BeatBankerBTMOB RATCybersecurityGoogle AndroidGReAT researchMalwareMalware descriptionsMalware TechnologiesMinerMobile MalwareMobile threatsRATTrojanTrojan Banker
BeatBanker: A dual‑mode Android Trojan
Recently, we uncovered BeatBanker, an Android‑based...
AdwareBackdoorCybersecurityGoogle AndroidGoogle PlayKeenaduMalware descriptionsMalware reportsMalware StatisticsMamontMobile MalwareMobile threatsTriadaTrojanTrojan BankerTrojan-Spy
Mobile malware evolution in 2025
Starting from the third quarter of...
Arkanix StealerCybersecurityData theftGReAT researchInfostealersMalwareMalware descriptionsMalware TechnologiesMalware-as-a-ServicePythonTrojanTrojan-stealerUnix and macOS malwareWindows malware
Arkanix Stealer: a C++ & Python infostealer
Introduction In October 2025, we discovered...
AdwareBADBOXBotnetsCybersecurityGoogle AndroidKeenaduMalwareMalware descriptionsMalware TechnologiesMobile MalwareMobile threatsTriadaTrojanTrojan ClickerVo1d
Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets
In April 2025, we reported on...
Antivirus TechnologiesCybersecurityIncidentsLummaMalwareMalware descriptionsMalware TechnologiesOnline GamesSecurity technologyshellcodeTrojan-stealerWeb threatsWindows malware
The game is over: when “free” comes at too high a price. What we know about RenEngine
We often describe cases of malware...
CobaltStrikeCybersecurityDLL sideloadingGReAT researchIncidentsMalwareMalware descriptionsMalware TechnologiesshellcodeSupply-chain attackWindows malware
The Notepad++ supply chain attack — unnoticed execution chains and new IoCs
Introduction On February 2, 2026, the...
APTAPT (Targeted attacks)APT reportsBackdoorBrowserCybersecurityFirefoxGoogle ChromeGReAT researchHoneyMyteInfostealersMalwareMalware descriptionsMalware TechnologiesMicrosoft EdgeTargeted attacksTrojan-stealer
HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns
Over the past few years, we’ve...
APTAPT (Targeted attacks)APT reportsBackdoorCybersecurityGReAT researchHoneyMyteMalwareMalware descriptionsRootkitsTargeted attacks
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor
Overview of the attacks In mid-2025,...
APTAPT (Targeted attacks)APT reportsCybersecurityDefense evasionDNS manipulationencryptionEvasive PandaGReAT researchMalwareMalware descriptionsMalware TechnologiesshellcodeTargeted attacksWindows malware
Evasive Panda APT poisons DNS requests to deliver MgBot
Introduction The Evasive Panda APT group...
BackdoorCybersecurityGitHubMalwareMalware descriptionsTrojanVulnerabilities and exploitsWebratWindows malware
From cheats to exploits: Webrat spreading via GitHub
In early 2025, security researchers uncovered...