Malwarebytes
Coverage of Malwarebytes in the Nexus archive.
- Why Facebook’s war on ad blockers could help scammers
Ad blocking extends beyond mere inconvenience, serving as a critical security measure by preventing users from accessing malicious and scam ads. Large platforms maintain a structural advantage because they control the entire ad delivery stack, enabling them to alter patterns that independent filter-list maintainers struggle to keep pace with due to limited resources.
- Junk Cleaner clears the clutter from your Android
Junk Cleaner, a new feature in Malwarebytes for Android 5.22, helps users remove storage clutter by identifying and deleting leftover files, old downloads, and hidden app caches. The tool focuses on freeing up space without affecting photos, messages, or documents.
- Travelers targeted when logging into hotel Wi-Fi networks
Microsoft has warned that a Russian group is exploiting hotel and hospitality Wi-Fi networks to target travelers via DNS and HTTP traffic manipulation. The campaign, named 'CaptiveCrunch,' uses phishing pages, malware like CornFlake and ChocoShell, and fake system update prompts to steal credentials and compromise devices. Malwarebytes advises using personal hotspots or VPNs with Kill Switch features to mitigate risks.
- A week in security (July 27 – August 2)
The article highlights recent cybersecurity threats and updates, including fake Fortnite rewards stealing accounts, the AtlasRAT malware via fake Flash Player installs, and Hims & Hers facing lawsuits over data privacy failures. It also covers Apple's AI worm issue, a $1.8 million crypto app scam, and vulnerabilities in the Vatican's Click To Pray app exposing 700,000 users' data. Malwarebytes announces new security tools and updates.
- Fake Flash Player installs AtlasRAT
A fake Flash Player installer is distributing a remote access Trojan (AtlasRAT) by exploiting users seeking outdated Flash content. The malware uses fileless techniques and a self-signed certificate to establish encrypted communication with Command and Control servers, enabling remote system control and data exfiltration.
- Malwarebytes for Windows, now available on the Microsoft Store
Malwarebytes for Windows is now available on the Microsoft Store, offering users a trusted method to install the full version of the security software. The Microsoft Store version includes the same real-time protection, Windows integration, and features as the website version, with no limitations or compromises.
- We found 120 fake Walmart stores trying to steal your credit card
Over 120 fake Walmart websites are scamming users by offering deep discounts on liquor and prompting credit card details at checkout. These sites use identical templates and borrowed trust from Walmart's brand to steal financial information.
- We rebuilt Malwarebytes Mobile Security for the scams of today
Malwarebytes rebuilt its Mobile Security app to combat rising phone scams, which affect nearly half of users daily. Features like Scam Guard, Text/Call Protection, and the Digital Footprint Portal aim to detect AI-driven threats, block scams, and expose compromised personal data. A 2025 survey found 25% of victims faced harassment or blackmail, 20% had private information exposed, and 15% lost money.
- What’s your data worth on the dark web? (Lock and Code S07E15)
Malwarebytes researchers found personal data packages called 'fullz' on the dark web, which can be purchased for 95 cents and include enough information to commit identity fraud. Over 7,500 compromised data sets containing 8.4 billion records were identified in the first six months of 2026. The article explores why hackers seek such data for cybercriminal activities.
- Call of Duty Mobile scam uses fake free points to steal player accounts
A phishing campaign targeting Call of Duty Mobile players offers fake free points in exchange for login credentials and two-factor authentication codes, enabling account theft. Stolen accounts are valuable due to stored payment methods, purchase history, and linked gaming platforms like Xbox, PlayStation, or Battle.net.
- Chick-fil-A loyalty accounts hijacked using stolen passwords
Chick-fil-A warned customers about a credential stuffing attack on its loyalty accounts between June 17 and June 19, 2026, where attackers used stolen passwords from previous breaches to hijack accounts. The company reset passwords and ended active sessions for affected accounts, and breach notifications indicated potential access to personal and financial information.
- What happens if you visit a WordPress site hacked through wp2shell?
WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.
- How to use GitHub safely
GitHub's popularity has made it a platform for cybercriminals to distribute malicious software through fake repositories. Users are warned to exercise caution when downloading from GitHub, as cybercriminals create convincing repositories impersonating well-known brands like Malwarebytes and LastPass. Red flags include brand impersonation, recently created accounts, and unusual download methods.
- [US] Opened a dodgy link, what's the likelihood of any issues?
A user joined a Discord to obtain a VRChat skin code, opened a link checked via VirusTotal (no threats detected), and later found Ngrok in their AppData folder via Malwarebytes. The user quarantined Ngrok but is uncertain about its origin and current risk.
- This new Windows malware can take over your PC and wipe it clean
Microsoft identified GigaWiper, a modular Windows backdoor combining remote access and data destruction capabilities, which integrates components from Crucio ransomware and FlockWiper. The malware allows espionage features like screen capture and remote control, alongside destructive commands to irreversibly wipe systems, with C2 servers detected and blocked by Malwarebytes.
- Microsoft fixes RoguePlanet zero-day in Defender
Microsoft has patched the RoguePlanet zero-day vulnerability (CVE-2026-50656) in Microsoft Defender, an elevation of privilege flaw that could allow attackers to gain system-level access. The fix is included in the updated Malware Protection Engine version 1.1.26060.3008, which automatically updates for most users. Systems with other antivirus software like Malwarebytes are not affected if Defender is disabled.
- NetNut botnet takes a hit. Don’t be part of the next one.
Google, the FBI, and partners disrupted the NetNut botnet, which used hijacked consumer devices as residential proxies. The operation reduced the botnet's device pool by millions through account disabling, infrastructure sharing, and app warnings. NetNut tricked users into installing malicious apps under the guise of 'bandwidth sharing' payouts.
- [GR] Fake Cloudflare Human Verification Scam (me3k.trappopbuttonrightnow.monster) - Executed PowerShell Script
A user was redirected to a fake Cloudflare Human Verification page that tricked them into executing a PowerShell script. The script downloaded and ran code from a suspicious domain, prompting the user to disconnect their PC from the internet and run malware scans, which found no threats.
- Watch out for renewal scams pretending to be Malwarebytes
Fake subscription renewal notices impersonating Malwarebytes and other companies are being used in phishing and tech support fraud scams. These emails often include fabricated details, high charges, and fake contact information to trick recipients into divulging personal or financial information.
- Got drained 1434 USDT on Arbitrum — exhausted all leads, need help identifying the source Help Needed
The user's MetaMask wallet on Arbitrum was drained of 1434 USDT without authorization, and they are seeking help to identify the source of the issue. The user has already investigated and ruled out several potential causes. The transaction that drained the wallet was a simple ETH transfer to an address funded by SideShift.
- Malicious trading website drops malware that hands your browser to attackers
A malicious trading website has been distributing malware that allows attackers to take control of users' browsers. The threat, highlighted by cybersecurity firm Malwarebytes, poses a significant risk to online security.