Tuesday 23 June 2026 19:49:05 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

Malware & Botnets


CryptoBandits Turns a USB Habit Into a Crypto Theft Risk

Published: 23 June 2026 17:19Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A new Windows malware family is reported to spread through USB devices and use Tor, while altering wallet addresses to steal cryptocurrency.

Inside the Windows Trapdoor: A Shortcut, a Public Folder, and a Memory-Resident RAT

Published: 23 June 2026 16:50Category: Malware & BotnetsAuthor: IRONQUERY

A lure built around a geopolitical theme masked a loader chain that leaned on user execution, writable paths, and trusted Windows components to keep the final payload off disk.

When a Windows Helper Becomes the Hideout

Published: 23 June 2026 14:44Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A legitimate Microsoft binary, a sideloaded DLL, and a memory-resident RAT show how attackers can turn normal loader behavior into a stealth delivery path.

Lookalike npm Packages Turn a CSS Search into a Supply-Chain Trap

Published: 23 June 2026 12:19Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A small cluster of PostCSS-themed npm packages shows how name confusion and install-time trust can turn routine dependency work into a Windows malware risk.

When the Firewall Starts Watching the Users

Published: 23 June 2026 10:33Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A Go-based tool tied to compromised FortiGate appliances turns the network edge into a credential risk, not just a traffic-control point.

SocGholish Knocked Back: Why This Takedown Hits the Crimeware Delivery Layer

Published: 23 June 2026 10:30Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

An international operation targeted SocGholish, also known as FakeUpdates, and disrupted an infrastructure described as tied to Evil Corp - a reminder that the front door of cybercrime is often more important than the payload behind it.

When a Mac App Becomes a Moving Target: The FlutterShell Case

Published: 23 June 2026 10:24Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A macOS malware family linked to remote JavaScript delivery shows how attackers can shift meaningful logic off the binary and into infrastructure that can change at any time.

When Flutter and WebViews Become a Backdoor’s Quietest Route

Published: 23 June 2026 10:20Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A macOS malware family named FlutterShell shows how ordinary app frameworks can be repurposed for runtime command execution without looking like a classic implant.

Fake Popularity, Real Theft: The Clip-on Trap Hiding Behind GitHub Stars and VirusTotal Votes

Published: 22 June 2026 19:16Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A deceptive trust layer is being abused to make a crypto clipper look safer than it is, turning stars, reviews, and clipboard swaps into a quiet route to theft.

Sponsored Search, Silent Loader: How a Fake Ad Chain Turns Into Credential Theft

Published: 22 June 2026 19:06Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A newly described malware loader, OXLOADER, shows how a simple ad click can become a staged delivery path for CastleStealer and other credential-grabbing payloads.

Trusted Chat, Untrusted Payload: How WhatsApp Messages Became a Windows Delivery Route

Published: 22 June 2026 18:22Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Compromised WhatsApp accounts are being used to push malicious VBScript files, then legitimate RMM tools are abused to keep access alive on infected Windows machines.

Rokarolla and the Android Trap: When a Banking Trojan Wants the Whole Phone

Published: 22 June 2026 15:32Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

The malware family linked to Android banking fraud is interesting not for one trick, but for the way it turns ordinary handset features into a potential control layer for attackers.

Old Router Flaws, New Quiet Threat: AryStinger Turns Edge Devices Into Reconnaissance Nodes

Published: 22 June 2026 15:11Category: Malware & BotnetsAuthor: IRONQUERY

A malware family built for scanning, tunneling, and persistence shows how long-forgotten router bugs can still power a modern access network.

Forgotten Edge Devices, New Operator Tricks: AryStinger’s Quiet Relay Game

Published: 22 June 2026 15:05Category: Malware & BotnetsGeo: Asia / ChinaAuthor: IRONQUERY

A newly analyzed botnet turns aging routers and NAS appliances into scanning and tunneling nodes, showing how small edge devices can become useful infrastructure for hiding attacker origin and widening reach.

Paper Trail, Hidden Payload: How a Stealthy Remcos Phish Slips Past the Obvious Defenses

Published: 22 June 2026 14:57Category: Malware & BotnetsAuthor: IRONQUERY

Financial-themed attachments, a concealed payload, and fileless staging turn a routine phishing theme into a harder-to-spot Remcos delivery chain.

A Lookalike npm Name, Then a Windows Script Chain: The Supply-Chain Trap Behind a RAT Drop

Published: 22 June 2026 14:52Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A typosquatted package in the npm ecosystem shows how a single confusing name can hand attackers a path from dependency install to Windows-native execution.

The Phishing File That Hid a Loader, Then Unleashed a Second Wave

Published: 22 June 2026 14:22Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A business-themed archive attachment led to a packed .NET loader, a steganographic second stage, and a payload chain that included Remcos RAT and multiple infostealers.

Mastra’s npm Trail Turns a Package Update Into a Crypto-Extension Risk

Published: 22 June 2026 14:14Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A malicious dependency found in more than 140 Mastra packages shows how a software supply-chain incident can move from build tools to browser-facing cryptocurrency surfaces.

A Lookalike npm Package Turned a Trusted CSS Name Into a Windows Malware Pipe

Published: 22 June 2026 14:07Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A deceptive package name in the PostCSS orbit shows how open-source trust can be abused before any code ever reaches production.

GitHub as a Malware Conveyor Belt: What a 10,000-Repo Abuse Case Reveals

Published: 22 June 2026 10:49Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A large repository-abuse campaign puts a hard truth in focus: on code-sharing platforms, reputation can be weaponized as easily as code.