Malware Security News

Malware families, new samples, and analysis of the techniques malicious software uses to infect and persist on systems.

Malware covers everything from commodity trojans and infostealers to sophisticated custom implants used in targeted intrusions. New samples, family updates and analyst write-ups on how a given piece of malware infects, persists and talks to its operators land here. Worth pairing with the ransomware and APT feeds, since most major campaigns rely on custom or repurposed malware.

Recent Malware items

I've got like a dozen or so people DMing me about more Steam goop (malware) but NO ONE has the actual goop to show me. GIVE ME THE GOOP BEFORE ANYTHING ELSE. oHhH SchMellY ThE mAlWaRe iS DoInG SomeThi…
@vxunderground · Sep 28, 2026
I've got like a dozen or so people DMing me about more Steam goop (malware) but NO ONE has the actual goop to show me. GIVE ME THE GOOP BEFORE ANYTHING ELSE. oHhH SchMellY ThE mAlWaRe iS DoInG SomeThi…
@vxunderground · Sep 28, 2026
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts https://ift.tt/KXu476w
@ctinow · Sep 28, 2026
NeedyMantis Hides Its Next Stage Behind Familiar DLL Names A legitimate translation editor can start normally while a replacement library beside it opens an attacker’s next stage. That is one of the d…
@topcybersecurity · Sep 28, 2026
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent 🖋️ Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting ex…
@cibsecurity · Sep 28, 2026
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims 🖋️ RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according…
@cibsecurity · Sep 28, 2026
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks 🖋️ Hackers have used a malware family called NeedyMantis to maintain longterm access to networks they had already breached, Mi…
@cibsecurity · Sep 28, 2026
be me > get dm > "Smelly, you said you accidentally executed an information stealer on your PC. What happens if you accidentally executed ransomware on your PC?" p much this tbh (ive done it before wi…
@vxunderground · Sep 28, 2026
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims https://ift.tt/PbhWLZu
@ctinow · Sep 28, 2026
NeedyMantis keeps attackers inside networks they already breached. Microsoft saw the malware in a small number of targeted intrusions, where it uses DLL sideloading and a WebSocket C2 channel to load…
@thehackernews · Sep 28, 2026
RatHat, an Android banking trojan, uses Gemini to rank infected phones by estimated bank balance. Cleafy traced nearly 100 console deployments since April 2026. Gemini helps operators prioritize victi…
@thehackernews · Sep 28, 2026
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions https://ift.tt/odI1tNu
@ctinow · Sep 28, 2026
CVE-2026-82928 mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authenticatio…
@cveNotify · Sep 28, 2026
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations https://ift.tt/mnEMTW0
@ctinow · Sep 28, 2026
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging…
@bleepingcomputer · Sep 28, 2026
CVE-2026-82928 mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authenticatio…
@cveNotify · Sep 28, 2026
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent https://ift.tt/NqMOIXx
@ctinow · Sep 28, 2026
Carbonato compromises unauthenticated Docker daemons, then deploys Hermes Agent for Telegram-driven, LLM-generated commands. The botnet persists on infected hosts and scans nearby networks every five…
@thehackernews · Sep 28, 2026
Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. AsyncRAT climbed 35%, while Quasar, DonutLoader, and Lumma saw…
@anyrun_app · Sep 28, 2026
CVE-2026-96896 The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite ad…
@cveNotify · Sep 28, 2026
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116 https://securityaffairs.com/199850/malware/security-affairs-malware-newsletter-round-116.html
@PentestingNews · Sep 27, 2026
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116 https://ift.tt/If9shFa
@ctinow · Sep 27, 2026
CyberCodex: Autonomous 22-Source Zero-Cost OSINT, Data Breach, Infostealer & Threat Intelligence CLI Engine + Cyber Warfare Encyclopedia (Zero Dependencies, 0 API Keys) https://ift.tt/rkBJavK
@ctinow · Sep 27, 2026
Aussie family shattered when fit dad, 32, suffers sudden heart failure after assuming he'd caught 'another daycare virus': 'The signs were very different to a heart attack' https://ift.tt/5ph6FcY
@ctinow · Sep 27, 2026
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials 🖋️ The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFixstyle Cloud…
@cibsecurity · Sep 27, 2026
CVE-2026-96896 The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite ad…
@cveNotify · Sep 27, 2026
CVE-2026-100863 Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input lo…
@cveNotify · Sep 27, 2026
My projector commited click-fraud: Reverse engineering Badbox malware in the Wielo Smart Mini projector AT-M269 H713 to clean it. https://github.com/florentineprinzessinzusachsen/badbox-h713-projector…
@secharvester · Sep 26, 2026
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials https://ift.tt/TvnAYa9
@ctinow · Sep 26, 2026
Lunex uses a vulnerable AMD driver to blind security monitoring before stealing browser credentials. The BYOVD chain zeroes kernel callbacks tied to security products, then the stealer collects creden…
@thehackernews · Sep 26, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.