Malware

In the cybersecurity landscape, the world of malware represents a constantly evolving ecosystem of malicious software designed to infiltrate systems, disrupt operations, steal data, or generate illicit revenue. Modern malware extends well beyond traditional viruses and worms to include ransomware, spyware, credential stealers, botnets, and fileless threats that exploit legitimate system components to evade detection. Threat actors continuously adapt their techniques, leveraging social engineering, software supply chain compromises, and zero-day vulnerabilities to bypass security controls. As organizations expand their digital footprints across cloud services, mobile platforms, and interconnected infrastructure, the malware threat surface grows in parallel, making continuous monitoring, defense-in-depth strategies, and timely threat intelligence essential to maintaining cyber resilience and operational continuity.

Medusa Ransomware Passes 500 Victims: Phishing Remains One of Its Doors In

Medusa ransomware has now affected more than 500 organizations since it was first identified in June 2021, according to an updated joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency, and the U.S. Department of Health and Human Services. Released on August 18, 2026, the update incorporates information from FBI investigations conducted as recently as April 2026. The victim list crosses multiple critical-infrastructure sectors, including healthcare, defense, critical manufacturing, government services, information technology, and financial services. Organizations in education, law, insurance, technology, and other industries have also been affected. The number is important, but the structure behind it is more revealing. Medusa is no longer simply a ransomware developer deploying its own malware. It has become an access-driven [...]

AutoIT Is Back: Why Script Interpreters Remain a Powerful Malware Delivery Layer

For years, defenders have associated malware with macros, Office documents, and suspicious executables. Yet attackers continue to rely on something far less conspicuous: legitimate scripting frameworks already trusted by the operating system. A recent analysis published by SANS Internet Storm Center demonstrates exactly how dangerous this approach remains. Threat actors are abusing AutoIT—a legitimate Windows automation platform—to deliver multi-stage malware that ultimately injects malicious code into trusted system processes. The campaign itself is not revolutionary. What matters is the architectural lesson: attackers no longer need obviously malicious binaries if they can weaponize trusted interpreters and hide malicious behavior behind multiple layers of decoding and process injection. The Infection Chain: From Email to Memory Injection The observed attack begins with a [...]

How WebDAV and MSHTA Delivery Turns One Lure Into an Invisible Theft

Threat Analysis  |  File-Based Delivery  |  FileDNA CADR Microsoft has warned enterprise defenders about a sustained surge in ACR Stealer activity that ran from late April 2026 into mid-June 2026, observed across customer environments by its Defender Experts team. The campaigns share a single social engineering entry point, the now familiar ClickFix lure, yet they split into two very different delivery and execution chains once a victim takes the bait. That divergence is the entire point. By varying how the payload arrives and runs, the operators make two waves of the same theft look like unrelated incidents, stretching security teams thin and delaying recognition of a shared objective. ACR Stealer is an information-stealing malware family that Microsoft assesses is sold [...]

GigaWiper and the File That Starts the Attack

What Microsoft found inside GigaWiper, and where preventing a single file stops the damage before it begins. In October 2025, Microsoft Threat Intelligence began seeing machines being wiped clean inside compromised networks. When researchers looked closer, they found the tool behind it. On July 9, 2026, Microsoft published its analysis of that tool, which it now tracks as GigaWiper. GigaWiper is not one program with one job. It is a Go-based backdoor that bundles several older attack tools into a single package, and it lets the attacker choose how to cause damage once they are inside. It can wipe a physical disk, it can pretend to be ransomware while making files impossible to recover, and it can quietly spy on [...]

QuimaRAT Shows How Malware-as-a-Service Is Moving Beyond Windows

A new malware-as-a-service operation is giving lower-skill attackers a full cross-platform toolkit, and it says something important about where file-based attacks are heading in 2026. Researchers at LevelBlue SpiderLabs have published an analysis of QuimaRAT, a Java-based remote access trojan capable of running on Windows, Linux, and macOS from a single codebase. The finding is notable not because QuimaRAT is a particularly novel implant on its own, but because of what surrounds it. The threat actor behind it is not selling a single piece of malware. They are selling a delivery ecosystem, complete with subscription pricing, a builder, a browser-based loader, and a dedicated payload dropper, all aimed at helping customers get a RAT onto a target machine without tripping [...]

StrikeShark and SharkLoader: How Modern Intrusions Still Begin at the File and Application Layer

A newly identified cyber espionage campaign tracked as StrikeShark shows how advanced threat actors keep combining public facing vulnerability exploitation, malicious software installers, and stealth memory loading techniques to quietly establish long term access inside high value enterprise environments. Security researchers have linked the activity to a previously undocumented malware family named SharkLoader, a custom loader designed specifically to deploy a Cobalt Strike Beacon while evading conventional endpoint detection. A Globally Distributed Targeting Campaign Researchers tracking the activity observed victims spanning multiple sectors and geographic regions, which points to a broad opportunistic campaign rather than a narrowly focused operation. Confirmed targets include a diplomatic organization in Indonesia, government entities in Taiwan, internationally operating software development firms, and organizations located in [...]

TA577 Group: The Growing Business of File-Based Cyberattacks

Not every cybercriminal group spends its time building ransomware or developing advanced malware. Some focus on something much simpler, and often much more effective: getting inside organizations by tricking people into opening files they trust. One of the best examples right now is TA577, one of the most consistently active cybercrime groups operating today. Rather than running attacks from start to finish, TA577 mainly specializes in the earliest stage of compromise — delivering malicious files, phishing links, and carefully crafted emails that open the door for other malware operators. Their campaigns highlight a growing problem for security teams. In many modern attacks, malware is no longer the starting point. The attack often begins with an ordinary-looking file. A Threat Group [...]

Grandoreiro: The Banking Trojan That Refuses to Die

What started as a regional Brazilian banking fraud tool in 2016 has grown into one of the most persistent financial malware operations on the planet. Law enforcement arrested its operators, dismantled its infrastructure, and declared victory. The malware came back stronger. Most malware families have a natural lifespan. They emerge, spread, get detected, and eventually fade as defenders adapt. Grandoreiro has spent nearly a decade defying this pattern. Originating in Brazil, it quietly expanded across Latin America, crossed the Atlantic to Spain and Portugal, pushed into Africa, and as of 2025 is actively targeting banks in Japan, Italy, the Netherlands, and South Africa. Despite international arrests in 2021 and 2024 and the involvement of INTERPOL, ESET, and Group-IB in attempted [...]

File-Based Malware Delivery and the Growing Role of Content-Aware Security

Modern cyberattacks increasingly rely on deception rather than direct exploitation. Instead of immediately deploying obvious malware binaries, threat actors now use carefully engineered social engineering campaigns designed to convince users to voluntarily download and execute malicious files. These attacks often begin with phishing emails, fake collaboration notifications, fraudulent invoices, cloned login portals, or malicious advertisements that redirect victims toward attacker-controlled infrastructure. In many cases, the downloaded payload initially appears harmless, disguised as a business document, compressed archive, CAPTCHA verification tool, software update, SVG image, PDF attachment, or browser-generated download. Where Windows Downloads Landed? A common characteristic across these attacks is that the malicious content almost always lands first inside the Windows default Downloads directory before execution occurs. This behavior creates [...]

Turla Rebuilds Kazuar Into a Resilient Peer-to-Peer Espionage Framework

The Russian state-sponsored threat group commonly tracked as Turla has significantly redesigned its long-running Kazuar malware platform, transforming the once monolithic backdoor into a modular peer-to-peer botnet engineered for operational resilience, stealth, and long-term intelligence collection. Associated with Russia's Federal Security Service (FSB), specifically Center 16, Turla has historically conducted cyber-espionage operations against government agencies, diplomatic entities, military organizations, and strategic infrastructure targets across Europe and Central Asia. The group is widely recognized under numerous aliases including Secret Blizzard, Snake, Venomous Bear, Waterbug, and Uroburos. Recent analysis indicates that the group is no longer relying solely on conventional stealth methods such as living-off-the-land binaries (LOLBins). Instead, Turla appears to be embedding resilience, distributed coordination, and anti-analysis functionality directly into its [...]

Go to Top