Packagist: PHP Package Repository Used in Supply Chain Attack
Packagist is the main package repository for PHP that was used to distribute malicious development versions of 10 packages associated with a…
Packagist is the main package repository for PHP that was used to distribute malicious development versions of 10 packages associated with a…
INFINITERED is custom malware deployed by UNC6508 that trojanizes REDCap system files. It hijacks the upgrade process to persist, harvests login credentials…
ScarCruft, also known as APT37, is a North Korean state-sponsored hacking group known for spear-phishing campaigns and deploying malware like RokRAT and…
APT37, also known as ScarCruft, is a North Korean cyber espionage group that has been active since at least 2012. They are…
RokRAT is a malware family exclusively attributed to the North Korean hacking group ScarCruft (APT37). It has been used in previous campaigns,…
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Ravie LakshmananJun 16, 2026Malware / Cyber Espionage Cybersecurity researchers have flagged two previously…
Security researchers at Zimperium's zLabs have identified a new Android banking trojan named Rokarolla, which targets 217 banking and cryptocurrency apps and…
Rokarolla is a new Android banking trojan discovered by Zimperium's zLabs. It targets 217 banking and cryptocurrency apps, uses 137 remote commands,…
HOOK is an Android banking trojan referenced in the Rokarolla report, noted for having 107 remote commands. It is part of the…
A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from…