search
malware
Trends
- 1Crypto-stealing operation drains $100,000 from victimsβ$100k in Crypto Drained by the Underground Operation A cryptocurrency-stealing operation utilizing an Aotera/Tedy loader
Researchers report that a malware operation using an Aotera/Tedy loader has stolen roughly $100,000 in cryptocurrency. The loader injects a Vidar-class infostealer into Windows processes, then launches Chrome or Edge to run malicious scripts inside victims' browser sessions, capturing wallets and credentials. Security observers are warning Windows users to be cautious, as the malware builder is being circulated among underground actors.
- 2Android 17 to Lock Accessibility Services Behind Verified ToolsβAndroid 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google's Android 17 Advanced Protection mode will restrict accessibility services so they can only be enabled for verified accessibility tools. The change is aimed at closing a common abuse vector, since malware frequently exploits accessibility permissions to take over devices, read screen content and perform unauthorized actions.
- 3AI-Powered Malware Framework BraZetsu Hits Latin Americaβ(group-ib.com) BraZetsu: The AI-Powered Malware Framework Fueling Latin America's Cybercrime Ecosystem In brief - This a
Cybersecurity firm Group-IB has detailed BraZetsu, a sophisticated Python-based malware framework used by Brazilian threat actor Exilware. The framework reportedly supports initial access broker operations and is described as AI-powered, fueling a broader cybercrime ecosystem across Latin America. Security researchers are sharing the findings, flagging the growing use of automation and AI tooling by criminal groups in the region.
- 4Interpol warns AI is making cyberattacks faster and harder to detectβAI is making cyberattacks faster and harder to detect, Interpol warns. Hereβs what companies should watch
Interpol has issued a warning that artificial intelligence is enabling cyberattacks that are faster, more automated and harder to detect, according to CNBC. The alert highlights what companies should watch for as criminals use AI tools to scale phishing, malware and other attacks. Businesses are being urged to reassess their cyber defenses as threats grow more sophisticated.
- 5Sucuri details self-rebuilding WordPress backdoor tied to wpForo attacksβπ€ Sucuri dissects a WordPress backdoor ("SC") that rebuilds itself after cleanup: persistence via files, DB entries, and
Security firm Sucuri has analyzed a WordPress backdoor, dubbed "SC", that restores itself after administrators clean infected sites. The malware persists through injected files, database entries, and shared memory, making removal difficult. Sucuri links it to exploit attempts targeting the wpForo forum plugin, with fewer than 20 incidents observed since July 3. WordPress site owners are being urged to check for signs of infection.