Windows

Hackers Use Fake Google Gemini App to Steal Windows Users’ Browser Credentials

Threat actors are increasingly abusing the growing popularity of generative AI tools to spread malware. In a recent incident observed by Darktrace, attackers used...

Shadow hVNC Lets Hackers Operate a Second Windows Desktop Invisible to the Victim

Cybersecurity researchers have uncovered a feature-rich malware strain called Shadow hVNC that gives attackers control of a hidden Windows desktop on an infected system....

Windows Malware Corrupts PE Headers While Dropping Files to Evade On-Access Scanners

Researchers have uncovered a custom Windows backdoor that uses several low-noise techniques to avoid detection, including corrupting executable headers while writing dropped files to...

DCRat Malware Uses DLL Sideloading and Process Hollowing to Hide Inside Trusted Windows Process

The attack ultimately hides a remote-access trojan inside a legitimate Windows-related process, helping it blend into normal endpoint activity. The campaign uses a fake legal-notice...

CNCMachineRMS Hides Windows APIs With Runtime Hashing and Ships With No Import Table

Security researchers have uncovered CNCMachineRMS, a 1.14 MB x64 remote access trojan (RAT) delivered at the end of a BabaDeda-based infection chain. The malware...

Popular

Subscribe