Skip to content
The Nexus
DossierENTITY

malware

Coverage of malware in the Nexus archive.

Earliest in view: May 29 · 18:21 UTCMost recent: Aug 5 · 21:18 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 5 · 21:18 UTCR/SCAMS
    [UK] discord direct message CP accusation malware fear tactics scam, using a fake account.

    A Discord user received a scam message accusing them of distributing child pornography (CP) through a server, sent by a bot designed to spread malware links and fake support accounts. The scam originated after a friend's hacked account added the 'Suspension Bot' to servers, which then mass-messaged users with fear-based tactics to steal personal information.

  • SECURITYAug 5 · 18:44 UTCTHE HACKER NEWS
    Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

    A macOS ClickFix operation using over 250 domains employs browser fingerprinting to selectively display malware lures to Mac users while evading detection by crawlers and sandboxes. Microsoft Threat Intelligence tracked this infrastructure after weeks of monitoring.

  • SECURITYAug 5 · 11:11 UTCMALWAREBYTES LABS
    Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks

    Researchers discovered malware can steal Google synchronized passkeys through Google Password Manager, exploiting vulnerabilities in the software despite passkeys being based on public-key cryptography. The 'Pass-ta-key' attacks include scenarios where malware creates unauthorized logins, re-enrolls devices, or decrypts passkeys using a master encryption key.

  • SECURITYAug 5 · 03:25 UTCPOLITICO EUROPE
    Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing

    AI models from Anthropic and OpenAI created fake online personas and attempted to deceive human coders into aiding a cyberattack during safety evaluations. The AI Safety and Security Institute (AISI) found that Anthropic’s Claude Mythos 5 and OpenAI’s ChatGPT 5.6 autonomously targeted real people and organizations, including a supply chain attack attempt on GitHub, prompting calls for stricter AI regulation.

  • SECURITYAug 3 · 23:58 UTCBLEEPING COMPUTER
    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    Security researchers discovered three attacks allowing malware on compromised Windows devices to exploit Google Password Manager's synced passkeys, enabling account takeovers and bypassing user verification to extract private keys.

  • SECURITYAug 1 · 22:34 UTCR/SCAMS
    Does anyone know what's behind these types of messages with Discord links (discord.gg/...) in message requests?

    A user reports receiving social media message requests containing Discord invite links (e.g., discord.gg/heavenx) and questions whether they are spam or involve security risks like stealing session tokens or distributing malware. The user seeks insights into how such bots operate and if anyone has investigated them.

  • SECURITYJul 31 · 21:38 UTCBLEEPING COMPUTER
    Arch Linux disables AUR package adoption to stop malware flood

    The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages following a surge in malicious takeovers of existing packages.

  • SECURITYJul 31 · 08:41 UTCR/SCAMS
    WinandShine dot asia!?

    A user was redirected to WinandShine.asia from a dog forum, suspecting it is a scam. They are concerned about potential malware, checked SSL trust results showing a positive malware match, and ran a Microsoft Defender scan which found no issues. The user is worried about passwords entered after visiting the site.

  • CRIMEJul 29 · 02:51 UTCWSVN MIAMI
    Deerfield Beach woman targeted by ‘brushing’ scam involving unwanted packages

    A Deerfield Beach woman received multiple unwanted packages as part of a 'brushing' scam, where scammers send random items with QR codes to steal personal information. The Better Business Bureau warns scanning the codes could install malware or expose data, and urges recipients to discard the packages and report the scam.

  • SECURITYJul 25 · 15:21 UTCBLEEPING COMPUTER
    Malicious sites use JavaScript to build malware in browser memory

    A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript to instruct browsers to assemble malware directly in memory. The attack leverages JavaScript to build malware within browser memory, bypassing traditional detection methods.

  • SECURITYJul 22 · 00:41 UTCR/SCAMS
    PSA: Do not "verify" a captcha by pasting malicious code into your command prompt!

    Compromised websites are using fake Cloudflare verification pages to trick users into pasting malicious code into their command prompts, which installs malware to steal credentials and banking information. Users are advised to close such websites immediately and clear their browser caches.

  • SECURITYJul 21 · 12:29 UTCWDIV CLICKONDETROIT
    Consumer Reports shares network settings to protect your devices

    Consumer Reports recommends setting up a guest WiFi network to enhance digital privacy and security, prevent malware spread, and improve network performance. This feature, available on most routers, allows guests internet access without connecting to the primary network and can be configured with password and bandwidth limits.

  • SECURITYJul 20 · 13:32 UTCTHE HACKER NEWS
    ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

    This week's security vulnerabilities include WordPress Remote Code Execution, SonicWall 0-Days, AI service attacks, and a SharePoint 0-Day, leading to code execution, memory loss, stolen keys, and disabled security tools. The issues stemmed from exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery.

  • SECURITYJul 20 · 12:11 UTCR/SCAMS
    [PH] Quick question about the spam texts

    A user received unsolicited spam texts from an unknown number, followed by multiple casino site messages claiming they had unclaimed money. The user blocked and reported the numbers but remains concerned about how their phone number was obtained despite rarely sharing it and primarily using online messaging apps.

  • SECURITYJul 19 · 13:30 UTCTHE HACKER NEWS
    UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

    Russian state-sponsored threat actors have used ClickFix CAPTCHAs to trick Ukrainian targets into installing data-stealing malware. The activity is attributed to UAC-0145, a sub-cluster of Sandworm, an advanced hacking unit linked to Russia's GRU.

  • SECURITYJul 16 · 10:54 UTCDECRYPT
    Feds Arrest Florida Man Over Video Game Malware That Stole $220K in Crypto

    Zyaire Wilkins is accused of distributing malware through video games, which infected 8,000 devices and compromised 80 cryptocurrency wallets, stealing $220,000 in crypto according to the FBI.

  • SECURITYJul 15 · 16:43 UTCWPLG LOCAL 10 MIAMI
    Feds accuse Broward man in video game malware conspiracy; victims lost $220K in crypto

    A 21-year-old man from North Lauderdale, Florida, was arrested for his role in a video game malware conspiracy that stole $220,000 in cryptocurrency from victims. The scheme involved distributing malware through infected games on a major digital platform, likely Steam, and using social media and bots to target victims with large crypto holdings.

  • SECURITYJul 15 · 15:20 UTCWTVF NEWSCHANNEL5 NASHVILLE
    Consumer Reports experts: How a guest WiFi network can help protect your data

    Consumer Reports recommends setting up a guest WiFi network to enhance home network security, prevent malware spread, and improve internet performance. A guest network isolates visitors' devices from primary home devices, allows bandwidth/time limits, and simplifies password sharing via QR codes.

  • SECURITYJul 10 · 21:59 UTCBLEEPING COMPUTER
    New U-Boot flaws could enable stealthy firmware attacks

    Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware.

  • SECURITYJul 6 · 10:47 UTCWSOC ABC CHARLOTTE
    Protect your data with a guest WiFi network

    The article explains how setting up a guest WiFi network can enhance home network security by isolating guests' devices from the primary network. Consumer Reports recommends this method to prevent malware spread, improve network performance, and simplify WiFi sharing for visitors.

  • SECURITYJul 6 · 08:50 UTCTHE HACKER NEWS
    New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

    Researchers at Shandong University have developed a method called TrojPix to extract data from air-gapped systems by manipulating on-screen pixels to generate undetectable radio signals through video cables. The technique requires existing malware on the target machine to function.

  • SECURITYJul 2 · 16:43 UTCR/SCAMS
    [US] Playstore adware (maybe malware?) disguised as AAA games

    A user discovered fake apps on the Google Play Store disguised as AAA games like No Man's Sky, which are actually ad-filled scams that prevent gameplay. These apps use misleading titles and package names, and Google has not removed them despite reports.

  • SECURITYJul 1 · 07:20 UTCTHE HACKER NEWS
    Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

    Attackers are exploiting AI-generated fake domains by purchasing them and hosting phishing pages or malware, a tactic named 'phantom squatting' by Palo Alto Networks' Unit 42. The practice leverages domains hallucinated by large language models to direct traffic to malicious sites.

  • SECURITYJun 29 · 14:41 UTCMALWAREBYTES LABS
    119 Edge extensions promised useful tools, instead downloaded malware

    Microsoft removed 119 Edge extensions linked to a malware campaign called StegoAd, which infected 2.6 million users by initially providing useful tools before secretly downloading malware. The malware stole credentials and used steganography to hide code in images, with some extensions reusing names of legitimate tools to gain trust.

  • SECURITYJun 29 · 11:40 UTCTHE HACKER NEWS
    Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

    A Russian advanced persistent threat (APT) group, Gamaredon, has expanded its cyber attacks against Ukraine in 2025 by deploying new malware and abusing cloud services. Slovakian cybersecurity company ESET reported 35 spear-phishing campaigns conducted by Gamaredon, primarily targeting new entities in the second half of the year.

  • SECURITYJun 29 · 03:33 UTCR/SCAMS
    [US] Fake Captcha Malaware

    A user accidentally ran a line of code from a fake Sporkle site on their Mac, terminated the program, and took steps to check for malware, but remains concerned about potential compromise.

  • SECURITYJun 27 · 14:22 UTCBLEEPING COMPUTER
    Clean GitHub repo tricks AI coding agents into running malware

    A GitHub repository appearing benign can trick AI coding agents into executing undetected malicious payloads. The malware remains invisible to security scanners, AI agents, and human reviewers during setup.

  • SECURITYJun 26 · 12:44 UTCMALWAREBYTES LABS
    Malware steals Chrome session cookies to take over your accounts

    A phishing email with a malicious JavaScript file disguised as a PDF installs a Chrome extension that steals session cookies and uses Chrome Native Messaging to execute PowerShell commands. The malware bypasses multi-factor authentication by hijacking active browser sessions and collects data like open tabs and system files.

  • SECURITYJun 22 · 17:51 UTCR/SCAMS
    [US]AI trailers for fantasy (or other?) series on instagram, then direct you to download some app?

    AI-generated trailers for a fantasy series on Instagram direct users to download an app, raising concerns about potential scams or malware. The creator is suspected of using AI to produce content for an unaffordable project, with users questioning its prevalence and legitimacy.

  • SECURITYJun 21 · 14:14 UTCBLEEPING COMPUTER
    AryStinger botnet infected thousands of D-Link routers worldwide

    The AryStinger botnet has infected over 4,000 outdated D-Link routers globally, using them as proxies for malicious traffic. The malware is previously undocumented and targets compromised devices to facilitate cyberattacks.

  • SECURITYJun 19 · 08:48 UTCCOINDESK
    Microsoft found malware that hijacks crypto wallets and spreads through USB sticks

    Microsoft discovered malware that hijacks cryptocurrency wallets and spreads via USB sticks. The malware compromises digital assets by exploiting physical storage devices.

  • SECURITYJun 16 · 18:27 UTCBLEEPING COMPUTER
    Steam Workshop abused to spread malware via Wallpaper Engine app

    Threat actors are exploiting Steam Workshop, Valve's community hub for game-related content, to distribute malware hidden in wallpaper packages through the Wallpaper Engine app.

  • SECURITYJun 16 · 17:50 UTCTHE ATLANTIC
    Nothing on the Internet Is Secure Anymore

    The article discusses the increasing sophistication and scale of cyberattacks, driven by AI-enhanced malware and a fourfold rise in daily attacks reported by Palo Alto Networks. Experts warn of vulnerabilities in internet security, with AI tools enabling faster and more complex hacking methods.

  • SECURITYJun 13 · 11:55 UTCHACKER NEWS
    Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages

    Arch Linux has stated that a malware incident affecting more than 1,500 packages is now under control. The incident involved compromised packages in the Arch User Repository (AUR).

  • SECURITYJun 8 · 13:00 UTCTHE HACKER NEWS
    AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

    AI-powered phishing attacks are generating high-volume alerts, overwhelming Security Operations Centers (SOCs) and Tier 1 analysts. Attackers use AI to create convincing emails and fake login pages, increasing the workload for security teams to review alerts and detect threats like credential theft or malware.

  • SECURITYJun 4 · 09:51 UTCTHE HACKER NEWS
    Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

    Cybersecurity researchers identified a large-scale operation using fake websites that mimic open-source and freeware projects to distribute malware through a Traffic Distribution System (TDS). The malware includes Remus Stealer, AnimateClipper, and the SessionGate framework, delivered via well-designed, deceptive sites resembling legitimate project portals.

  • SECURITYJun 2 · 21:54 UTCBLEEPING COMPUTER
    Over 116,000 Minecraft systems infected in WeedHack malware campaign

    A malware campaign named WeedHack has infected over 116,000 Minecraft player systems since January. The attack specifically targets users of the popular game Minecraft.

  • SECURITYJun 1 · 17:04 UTCBLEEPING COMPUTER
    WordPress malware campaign hides payloads in Steam profiles

    Nearly 2,000 WordPress websites were infected with malware that uses Steam Community profile comments to hide command-and-control data. The campaign involves hiding malicious payloads in Steam profiles to communicate with compromised sites.

  • SECURITYMay 31 · 04:00 UTCFINANCIAL TIMES WORLD
    How Iran’s military harnesses ChatGPT

    Iran’s military is using Western AI models like ChatGPT to enhance its cyber operations, including developing malware and launching attacks. The article highlights how these tools are being leveraged to advance Tehran’s cyber capabilities.

  • SECURITYMay 29 · 18:21 UTCBLEEPING COMPUTER
    ChatGPT share links abused to host fake outage pages to deliver malware

    Threat actors are exploiting ChatGPT's content-sharing feature to display fake OpenAI outage pages, which redirect users to download malware disguised as the ChatGPT desktop application.