Tagged: malware

Crypto Hacks Netted Nearly $3B in 2026: NordVPN

According to the data collected by Slowmist, cybercriminals stole nearly $3 billion in crypto hacks and scams in 2025. Researchers recorded a total of 202 hack events, of which one was responsible for almost half of all losses. In February, a large-scale outflow of funds… Read More

Ghost Tap Malware Drives Spike in Contactless Payment Scams

In the evolving landscape of cyber threats, a sophisticated Android-based malware known as Ghost Tap is now said to be behind a notable increase in fraudulent contactless payments. This malicious software allows cybercriminals to execute tap-to-pay transactions remotely, bypassing the need for direct access to… Read More

Cyberattacks and Sophisticated Online Threats Examined in Blockchain Security Report

In 2025, the blockchain industry navigated a turbulent landscape marked by sophisticated cyber threats, regulatory advancements, and substantial financial losses. SlowMist‘s annual report highlights a year of professionalized attacks and maturing anti-money laundering (AML) efforts, underscoring the need for adequate security measures amid technological advancements…. Read More

Fraudsters Find Telegram Useful for Malicious Activities, but Risk-Reward Balance Is Shifting, Report Claims

Longer underground channel lifespans are mirrored by sharply higher blocking rates, prompting fraudsters to explore alternatives. Modern digital messengers, like WhatsApp, Telegram, Signal and various others, are now often being used for illicit activities. Kaspersky Digital Footprint Intelligence has conducted an in-depth monitoring of more… Read More

Sonatype’s Q3 Open Source Malware Index Shows Hackers Are Playing the Long Game

Sonatype, a provider of AI-centric DevSecOps, this week released the Open Source Malware Index, Q3 2025, which analyzed 34,319 open source malware packages discovered by Sonatype across major open source registries, including npm, PyPI, Hugging Face, and more. This quarter’s count brings the total number of… Read More

Cybercriminals Launch Campaign to Steal Sensitive Documents from APAC Nations, Report Reveals

Earlier this year, Kaspersky’s Global Research and Analysis Team (GReAT) identified a campaign by the ‘Mysterious Elephant’ APT. The group mainly targets government entities as well as foreign affairs organizations across the APAC area, with a particular focus on Pakistan, Bangladesh, Afghanistan, Nepal, Sri Lanka… Read More

Hackers Conceal Malware in Ethereum Smart Contracts According to New Cybersecurity Report

Cybercriminals are leveraging the complexity of blockchain technology to obscure malicious activities, with a new tactic involving the concealment of malware within Ethereum smart contracts, according to a recent report by cybersecurity firm ReversingLabs. This sophisticated approach allows hackers to disguise harmful traffic as routine… Read More

Emerging Online Threats and AI Trends Examined in Cybersecurity Report

In the landscape of cybersecurity and technology, Kaspersky’s recent reports highlight critical developments in cyber threats and the growing role of artificial intelligence in everyday applications. From sophisticated malware campaigns targeting financial institutions to the resurgence of a notorious backdoor and the underutilized potential of… Read More

Sonatype Report Shows Malware Surge

Sonatype, a software supply chain security company, this week released the Q2 2025 edition of its Open Source Malware Index, uncovering 16,279 malicious open source packages across major ecosystems including npm and PyPI. This quarter’s count brings the total number of open source malware packages Sonatype has discovered… Read More

Malware on App Store and Google Play Reportedly Found to Steal Cryptocurrency from Southeast Asia Residents

Kaspersky researchers have discovered a new Trojan spy called SparkKitty which targets smartphones on iOS and Android. It sends images from an infected phone and information “about the device to the attackers.” This malware was embedded in apps related “to crypto and gambling, as well… Read More

Over 19 Million Cyberattacks Reportedly Attempted by Using Gen Z’s Favorite Games as Bait

From April 1, 2024 to March 31, 2025, Kaspersky detected over 19 million attempts to download malicious or unwanted files disguised as popular Gen Z games. With GTA, Minecraft and Call of Duty among the most exploited, it’s clear that cybercriminals “are actively following gaming… Read More

Mobile Malware Posing as Invoice Reportedly Steals Banking Credentials from Unsuspecting Users

Kaspersky Global Research and Analysis Team (GReAT) discovered a new version of the Zanubis mobile banking trojan targeting users in Peru. When Zanubis originally emerged in 2022, it “mimicked PDF readers or Peru government organizations’ apps, and now in 2025 it disguises itself as two… Read More

Massive Data Breach Exposes 184 Million Login Credentials

A major cybersecurity breach has recently been unveiled, revealing a staggering 184 million login credentials, including emails and passwords, likely harvested through infostealer malware. Discovered by cybersecurity researcher Jeremiah Fowler, the unprotected 47GB database was found on a misconfigured cloud server, accessible to anyone without… Read More

Ransomware Attacks Increased Globally As Cybercriminals Prioritize High-Value Targets – Report

Anti-Ransomware Day was established on May 12 in 2020 by INTERPOL in collaboration with Kaspersky to commemorate the anniversary of the infamous WannaCry ransomware attack that occurred on May 12, 2017. The purpose of Anti-Ransomware Day is to raise global awareness about the threats “posed… Read More

Lazarus Group led Cyberattacks Targeting South Korean Supply Chains Uncovered – Report

Kaspersky’s GReAT team has uncovered a new Lazarus campaign, combining a watering hole attack with the “exploitation of vulnerabilities in third-party software to target organizations in South Korea.” During the research, company experts have also “discovered a zero-day vulnerability in the widely used South Korean… Read More

Cybersecurity Report: Zero-Day Vulnerability in Google Chrome Allowed Attackers to Bypass Browser’s Sandbox Protection System

save

Kaspersky has identified and helped patch a sophisticated zero-day vulnerability in Google Chrome (CVE-2025-2783) that allowed attackers to bypass the browser’s sandbox protection system. The exploit, discovered by Kaspersky’s Global Research and Analysis Team (GReAT), required no user interaction “beyond clicking a malicious link and… Read More

Stealer Malware Leaked More than 2 Million Bank Cards – Report

Kaspersky Digital Footprint Intelligence estimates that 2.3 million bank cards were leaked on the dark web, based on an “analysis of data-stealing malware log files from 2023-2024.” On average, every 14th infostealer infection results in stolen credit card information, with nearly “26 million devices compromised… Read More

Human-Driven Cyber Attacks Continue to Exploit Vulnerabilities Across Sectors – Cybersecurity Report

According to the latest Kaspersky Managed Detection and Response (MDR) analyst report, advanced persistent threats (APTs) have been detected in 25% of companies, accounting for over 43% of all high-severity incidents. This marks a staggering 74% increase compared to 2023. The Managed Detection and Response… Read More

OKX and SlowMist Report: Bom Malware Impacts Thousands of Users, Stealing $1.82M+ in Crypto

OKX and SlowMist noted in a report that on February 14, 2025, multiple users reported unauthorized access to their wallet assets. On-chain data analysis indicated that the incidents “exhibited characteristics of mnemonic phrase/private key leakage.” Further follow-ups with affected users revealed “that most of them… Read More

Kaspersky Exposes Malware on GitHub Stealing User Data and Bitcoin

Kaspersky Global Research & Analysis Team (GReAT) discovered hundreds of open source repositories with multistaged malware targeting gamers and crypto investors within a new campaign that was dubbed by Kaspersky as GitVenom. The infected projects include an automation instrument for “interacting with Instagram accounts, a… Read More

Send this to a friend