Endpoint Security

Cybersecurity
Cruciferra Crypter Combines BYOVD and Process Ghosting to Kill EDR
Cruciferra, a MaaS crypter active since fall 2025, bypasses EDR via BYOVD and Process Ghosting. TA4922, Silver Fox, and 11 malware families are linked to ...
Cybersecurity
MedusaHVNC Hides Covert Browser Sessions in Windows Desktops
BlackFog exposed MedusaHVNC, a MaaS RAT that runs browsers on a hidden Windows virtual desktop to commit banking fraud without the victim's awareness.
Cybersecurity
TELESHIM Backdoor Hits Middle East Governments via Telegram C2
Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern governments.
Application Security
SourTrade Malvertising Assembles Malware in Browser Memory
SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.
Cybersecurity
Steam ClickFix Campaign Installs SYSTEM-Level XMRig Miner
Attackers target Steam discussion forums with ClickFix social engineering, tricking players into running PowerShell that installs a SYSTEM-level XMRig miner.
Cybersecurity
ClickLock macOS Stealer Uses App-Kill Loop to Coerce Passwords
Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims across 33 countries.
Cybersecurity
Elastic Exposes TELEPUZ: C Malware Sold as MaaS via ClickFix Chain
Elastic Security Labs disclosed TELEPUZ, a C-based malware distributed through a ClickFix-to-Vidar chain with VirusTotal volumes indicating a MaaS operation.
Cybersecurity
Russian Threat Actor Uses Gemini CLI to Run Dental Clinic Botnet
Trend Micro documented Russian actor 'bandcampro' using Gemini CLI as a hacking assistant in a dental clinic botnet attack on an OpenDental patient database.
Cybersecurity
Nightmare Eclipse Drops LegacyHive PoC on Fully Patched Windows
Security group Nightmare Eclipse released LegacyHive, a PoC targeting an unpatched Windows privilege escalation flaw that survived July Patch Tuesday.
Cybersecurity
Bitdefender Exposes Windows Bind Link Attacks That Bypass EDR Tools
Bitdefender documented three Windows bind link techniques — file-binding, process-binding, and silo-binding — that redirect OS path resolution to hide malware from EDR tools.