Security News

North Korean APT Kimsuky Uses forceCopy Malware to Steal Browser-Stored Credentials
2025-02-06 11:05

The North Korea-linked nation-state hacking group known as Kimsuky has been observed conducting spear-phishing attacks to deliver an information stealer malware named forceCopy, according to new...

New Microsoft script updates Windows media with bootkit malware fixes
2025-02-05 23:16

Microsoft has released a PowerShell script to help Windows users and admins update bootable media so it utilizes the new "Windows UEFI CA 2023" certificate before the mitigations of the BlackLotus...

Crypto-stealing iOS, Android malware found on App Store, Google Play
2025-02-05 11:09

A number of iOS and Android apps on Apple’s and Google’s official app stores contain a software development kit (SDK) that allows them to exfiltrate cryptowallets’ seed recovery phrases, Kaspersky...

North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS
2025-02-04 12:11

The North Korean threat actors behind the Contagious Interview campaign have been observed delivering a collection of Apple macOS malware strains dubbed FERRET as part of a supposed job interview...

DeepSeek AI tools impersonated by infostealer malware on PyPI
2025-02-03 16:33

Threat actors are taking advantage of the rise in popularity of the DeepSeek to promote two malicious infostealer packages on the Python Package Index (PyPI), where they impersonated developer...

Coyote Malware Expands Reach: Now Targets 1,030 Sites and 73 Financial Institutions
2025-02-03 11:39

Brazilian Windows users are the target of a campaign that delivers a banking malware known as Coyote. "Once deployed, the Coyote Banking Trojan can carry out various malicious activities,...

Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware
2025-02-03 05:30

A Russian-speaking cybercrime gang known as Crazy Evil has been linked to over 10 active social media scams that leverage a wide range of tailored lures to deceive victims and trick them into...

Fake Reddit and WeTransfer Sites are Pushing Malware
2025-01-30 12:44

There are thousands of fake Reddit and WeTransfer webpages that are pushing malware. They exploit people who are using search engines to search sites like Reddit. Unsuspecting victims clicking on...

New Aquabotv3 botnet malware targets Mitel command injection flaw
2025-01-30 00:55

A new variant of the Mirai-based botnet malware Aquabot has been observed actively exploiting CVE-2024-41710, a command injection vulnerability in Mitel SIP phones. [...]

DeepSeek’s popularity exploited by malware peddlers, scammers
2025-01-29 13:11

As US-based AI companies struggle with the news that the recently released Chinese-made open source DeepSeek-R1 reasoning model performs as well as theirs for a fraction of the cost, users are...