Tagged: malware

Sonatype’s Q3 Open Source Malware Index Shows Hackers Are Playing the Long Game

Sonatype, a provider of AI-centric DevSecOps, this week released the Open Source Malware Index, Q3 2025, which analyzed 34,319 open source malware packages discovered by Sonatype across major open source registries, including npm, PyPI, Hugging Face, and more. This quarter’s count brings the total number of… Read More

Cybercriminals Launch Campaign to Steal Sensitive Documents from APAC Nations, Report Reveals

Earlier this year, Kaspersky’s Global Research and Analysis Team (GReAT) identified a campaign by the ‘Mysterious Elephant’ APT. The group mainly targets government entities as well as foreign affairs organizations across the APAC area, with a particular focus on Pakistan, Bangladesh, Afghanistan, Nepal, Sri Lanka… Read More

Hackers Conceal Malware in Ethereum Smart Contracts According to New Cybersecurity Report

Cybercriminals are leveraging the complexity of blockchain technology to obscure malicious activities, with a new tactic involving the concealment of malware within Ethereum smart contracts, according to a recent report by cybersecurity firm ReversingLabs. This sophisticated approach allows hackers to disguise harmful traffic as routine… Read More

Emerging Online Threats and AI Trends Examined in Cybersecurity Report

In the landscape of cybersecurity and technology, Kaspersky’s recent reports highlight critical developments in cyber threats and the growing role of artificial intelligence in everyday applications. From sophisticated malware campaigns targeting financial institutions to the resurgence of a notorious backdoor and the underutilized potential of… Read More

Sonatype Report Shows Malware Surge

Sonatype, a software supply chain security company, this week released the Q2 2025 edition of its Open Source Malware Index, uncovering 16,279 malicious open source packages across major ecosystems including npm and PyPI. This quarter’s count brings the total number of open source malware packages Sonatype has discovered… Read More

Malware on App Store and Google Play Reportedly Found to Steal Cryptocurrency from Southeast Asia Residents

Kaspersky researchers have discovered a new Trojan spy called SparkKitty which targets smartphones on iOS and Android. It sends images from an infected phone and information “about the device to the attackers.” This malware was embedded in apps related “to crypto and gambling, as well… Read More

Over 19 Million Cyberattacks Reportedly Attempted by Using Gen Z’s Favorite Games as Bait

From April 1, 2024 to March 31, 2025, Kaspersky detected over 19 million attempts to download malicious or unwanted files disguised as popular Gen Z games. With GTA, Minecraft and Call of Duty among the most exploited, it’s clear that cybercriminals “are actively following gaming… Read More

Mobile Malware Posing as Invoice Reportedly Steals Banking Credentials from Unsuspecting Users

Kaspersky Global Research and Analysis Team (GReAT) discovered a new version of the Zanubis mobile banking trojan targeting users in Peru. When Zanubis originally emerged in 2022, it “mimicked PDF readers or Peru government organizations’ apps, and now in 2025 it disguises itself as two… Read More

Massive Data Breach Exposes 184 Million Login Credentials

A major cybersecurity breach has recently been unveiled, revealing a staggering 184 million login credentials, including emails and passwords, likely harvested through infostealer malware. Discovered by cybersecurity researcher Jeremiah Fowler, the unprotected 47GB database was found on a misconfigured cloud server, accessible to anyone without… Read More

Ransomware Attacks Increased Globally As Cybercriminals Prioritize High-Value Targets – Report

Anti-Ransomware Day was established on May 12 in 2020 by INTERPOL in collaboration with Kaspersky to commemorate the anniversary of the infamous WannaCry ransomware attack that occurred on May 12, 2017. The purpose of Anti-Ransomware Day is to raise global awareness about the threats “posed… Read More

Lazarus Group led Cyberattacks Targeting South Korean Supply Chains Uncovered – Report

Kaspersky’s GReAT team has uncovered a new Lazarus campaign, combining a watering hole attack with the “exploitation of vulnerabilities in third-party software to target organizations in South Korea.” During the research, company experts have also “discovered a zero-day vulnerability in the widely used South Korean… Read More

Cybersecurity Report: Zero-Day Vulnerability in Google Chrome Allowed Attackers to Bypass Browser’s Sandbox Protection System

save

Kaspersky has identified and helped patch a sophisticated zero-day vulnerability in Google Chrome (CVE-2025-2783) that allowed attackers to bypass the browser’s sandbox protection system. The exploit, discovered by Kaspersky’s Global Research and Analysis Team (GReAT), required no user interaction “beyond clicking a malicious link and… Read More

Stealer Malware Leaked More than 2 Million Bank Cards – Report

Kaspersky Digital Footprint Intelligence estimates that 2.3 million bank cards were leaked on the dark web, based on an “analysis of data-stealing malware log files from 2023-2024.” On average, every 14th infostealer infection results in stolen credit card information, with nearly “26 million devices compromised… Read More

Human-Driven Cyber Attacks Continue to Exploit Vulnerabilities Across Sectors – Cybersecurity Report

According to the latest Kaspersky Managed Detection and Response (MDR) analyst report, advanced persistent threats (APTs) have been detected in 25% of companies, accounting for over 43% of all high-severity incidents. This marks a staggering 74% increase compared to 2023. The Managed Detection and Response… Read More

OKX and SlowMist Report: Bom Malware Impacts Thousands of Users, Stealing $1.82M+ in Crypto

OKX and SlowMist noted in a report that on February 14, 2025, multiple users reported unauthorized access to their wallet assets. On-chain data analysis indicated that the incidents “exhibited characteristics of mnemonic phrase/private key leakage.” Further follow-ups with affected users revealed “that most of them… Read More

Kaspersky Exposes Malware on GitHub Stealing User Data and Bitcoin

Kaspersky Global Research & Analysis Team (GReAT) discovered hundreds of open source repositories with multistaged malware targeting gamers and crypto investors within a new campaign that was dubbed by Kaspersky as GitVenom. The infected projects include an automation instrument for “interacting with Instagram accounts, a… Read More

Malware Report: Crypto Stealing Trojan Discovered by Kaspersky in Apple App Store, Google Play

Kaspersky has discovered a new data-stealing Trojan, SparkCat, active in the Apple App Store and Google Play. This is said to be the “first known instance” of optical recognition-based malware appearing in AppStore. Kaspersky said they found comments in the code written in Chinese, possibly… Read More

Malware and Phishing Attacks Disguised as Zoom Meeting Links Analyzed by Crypto-focused Firm SlowMist

Recently, several users on X reported a phishing attack disguised as Zoom meeting links, according to an update from SlowMist. In one case, SlowMist pointed out that a victim installed malicious software after clicking on a fake Zoom meeting link, reportedly resulting in the “theft… Read More

Malware Disguised as Open-Source Plugin: Devices Infected via Compromised Archive Files Appearing to be Skill Assessment Tests

Lazarus’ key operation – “Operation DreamJob” – continues to evolve with sophisticated tactics (involving malware and malicious activities) that have persisted for over five years, according to Kaspersky‘s Global Research and Analysis Team. The targets reportedly include workers from a nuclear-related organization, who were infected… Read More

Kaspersky Warns of Rising Crypto-Drainer Malware, Data Breach Ads on Dark Web

Cybercriminal activity on the dark web surged in 2024, with significant growth in discussions around crypto-drainer malware and advertisements for corporate database breaches, according to Kaspersky’s latest Security Bulletin. The report highlights an evolving cyber threat landscape, with increased interest in malware targeting cryptocurrency wallets… Read More

Send this to a friend