ALERTS JULY 2026 2025 2024 2023 2022
HOME AI
APT
BOTNET
CAMPAIGN
CRIME
CRYPTOCURRENCY
EXPLOIT
HACKING
GROUP
OPERATION
PHISHING
RANSOM
SPAM
VIRUS
VULNEREBILITY
| 2024
2025
2026 January(30)
February(48)
March(53)
April(50)
May(50)
June(41)
July(43)
August(0) SEPTEMBER(0)
October(0)
November(0)
December(0)
|
30.7.26 |
Fake apps used to target Web3 professionals with malware | SlowMist researchers have reported on a sophisticated scam campaign aimed at Web3 professionals, delivering cross-platform infostealing malware disguised as legitimate software. Posing as corporate recruiters, attackers target job seekers with prospective interview opportunities, instructing them to download "Relay" - a fraudulent AI-driven collaboration tool as part of the standard onboarding process. | ALERTS | VIRUS |
|
30.7.26 |
Tengu Botnet | Researchers at Nozomi Networks recently reported a new malware family dubbed Tengu, which significantly modernizes the traditional Mirai botnet architecture. According to their analysis, this threat primarily targets poorly secured internet-of-things devices, embedded Linux systems, and potentially Android-based platforms like set-top boxes. | ALERTS | BOTNET |
|
30.7.26 |
Dysphoria Botnet | Dysphoria is a highly adaptable Internet of Things (IoT) botnet family reported recently to have infected over 200,000 devices globally, undergoing frequent updates in efforts to withstand disruption attempts. As investigated by the researchers from Xlab, Dysphoria utilizes decentralized, blockchain-based domain resolution - such as Ethereum (ENS) or Solana (SNS) name services - to hide its underlying command-and-control (C2) infrastructure. | ALERTS | BOTNET |
|
30.7.26 |
BlueNoroff continues campaigns leveraging Zoom and Microsoft Teams lures | JUMPSEC researchers shared findings from an investigation into an active phishing framework operated by BlueNoroff, a North Korean state-sponsored threat group tied to the Lazarus Group. The operation is targeting Web3 and financial sector personnel. | ALERTS | CAMPAIGN |
|
30.7.26 |
New modular tools and execution tactics leveraged by TAG-195 threat group | Insikt Group has identified four new malware families developed by TAG-195, a financially motivated Malware-as-a-Service (MaaS) group also known as Golden Chickens or Venom Spider. The new toolset includes TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator - a browser credential theft helper. | ALERTS | GROUP |
|
23.7.26 |
Lampion malware returns in campaign targeting Portuguese users | The Acronis Threat Research Unit has uncovered an active Lampion malware campaign targeting users in Portugal through localized administrative and financial phishing lures. The infection vector commences with compressed archives attached to emails containing heavily obfuscated HTML documents. | ALERTS | CAMPAIGN |
|
23.7.26 |
New TrickBot vartiant adopts DNS Tunneling to evade detection | Cybersecurity researchers at FortiGuard Labs recently investigated a novel iteration of the well-known TrickBot malware family that exhibits an evolution in command-and-control (C2) communication tactics. Unlike historical variants that primarily depended on standard HTTP traffic to interact with attacker infrastructure, this variant utilizes DNS tunneling. | ALERTS | VIRUS |
|
23.7.26 |
Multi-Stage Phishing Campaign Uses Fileless Execution to Deploy Phantom Stealer v3.5.0 | Researchers from Seqrite reported on a recently observed phishing operation that leverages realistic corporate lures to compromise enterprise networks. Attackers distribute malicious JavaScript payloads within compressed email attachments, pretending to represent reliable institutions such as the Malaysian Inland Revenue Board or UPS Forwarding Hub. | ALERTS | PHISHING |
|
23.7.26 |
PylangGhost and GolangGhost RATs delivered by Purseweb in the latest ClickFake Interview campaign | SOCRadar’s Threat Research Unit recently detailed the "ClickFake Interview" campaign, a sophisticated social engineering scheme conducted by the North Korea-aligned threat actor Purseweb (aka Famous Chollima, Wagemole). Posing as recruiters on social media platforms, the attackers entice prospects with high-paying opportunities before directing them to fake skill-assessment websites. | ALERTS | VIRUS |
|
23.7.26 |
HollowGraph malware leverages Microsoft 365 Calendar events for C2 communication | Group-IB researchers have uncovered HollowGraph, a novel malware variant attributed with to the Cavern backdoor framework, which is associated with Iranian threat actors targeting organizations in Israel. The malware covertly manages command-and-control (C2) operations by abusing the Microsoft Graph API through a compromised Microsoft 365 accounts, seamlessly blending malicious activity into legitimate network traffic. | ALERTS | VIRUS |
|
21.7.26 |
Cybersecurity researchers at XLab identified NadMesh, a new Go-based botnet designed to target exposed artificial intelligence (AI) frameworks and Model Context Protocol (MCP) environments. Operating as an autonomous threat platform, NadMesh integrates expansive cloud network scanning with more than twenty exploitation pathways to compromise systems running Kubernetes, Docker, Redis and more. | ALERTS | AI | |
|
21.7.26 |
A new campaign documented by Fortinet highlights a loader operation targeting global organizations. Attackers initiate the intrusion by impersonating trusted business entities via phishing emails that contain malicious archives. These archives contain heavily obfuscated JScript droppers designed to bypass signature-based detection using string array mapping and control flow flattening. | ALERTS | VIRUS | |
|
21.7.26 |
Researchers from Group-IB recently uncovered a novel macOS malware dubbed ClickLock Stealer. Operating without requiring administrative privileges or system exploits, this modular shell script spreads through deceptive ClickFix prompts hosted on compromised WordPress sites, utilizing Telegram for its C2 infrastructure. | ALERTS | VIRUS | |
|
21.7.26 |
Elastic Security Labs shared details of an emerging threat named Telepuz, a lightweight and modular malware-as-a-service (MaaS) family that has been active since late April 2026. Distributed broadly through ClickFix social engineering campaigns, the attack chain begins when an unsuspecting user executes a malicious PowerShell command on a compromised web page. | ALERTS | VIRUS | |
|
21.7.26 |
UAT-11795 Leverages Trojanized Software Installers to Deliver Custom Python and PowerShell Payloads |
In a recent write-up, Cisco Talos details a financially motivated campaign attributed to the Russian-speaking threat group UAT-11795, which has been active since at least June 2025 against users in the U.S. and Europe. Initial intrusion is achieved via ClickFix social engineering tricks that trigger a weaponized HTA stager, ultimately placing trojanized installers for common administration and collaboration utilities on the endpoint. | ALERTS | APT |
|
18.7.26 |
CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite | In a recent write-up, Oracle details a critical security flaw in the Oracle Payments module of its E-Business Suite, tracked as CVE-2026-46817. The vulnerability impacts product versions 12.2.3 through 12.2.15 and stems from missing authentication and improper privilege management within the file transmission component. | ALERTS | VULNEREBILITY |
|
18.7.26 |
Operation ShadowRecruit Deploys RMM and SheetAgent RAT | A new campaign documented by Seqrite, dubbed Operation ShadowRecruit, targets Indian job seekers with recruitment-themed lures. Specifically focused on candidates applying for government roles, the attack relies on malicious ZIP archives containing disguised Windows shortcuts. | ALERTS | OPERATION |
|
18.7.26 |
Active Directory Federation Services Privilege Escalation Flaw (CVE-2026-56155) | According to Microsoft, a high-severity vulnerability (CVE-2026-56155) in Active Directory Federation Services (AD FS) is actively being exploited in the wild. The flaw stems from insufficient granularity of access control, allowing an authenticated, local attacker to improperly elevate their privileges on compromised machines. | ALERTS | VULNEREBILITY |
|
18.7.26 |
TuxBot v3 Targets IoT for DDoS Operations | In a recent write-up, Palo Alto Networks details TuxBot v3 Evolution, an advanced internet-of-things botnet framework designed for distributed denial-of-service operations. T | ALERTS | BOTNET |
|
18.7.26 |
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company | A previously unseen ransomware family, named Spirals by its operators, was deployed in a double extortion attack against an IT services company in South Asia in June 2026, the Symantec Threat Hunter Team can reveal. The Rust-based payload is either a new ransomware threat or one purpose-built for this attack. The actor behind the attack remains unknown | ALERTS | RANSOM |
|
18.7.26 |
BoryptGrab-Lineage Infostealer via Fake GitHub Repositories | Researchers at Arctic Wolf recently reported a malicious campaign leveraging hundreds of fake GitHub repositories to deliver a BoryptGrab-lineage infostealer. Actors behind this activity established over 290 deceptive project pages impersonating various legitimate software and security vendors. | ALERTS | VIRUS |
|
18.7.26 |
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor | More than four years after Symantec first uncovered Backdoor.Daxin, the malware has resurfaced. Symantec's Threat Hunter Team uncovered Daxin in active use on a compromised host in Taiwan in May 2026, long after the tool was last found. | ALERTS | VIRUS |
|
18.7.26 |
LabubaRAT | Blackpoint's Adversary Pursuit Group (APG) has recently identified a previously undocumented Rust-based remote access tool, tracked as LabubaRAT, that masquerades as NVIDIA software. | ALERTS | VIRUS |
|
18.7.26 |
CrashStealer Malware Targets macOS Users via Mimicked Crash Reporter | In a recent write-up, Jamf Threat Labs researchers detail CrashStealer, a native C++ macOS infostealer designed to masquerade as the operating system's built-in crash-reporting framework. The malware is initially distributed via a signed and Apple-notarized dropper disguised as a meeting application, allowing it to easily bypass Gatekeeper protections. | ALERTS | VIRUS |
|
18.7.26 |
Albiriox Android RAT Spread via Fake Bank Rewards | Researchers at D3Lab recently reported an Android campaign abusing a major Italian banking brand to distribute the Albiriox banking RAT. A lookalike domain advertises a fake cash reward and redirects victims to a Telegram bot, which offers money for installing an APK and more for referrals, turning the fraud into a self-propagating distribution channel. | ALERTS | VIRUS |
|
18.7.26 |
CrySome RAT Delivered via Logistics-Themed Phishing Campaign | Researchers at LevelBlue's recently reported a multi-stage intrusion that culminates in deployment of the CrySome remote access trojan. Initial access came from a spear-phishing email impersonating a freight rate confirmation, directing the recipient to an actor-controlled portal that delivered a batch file rather than the expected PDF. | ALERTS | VIRUS |
|
18.7.26 |
GigaWiper Implant Employs Modular Design for Espionage and Irreversible Wiping | A new malware family documented by Microsoft Threat Intelligence, known as GigaWiper, combines multiple legacy destructive payloads into a single Go-based backdoor platform4. Operating in compromised Windows environments since late 2025, this threat masquerades as a OneDrive executable and utilizes legitimate messaging and storage services for command-and-control communication. | ALERTS | VIRUS |
|
18.7.26 |
Salat Stealer deployments bundled with Xeno Executor tool | Salat Stealer is a Go-based information-gathering and spying utility that targets unsuspecting gamers and cryptocurrency holders. The malware spreads primarily via social engineering campaigns, or as recently observed by the Splunk researchers, bundled with third-party game modification tools such as Xeno Executor, a Roblox scripting utility. | ALERTS | VIRUS |
|
18.7.26 |
Everest Ransomware variant | Active since late 2020, Everest is a sophisticated double-extortion ransomware operation targeting diverse global industries including government and healthcare across North America, Europe, and Asia. Initial access is typically gained via phishing, stolen credentials, or exploitation of vulnerable applications. | ALERTS | RANSOM |
| 10.7.26 | SCMBANKER - a PowerShell toolkit leveraged in a recent ClickFix campaign | Researchers from Elastic reported on a new Mexican banking fraud operation dubbed REF6045. The attack begins when victims encounter deceptive verification screens mimicking CAPTCHA checks. These fraudulent pages trick users into manually executing a system command that downloads SCMBANKER, a malicious PowerShell-based toolkit. | ALERTS | VIRUS |
| 10.7.26 | Android Malware: Redwing | Zimperium's zLabs team has published a report documenting RedWing, an Android spyware variant marketed as a subscription-based malware service through Telegram channels with apparent links to Russian threat actors. The MaaS integrates a customizable dropper constructor that generates convincing phishing sites mimicking legitimate app stores, delivering payloads that abuse Accessibility Services to achieve deep device compromise. | ALERTS | VIRUS |
| 10.7.26 | GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses | Analysis of a recent GodDamn ransomware attack indicates that this seemingly new ransomware is in fact the latest rebrand of the Beast ransomware, which in itself was a rebrand of the Monster ransomware, which was first seen in 2022. The Symantec Threat Hunter Team tracks the developer behind these ransomware families as Hyadina. | ALERTS | RANSOM |
| 10.7.26 | Recent activities attributed to the Swallowtail threat group | The 360 Advanced Threat Research Institute recently exposed a sophisticated cyberespionage campaign conducted by the notorious state-sponsored hacking group Swallowtail (aka APT-C-20, Fancy Bear, APT28). The group is known to leverage a multi-stage infection process starting with a deceptive, macro-enabled documents. To trick users, the file displays randomized characters and hides its malicious intent using visual object manipulation while presenting a fake Eastern European defense ministry decoy. | ALERTS | GROUP |
| 10.7.26 | Financially Motivated Actors Deploying Dual-Threat Vidar Stealer and XMRig Payloads | Palo Alto Networks Unit 42 has recently identified a financially motivated campaign delivering a combination of info-stealing malware and cryptocurrency miners globally. The activity targets corporate and consumer endpoints primarily located in the United States and European Union by using malicious search advertisements for pirated applications. | ALERTS | VIRUS |
| 8.7.26 | Newly Unveiled Cavern C2 Toolset Targets Israeli Government and IT Sectors | A sophisticated Iran-nexus threat actor dubbed Cavern Manticore has deployed a new post-exploitation framework targeting Israeli networks. Known as "Cavern," this highly modular toolset stands out because it deliberately splits its components across three distinct .NET compilation formats. By blending pure .NET, Mixed-Mode C++/CLI, and NativeAOT binaries, the malware forces defenders to switch between entirely different reverse-engineering workflows, serving as an effective anti-analysis barrier. | ALERTS | APT |
| 8.7.26 | FBI Warns of TeamPCP Cybercrime Group Compromising CI/CD Pipelines | An FBI flash alert warns of extensive software supply chain breaches conducted by the cybercriminal organization TeamPCP. Security teams should monitor for specific custom malware deployed during these operations. This includes CanisterWorm, which is built to harvest cloud access tokens and API keys across AWS, Azure, and GCP infrastructure. | ALERTS | GROUP |
| 8.7.26 | Fake VPN and Media Tools Deliver MarkiRAT | According to Insikt Group, an Iran-linked surveillance campaign is distributing MarkiRAT through fraudulent VPN, media-player and utility applications. The activity primarily targets Farsi-speaking users in Iran, as well as Iranian dissidents and anti-government communities in Europe and North America. | ALERTS | VIRUS |
| 4.7.26 | PureLog Stealer distributed via Veil#Drop framework | Veil#Drop is a sophisticated, multi-phase malware delivery framework designed to deploy PureLog Stealer directly into a system's memory. As reported by researchers from Securonix, the infection chain begins with social engineering, tricking victims into opening a malicious JavaScript file disguised as a legitimate PDF. | ALERTS | VIRUS |
| 4.7.26 | Silent Swap Campaign Deploys Malicious Notes Extension to Intercept Crypto Transactions | In a recent write-up, McAfee Advanced Threat Research details an active campaign, dubbed Silent Swap, that distributes a cryptocurrency-stealing browser extension via sideloading. Delivered via unsigned .NET and Golang installers, the malware targets Chromium-based browsers on Windows endpoints, opportunistically scanning for active browser profiles. | ALERTS | VIRUS |
| 4.7.26 | QuimaRAT: Cross-Platform Remote Access Trojan | LevelBlue has published a report on QuimaRAT, a subscription-based Java remote access trojan designed for Windows, Linux, and macOS. Per their analysis, QuimaRAT decrypts its embedded configuration, validates the host environment, installs platform-specific persistence, and connects to operator infrastructure. | ALERTS | VIRUS |
| 4.7.26 | CVE-2026-55255 - LangFlow vulnerability | CVE-2026-55255 is a recently disclosed critical (CVSS score 9.9) Authentication Bypass vulnerability affecting Langflow (pip), which is an open-source tool for building and deploying AI-powered agents and workflows. If successfully exploited the flaw might allow an authenticated attacker to execute any flow belonging to another user leading to cross-tenant access and potential data exposure. The vulnerability has been fixed in 1.9.2 version of the product. | ALERTS | VULNEREBILITY |
| 1.7.26 | Espionage Group Abuses Legitimate Cloud Platform in Campaigns Against India | In a recent write-up, Acronis TRU Security details two cyber espionage campaigns orchestrated by the China-aligned threat actor Fireant (aka Mustang Panda) against the government and hydropower sectors in India. The threat group compromised public networks, including workstations used by senior administrative personnel, using spear-phishing emails containing malicious ZIP archives. | ALERTS | CAMPAIGN |
| 1.7.26 | TinyRCT backdoor delivered in CL-STA-1062 campaign | Active since early 2022, a Chinese-speaking cyberespionage collective tracked as CL-STA-1062 (aka UAT-7237) has maintained a persistent focus on strategic entities across East and Southeast Asia. As reported by Palo Alto researchers, lately the group targeted state-owned energy and governmental organizations in Southeast Asia. To execute their operations, these threat actors employ a blended toolkit. | ALERTS | CAMPAIGN |