Monday, May 25, 2026
HomeMalware

Malware

Anatsa Malware Strikes Android Banking Apps on Google Play, Targeting Users in the U.S. and Canada

ThreatFabric researchers have uncovered a new campaign involving the Anatsa Android banking trojan, marking the third instance of this sophisticated malware targeting mobile banking customers in North America. The latest operation demonstrates the group's continued expansion into U.S. and Canadian markets, utilizing the official...

XMRig Malware Blocks Windows Update and Scheduled Tasks to Ensure Continuous Presence

Security researchers have identified a sophisticated resurgence of XMRig cryptomining malware following a two-year hiatus, with threat actors leveraging a multi-staged attack that systematically disables Windows Update services to maintain persistent access to infected systems. The campaign, analyzed by Sean Cartagena, Josemaria Grana, and...

Q2 Sees Surge in Android Malware – Banking Trojans and Spyware on the Rise

The latest detection statistics from Dr.Web Security Space for mobile devices reveal troubling trends in Android malware for the second quarter of 2025. Adware Trojans remain the most prevalent threat, but banking trojans and sophisticated spyware campaigns have significantly increased, exposing users to new...

Leveraging Coding Agents – A New Slopsquatting Attack Disrupts Malware Delivery Workflows

The rapid integration of AI-driven coding agents, such as Claude Code CLI, OpenAI Codex CLI, and Cursor AI, has revolutionized developer workflows, boosting productivity through auto-completion, dependency suggestions, and automated installations. Yet, beneath this seamless “vibe-coding” experience lurks a sophisticated supply-chain risk that is...

Malware Payloads Deployed in the Wild Using Abused AV/EDR Evasion Framework

Elastic Security Labs has sounded the alarm after uncovering multiple active infostealer campaigns leveraging the commercial AV/EDR evasion framework SHELTER for malicious purposes. Once marketed exclusively to offensive security professionals for red team simulation, SHELTER is now being abused by threat actors to bypass...

Cybercriminals Abuse Genuine Inno Setup Installer to Distribute Malware

In a concerning trend for Windows users and the broader cybersecurity landscape, cybercriminals are increasingly leveraging legitimate software installation frameworks such as Inno Setup to distribute potent malware strains. Once trusted as a staple for streamlined, user-friendly application deployment, these installer packages are now...