Virus Bulletin @virusbtn.bsky.social · 15hA recent Microsoft blog post provides an updated technical analysis of the Russian threat actor Star Blizzard’s TTPs. In 2026 Star Blizzard adopted RedFlick, a malware delivery technique that helps evade detection and deploy the custom backdoor CosmicPulse. www.microsoft.com/en-us/securi... 110
Virus Bulletin @virusbtn.bsky.social · 15heSentire's TRU team shows how a threat actor exploited an internet-facing PaperCut MF server to deploy a Java loader & a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. www.esentire.com/blog/papercu... 002
Virus Bulletin @virusbtn.bsky.social · 15hK7 Labs' Harihara Sudhan looks into a multi-stage infection chain that started from a KMS Auto execution and led to cryptocurrency mining activity, remote access software deployment, and finally the delivery of a scareware payload masquerading as ransomware. labs.k7computing.com/index.php/fr... 000
Virus Bulletin @virusbtn.bsky.social · 29/09/2026Cleafy's Simone Mattia & Alberto Giust look inside the evolving C2 panel behind RATHat. RATHat's Android malware remained largely static from late 2025 to Sept 2026, while its C2 panel was replaced entirely and has gone through three generations in six months. www.cleafy.com/cleafy-labs/... 000
Virus Bulletin @virusbtn.bsky.social · 29/09/2026Microsoft researchers identified NeedyMantis, a modular post-compromise malware family observed in targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government contractors. www.microsoft.com/en-us/securi... 000
Virus Bulletin @virusbtn.bsky.social · 29/09/2026Proofpoint researchers identified an active TeamFiltration campaign - tracked as UNK_CondorFiltration - that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean organizations. www.proofpoint.com/us/blog/thre... 000
Virus Bulletin @virusbtn.bsky.social · 28/09/2026The FortiGuard Incident Response (FGIR) team recently investigated an intrusion involving SectopRAT (also known as ArechClient2), which was used to control the victim’s device. www.fortinet.com/blog/threat-... 000
Virus Bulletin @virusbtn.bsky.social · 28/09/2026K7 researchers analyse a Python-based MaaS infostealer builder and an embedded infostealer payload. Operators are able to generate customized Windows executables using Nuitka or PyInstaller, with webhook configuration integrated into the build process. labs.k7computing.com/index.php/th... 011
Virus Bulletin @virusbtn.bsky.social · 28/09/2026G Data's Karsten Hahn shows how threat actors recompile open-source software such as the 7zip SFX stub to sneak a reflective loader into it. blog.gdatasoftware.com/2026/09/3849... 000
Virus Bulletin @virusbtn.bsky.social · 25/09/2026Gambit Security's Eyal Sela writes about a financially motivated threat actor that is using open-source AI harnesses to attack hundreds of online retailers, at a marginal cost of tens of dollars per company. gambit.security/blog-posts/a... 000
Virus Bulletin @virusbtn.bsky.social · 25/09/2026Microsoft researchers delve into the attack techniques attributed to Storm-2570, a ransomware affiliate linked to multiple ransomware payloads like Qilin, DragonForce, Anubis, and BERT ransomware. www.microsoft.com/en-us/securi... 010
Virus Bulletin @virusbtn.bsky.social · 25/09/2026Huntress researchers Harlan Carvey & Lindsey O'Donnell-Welch found a threat actor doing something unique: instead of simply dropping a miner, one was compiled directly on the victim endpoint, tailoring the payload while generating unusually conspicuous EDR telemetry. www.huntress.com/blog/threat-... 000
Virus Bulletin @virusbtn.bsky.social · 25/09/2026Varonis Threat Labs recently discovered AvisLoader, a new Windows loader named after the Latin word for bird. They found it on an exposed staging server alongside a ClickFix lure, supporting tools, and its command centre. www.varonis.com/blog/meet-av... 011
Virus Bulletin @virusbtn.bsky.social · 24/09/2026The VB2026 programme has just been updated with this year’s last-minute papers, adding even more timely research to the line-up. 🔍 View the full programme: vb2026.virusbulletin.com 🎟️ Get your ticket: vb2026.virusbulletin.com#tickets #VB2026 #VBConference #SecurityResearch #Seville 001
Virus Bulletin @virusbtn.bsky.social · 24/09/2026ThreatDown researchers uncovered CARBONATO, which targets unauthenticated Docker daemons, then installs the legitimate Hermes Agent. A modified SOUL.md tells it to take Telegram tasks and prioritise AI API keys over credentials. www.threatdown.com/blog/carbona... 100
Virus Bulletin @virusbtn.bsky.social · 24/09/2026DarkMe has dropped the WinRAR and SmartScreen zero-days it used previously. Huntress saw it delivered through a phising-linked .pif file, with persistence hidden behind a custom protocol handler. www.huntress.com/blog/darkme-... 001
Virus Bulletin @virusbtn.bsky.social · 24/09/2026More than 1200 Meta ads pushed 17 malicious apps through Google Play in a Polish toll-fraud operation. CERT Polska saw the C2 assign premium SMS and carrier-billing jobs to infected devices. cert.pl/en/posts/202... 000
Virus Bulletin @virusbtn.bsky.social · 24/09/2026PavokwiLoader buries its logic in an 80,000-instruction function and uses custom API hashing to slow analysis. Malbear Labs links the loader to an intrusion chain that also deployed RMMCRAT. malbearlabs.com/posts/novel-... 000
Virus Bulletin @virusbtn.bsky.social · 23/09/2026MacOS credentials are under fire from PAMStealer (Wavel), a new infostealer using PAM-based credential validation. Jamf caught it using a server-side key exchange that prevents static payload recovery. www.jamf.com/blog/pamstea... 010
Virus Bulletin @virusbtn.bsky.social · 23/09/2026Securonix researchers identified a stealthy backdoor capable of exfiltrating business documents. TASK#STOMP uses encoded PowerShell scripts and Scheduled Tasks for persistent remote access. www.securonix.com/blog/task-st... 000
Virus Bulletin @virusbtn.bsky.social · 23/09/2026Autonomous AI-driven implants are moving from theory to practice. Cisco Talos breaks down CLOSEDQUORUM, a Windows implant that asks commercial LLM APIs to vote on post-exploitation actions without a dedicated attacker-controlled C2 server. blog.talosintelligence.com/the-closed-q... 010
Virus Bulletin @virusbtn.bsky.social · 23/09/2026Device Code phishing continues to evolve with EvilTokens, a framework built to bypass MFA. Microsoft details how it tricks users into approving rogue OAuth requests to authorise attacker-controlled sessions and steal tokens. www.microsoft.com/en-us/securi... 000
Virus Bulletin @virusbtn.bsky.social · 22/09/2026Sekoia uncovers Exvicy, a new ClickFix MaaS copied from ErrTraffic. It leverages hacked WordPress sites and fake Cloudflare prompts to trick users into executing malicious PowerShell payloads. www.sekoia.com/blog/exvicy-... 000
Virus Bulletin @virusbtn.bsky.social · 22/09/2026Volexity has linked Chinese APT group UTA0565 to a campaign chaining Chrome and Windows zero-days via spoofed media and NGO sites. Successful exploitation drops a custom payload called CLEANGULP. www.volexity.com/blog/2026/09... 000
Virus Bulletin @virusbtn.bsky.social · 22/09/2026Vidar keeps making static analysis harder. Zscaler shows how newer builds dropped XOR and ChaCha20 in favour of a custom VM and pre-build stream ciphers, effectively blinding automated tooling. www.zscaler.com/blogs/securi... 011
Virus Bulletin @virusbtn.bsky.social · 21/09/2026TraderTraitor (DPRK) is shifting beyond crypto, using fake job workflows and weaponised Terraform projects to target DevOps teams. SentinelOne breaks down the new FLATROOF and ROOFDECK macOS backdoors behind the campaign. www.sentinelone.com/labs/dont-ca... 100
Virus Bulletin @virusbtn.bsky.social · 21/09/2026SideCopy is now targeting the education sector. Trellix details the threat actor's new attack chain using weaponised LNKs and mshta.exe to execute ReverseRAT directly into memory. www.trellix.com/blogs/resear... 000
Virus Bulletin @virusbtn.bsky.social · 18/09/2026K7 reseachers examine a multi-stage infection that relied heavily on obfuscation, registry-based payload storage, covert data delivery, persistence mechanisms, security-control tampering, and in-memory execution. labs.k7computing.com/index.php/fr... 001
Virus Bulletin @virusbtn.bsky.social · 18/09/2026We've just published the results of the Q3 2026 VB ESA - M365 test, part of a continuously running performance test programme for solutions that supplement Microsoft 365’s native security Exchange Online Protection by adding extra detection layers. www.virusbulletin.com/virusbulleti... 000
Virus Bulletin @virusbtn.bsky.social · 18/09/2026ESET researchers document SparroWocky, the new flagship backdoor of the China-aligned FamousSparrow APT group. SparroWocky is a full-featured backdoor that manipulates low-level structures in memory, and patches code at runtime in order to avoid detection. www.welivesecurity.com/en/eset-rese... 000
Virus Bulletin @virusbtn.bsky.social · 18/09/2026Huntress researchers Harlan Carvey & Lindsey O'Donnell-Welch analyse Settra, a newer ransomware variant observed in two recent incidents. Both used ransomware executables named after the victim organization's domain & followed a highly similar operational pattern. www.huntress.com/blog/new-set... 000
Virus Bulletin @virusbtn.bsky.social · 17/09/2026VB congratulates the researchers shortlisted for the 2026 Péter Szőr Award, both for their nominations and for the outstanding research they have contributed to the field. The winner will be announced at the VB2026 gala dinner on 15 October in Seville. www.virusbulletin.com/blog/2026/09... 000
Virus Bulletin @virusbtn.bsky.social · 17/09/2026Infoblox examines the crime hidden behind proliferating betting sites: illegal gambling/money laundering across China & Asia; scamming customers out of winnings ("scambling"); and running C2 infrastructure disguised as casino sites. www.infoblox.com/blog/threat-... 000
Virus Bulletin @virusbtn.bsky.social · 17/09/2026Hunt.io researchers analyse the SilkParasite infrastructure, with SpiceRAT C2 servers tied to energy and government targets across Central Asia. hunt.io/blog/silkpar... 000
Virus Bulletin @virusbtn.bsky.social · 17/09/2026Zscaler ThreatLabz observed new APT36 (Pakistan-nexus) activity in a campaign tracked as Operation RapidRust. APT36 has maintained a high operational tempo & updated its TTPs in continued attacks targeting organizations in India & Afghanistan. www.zscaler.com/blogs/securi... 000
Virus Bulletin @virusbtn.bsky.social · 16/09/2026Recorded Future looks into the phishing, payment card theft, and money laundering activities of the Tajin Group, which actively targets mainland Chinese citizens & Chinese banks. www.recordedfuture.com/research/taj... 021
Virus Bulletin @virusbtn.bsky.social · 16/09/2026eSentire TRU dissects the GhostCode phishing kit distributed through web contact forms. Device code phishing kits abuse the OAuth 2.0 device authorization grant flow to gain access to Microsoft accounts. www.esentire.com/blog/ghostco... 011
Virus Bulletin @virusbtn.bsky.social · 16/09/2026Elastic Security Labs researchers Cyril François & Andrew Pease analyse KREMLIN, a malicious browser extension installer from a Brazilian banking malware operation. www.elastic.co/security-lab... 021
Virus Bulletin @virusbtn.bsky.social · 15/09/2026IIJ-SECT's Bynaoki Takayam analyses PIVOTPIPE, an unofficial Beacon payload with many features that differ from the existing Cobalt Strike Beacon: code to evade detection, a custom loader implementation, and a method for obfuscating strings within the binary. sect.iij.ad.jp/blog/2026/09... 000
Virus Bulletin @virusbtn.bsky.social · 15/09/2026We've just published the results of the Q3 2026 VBSpam test. The threats observed during this period demonstrate how modern phishing campaigns increasingly blend familiar business and consumer lures with lightweight evasive infrastructure. www.virusbulletin.com/virusbulleti... 000
Virus Bulletin @virusbtn.bsky.social · 15/09/2026Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. www.acronis.com/en/tru/posts... 000
Virus Bulletin @virusbtn.bsky.social · 15/09/2026Researchers from Hudson Rock & ADAMnetworks analysed PasteSwitch, a cross-platform delivery operation delivering macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers. www.infostealers.com/article/hbo-... 000
Virus Bulletin @virusbtn.bsky.social · 14/09/2026One month to go!🔥 #VB2026 is almost here. Join us in Seville for three days of technical security research, expert-led talks and the chance to meet fellow researchers and security professionals from across the global industry. 📅 14–16 October 2026 📍 Seville, Spain 🎟️ Tickets: tinyurl.com/5cf98dyd 000
Virus Bulletin @virusbtn.bsky.social · 14/09/2026KnowBe4 Threat Lab explains how attackers started to abuse Direct Send, a built-in path designed to allow office printers, scanners and legacy on-premises applications to send email without needing a dedicated account and bypassing security gateways. blog.knowbe4.com/direct-send-... 000
Virus Bulletin @virusbtn.bsky.social · 14/09/2026Sophos researchers analyse a malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center devices. This is a new variant of the Cyclops Blink malware previously analysed by the UK NCSC. www.sophos.com/en-gb/blog/-... 020
Virus Bulletin @virusbtn.bsky.social · 13/09/2026For those who like to submit at the very last minute, the #VB2026 call for last-minute papers closes today (13 Sept) at midnight Hawaii time (10am UTC on Monday). You will be able to add, view and edit your submissions until the deadline! www.virusbulletin.com/conference/v... 035
Virus Bulletin @virusbtn.bsky.social · 11/09/2026Palo Alto Networks researchers analyse the CL-CRI-1171 group, which provides a pay-per-install marketplace through YouTube channels and a parallel SEO-poisoning funnel, all using the same custom loader. unit42.paloaltonetworks.com/ppi-network-... 010
Virus Bulletin @virusbtn.bsky.social · 11/09/2026Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins are followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, and cloud data access. www.microsoft.com/en-us/securi... 010
Virus Bulletin @virusbtn.bsky.social · 11/09/2026Huntress researcher Sarah Reddish analyses two attacks that started with a phishing message, redirected victims to a browser-in-the-browser (BiTB) page, prompted them to download an "updated Adobe Reader" version to view files, & led to rogue ScreenConnect RMM. www.huntress.com/blog/phishin... 000
Virus Bulletin @virusbtn.bsky.social · 11/09/2026Proofpoint, in collaboration with Google, Microsoft and Volexity, identified four espionage-motivated threat actors employing BlueMoon, a new exploit kit that chains multiple Chrome browser & Microsoft Windows vulnerabilities. www.proofpoint.com/us/blog/thre... 110