⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs

Cyber threats are increasingly complex, layered, and often hidden until they cause damage, emphasizing the need for proactive detection and focused analysis. Recent actions include takedowns of malware infrastructure like Lumma Stealer and DanaBot, and new exploitation techniques such as AI-generated videos and malicious Chrome extensions. #DanaBotDisruption #TikTokMalware #APT28 #ChromeExtensions #StarkIndustries…

Read More
Dissecting the macOS ‘AppleProcessHub’ Stealer: Technical Analysis of a Multi-Stage Attack

A MacOS infostealer disguised as a dylib file named libsystd.dylib was discovered, designed to steal sensitive user data like keychain passwords and SSH configs and upload them to the attacker’s server. The malware uses Objective-C, AES encryption for C2 URLs, Grand Central Dispatch for scheduling, and executes scripts from a command and control server named appleprocesshub[.]com. #libsystd #appleprocesshub #MoonlockLab

Read More
Cybersecurity News | Daily Recap [23 May 2025]

This cybersecurity recap highlights law enforcement operations that dismantled major ransomware networks like QakBot, TrickBot, and DanaBot, seizing servers and assets worldwide. It also covers notable exploits, such as Chinese hackers targeting U.S. government agencies with zero-day vulnerabilities, along with emerging malware campaigns using AI-generated content and social engineering tactics. #QakBot #DanaBot

Read More
Katz Stealer Threat Analysis – Nextron Systems

Katz Stealer is a credential-stealing malware as a service that targets browsers, communication apps, crypto wallets, and gaming platforms to exfiltrate sensitive data using sophisticated evasion and injection techniques. Its infection chain involves obfuscated JavaScript and PowerShell scripts, .NET loader payloads, process hollowing, UAC bypass, and geofencing, with detailed YARA and Sigma detection rules available. #KatzStealer #ProcessHollowing #DiscordHijacking #AppBoundEncryption

Read More
Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique

The Latrodectus malware now uses the ClickFix technique for undetectable in-memory execution and is part of a broader threat landscape involving various malware campaigns. These attacks leverage social media platforms like TikTok and fake apps to trick users into executing malicious commands and stealing sensitive information. #Latrodectus #ClickFix #TikTokMalware #LedgerFraud…

Read More
TikTok videos now push infostealer malware in ClickFix attacks

Cybercriminals are leveraging TikTok’s widespread reach and AI-generated videos to trick users into executing PowerShell commands that install Vidar and StealC malware, leading to credential, credit card, and cryptocurrency theft. This campaign highlights the use of automated, social engineering techniques in broad-scale malware distribution, with state-sponsored groups also adopting similar tactics. #Vidar #StealC #ClickFix #TikTokThreats #AIGeneratedVideos

Read More
60 Malicious npm Packages Leak Network and Host Data in Active Malware Campaign

Socket’s Threat Research Team identified an ongoing malicious campaign involving 60 npm packages across three accounts, each embedding a script that collects and exfiltrates detailed network and host information to a Discord webhook. The campaign targets Windows, macOS, and Linux systems, leveraging sandbox evasion to focus on active developer and CI environments, posing a strategic risk for future supply chain attacks. #npm #supplychaincompromise #DiscordWebhook

Read More
Hackers use fake Ledger apps to steal Mac users’ seed phrases

Cybercriminals are deploying fake Ledger apps on macOS to deceive users and steal their seed phrases, which are vital for accessing cryptocurrency wallets. Recent campaigns have evolved to include sophisticated malware like Odyssey and AMOS that mimic legitimate Ledger interfaces and exfiltrate sensitive recovery information. #Odyssey #AMOS #LedgerSecurity #SeedPhraseTheft

Read More
Malicious npm Packages Target React, Vue, and Vite Ecosystems with Destructive Payloads

Socket’s Threat Research Team uncovered a multi-year campaign involving eight malicious npm packages targeting popular JavaScript frameworks like React, Vue.js, and Vite. These packages employ typosquatting, progressive attacks including file deletion, data corruption, and system shutdowns to disrupt developer workflows and production environments. #vite-plugin-bomb #js-hood #quill-image-downloader #js-bomb #xuxingfeng

Read More
FrigidStealer_Malware

FrigidStealer is a macOS-targeting information-stealing malware that disguises itself as a browser update to exfiltrate sensitive user data, including credentials and cryptocurrency wallets. This article explains its behavior and demonstrates how to detect FrigidStealer using Wazuh custom decoders and rules on macOS endpoints. #FrigidStealer #EvilCorp

Read More