WithSecure Tracks WeevilProxy Stealer
WithSecure is a cybersecurity company that tracks the stealer malware identified in the TradingView malvertising campaign as WeevilProxy. The same malware is…
WithSecure is a cybersecurity company that tracks the stealer malware identified in the TradingView malvertising campaign as WeevilProxy. The same malware is…
The Bun runtime, a legitimate JavaScript runtime built on Apple's JavaScriptCore engine, is used by the SourTrade malvertising campaign as a base…
StreamSaver.js is an open-source streamed-download library that was used in earlier SourTrade activity tracked through April 30, 2026. The current campaign retains…
Group-IB has uncovered a China-nexus cyber operation tracked as JadeProx, which has been targeting government, healthcare, and education organizations across Asia and…
SANS ISC handler Brad Duncan documented an ACR Stealer infection traced to a page impersonating Claude AI, reached through malicious Google ads.
ACR Stealer, an infostealer active since 2024, is targeting enterprise networks by stealing saved browser passwords, live session tokens, PDFs, Microsoft 365…
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service (DDoS) botnet for roughly…
Cybersecurity researchers at Infoblox have uncovered a threat actor tracked as Lurking Lizard, operating an end-to-end malicious residential proxy business since at…
A long-running North Korean cyber campaign that typically uses fake job offers and coding tests to lure victims. This iteration uses malvertising…
Cybersecurity researchers from Elastic Security Labs have disclosed a new campaign that delivers the CastleStealer information stealer via a previously unreported malware…