Home/ Blog/ Topics/ Malware & C2
Topic

Malware & C2

Backdoors, web shells, rootkits, loaders, and the command-and-control tradecraft behind active intrusions.

Security news

Microsoft Exchange auth-bypass CVE-2026-62911 gives attackers a SYSTEM webshell, and a public exploit is out

CVE-2026-62911 lets attackers relay an Exchange server's own machine account into a SYSTEM webshell.

Security news

VulnCheck finds two factory backdoors in ZBT routers that hand attackers full control. No fix exists.

VulnCheck found two more factory implants in ZBT router firmware, SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233), that grant remote root access.

Security news

Weedhack stealer survives takedown by hiding servers on Ethereum, still spreading via fake Minecraft sites

Weedhack, an infostealer spread through fake Minecraft sites, survived a C2 takedown by reading server addresses from the Ethereum blockchain. How to detect it.

Security news

Malware turns Android car head units into a proxy botnet that hides attacks behind trusted home IPs

Kaspersky found the first malware built for Android car head units. It ignores the vehicle and rents the car's connection as a residential proxy.

Security news

Elementor Pro flaw (CVE-2026-32475) lets an unauthenticated attacker upload PHP and run code. Patch to 4.2.2.

Elementor Pro before 4.2.2 has a critical file upload flaw (CVE-2026-32475, CVSS 9.0) letting an unauthenticated attacker plant a PHP webshell. Patch now.

Security news

Malicious Rust crates arrayref, internment and append-only-vec ran a stealer at build time. Pin now.

Three popular Rust crates, including arrayref with 245M downloads, were briefly poisoned to run an infostealer during cargo build on August 20.

Security news

A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.

Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.

Security news

TWINLOOT runs its command channel inside Microsoft 365 and steals passwords with a fake Windows lock screen

TWINLOOT hides its command channel in SharePoint, Teams, and Edge and steals passwords with a fake Windows lock screen. No CVE. Here is how to detect it.

Security news

Forminator WordPress plugin flaw lets attackers run code with no login (CVE-2026-15748)

CVE-2026-15748 is a CVSS 9.8 unauthenticated file-upload RCE in the Forminator WordPress plugin. Affects versions up to 1.56.1. Update to 1.56.2 now.

Security news

Anthropic ran three Claude agents on one codebase and they built malware to sabotage each other

Anthropic's red team ran three Claude agents on one codebase, unaware of each other. They built self-replicating malware to win. What defenders should do.

Security news

Mustang Panda's kernel rootkit hides its backdoor from host tools

Mustang Panda's CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.

Security news

AmnesiaStealer hijacks live macOS browser sessions, not just saved passwords

AmnesiaStealer is a Rust macOS infostealer spread via fake GitHub ClickFix pages. It steals keychain and browser data, then takes live control of your session.

Security news

Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.

Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.

Security news

North Korea's Lazarus used fake job offers and a Windows zero-day to hijack defense firms' PCs

North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.

Security news

BdThemes WordPress plugins were hijacked to plant hidden admin accounts and a webshell

A supply-chain attack poisoned a data feed in BdThemes WordPress plugins to create hidden admin accounts and drop a webshell.

Security news

Malicious npm packages skip install scripts and hide their C2 in DNS to drop a cross-platform stealer

Flooding Dropper seeded close to 800 malicious npm packages that run on require() and fall back to DNS TXT records for C2. How to detect it and clean up.

Security news

Malware can use Windows Hello keys to sign into Entra ID as you

Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.

Security news

Attackers turn unpatched TrueConf servers into backdoor delivery, pushing trojanized client installers

Head Mare exploited unpatched TrueConf servers (before 5.3.9, 5.4.9, 5.5.5) to swap client installers for unsigned backdoors.

Security news

VulnCheck: Zbtlink routers ship a factory root shell with no fix. The model list is not where you start.

VulnCheck found a factory-shipped remote-access implant in 20 Zbtlink router models that calls home and hands a remote root shell. There is no patched firmware.

Security news

The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.

The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.

Security news

A signed ScreenConnect installer becomes a backdoor after malware turns Defender off

The SMOKE#SCREEN campaign disables Windows Defender, then installs a legitimately signed ScreenConnect agent your allowlist trusts.

Security news

DOUBLECUP loader service stages malware in the browser cache to drop a RAT on Windows and macOS

DOUBLECUP, a Russian loader service, stages malware in the browser cache via ClickFix, then rebuilds it with trusted tools to drop a RAT on Windows and macOS.

Security news

Malware can hijack Google Chrome passkey logins and sign in as you, even with two-factor on

Google Chrome passkeys can be hijacked by malware: Unit 42 showed the device key can be copied and replayed when a site skips the user-verified check.

Security news

Russian OWAReaper implant exploits an Outlook Web Access flaw, and a password reset won't evict it

Russian group Void Blizzard is exploiting Outlook Web Access flaw CVE-2026-42897 to plant OWAReaper, a backdoor whose server-side mailbox access survives

Security news

Dysphoria botnet hides on the blockchain to survive takedowns

Dysphoria, a DDoS-for-hire IoT botnet, survived a March takedown by anchoring its command servers to Ethereum and Solana names no registrar can seize, and now

Explainers

Public DNS servers with filtering: a verified list of what each IP really blocks

Public DNS servers with filtering, verified against official docs: what the Cloudflare, Quad9, AdGuard, CleanBrowsing, ControlD, Mullvad and OpenDNS IPs block.

Security news

SourTrade malvertising builds an infostealer inside your browser, so no file crosses the wire to scan

SourTrade malvertising makes the victim's browser assemble a Windows infostealer in memory, with a unique hash per visitor, so no scannable file ever crosses

Security news

Fake Notepad++ plugin drops a Windows loader that slips past sandboxes and app allowlists

CERT-UA ties UAC-0099 to a campaign hiding a Windows loader in a genuine Notepad++ via DLL sideloading.

Security news

HollowGraph turns Microsoft 365 into a C2 channel with no patch

HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.

Security news

wp2shell went from patch to public exploit in a day. Patching is no longer enough.

Public proof-of-concept exploits for the wp2shell WordPress Core RCE (CVE-2026-63030) are live and the mechanism is disclosed.

Security news

ACR Stealer steals live sessions. A password reset won't help.

ACR Stealer, now surging per Microsoft, steals live browser sessions and Microsoft 365 files through ClickFix lures.

Security news

A stranger with no login can take over WordPress sites on 6.9 and 7.0. Patch now.

WordPress Core 6.9 and 7.0 carry wp2shell (CVE-2026-63030), an unauthenticated remote code execution flaw. Update to 6.9.5 or 7.0.2 right away, then hunt.

Security news

ClickLock locks your Mac until you hand over the password

ClickLock is a macOS infostealer that kills your apps every 210ms until you type your login password into a fake prompt.

Security news

AI wrote most of this IoT botnet, badly. That helps defenders.

Unit 42 found TuxBot v3, an IoT botnet largely written with an AI. The build is 70% broken, the working core is plain Mirai, and your defenses still hold.

Security news

AsyncAPI's npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.

Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.

Security news

Notarized by Apple, still malware: the CrashStealer Mac stealer

CrashStealer is a macOS info-stealer that Apple notarized, so Gatekeeper cleared it on launch before it drained keychains, browser logins and crypto wallets.

Security news

Mass CMS campaign turns unpatched plugins into webshells

Australia's cyber agency warns of a global campaign mass-exploiting 16 known CMS and plugin flaws to drop webshells on WordPress, Joomla and Craft sites.

Security news

A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.

An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.

Security news

npm just killed install-script malware by default. This week's other attack walks right past it.

npm 12 disables install scripts by default, which would have stopped this week's jscrambler infostealer.

Security news

Super Forms flaw lets anyone take over a WordPress site, and a working exploit is now public

A critical flaw (CVSS 9.8) in the Super Forms WordPress plugin lets unauthenticated attackers run code on the server.

Security news

GigaWiper fakes a ransomware hit to cover a disk wipe, and the only early warning is on the host

GigaWiper encrypts files to .candy with no key and no ransom note, because the ransomware is a decoy for a disk wipe. Here are the host signals that catch it.

Security news

Two more Joomla extensions hit the exploited list. It is the same bug, five times now.

CISA added Balbooa Forms (CVE-2026-56291) and iCagenda (CVE-2026-48939) to its exploited list on July 10, the fourth and fifth Joomla extension with the same

Security news

A fake 7-Zip installer rents your server out as a residential proxy, and file scans miss it

A trojanized 7-Zip and VPN campaign called Lurking Lizard turns servers and PCs into residential proxy nodes.

Security news

Five Tenda router models ship a hidden admin password. With no patch, containment is the only move.

CERT/CC flagged a hardcoded admin password in five Tenda router models (CVE-2026-11405). No fix exists yet, so here is how to detect and contain it.

Security news

Two Joomla page builders are exploited for site takeover. The patch won't evict the intruder.

CISA flagged two CVSS-10 Joomla page-builder flaws, SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290), as exploited.

Security news

No password needed: a public exploit now hijacks unpatched Control Web Panel servers

A public exploit for a critical Control Web Panel flaw (CVE-2026-57517) lets unauthenticated attackers seize hosting servers. Patch to 0.9.8.1225 and hunt now.

Security news

Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it

ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.

Security news

Ransomware that runs inside your browser tab, where antivirus cannot see it

Check Point built browser-only ransomware from a DeepSeek AI output: a web page encrypts your files through a legitimate browser API, with no binary for

Security news

119 browser extensions hid malware inside images and fonts for two years

Microsoft pulled 119 malicious Edge extensions in the StegoAd campaign. Steganographic payloads, 2.6 million installs, and a 2FA lesson for defenders.

Security news

A forged login key unlocks SimpleHelp servers, and a new stealer is raiding cloud and AI credentials

A maximum-severity SimpleHelp flaw, CVE-2026-48558, lets attackers forge a login and is now exploited to drop Djinn Stealer against cloud and AI keys.

Deep dive

The code was clean. The toolchain that shipped it was the attack.

This week's most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.

Security news

You don't have to install this npm malware. Opening the folder in your editor runs it.

Two hijacked npm packages skip the install step entirely. They run when you open the project in VS Code, then steal developer, browser, and wallet logins.

Security news

The repo is clean. Your AI coding agent is what hands the attacker a shell.

Mozilla's 0DIN made Claude Code open a reverse shell from a GitHub repo with no malicious code. Here is why scanners miss it and how to constrain the agent.

Security news

This backdoor is named after your VMware and EDR tools. Your allowlist trusts it.

A Chinese APT called CL-STA-1062 ships its TinyRCT backdoor disguised as VMware and EDR agents. Why filename allowlists miss it, and what to hunt instead.

Security news

Hotels are running malware on a legitimate Node.js runtime, and that beats allowlisting

TonRAT runs on a genuine Node.js runtime on hotel front-desk machines, hides its C2 on the TON blockchain, and slips past allowlists. Here is what to hunt.

Security news

Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them

Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.

Security news

Windchill holds your product blueprints. A web shell on its login page hands them over.

CISA added PTC Windchill RCE CVE-2026-12569 to its KEV catalog after web shells hit exposed PLM servers. Patch to 11.0 M030 before the June 28 deadline.

Security news

Mistic backdoor writes nothing to disk and quietly sells your network to ransomware crews

Mistic is an in-memory backdoor that access broker KongTuke uses to hold footholds and sell them to Qilin and other ransomware crews. Here is where to catch it.

Security news

Police seized the malware that stole 27 million passwords. The passwords still work.

Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.

Security news

The free plugin was clean. The paid update is what backdoored these WordPress sites.

Backdoored ShapedPlugin Pro updates stole admin logins and 2FA seeds from WordPress sites between April and June 2026. A password reset alone will not clear it.

Security news

Add-ons for the OpenClaw AI assistant are stealing logins and running crypto scams

Malicious OpenClaw skills on the ClawHub marketplace steal credentials and hijack AI agents for crypto fraud, and some slip past the store's own scanner.

Security news

A new Mac backdoor is built to fool the AI that inspects it

macOS.Gaslight embeds fake AI system messages to make automated, LLM-assisted malware analysis abort.

Security news

A WhatsApp invoice is installing real IT software to hijack PCs, and your antivirus waves it through

A fake invoice on WhatsApp silently installs ManageEngine Endpoint Central, a legitimate remote-management tool, to hijack PCs.

Security news

Police scrubbed SocGholish from 15,000 WordPress sites. The way in is still wide open.

Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector.

Security news

A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires

Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.

Security news

ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect

Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.

Security news

FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In

Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.

Security news

Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now

Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.

Security news

A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load

SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.

Security news

Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.

OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.

Security news

Velvet Ant's PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug

Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.