Monday, May 25, 2026
HomeMalware

Malware

Chinese Hackers Leverage Tibetan Community Lures and Filenames to Deploy Pubload Malware

Recent cybersecurity findings by IBM X-Force reveal a surge in targeted cyberattacks by a China-aligned threat actor known as Hive0154. The group is exploiting the Tibetan community’s geopolitical concerns, using tailored lure documents and filenames to spread highly sophisticated malware, most notably the Pubload...

US University Targeted by Androxgh0st Botnet for C2 Logger Hosting and Exploitation

A recent investigation by CloudSEK has revealed that the Androxgh0st botnet, which has been active since at least March 2023, has significantly expanded its capabilities and attack vectors. The botnet is now leveraging a wide array of Initial Access Vectors (IAVs) to target misconfigured...

New BUBBAS GATE Malware on Telegram Claims SmartScreen & AV/EDR Bypass

A new malware loader called "BUBBAS GATE" being actively promoted on underground forums and Telegram channels. The malicious software was first advertised on June 22, 2025, through a post on a well-known cybercrime forum, with threat actors claiming it offers advanced evasion capabilities against...

Cybercriminals Manipulate Search Engines, Leveraging ChatGPT and Luma AI Trends to Distribute Malicious Payloads

In a striking escalation of cybercrime tactics, threat actors are now exploiting the surging popularity of artificial intelligence tools, such as ChatGPT and Luma AI, to weaponize search engine results and deliver advanced malware to unsuspecting victims. A recent investigation by Zscaler’s ThreatLabz has...

APT Groups Exploit Microsoft ClickOnce for Malware Execution via Trusted Hosts

A recent report by the Trellix Advanced Research Center has exposed a highly advanced malware campaign, dubbed “OneClik,” which leverages Microsoft ClickOnce technology to execute malicious payloads on targeted systems. The attackers specifically focus on the energy, oil, and gas sector, using phishing emails...

RIFT – Microsoft’s New Open-Source Tool for Analyzing Malware in Rust Binaries

The release of RIFT (Rust Identification and Function Tagging), an open-source tool designed to help malware analysts identify attacker-written code within Rust binaries. The tool addresses growing cybersecurity challenges as threat actors increasingly adopt Rust programming language for malware development, taking advantage of its...