Security firm Sublime found that malicious calendar invites sent via email, known as ICS phishing, have surged dramatically, rising 282% in June, 338% in July, and 1,216% in August, with a projected 2,852% jump in September. These fake invites exploit a default feature in Outlook, Gmail, and Apple Mail that auto-adds ICS files to a user's calendar before they accept or decline them.
zdnet.com
· 2026-09-18
Zimperium zLabs identified a new Android malware family, RatHat, spread via malvertising, SMS and phishing sites offering APK downloads outside Google Play. It abuses Accessibility permissions and enables Developer Options and Wireless Debugging to gain shell-level control, installing companion agents that maintain persistence, log keystrokes, and steal banking or crypto credentials through fake overlays. Researchers link the operation to Chinese-speaking actors based on Chinese-language prompts found in its AI automation engine.
bleepingcomputer.com
· 2026-09-17
Cybersecurity agencies from the U.S., U.K. and Netherlands, alongside the FBI, issued a joint advisory exposing an Iranian state-linked campaign using Windows malware called CHOSEN BRICK to spy on dissidents, journalists and activists. Attackers pose as trusted contacts or tech support over WhatsApp and Telegram, luring victims into launching disguised fake apps that secretly install the spyware and evade Windows Defender.
bleepingcomputer.com
· 2026-09-16
Elastic Security Labs uncovered a malware toolkit called KREMLIN, active since mid-2025, that tricks victims into opening fake invoice or receipt files to install malicious Chrome and Edge extensions without any user approval. The toolkit recreates Chromium's cryptographic integrity checks so the browser treats the rogue extension as legitimate, then harvests login credentials, session tokens and other sensitive data. Elastic ties the operation to a Brazilian group that has run at least seven campaigns impersonating 12 banks since May.
bleepingcomputer.com
· 2026-09-16
A malware-as-a-service platform called VectraRAT is being sold on underground markets for roughly $250 monthly, giving buyers a Windows-based remote access implant, command-and-control infrastructure, and a management panel. The package effectively bundles everything needed to compromise and control enterprise Windows systems without requiring technical expertise from the attacker.
darkreading.com
· 2026-09-15
Security researchers outline how spyware on Android phones can be spotted through symptoms like sudden battery drain, overheating, unexplained data usage, unfamiliar apps, or apps unexpectedly requesting camera and microphone access. Infections most often occur through phishing links or sideloaded apps outside the Play Store, though rogue apps occasionally slip past Google Play Protect too.
engadget.com
· 2026-09-15
Researchers at Lumen's Black Lotus Labs identified a previously undocumented malware framework, BambooToken, active since 2023, that in its 2024-2025 variants switched to the MQTT messaging protocol for command-and-control. Infected systems subscribe to unique topics on a central broker to receive operator commands and report status, and the malware has infected servers tied to mobile apps, legal, financial, and software development firms via side-loading disguised as Tendyron OnKey USB-token software or a fake Kingsoft Office suite.
bleepingcomputer.com
· 2026-09-15
Attackers took over HBO Max's official, verified Reddit account and used it to post 108 malicious ads over roughly two days, tricking Windows and macOS users into installing information-stealing malware. The ads used the ClickFix technique, luring victims into pasting attacker-supplied commands into Run, PowerShell, or Terminal under the guise of fixing errors or verifying CAPTCHAs, with some posts impersonating a fake HBO Max app and others posing as AI tools or developer utilities.
bleepingcomputer.com
· 2026-09-14
Security researchers report that ClickFix, a malware technique relying on fake CAPTCHA prompts and terminal commands, has exploded in popularity among attackers, including state-backed hacking groups. The attack tricks victims into copying and pasting a malicious command into Windows Run, PowerShell, or macOS Terminal after clicking through a fraudulent verification screen on a compromised website.
arstechnica.com
· 2026-09-11
Huntress' Security Operations Center reports that over the past nine months, attackers have been abusing legitimate sharing features on AI platforms—like Claude Artifacts, claude.ai/share links, and indexable ChatGPT and Grok conversations—to distribute malware. These campaigns exploit the trust users place in familiar AI branding, often surviving only hours or days before the platforms take the content down.
bleepingcomputer.com
· 2026-09-11
Group-IB researchers found that the Chinese-speaking threat group GoldFactory has been abusing Google's Work Profile feature to clone victims' banking apps into isolated, hidden environments where fraud-detection tools can't reach. The campaign, powered by the Gigabud Android Trojan and a cloning tool called Vwork, compromised roughly 1,469 devices and 1,281 logins in Indonesia between February and July, causing nearly $1 million in losses.
darkreading.com
· 2026-09-11
Security firm Zimperium has identified a new Android malware called Mantax Otax that combines file encryption with data theft, distributed via malicious APKs outside Google Play through phishing lures aimed at Indonesian users. Once installed, it abuses Accessibility permissions to harvest device data, report to a GitHub-hosted command server, and on older Android versions (9 and below) encrypts files, replaces images with ransom notes, and opens a Firebase-hosted chat to negotiate payment. Researchers exploited a misconfigured Firebase server to expose the attackers' actual conversations with victims.
bleepingcomputer.com
· 2026-09-10