HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Ravie LakshmananJul 31, 2026Endpoint Security / Malware Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called...
Ravie LakshmananJul 31, 2026Endpoint Security / Malware Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called...
Ravie LakshmananJul 19, 2026Vulnerability / Network Security A previously undocumented threat actor has been attributed to the exploitation of recently...
Ravie LakshmananJul 17, 2026Cyber Espionage / Threat Intelligence Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has...
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs...
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to...
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing...
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the...
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as...
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that...
Ravie LakshmananJun 25, 2026AI Security / Malware A previously undocumented Rust-based macOS implant and information stealer has been found to...
Ravie LakshmananJun 05, 2026Cyber Espionage / Threat Intelligence Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where...
Ravie LakshmananMay 29, 2026Cyber Espionage / Artificial Intelligence A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing...
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and...
Ravie LakshmananMay 08, 2026Linux / DevOps A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers' systems...
Ravie LakshmananMay 04, 2026Vulnerability / Network Security A previously unknown threat actor has been observed targeting government and military entities...