Malware preinstalled on cheap Android phones generates ad fraud
Malware has been discovered preinstalled on thousands of inexpensive Android phones, capable of generating fraudulent ad revenue and potentially turning infe...
Malware has been discovered preinstalled on thousands of inexpensive Android phones, capable of generating fraudulent ad revenue and potentially turning infe...
More than 17,000 fake repositories on GitHub are currently distributing the SmartLoader malware, a reactivation of the FakeGit campaign that began earlier th...
A likely Russia-affiliated cyber-espionage group, identified as UAC-0099, is employing an increasingly sophisticated malware downloader named MatchBoil to ta...
CastleStealer, a C# information stealer first publicly identified in April 2026, has expanded its capabilities beyond credential theft. New samples analyzed ...
Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices. The post Pre-Baked Firmware Malware Hits ...
A campaign in July 2026 using a trojanized Terraform provider to deploy cross-platform malware against developer environments. The operation delivers FLATROO...
Warden Stealer as a rapidly growing malware-as-a-service operation targeting data stored by AI assistants and coding agents, including Claude, Codex, Grok, a...
MATCHBOIL’s evolution from a basic C# downloader into a more evasive implant supporting recurring command-and-control communication. Operated by UAC-0099, th...
A backdoor that makes no noise is hard to catch, and that’s the point of BPFDoor. The Linux malware waits for a special “magic packet” before it acts.
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware,...
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the S...
Low-cost Android phones can arrive already compromised, with malware embedded in their firmware before buyers switch them on.
A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud sup...
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware f...
Russian-aligned hackers have targeted Ukrainian transportation, manufacturing and energy companies with a constantly evolving malware strain designed to harv...
Hackers are targeting hotels with fabricated guest complaints and negative reviews to distribute EtherRAT and TONResolver, two malware families that abuse pu...
ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windo...
A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing appli...
MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages. Linked to an apparent single operator active si...