⤷ Title: Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 21 May 2026 10:18:11 +0000
════════════════════════
⌗ Tags: #Security #Malware #Microsoft #Cyber Attack #Cybersecurity #Fileless #LOLBIN #MSHTA #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 21 May 2026 10:18:11 +0000
════════════════════════
⌗ Tags: #Security #Malware #Microsoft #Cyber Attack #Cybersecurity #Fileless #LOLBIN #MSHTA #Vulnerability
Hackread
Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks
Despite Internet Explorer’s retirement, hackers are abusing the legacy MSHTA utility in stealthy fileless malware attacks targeting Windows users.
⤷ Title: In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
Daily CyberSecurity
In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
TrendAI exposes Banana RAT, a fileless banking trojan by SHADOW-WATER-063 that uses in-memory execution and fake UI overlays to hijack Pix-QR transfers.
⤷ Title: Global Malicious AI Installer Campaign Targets Developer Workstations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude Code #developer security #EclecticIQ #Fileless Malware #Gemini CLI #Infostealer Campaign #SEO Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude Code #developer security #EclecticIQ #Fileless Malware #Gemini CLI #Infostealer Campaign #SEO Poisoning
⤷ Title: Advanced Lazarus Memory-Only Toolset Deeply Analyzed by Fox-IT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 06:33:06 +0000
════════════════════════
⌗ Tags: #Malware #DPAPILoader #Fileless Malware #Fox_IT #Lazarus Group #Memory_Only Malware #RemotePE #RemotePELoader #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 06:33:06 +0000
════════════════════════
⌗ Tags: #Malware #DPAPILoader #Fileless Malware #Fox_IT #Lazarus Group #Memory_Only Malware #RemotePE #RemotePELoader #threat intelligence
Daily CyberSecurity
Advanced Lazarus Memory-Only Toolset Deeply Analyzed by Fox-IT
Fox-IT uncovers a sophisticated Lazarus memory-only toolset used to compromise financial firms via an evasive three-stage malware pipeline.
⤷ Title: PureLogs Info Stealer Campaign Exploits Trusted Windows Process
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:02:45 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #FortiGuard Labs #info_stealer #Phishing Campaign #Process Hollowing #PureLogs #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:02:45 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #FortiGuard Labs #info_stealer #Phishing Campaign #Process Hollowing #PureLogs #threat intelligence
Daily CyberSecurity
PureLogs Info Stealer Campaign Exploits Trusted Windows Process
FortiGuard Labs exposes a highly evasive PureLogs info stealer campaign utilizing process hollowing and fileless execution.
⤷ Title: Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 30 May 2026 17:13:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #AI #Artificial Intelligence #Claude Code #Cyber Attack #Cybersecurity #Developers #Fileless #Infostealer #SEO Poisoning
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 30 May 2026 17:13:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #AI #Artificial Intelligence #Claude Code #Cyber Attack #Cybersecurity #Developers #Fileless #Infostealer #SEO Poisoning
Hackread
Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users
Fake Anthropic websites are being used to target Claude Code users with a fileless infostealer campaign that steals browser credentials and evades detection.
⤷ Title: Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 10:46:42 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Scams and Fraud #Cyber Attack #Cybersecurity #Fileless #Fraud #PureLogs #Scam #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 10:46:42 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Scams and Fraud #Cyber Attack #Cybersecurity #Fileless #Fraud #PureLogs #Scam #Windows
Hackread
Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives
Hackers are using fake purchase order emails and process hollowing to deploy fileless PureLogs malware to steal Windows users' browser, crypto, and Discord data.
⤷ Title: Remcos RAT Delivered by a Steganographic Loader in Phishing Emails
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 06:12:01 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #India #K7 Security Labs #Loader_as_a_Service #phishing #Process Hollowing #Remcos RAT #steganographic loader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 06:12:01 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #India #K7 Security Labs #Loader_as_a_Service #phishing #Process Hollowing #Remcos RAT #steganographic loader
Daily CyberSecurity
Remcos RAT Delivered by a Steganographic Loader in Phishing Emails
A steganographic loader hides Remcos RAT inside a bitmap and runs it in memory. K7 ties the fileless campaign to India via fake GST lures.
⤷ Title: ValleyRAT Malware Hits Japanese and Chinese Users Through Email Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:21:55 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #Fileless Malware #LevelBlue #Remote Access Trojan #ValleyRAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:21:55 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #Fileless Malware #LevelBlue #Remote Access Trojan #ValleyRAT
Daily CyberSecurity
ValleyRAT Malware Hits Japanese and Chinese Users Through Email Attacks
At a glance Details Malware family ValleyRAT (Remote Access Trojan) Threat actor Often linked to SilverFox; attribution disputed and unconfirmed Targets Japanese and Chinese-speaking users, includ…
⤷ Title: Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
Daily CyberSecurity
Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
Malware family PureLog Stealer (delivered by the Veil#Drop framework) Threat actor Not attributed by Securonix Targets Windows users; victim count not disclosed Delivery vector Malicious JavaScrip…
⤷ Title: XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
Daily CyberSecurity
XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
At a glance Field Detail Malware family Modified XMRig 6.25.0 botnet implant (marked “PRIVATE VERSION FOR BOTNET”), cross-compiled with musl libc Threat actor Unidentified; campaign tr…