ALERTS   H  ALERT  ALERTS  |  2026  2025  2024  | 


HOME  AI  APT  BOTNET  CAMPAIGN  CRIME  CRYPTOCURRENCY  EXPLOIT  HACKING  GROUP  OPERATION  PHISHING  RANSOM  SPAM  VIRUS  VULNEREBILITY
2026  January(30) February(48) March(53) April(50) May(50) June(41) July(43) August(52) SEPTEMBER(39) October(0) November(0) December(0)


DATE

NAME

INFO

CATEGORY

SUBCATE

2.10.26

Malicious packages posing as KakaoTalk messaging app installers ASEC Ahnlab researchers reported about an evolution of recently monitored campaigns where adversaries are manipulating search engine optimization (SEO) to steer unsuspecting users toward counterfeit KakaoTalk installers. The packaging of these trojanized setup packages progressively shifted across NSIS, Advanced Installer, and Inno Setup formats, bundling authentic software alongside malicious components. ALERTS VIRUS

2.10.26

Antino Malware Targets Asian Governments In a recent write-up, Cisco Talos details UAT-11587, a China-nexus cluster active since September 2025 that delivers a previously undocumented Rust backdoor named Antino. The targets are government, defense, diplomatic, legislative and research organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. ALERTS VIRUS

2.10.26

CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer According to Jamf Threat Labs, researchers discovered a two-stage macOS backdoor dubbed CloudSyncD that arrives hidden inside fake Zoom application installers. The malicious dropper convinces users into bypassing Gatekeeper protections and entering their system password ALERTS VIRUS

2.10.26

Warlock ransomware targets water and telecom operators The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. ALERTS RANSOM

2.10.26

BotHelper RAT Researchers at Point Wild recently reported a new malware family dubbed BotHelper, a .NET remote access trojan equipped with real-time desktop monitoring functions. Targeting Windows environments, the infection begins with a native executable stager that fingerprints the host machine and intentionally disables TLS certificate validation to retrieve an encrypted payload from a remote server. ALERTS VIRUS

2.10.26

Brimstone APT Delivers ComicPulse Backdoor Through RedFlick Technique Researchers at Microsoft Threat Intelligence recently reported on evolving cyberespionage tradecraft from the Russian state-sponsored group Brimstone (aka Star Blizzard). The group has pivoted from narrow spear-phishing toward broader initial-contact email operations while adopting compromised host platforms to distribute malicious content. ALERTS APT

2.10.26

Multi-stage attack leveraging KMS Auto that leads to scareware A recent K7 Security Labs investigation highlights a multi-phase intrusion campaign wherein adversaries leverage KMS Auto, which is an an unofficial third-party utility used to bypass licensing and activate various Microsoft products. ALERTS SPAM

2.10.26

LxBase RAT Hits Russian Firms In a recent write-up, BI.ZONE Threat Intelligence details a new campaign deploying LxBase RAT against Russian organizations. Between July and September 2026, attackers targeted a wide array of domestic industries, including finance, energy, retail, logistics, and engineering. ALERTS VIRUS

2.10.26

New PamStealer Variant Targets macOS Users A new variant documented by Jamf Threat Labs targets macOS environments with an upgraded version of the PamStealer infostealer. Attackers trick users into downloading a malicious disk image by impersonating a multichain cryptocurrency wallet called Wavel. ALERTS VIRUS