Category: Research
New ClickLock macOS Malware Locks Out Users Until They Type Their Password
Group-IB has identified a new macOS stealer called ClickLock that freezes the system and repeatedly kills processes to coerce victims into typing…
OkoBot Framework Uses 20+ Payloads to Drain Crypto Wallets and Credentials
Kaspersky researchers detail OkoBot, a modular malware framework spread via ClickFix lures and fake GitHub tools that deploys keyloggers, seed-phrase stealers, and…
Wyden Warns Canada’s Lawful Access Act Could Turn US Tech Into Spy Tools
Senator Ron Wyden is urging acting Attorney General Todd Blanche and Secretary of State Marco Rubio to push back on Canadian surveillance…
Dutch Police Dismantle €100 Million-a-Month Investment Fraud Network
A sprawling international call center operation that used fake trading dashboards to fleece tens of thousands of victims has been broken up,…
Nearly 300 Fake GitHub Repos Used to Push BoryptGrab Infostealer
A Russia-linked campaign impersonated legitimate security, crypto, and developer tools across 292 GitHub repositories to trick users into downloading a memory-resident infostealer.
Google, Microsoft Pull ModHeader Extension Over Hidden History Collector
A dormant browsing-history collector was discovered inside the official store version of ModHeader, a header-editing extension with about 1.6 million installs, prompting…
EU Weighs Bloc-Wide Social Media Age Limit of 13 for Kids
European Commission President Ursula von der Leyen is floating a harmonized EU rule barring unsupervised under-13s from social media, as member states…
CrashStealer Malware Impersonates Apple Crash Reporter to Raid macOS Keychains and Crypto Wallets
A notarized, Apple-signed installer slips past Gatekeeper to drop CrashStealer, a new macOS infostealer that fakes a password prompt to unlock the…
Supreme Court Location Ruling Could Reshape License Plate Camera Surveillance
A landmark Fourth Amendment decision on cell phone geofence warrants is fueling legal arguments that automated license plate reader networks like Flock…
RedHook Android Malware Abuses Wireless ADB to Gain Shell Access
A new RedHook variant tricks victims into enabling Wireless Debugging, then uses a Shizuku-based framework to run shell-level commands and expand its…
Dormant GitHub Ghost Accounts Fuel Mass Reconnaissance Campaign
Datadog researchers say over 50 dormant GitHub accounts, some registered years ago, are being used to systematically enumerate organizations, repositories, and users…
Balochistan Police Portal Compromised in Multi-Group Espionage Campaign
Researchers say suspected China- and India-aligned threat actors breached servers tied to a Pakistani police portal over more than two years, exposing…