Fortinet's FortiGuard Labs identified a new variant of the SectopRAT remote access Trojan concealed within legitimate digital-audio software from an Italian company. Researcher Xiaopeng Zhang said attackers modified the FrameworkBase.dll file after the software was already installed on victim machines, secretly loading the SectopRAT payload rather than compromising the vendor itself.
darkreading.com
· 2026-09-24
Security researchers at SafeDep discovered that a malicious npm package called mathmain, disguised as a copy of the popular mathjs library, contains a hidden remote access implant. The malicious code stays encrypted and dormant until a specific equation is solved using the library's lusolve() solver function, which acts as a decryption key to unlock and execute the payload.
safedep.io
· 2026-09-21
Cybersecurity agencies from Japan, the US, Australia and Germany issued a joint advisory identifying North Korea's WaterPlum group as the actor behind malware hidden in fake job application coding tests. The scheme has infected over 30,000 devices across 100 countries and compromised more than 7,000 crypto wallets, netting $10.71 million believed to fund the North Korean government.
tomshardware.com
· 2026-09-20
A malware-as-a-service platform called VectraRAT is being sold on underground markets for roughly $250 monthly, giving buyers a Windows-based remote access implant, command-and-control infrastructure, and a management panel. The package effectively bundles everything needed to compromise and control enterprise Windows systems without requiring technical expertise from the attacker.
darkreading.com
· 2026-09-15
Attackers are exploiting a chain of legitimate Google services, including redirect links, to disguise malicious URLs and slip past email security filters. Victims who follow the multi-hop links are directed either to credential-harvesting phishing pages or prompted to install ScreenConnect remote access software.
darkreading.com
· 2026-09-08
ConnectWise disclosed a new security flaw in its ScreenConnect remote access platform affecting file transfer behavior in both cloud and on-premises deployments. The vulnerability has no CVE identifier yet and no official patch, though the company says a fix is coming later this week. In the meantime, ConnectWise published manual mitigation steps requiring administrators to disable file transfer permissions across user roles.
bleepingcomputer.com
· 2026-09-07