LofyGang Revives With Minecraft-Focused LofyStealer Campaign

Meet LofyGang, a notorious threat actor that's back in the game with a sneaky new campaign called LofyStealer, targeting Minecraft fans with malware disguised as a hack called 'Slinky'. This Brazil-based group has a history of infiltrating gaming communities and digital entertainment services.

https://osintsights.com/lofygang-revives-with-minecraft-focused-lofystealer-campaign?utm_source=mastodon&utm_medium=social

#Lofygang #Minecraft #MalwareCampaign #StealerMalware #GamingCommunities

LofyGang Revives With Minecraft-Focused LofyStealer Campaign

LofyGang resurfaces with LofyStealer malware targeting Minecraft gamers, learn how to protect yourself from this cyber threat now.

OSINTSights
Malware Campaign Abuses Booking.com Against Hospitality Sector

Securonix is detailing a multi-stage campaign that starts with a bogus Booking.com message that runs through a ClickFix technique and a fake Blue Screen of Death before dropping the DCRat malware that gives the attackers full remote control of the victim's system.

Security Boulevard

WebRat malware spreads via fake GitHub exploit repos — attackers are poisoning trust in open source to deliver payloads. Verify before you clone. 🧩⚠️ #OpenSourceSecurity #MalwareCampaign

https://www.bleepingcomputer.com/news/security/webrat-malware-spread-via-fake-vulnerability-exploits-on-github/

WebRAT malware spread via fake vulnerability exploits on GitHub

The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.

BleepingComputer

ShadyPanda is hijacking popular browser extensions to spy on users — turning everyday tools into covert surveillance channels. Trust no add-on without validation. 🧩🕵️‍♂️ #ExtensionSecurity #MalwareCampaign

https://thehackernews.com/2025/12/shadypanda-turns-popular-browser.html

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware

ShadyPanda abused browser extensions for seven years, turning 4.3M installs into a multi-phase surveillance and hijacking campaign.

The Hacker News

ShadyPanda extensions racked up 43M installs — turning convenience into mass surveillance. Even “helpful” add-ons can hide hostile code. 🧩⚠️ #ExtensionSecurity #MalwareCampaign

https://www.bleepingcomputer.com/news/security/shadypanda-browser-extensions-amass-43m-installs-in-malicious-campaign/

ShadyPanda browser extensions amass 4.3M installs in malicious campaign

A long-running malware operation known as "ShadyPanda" has amassed over 4.3 million installations of seemingly legitimate Chrome and Edge browser extensions that evolved into malware.

BleepingComputer

GlassWorm malware is evolving—using invisible code tricks to sneak into GitHub, NPM, and beyond. Could your favorite dev tools be next in its global pursuit? Read more to find out.

https://thedefendopsdiaries.com/glassworm-malware-campaign-expands-new-platforms-sophisticated-obfuscation-and-global-impact/

#glassworm
#malwarecampaign
#cybersecurity
#obfuscation
#vscodeextensions

GlassWorm Malware Campaign Expands: New Platforms, Sophisticated Obfuscation, and Global Impact

Explore how the GlassWorm malware campaign is evolving with new platforms, advanced obfuscation, and global impact on developers and users.

The DefendOps Diaries
Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures

Noodlophile stealer targets enterprises via copyright phishing since 2024, using Gmail, Dropbox, and Telegram for evasion.

The Hacker News

Scammers are twisting SourceForge's trusted face—disguising malware as Microsoft Office add-ins. Ever wondered how they pull off this digital con? Read on to uncover the deception.

https://thedefendopsdiaries.com/unmasking-the-sourceforge-malware-campaign-a-deceptive-attack-on-users/

#sourceforge
#malwarecampaign
#cybersecurity
#microsoftoffice
#cybercrime

Unmasking the SourceForge Malware Campaign: A Deceptive Attack on Users

Explore how cybercriminals exploit SourceForge to distribute malware disguised as Microsoft Office add-ins, targeting users for financial gain.

The DefendOps Diaries
Understanding the 'DollyWay' Malware Campaign: A Persistent Cyber Threat

Explore the evolution and impact of the 'DollyWay' malware campaign, a persistent threat targeting WordPress sites globally.

The DefendOps Diaries

A recent cybersecurity study revealed a sophisticated malware campaign targeting NuGet, a package manager for .NET applications. Attackers used homoglyphs, characters that look similar but have different codes (for example, the number '0' and the letter 'O', or the lowercase 'l' and the uppercase 'I'), to create fake packages that seemed legitimate but contained malicious code. They also employed IL weaving, a method that alters .NET binaries to insert harmful modules disguised as legitimate ones. This campaign involved around 60 packages and 290 versions, highlighting the need for increased vigilance in software supply chains.

https://thecyberexpress.com/homoglyphs-il-weaving-malicious-nuget-campaign/

#cybersecurity #NuGet #malware #homoglyphs #ILWeawing #malwarecampaign #DotNet #CodeInjection #SecurityResearch

Malicious NuGet Packages Hidden With Homoglyphs and IL Weaving

A sophisticated malware campaign targeting the NuGet package manager employed advanced techniques such as homoglyphs and IL weaving to evade detection.

The Cyber Express