes MALWARE RAT

2.9.26

StreamRat Uncovering StreamRat: From Meta Ads to Full Device Takeover MALWARE RAT

31.8.26

BraZetsu Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets. MALWARE PYTHON
28.8.26 Spark RAT Cambodia-focused cluster uses multistage infection chain with localized lures MALWARE RAT
28.8.26 Dark Caracal During a targeted intrusion investigation, Arctic Wolf uncovered GoCaracal, a previously undocumented, modular framework written in Go. Its long-term development offers new insight into the evolution of Dark Caracal’s capabilities, operations, and tradecraft. MALWARE GO
26.8.26 SLEEPWALKER SLEEPWALKER: A Passive Backdoor With Its Own Command Language MALWARE BACKDOOR
24.8.26  WordlistLoader  WordlistLoader Delivering Amatera via ClearFake Campaigns MALWARE LOADER
24.8.26 Amatera Stealer 4.0.2 Amatera Stealer 4.0.2 Beta: What's New in This Variant MALWARE STEALER
23.8.26 SynkLoader SynkLoader: when you throw in everything but the kitchen sink MALWARE LOADER

20.8.26

Manic Manic: Blend between Banking Malware & Spyware MALWARE BANKING

20.8.26

ToxicPanda The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile MALWARE ANDROID

20.8.26

GoldDigger Striking gold: Inside the GoldDigger Android malware MALWARE ANDROID

19.8.26

NodeEdgeRAT (JavaScript), which ships its entire functionality spanning command execution, file management, and file transfer in one script. MALWARE RAT

19.8.26

GoginRAT (Go), which has architectural similarities with NomadRAT and uses a separate transmitter for C2, and implements file system and shell capabilities as independent plugins. The results of the plugin execution are routed through a shared callback. MALWARE RAT

19.8.26

NomadRAT (C++), which features a main orchestrator, a dedicated transmitter library that handles all C2 traffic, and plugins fetched from the server by numeric identifiers only when they are required. MALWARE RAT

19.8.26

CookiETagRAT (C++), which uses HTTP Cookie / ETag response headers as C2 to receive and execute commands. MALWARE RAT

19.8.26

DriveSilkRAT (.NET/C++), which uses Google Drive as command-and-control (C2) to poll a specific folder for tasking, run it through an in-memory .NET plugin system, and upload the results of the execution back to the same folder. It supports 12 plugins for process listing, system and network enumeration, file management, and command execution. MALWARE RAT

19.8.26

MacSync Stealer On 5 May 2026, an RST Cloud customer’s Jamf Protect blocked a download from jacksonvillemma[.]com. Four days earlier, the operator’s prior MacSync C2 had been publicly disclosed. Twenty-four hours after that disclosure, the new C2’s TLS certificate had been issued. Three days later, the new C2 was attempting to deliver its loader to a managed endpoint in our customer’s estate. MALWARE STEALER

18.8.26

HOLLOWGRAPH HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels MALWARE MALWARE

14.8.26

WindRelay Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme MALWARE RAT/NFC

14.8.26

PATCHCORD PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure MALWARE BACKDOOR

14.8.26

AmnesiaStealer AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers MALWARE STEALER

14.8.26

WindRelay Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme MALWARE RAT/NFC

14.8.26

PATCHCORD PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure MALWARE BACKDOOR

14.8.26

AmnesiaStealer AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers MALWARE STEALER

10.8.26

WhiteCobra Chassis Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer MALWARE STEALER

8.8.26

MythStealer A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. MALWARE STEALER

6.8.26

ENDLESSDOORS ENDLESSDOORS Is Phoning Home. Pick Up. MALWARE MALWARE

4.8.26

Fake Xeno Roblox Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums MALWARE JAVA

4.8.26

DOUBLECUP Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs MALWARE LOADER

2.8.26

VirtualGHOST A "VirtualGHOST" (or just Ghost) is a VMware Virtual Machine on an ESXi host that has been powered on manually from the command line. MALWARE VMware ESXi

1.8.26

Matryoshka Nested Trust: HollowFrame’s Layered Loader and Matryoshka Backdoors MALWARE Backdoor

30.7.26

SilkLurk OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia MALWARE BACKDOOR

30.7.26

OctLurk OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia MALWARE BACKDOOR

30.7.26

SIGNBT Detailed Analysis of SIGNBT Malware Cluster MALWARE CLUSTER

30.7.26

AtlasRAT Not Every Fox is Silver: Inside an AtlasRAT loader chain MALWARE RAT

30.7.26

AtlasRAT Not Every Fox is Silver: Inside an AtlasRAT loader chain MALWARE RAT

29.7.26

Flying Eagle Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon MALWARE ANDROID RAT

29.7.26

DEV#POPPER Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan MALWARE RAT

28.7.26

MedusaHVNC A Hidden Desktop That Steals Live Windows Sessions MALWARE RAT

28.7.26

AutoIT For a long time, AutoIT has been pretty common in the malware ecosystem. Threat actors still use it because it’s easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you’ll see below. MALWARE INJECTOR

28.7.26

NightLedger backdoor NightLedger is a recently identified Windows backdoor that we attribute to Mirage Kitten based on code and behavioral similarities to the historical implants developed and used by the group. The implant masquerades as SspiCli.dll and appears to be designed for DLL search-order hijacking, targeting a legitimate AppVShNotify.exe binary. MALWARE BACKDOOR

23.7.26

msaRAT Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel MALWARE RAT

21.7.26

Backdoor.Win32.TOFSEE.VSNTGE26 This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. MALWARE BACKDOOR

21.7.26

Trojan.Win64.COROXY.A This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It does not have any propagation routine. MALWARE TROJAN

21.7.26

TrojanSpy.Win32.XTRAT.A This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It does not have any propagation routine. MALWARE TROJAN

20.7.26

HOLLOWGRAPH HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels MALWARE BACKDOOR

18.7.26

BoryptGrab Malicious GitHub Campaign: Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer MALWARE INFOSTEALER

18.7.26

ChainVeil Sequel to ChainVeil npm Malware Targets Vite Ecosystem MALWARE PYTHON

18.7.26

Starland RAT Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. MALWARE RAT
17.7.26 ACR Stealer ACR Stealer: Two observed intrusion chains amid increased threat activity MALWARE STEALER
17.7.26 GoSerpent GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration MALWARE BACKDOOR
16.7.26 TELEPUZ TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains MALWARE MaaS
16.7.26 ClickLock Stealer ClickLock Stealer: Paste Once, Lose Everything MALWARE STEALER
16.7.26 Anti-Ledger “Anti-Ledger” malware: The battle for Ledger Live seed phrases MALWARE CRYPTOCURRENCY
16.7.26 Daxin Returns Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor MALWARE BACKDOOR
16.7.26 OkoBot OkoBot: new sophisticated malware framework targets cryptocurrency users MALWARE FRAMEWORK
16.7.26 Miasma RAT AsyncAPI Packages Compromised with Miasma RAT MALWARE RAT
14.7.26 LabubaRAT LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software MALWARE RAT
13.7.26 CrashStealer CrashStealer: C++ macOS infostealer posing as crash reporter MALWARE MacOS
13.7.26 ModHeader Malware ModHeader Malware: Inside the Chrome Spyware Google Removed MALWARE Spyware
13.7.26 SpAIware Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware) MALWARE SpAIware
10.7.26 BLUERABBIT BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive Capabilities MALWARE BACKDOOR
10.7.26 GigaWiper GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware MALWARE WIPPER
8.7.26 UAT-7810 UAT-7810 continues building ORB networks using new malware MALWARE BANKING
8.7.26 Oblivion Oblivion: The New $300 Android RAT That Beats Every Major Phone Manufacturer’s Security MALWARE RAT
8.7.26 RedWing RedWing: A Mobile Malware-as-a-Service Operation MALWARE ANDROID
7.7.26 DEBULL DEBULL: Storm-2372-Style Microsoft Device-Code Phishing With GraphSpy Post-Exploitation MALWARE TOOL
7.7.26 Vshell Vshell: A Chinese-Language Alternative to Cobalt Strike MALWARE TOOL
6.7.26 QuimaRAT Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux MALWARE RAT
5.7.26 ChocoPoC This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments. MALWARE RAT
4.7.26 Avalon New Avalon Malware Framework MALWARE FRAMEWORK
4.7.26 Glitch SPY CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control. MALWARE RAT
4.7.26 Banana RAT In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. MALWARE RAT
4.7.26 Void Dokkaebi’s Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. MALWARE STEALER
4.7.26 TONResolver RAT In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. MALWARE ANDROID
4.7.26 Arsink RAT The SonicWall Capture Labs threat research team identified an ongoing Android Remote Access Trojan (RAT) campaign that employs multiple techniques to harvest sensitive user information through phishing and data exfiltration activities by impersonating the actual app icons and using similar names. MALWARE ANDROID
3.7.26 BusySnake Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign MALWARE STEALER
3.7.26 PamStealer PamStealer: a Rust-based macOS infostealer that validates credentials through PAM MALWARE STEALER
2.7.26 AsyncRAT Reloaded AsyncRAT Reloaded: Using Python and TryCloudflare for Malware Delivery Again MALWARE RAT
2.7.26 Veil#Drop Veil#Drop: Blogspot-Hosted PowerShell Loader Delivers PureLog Stealer Through XOR-Encoded In-Memory .NET Payloads MALWARE LOADER
30.6.26 Silent Swap Silent Swap: A Crypto Clipper Extension Campaign MALWARE CRYPTO CLIPPER
30.6.26 TaskWeaver is a heavily obfuscated Node.js loader, delivered as jquery.js and executed through node.exe, that implements an encrypted, reusable payload delivery channel rather than a fixed set of post exploitation commands. MALWARE JAVASCRIPT
30.6.26 Djinn Stealer The observed second stage payload, Djinn Stealer, targets Windows, macOS, and Linux systems. MALWARE STEALER
29.6.26 MLTBackdoor In May 2026, Zscaler ThreatLabz identified a new malware family that we track as MLTBackdoor that is likely leveraged by a ransomware-related threat actor. MLTBackdoor has been observed by ThreatLabz being delivered in a multi-stage ClickFix infection chain. MALWARE BACKDOOR
27.6.26 StrikeShark StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader MALWARE LOADER
25.6.26 macOS.Gaslight macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox MALWARE MAC OS
25.6.26 Backdoor.Mistic Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker MALWARE BACKDOOR
22.6.26 CASTLESTEALER Lost in relocation: analysis of a new loader distributing CASTLESTEALER MALWARE STEALER
18.6.26 Crypto Clipper Crypto Clipper uses Tor and worm-like propagation for persistence and control MALWARE CLIPPER
17.6.26 Potemkin Someone's Hands Are on Your Keyboard Then Your Whole Network. Courtesy of ClickFix, Potemkin, RMMProject and EtherRAT MALWARE Loader
17.6.26 BabaDeda Loader What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign MALWARE Loader
16.6.26 Rokarolla Rokarolla : Android Banker with Complete Device Takeover Capabilities MALWARE BANKING
16.6.26 SprySOCKS FishMonger’s arsenal upgraded: SprySOCKS for Windows MALWARE BACKDOOR
16.6.26 NarwhalRAT Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2 MALWARE RAT
14.6.26 NFCShare NFCShare Android Trojan: NFC card data theft via malicious APK MALWARE ANDROID
8.6.26 Fighting Spyware WhatsApp caught and disrupted spear phishing attempts linked to NSO, a spyware firm blacklisted by the US government. MALWARE SPYWARE
7.6.26 Atlas RAT TA4922: The Suspected Chinese Crime Group is Going Global MALWARE RAT
6.6.26 Miasma Worm Miasma Worm Targets AI Coding Agents via GitHub Repos MALWARE WORM
6.6.26 IronWorm IronWorm: Shai-Hulud's rustier cousin MALWARE WORM
6.6.26 OverlayPhantom Cyble analyzes OverlayPhantom, an Android banking trojan targeting 180+ apps across 10 countries, stealing credentials via fake overlays and real-time screen streaming. MALWARE BANKING
5.6.26 Argamal In April 2026, we discovered a new malware campaign targeting players of “hentai” games. Once launched, the infected games install a previously unknown malicious implant on the user’s machine. MALWARE RAT
4.6.26 Calendaromatic Kroll has seen widespread installation of application, "Calendaromatic", which is classifying as a Potentially Unwanted Program (PUP) – Adware. MALWARE PUP
4.6.26 JSCoreRunner New malware JSCoreRunner is spreading via fake PDF converters MALWARE JS
4.6.26 DesckVB RAT DesckVB RAT first emerged around February 2026 and has been making the rounds ever since. The activity originated from a malspam kit. MALWARE RAT
3.6.26 Stealthy Loader A Missing Piece in PlushDaemon: Anatomy of a Stealthy Loader MALWARE LOADER
3.6.26 PixyNetLoader Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 MALWARE LOADER
1.6.26 TencShell Cato CTRL Threat Research: Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware MALWARE RAT
29.5.26 TrollAgent TrollAgent (Kimsuky Group) infected during the security program installation process MALWARE TROJAN
27.5.26 BTMOB BTMOB: A stealthy RAT burrowing deep into Android devices MALWARE RAT
27.5.26 Glassworm Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet MALWARE WORM
25.5.26 RemotePE RemotePE: The Lazarus RAT that lives in memory MALWARE RAT
25.5.26 TrapDoor TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io MALWARE CRYPTO
23.5.26 SHub SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain MALWARE MacOS
23.5.26 NPM Stealer I found a Node.js stealer that looked pretty well obfuscated. The file was not running out-of-the-box because it was uploaded on VT as “extracted-decoded.js” (and reformated). MALWARE STEALER
22.5.26 Showboat Introducing Showboat: A new malware family taunts defenses and targets international telecom firms MALWARE LINUX
20.5.26 Webworm Webworm: New burrowing techniques MALWARE WORM
20.5.26 Mikroceen Mikroceen: Spying backdoor leveraged in high-profile networks in Central Asia MALWARE BACKDOOR
17.5.26 Remus Remus: Unpacking the 64-bit Evolution of the Lumma Stealer MALWARE STEALER
16.5.26 Angry Spark A VM-obfuscated backdoor observed on a single machine in the UK, operated for one year, and vanished without a trace. MALWARE BACKDOOR
16.5.26 Gremlin Stealer This article examines new obfuscation techniques the Gremlin stealer malware uses to conceal malicious payloads within embedded resources. We analyze a variant protected by a sophisticated commercial packing utility that employs instruction virtualization, transforming the original code into a custom, non-standard bytecode executed by a private virtual machine. MALWARE STEALER
14.5.26 BitUnlocker BitUnlocker: Leveraging Windows Recovery to Extract BitLocker Secrets MALWARE TOOL
14.5.26 PebbleDash-based tools Kimsuky targets organizations with PebbleDash-based tools MALWARE TOOL
14.5.26 Gamaredon Gamaredon: Now Downloading via Windows Updates Best Friend “BITS” MALWARE LOADER
14.5.26 GammaLoad Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoadS MALWARE LOADER
12.5.26 Mini Shai-Hulud Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack MALWARE PYTHON
12.5.26 TrickMo New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps MALWARE ANDROID
9.5.26 TCLBANKER TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook MALWAREs BANKING
8.5.26 Plague ‘Plague’ malware exploits Pluggable Authentication Module to breach Linux systems MALWARE EXPLOIT
8.5.26 PamDOORa PamDOORa: Analyzing a New Linux PAM-Based Backdoor for Sale on the Dark Web MALWARE BACKDOOR
8.5.26 Quasar Linux Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities MALWARE RAT
8.5.26 PCPJack PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale MALWARE WORM
7.5.26 ZiChatBot While these wheel packages do implement the features described on their PyPI web pages, their true purpose is to covertly deliver malicious files. MALWARE Python
6.5.26 CloudZ RAT CloudZ RAT potentially steals OTP messages using Pheno plugin MALWARE RAT
30.4.26 PromptMink Claude adds malware to crypto agent MALWARE AI
29.4.26 LofyStealer LofyStealer: Malware targeting Minecraft players. MALWARE STEALER
26.4.26 fast16 fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet MALWARE FRAMEWORK
26.4.26 SparkCat SparkKitty, SparkCat’s little brother: A new Trojan spy found in the App Store and Google Play MALWARE TROJAN
25.4.26 FIRESTARTER The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation. MALWARE BACKDOOR
23.4.26 CanisterSprawl CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister MALWARE PYTHON
23.4.26 TeamPCP-Style CanisterWorm Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation. MALWARE WORM
22.4.26 LOTUSLITE LOTUSLITE: Targeted espionage leveraging geopolitical themes MALWARE LOADER
22.4.26 Lotus Wiper Lotus Wiper: a new threat targeting the energy and utilities sector MALWARE WIPER
17.4.26 PhantomPulse Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT MALWARE RAT
14.4.26 Mirax Mirax: a new Android RAT turning infected devices into potential residential proxy nodes MALWARE ANDROID RAT
14.4.26 JanelaRAT JanelaRAT: a financial threat targeting users in Latin AmericaLABYRINT MALWARE RAT
12.4.26 VENOM Meet VENOM: The PhaaS Platform That Neutralizes MFA MALWARE MALWARE
10.4.26 PRISMEX The Russian threat actor known as APT28 (aka Forest Blizzard and Pawn Storm) has been linked to a fresh spear-phishing campaign targeting Ukraine and its allies to deploy a previously undocumented malware suite codenamed PRISMEX. MALWARE MALWARE
10.4.26 Chaos Darktrace Identifies New Chaos Malware Variant Exploiting Misconfigurations in the Cloud MALWARE GO
10.4.26 LucidRook New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations MALWARE LUA
8.4.26 ChainShell ChainShell: MuddyWater’s Russian MaaS Link MALWARE SHELL
8.4.26 ROKRAT Scarcruft’s ROKRAT Malware: Recent Changes MALWARE RAT
3.4.26 Infiniti Stealer Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka MALWARE MACOS
3.4.26 CrystalX A laughing RAT: CrystalX combines spyware, stealer, and prankware features MALWARE RAT
2.4.26 Torg Grabber Torg Grabber: Anatomy of a New Credential Stealer MALWARE STEALER
31.3.26 AtlasCross RAT Trust the Tunnel, Get the Trojan: Silver Fox Delivers AtlasCross RAT via Weaponized VPN Installers MALWARE RAT
31.3.26 DeepLoad DeepLoad Malware Pairs ClickFix Delivery with AI-Generated Evasion MALWARE LOADER
30.3.26 CTRL TOOLKIT Under CTRL: Dissecting a Previously Undocumented Russian .Net Access Framework MALWARE TOOLKIT
28.3.26 VoidStealer VoidStealer: Debugging Chrome to Steal Its Secrets MALWARE STEALER
27.3.26 BPFdoor The strategic positioning of covert access within the world’s telecommunication networks MALWARE BACKDOOR

25.3.26

GlassWorm

GlassWorm Hides a RAT Inside a Malicious Chrome Extension

MALWARE

WORM

24.3.26 StoatWaffle StoatWaffle, malware used by WaterPlum MALWARE LOADER
21.3.26 CanisterWorm Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets MALWARE WORM
21.3.26 PureLog Stealer We look into a stealthy multi‑stage attack campaign that delivers PureLog Stealer entirely in memory using encrypted, fileless techniques. MALWARE STEALER
21.3.26 KEENADU Keenadu malware gives an attacker control over a device but appears to be used primarily to facilitate ad fraud MALWARE ANDROID
21.3.26 Scarface Stealer This week, the SonicWall Capture Labs Threat Research team analyzed a sample of ScarfaceStealer, a Go-compiled information stealer that utilizes sophisticated anti-analysis techniques including: MALWARE STEALER
20.3.26 Speagle New Malware Targets Users of Cobra DocGuard Software MALWARE INFOSTEALER
20.3.26 Perseus Perseus: DTO malware that takes notes MALWARE ANDROID
16.3.26 DRILLAPP Stealthy Backdoor Attack to Real-world Models in Android Apps MALWARE ANDROID
15.3.26 PhantomRaven The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks MALWARE PYTHON
15.3.26 BlackSanta A Silent Threat Targeting Recruitment Workflows MALWARE EDR and AV Killer
15.3.26 A0Backdoor New A0Backdoor Linked to Teams Impersonation and Quick Assist Social Engineering MALWARE BACKDOOR
14.3.26 XWorm XWorm has surged to the #3 global threat, using stealthy memory-only execution and the WinRAR CVE-2025-8088 exploit to bypass traditional security stacks. MALWARE WORM
14.3.26 Remcos RAT This blog examines a Remcos campaign demonstrating the transition from phishing-based initial access to fully fileless execution. MALWARE FILELESS
13.3.26 Slopoly A Slopoly start to AI-enhanced ransomware attacks MALWARE AI
13.3.26 VENON VENON: The First Brazilian Banker RAT in Rust MALWARE BANKING RAT
12.3.26 TAXISPY RAT TAXISPY RAT : Analysis of TaxiSpy RAT – Russian Banking – Focused Android Malware with Full Remote Control MALWARE RAT
12.3.26 BeatBanker BeatBanker: A dual‑mode Android Trojan MALWARE Android
8.3.26 GIFTEDCROOK GIFTEDCROOK’s Strategic Pivot: From Browser Stealer to Data Exfiltration Platform During Critical Ukraine Negotiations MALWARE STEALER
6.3.26 BadPaw and MeowMeow Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow MALWAREs LOADER
4.3.26 Encrypted RAT Malicious Packagist Packages Disguised as Laravel Utilities Deploy Encrypted RAT MALWARE RAT
3.3.26 BurrowShell SloppyLemming Deploys BurrowShell and Rust-Based RAT to Target Pakistan and Bangladesh MALWARE RAT
1.3.26 Arkanix Arkanix Stealer: a C++ & Python infostealer MALWARE STEALER
28.2.26 SURXRAT Cyble uncovers SURXRAT’s evolution across versions, built on ArsinkRAT code, and now downloading large LLM modules signaling an expansion of its operational capabilities. MALWARE AI
27.2.26 Rekoobe Backdoor Malicious Go “crypto” Module Steals Passwords and Deploys Rekoobe Backdoor MALWARE BACKDOOR
27.2.26 KazakRAT While hunting for C2 infrastructure on Censys, we uncovered a suspected state-affiliated cluster targeting Kazakh and Afghan entities in a persistent campaign, with C2 servers active at the time of writing (20th Jan 2026) that have been operating unreported since at least August 2022. MALWARE RAT
27.2.26 DesckVB_RAT This repository accompanies a full technical report documenting an active malware ecosystem centered around DesckVB RAT, a modular .NET Remote Access Trojan observed in live campaigns in early 2026. MALWARE RAT
27.2.26 Steaelite RAT Steaelite RAT Enables Double Extortion Attacks from a Single Panel MALWARE RAT
27.2.26 Dohdoor New Dohdoor malware campaign targets education and health care MALWARE BACKDOOR
21.2.26 Android.Phantom Android.Phantom trojans are bundled with modded games and popular apps to infiltrate smartphones. They use machine learning and video broadcasts to engage in click fraud MALWARE ANDROID
21.2.26 Pulsar RAT Uncovering a Recent Pulsar RAT Sample in the Wild MALWARE RAT
20.2.26 PromptSpy PromptSpy ushers in the era of Android threats using GenAI MALWARE ANDROID
18.2.26 Keenadu Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets MALWARE BACKDOOR
17.2.26 OpenClaw Hudson Rock Identifies Real-World Infostealer Infection Targeting OpenClaw Configurations MALWARE AI AGENT
17.2.26 SmartLoader SmartLoader Clones Oura Ring MCP to Deploy Supply Chain Attack MALWARE LOADER
16.2.26 RenEngine The game is over: when “free” comes at too high a price. What we know about RenEngine MALWARE ENGINE
15.2.26 ZeroDayRAT ZeroDayRAT - New Spyware Targeting Android and iOS MALWARE OS
15.2.26 WAVESHAPER  C++ backdoor that runs as a background daemon, collects host system information, communicates with C2 over HTTP/HTTPS using curl, and downloads and executes follow-on payloads. MALWARE BACKDOOR
15.2.26 HYPERCALL  Golang-based downloader that reads an RC4-encrypted configuration file, connects to C2 over WebSockets on TCP 443, downloads malicious dynamic libraries, and reflectively loads them into memory. MALWARE DOWNLOADER
15.2.26 HIDDENCALL  Golang-based backdoor reflectively injected by HYPERCALL that provides hands-on keyboard access, supports command execution and file operations, and deploys additional malware. MALWARE BACKDOOR
15.2.26 SILENCELIFT  Minimal C/C++ backdoor that beacons host information and lock screen status to a hard-coded C2 server and can interrupt Telegram communications when executed with root privileges. MALWARE BACKDOOR
15.2.26 DEEPBREATH  Swift-based data miner deployed via HIDDENCALL that bypasses macOS TCC protections by modifying the TCC database to gain broad filesystem access and steals keychain credentials, browser data, Telegram data, and Apple Notes data. MALWARE MINER
15.2.26 SUGARLOADER  C++ downloader that uses an RC4-encrypted configuration to retrieve next-stage payloads and was made persistent via a manually created launch daemon. MALWARE DEAMON
15.2.26 CHROMEPUSH  C++ browser data miner deployed by SUGARLOADER that installs as a Chromium native messaging host masquerading as a Google Docs Offline extension and collects keystrokes, credentials, cookies, and optionally screenshots. MALWARE MINER
15.2.26 LummaStealer LummaStealer Is Getting a Second Life Alongside CastleLoader MALWARE STEALER
15.2.26 CastleLoader GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries MALWARE LOADER
11.2.26 Koalemos RAT No Fool's Errand: The Koalemos RAT Campaign MALWARE RAT
3.2.26 Chrysalis Backdoor The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit MALWARE BACKDOOR
2.2.26 GlassWorm Loader GlassWorm Loader Hits Open VSX via Developer Account Compromise MALWARE LOADER
28.1.26 Python RAT Malicious PyPI Packages spellcheckpy and spellcheckerpy Deliver Python RAT MALWARE PYTHON
27.1.26 PeckBirdy PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups MALWARE FRAMEWORK
26.1.26 KONNI KONNI Adopts AI to Generate PowerShell Backdoors MALWARE POWERSHELL
24.1.26 DynoWiper Sandworm behind cyberattack on Poland’s power grid in late 2025 MALWARE WIPER
23.1.26 The Skeleton Key The Skeleton Key: How Attackers Weaponize Trusted RMM Tools for Backdoor Access MALWARE TOOL
21.1.26 VoidLink VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun MALWARE AI
21.1.26 Spread rat Open-Source Python Script Drives Social Media Phishing Campaign MALWARE PYTHON
20.1.26 Evelyn From Extension to Infection: An In-Depth Analysis of the Evelyn Stealer Campaign Targeting Software Developers MALWARE Stealer
19.1.26 ModeloRAT Dissecting CrashFix: KongTuke's New Toy MALWARE RAT
19.1.26 StealC UNO reverse card: stealing cookies from cookie stealers MALWARE Stealer
17.1.26 SOLYXIMMORTAL EXECUTIVE SUMMARY SolyxImmortal is a Python-based Windows information-stealing malware that combines credential theft, document harvesting, keystroke logging, screen surveillance, MALWARE PYTHON
17.1.26 Gootloader’s Planned failure: Gootloader’s malformed ZIP actually works perfectly MALWARE LOADER
17.1.26 LOTUSLITE LOTUSLITE: Targeted espionage leveraging geopolitical themes MALWARE BACKDOOR
14.1.26 VoidLink Unveiling VoidLink – A Stealthy, Cloud-Native Linux Malware Framework MALWARE Linux
10.1.26 RustyWater Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant MALWARE RAT
8.1.26 NodeCordRAT Malicious NPM Packages Deliver NodeCordRAT MALWARE RAT
5.1.26 VVS Discord VVS Discord Stealer Using Pyarmor for Obfuscation and Detection Evasion MALWARE STEALER