Tech News
← Home  ·  All topics

Malware

46 GoKawiil briefs on this topic

ICS calendar-invite phishing attacks spike over 1,200% since June, Sublime reports

Security firm Sublime found that malicious calendar invites sent via email, known as ICS phishing, have surged dramatically, rising 282% in June, 338% in July, and 1,216% in August, with a projected 2,852% jump in September. These fake invites exploit a default feature in Outlook, Gmail, and Apple Mail that auto-adds ICS files to a user's calendar before they accept or decline them.

RatHat Android trojan uses AI to autonomously navigate infected devices, Zimperium finds

Zimperium zLabs identified a new Android malware family, RatHat, spread via malvertising, SMS and phishing sites offering APK downloads outside Google Play. It abuses Accessibility permissions and enables Developer Options and Wireless Debugging to gain shell-level control, installing companion agents that maintain persistence, log keystrokes, and steal banking or crypto credentials through fake overlays. Researchers link the operation to Chinese-speaking actors based on Chinese-language prompts found in its AI automation engine.

Iranian state hackers deploy CHOSEN BRICK malware against journalists and activists

Cybersecurity agencies from the U.S., U.K. and Netherlands, alongside the FBI, issued a joint advisory exposing an Iranian state-linked campaign using Windows malware called CHOSEN BRICK to spy on dissidents, journalists and activists. Attackers pose as trusted contacts or tech support over WhatsApp and Telegram, luring victims into launching disguised fake apps that secretly install the spyware and evade Windows Defender.

KREMLIN toolkit forces fake Chrome and Edge extensions onto Brazilian banking targets

Elastic Security Labs uncovered a malware toolkit called KREMLIN, active since mid-2025, that tricks victims into opening fake invoice or receipt files to install malicious Chrome and Edge extensions without any user approval. The toolkit recreates Chromium's cryptographic integrity checks so the browser treats the rogue extension as legitimate, then harvests login credentials, session tokens and other sensitive data. Elastic ties the operation to a Brazilian group that has run at least seven campaigns impersonating 12 banks since May.

VectraRAT Malware Kit Sold for $250 a Month Targets Windows Enterprises

A malware-as-a-service platform called VectraRAT is being sold on underground markets for roughly $250 monthly, giving buyers a Windows-based remote access implant, command-and-control infrastructure, and a management panel. The package effectively bundles everything needed to compromise and control enterprise Windows systems without requiring technical expertise from the attacker.

Guide details warning signs and removal steps for Android spyware

Security researchers outline how spyware on Android phones can be spotted through symptoms like sudden battery drain, overheating, unexplained data usage, unfamiliar apps, or apps unexpectedly requesting camera and microphone access. Infections most often occur through phishing links or sideloaded apps outside the Play Store, though rogue apps occasionally slip past Google Play Protect too.

BambooToken malware framework uses MQTT protocol to control Windows and Linux hosts

Researchers at Lumen's Black Lotus Labs identified a previously undocumented malware framework, BambooToken, active since 2023, that in its 2024-2025 variants switched to the MQTT messaging protocol for command-and-control. Infected systems subscribe to unique topics on a central broker to receive operator commands and report status, and the malware has infected servers tied to mobile apps, legal, financial, and software development firms via side-loading disguised as Tendyron OnKey USB-token software or a fake Kingsoft Office suite.

HBO Max's verified Reddit account hijacked to spread ClickFix malware

Attackers took over HBO Max's official, verified Reddit account and used it to post 108 malicious ads over roughly two days, tricking Windows and macOS users into installing information-stealing malware. The ads used the ClickFix technique, luring victims into pasting attacker-supplied commands into Run, PowerShell, or Terminal under the guise of fixing errors or verifying CAPTCHAs, with some posts impersonating a fake HBO Max app and others posing as AI tools or developer utilities.

ClickFix scam using fake CAPTCHAs spreads rapidly across PCs and Macs

Security researchers report that ClickFix, a malware technique relying on fake CAPTCHA prompts and terminal commands, has exploded in popularity among attackers, including state-backed hacking groups. The attack tricks victims into copying and pasting a malicious command into Windows Run, PowerShell, or macOS Terminal after clicking through a fraudulent verification screen on a compromised website.

Attackers exploit shareable AI features on Claude, ChatGPT and Grok to spread malware

Huntress' Security Operations Center reports that over the past nine months, attackers have been abusing legitimate sharing features on AI platforms—like Claude Artifacts, claude.ai/share links, and indexable ChatGPT and Grok conversations—to distribute malware. These campaigns exploit the trust users place in familiar AI branding, often surviving only hours or days before the platforms take the content down.

GoldFactory's Gigabud Trojan Exploits Android Work Profiles in Indonesia Bank Fraud

Group-IB researchers found that the Chinese-speaking threat group GoldFactory has been abusing Google's Work Profile feature to clone victims' banking apps into isolated, hidden environments where fraud-detection tools can't reach. The campaign, powered by the Gigabud Android Trojan and a cloning tool called Vwork, compromised roughly 1,469 devices and 1,281 logins in Indonesia between February and July, causing nearly $1 million in losses.

Mantax Otax Android Malware Blends Ransomware and Spyware to Extort Indonesian Victims

Security firm Zimperium has identified a new Android malware called Mantax Otax that combines file encryption with data theft, distributed via malicious APKs outside Google Play through phishing lures aimed at Indonesian users. Once installed, it abuses Accessibility permissions to harvest device data, report to a GitHub-hosted command server, and on older Android versions (9 and below) encrypts files, replaces images with ransom notes, and opens a Firebase-hosted chat to negotiate payment. Researchers exploited a misconfigured Firebase server to expose the attackers' actual conversations with victims.