Sunday, May 3, 2026
HomeCyber News

Cyber News

XwormRAT Operators Enhance Stealth by Embedding Malicious Code into Legitimate Programs

Security analysts at AhnLab Security Intelligence Center (ASEC) are sounding the alarm over a surge in phishing emails delivering XwormRAT, a remote access trojan (RAT), through advanced steganography techniques. ASEC’s monthly “Phishing Email Trend Report” and “Infostealer Trend Report” flagged this new threat vector,...

Anatsa Malware Strikes Android Banking Apps on Google Play, Targeting Users in the U.S. and Canada

ThreatFabric researchers have uncovered a new campaign involving the Anatsa Android banking trojan, marking the third instance of this sophisticated malware targeting mobile banking customers in North America. The latest operation demonstrates the group's continued expansion into U.S. and Canadian markets, utilizing the official...

Outdated Billions of Leaked Credentials and ULP Files Flood Dark Web Forums, New Report Reveals

A comprehensive analysis of dark web credential markets reveals that billions of supposedly "fresh" login credentials circulating through combolists and URL-Login-Password (ULP) files are primarily recycled, outdated, or artificially generated data rather than genuine new breaches. The report, published by cybersecurity researchers on July...

Telecom Attacks Linked to China-Nexus VELETRIX Loader Exploit

Security researchers have uncovered a sophisticated cyber espionage campaign targeting China's telecommunications infrastructure through a previously unknown malware loader called VELETRIX. The campaign, dubbed "DragonClone," specifically targeted China Mobile Tietong Co., Ltd., a subsidiary of one of China's largest telecommunications companies, potentially providing attackers...

XMRig Malware Blocks Windows Update and Scheduled Tasks to Ensure Continuous Presence

Security researchers have identified a sophisticated resurgence of XMRig cryptomining malware following a two-year hiatus, with threat actors leveraging a multi-staged attack that systematically disables Windows Update services to maintain persistent access to infected systems. The campaign, analyzed by Sean Cartagena, Josemaria Grana, and...

Cloudflare Turnstile & Amazon S3 Exploited in Sophisticated New LogoKit Phishing Campaign

Cybersecurity researchers have uncovered a sophisticated phishing campaign targeting government agencies and organizations worldwide, exploiting trusted cloud services and security tools to enhance credibility and evade detection. The campaign, identified by Cyble Research and Intelligence Labs, demonstrates how threat actors are increasingly leveraging legitimate...