Skip to content
The Nexus
DossierENTITY

Malwarebytes

Coverage of Malwarebytes in the Nexus archive.

Earliest in view: Apr 27 · 19:21 UTCMost recent: Aug 17 · 08:59 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 17 · 08:59 UTCMALWAREBYTES LABS
    Why Facebook’s war on ad blockers could help scammers

    Ad blocking extends beyond mere inconvenience, serving as a critical security measure by preventing users from accessing malicious and scam ads. Large platforms maintain a structural advantage because they control the entire ad delivery stack, enabling them to alter patterns that independent filter-list maintainers struggle to keep pace with due to limited resources.

  • TECHNOLOGYAug 5 · 09:07 UTCMALWAREBYTES LABS
    Junk Cleaner clears the clutter from your Android

    Junk Cleaner, a new feature in Malwarebytes for Android 5.22, helps users remove storage clutter by identifying and deleting leftover files, old downloads, and hidden app caches. The tool focuses on freeing up space without affecting photos, messages, or documents.

  • SECURITYAug 4 · 12:05 UTCMALWAREBYTES LABS
    Travelers targeted when logging into hotel Wi-Fi networks

    Microsoft has warned that a Russian group is exploiting hotel and hospitality Wi-Fi networks to target travelers via DNS and HTTP traffic manipulation. The campaign, named 'CaptiveCrunch,' uses phishing pages, malware like CornFlake and ChocoShell, and fake system update prompts to steal credentials and compromise devices. Malwarebytes advises using personal hotspots or VPNs with Kill Switch features to mitigate risks.

  • SECURITYAug 3 · 07:01 UTCMALWAREBYTES LABS
    A week in security (July 27 – August 2)

    The article highlights recent cybersecurity threats and updates, including fake Fortnite rewards stealing accounts, the AtlasRAT malware via fake Flash Player installs, and Hims & Hers facing lawsuits over data privacy failures. It also covers Apple's AI worm issue, a $1.8 million crypto app scam, and vulnerabilities in the Vatican's Click To Pray app exposing 700,000 users' data. Malwarebytes announces new security tools and updates.

  • SECURITYJul 31 · 11:03 UTCMALWAREBYTES LABS
    Fake Flash Player installs AtlasRAT

    A fake Flash Player installer is distributing a remote access Trojan (AtlasRAT) by exploiting users seeking outdated Flash content. The malware uses fileless techniques and a self-signed certificate to establish encrypted communication with Command and Control servers, enabling remote system control and data exfiltration.

  • SECURITYJul 30 · 16:01 UTCMALWAREBYTES LABS
    Malwarebytes for Windows, now available on the Microsoft Store

    Malwarebytes for Windows is now available on the Microsoft Store, offering users a trusted method to install the full version of the security software. The Microsoft Store version includes the same real-time protection, Windows integration, and features as the website version, with no limitations or compromises.

  • SECURITYJul 29 · 10:32 UTCMALWAREBYTES LABS
    We found 120 fake Walmart stores trying to steal your credit card

    Over 120 fake Walmart websites are scamming users by offering deep discounts on liquor and prompting credit card details at checkout. These sites use identical templates and borrowed trust from Walmart's brand to steal financial information.

  • SECURITYJul 28 · 12:40 UTCMALWAREBYTES LABS
    We rebuilt Malwarebytes Mobile Security for the scams of today

    Malwarebytes rebuilt its Mobile Security app to combat rising phone scams, which affect nearly half of users daily. Features like Scam Guard, Text/Call Protection, and the Digital Footprint Portal aim to detect AI-driven threats, block scams, and expose compromised personal data. A 2025 survey found 25% of victims faced harassment or blackmail, 20% had private information exposed, and 15% lost money.

  • SECURITYJul 27 · 14:35 UTCMALWAREBYTES LABS
    What’s your data worth on the dark web? (Lock and Code S07E15)

    Malwarebytes researchers found personal data packages called 'fullz' on the dark web, which can be purchased for 95 cents and include enough information to commit identity fraud. Over 7,500 compromised data sets containing 8.4 billion records were identified in the first six months of 2026. The article explores why hackers seek such data for cybercriminal activities.

  • SECURITYJul 24 · 14:54 UTCMALWAREBYTES LABS
    Call of Duty Mobile scam uses fake free points to steal player accounts

    A phishing campaign targeting Call of Duty Mobile players offers fake free points in exchange for login credentials and two-factor authentication codes, enabling account theft. Stolen accounts are valuable due to stored payment methods, purchase history, and linked gaming platforms like Xbox, PlayStation, or Battle.net.

  • SECURITYJul 22 · 12:46 UTCMALWAREBYTES LABS
    Chick-fil-A loyalty accounts hijacked using stolen passwords

    Chick-fil-A warned customers about a credential stuffing attack on its loyalty accounts between June 17 and June 19, 2026, where attackers used stolen passwords from previous breaches to hijack accounts. The company reset passwords and ended active sessions for affected accounts, and breach notifications indicated potential access to personal and financial information.

  • SECURITYJul 21 · 14:57 UTCMALWAREBYTES LABS
    What happens if you visit a WordPress site hacked through wp2shell?

    WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.

  • SECURITYJul 17 · 10:43 UTCMALWAREBYTES LABS
    How to use GitHub safely

    GitHub's popularity has made it a platform for cybercriminals to distribute malicious software through fake repositories. Users are warned to exercise caution when downloading from GitHub, as cybercriminals create convincing repositories impersonating well-known brands like Malwarebytes and LastPass. Red flags include brand impersonation, recently created accounts, and unusual download methods.

  • SECURITYJul 16 · 02:54 UTCR/SCAMS
    [US] Opened a dodgy link, what's the likelihood of any issues?

    A user joined a Discord to obtain a VRChat skin code, opened a link checked via VirusTotal (no threats detected), and later found Ngrok in their AppData folder via Malwarebytes. The user quarantined Ngrok but is uncertain about its origin and current risk.

  • SECURITYJul 10 · 13:25 UTCMALWAREBYTES LABS
    This new Windows malware can take over your PC and wipe it clean

    Microsoft identified GigaWiper, a modular Windows backdoor combining remote access and data destruction capabilities, which integrates components from Crucio ransomware and FlockWiper. The malware allows espionage features like screen capture and remote control, alongside destructive commands to irreversibly wipe systems, with C2 servers detected and blocked by Malwarebytes.

  • SECURITYJul 9 · 11:38 UTCMALWAREBYTES LABS
    Microsoft fixes RoguePlanet zero-day in Defender

    Microsoft has patched the RoguePlanet zero-day vulnerability (CVE-2026-50656) in Microsoft Defender, an elevation of privilege flaw that could allow attackers to gain system-level access. The fix is included in the updated Malware Protection Engine version 1.1.26060.3008, which automatically updates for most users. Systems with other antivirus software like Malwarebytes are not affected if Defender is disabled.

  • SECURITYJul 6 · 11:52 UTCMALWAREBYTES LABS
    NetNut botnet takes a hit. Don’t be part of the next one.

    Google, the FBI, and partners disrupted the NetNut botnet, which used hijacked consumer devices as residential proxies. The operation reduced the botnet's device pool by millions through account disabling, infrastructure sharing, and app warnings. NetNut tricked users into installing malicious apps under the guise of 'bandwidth sharing' payouts.

  • SECURITYJun 24 · 22:33 UTCR/SCAMS
    [GR] Fake Cloudflare Human Verification Scam (me3k.trappopbuttonrightnow.monster) - Executed PowerShell Script

    A user was redirected to a fake Cloudflare Human Verification page that tricked them into executing a PowerShell script. The script downloaded and ran code from a suspicious domain, prompting the user to disconnect their PC from the internet and run malware scans, which found no threats.

  • SECURITYJun 24 · 14:18 UTCMALWAREBYTES LABS
    Watch out for renewal scams pretending to be Malwarebytes

    Fake subscription renewal notices impersonating Malwarebytes and other companies are being used in phishing and tech support fraud scams. These emails often include fabricated details, high charges, and fake contact information to trick recipients into divulging personal or financial information.

  • SECURITYMay 5 · 08:12 UTCR/DEFI
    Got drained 1434 USDT on Arbitrum — exhausted all leads, need help identifying the source Help Needed

    The user's MetaMask wallet on Arbitrum was drained of 1434 USDT without authorization, and they are seeking help to identify the source of the issue. The user has already investigated and ruled out several potential causes. The transaction that drained the wallet was a simple ETH transfer to an address funded by SideShift.

  • SECURITYApr 27 · 19:21 UTCR/CRYPTOMARKETS
    Malicious trading website drops malware that hands your browser to attackers

    A malicious trading website has been distributing malware that allows attackers to take control of users' browsers. The threat, highlighted by cybersecurity firm Malwarebytes, poses a significant risk to online security.