Gaslight macOS Malware Uses Prompt Injection to Bypass AI Analysis
A new macOS malware called Gaslight uses embedded prompt injection strings and fake debugging data to confuse AI-assisted malware analysis tools. It…
Malware families, payloads, loaders, ransomware and related tooling.
A new macOS malware called Gaslight uses embedded prompt injection strings and fake debugging data to confuse AI-assisted malware analysis tools. It…
KuinaExtractor is a new Rust-based information stealer that harvests web browser data, crypto wallets, and credentials for Roblox, Steam, and Discord. It…
SHARDLOADER is a malware loader used by Mustang Panda that sideloads a malicious DLL through legitimately signed binaries like Solid PDF Creator…
MINIRECON is a reworked variant of the Toneshell backdoor, beaconing over WebSocket on HTTPS, used by Mustang Panda.
ZOHOMURK is a novel malware that uses hardcoded Zoho OAuth credentials to turn an attacker-controlled WorkDrive account into a dead drop for…
Toneshell is a backdoor malware documented by IBM X-Force, used as a base for the MINIRECON variant by Mustang Panda.
LOTUSLITE is a backdoor used by Mustang Panda in attacks on India's banking sector and South Korean policy circles, staged through legitimate…
A modular backdoor malware previously hosted on the same staging server used in the Thai Ministry of Finance attack. It is known…
PteroSand is a malware payload delivered by Gamaredon via HTA downloaders in spear-phishing campaigns targeting Ukraine.
PteroLNK is a weaponizer used by Gamaredon to infect USB and network drives with malicious LNK files for lateral movement.