M-Infostealer

04
Sep
The Whole Pipeline: How Breached Data Becomes Cash, Leverage, and Sextortion Material- 306

The Whole Pipeline: How Breached Data Becomes Cash, Leverage, and Sextortion Material- 306

August 13, 2026 A data breach is usually reported as a single event — a company discloses an intrusion, a number
7 min read
04
Sep
The Authentic Trap: How H1 2026's Scam Campaigns Learned to Borrow Trust Instead of Faking It- 305

The Authentic Trap: How H1 2026's Scam Campaigns Learned to Borrow Trust Instead of Faking It- 305

August 15, 2026 Security vendors publish threat reports constantly, and most of them read the same way: a pie chart
4 min read
27
Aug
Borrowed Trust: How Moscow Turns Everyday Software Into an Access Network- 296

Borrowed Trust: How Moscow Turns Everyday Software Into an Access Network- 296

August 5, 2026 A fake job offer, a hijacked hotel Wi-Fi login, a criminal marketplace listing, and an advertising
6 min read
03
Aug
A blank marketing email as a spy's front door: how suspected Chinese operators are quietly reading university mailboxes- 285

A blank marketing email as a spy's front door: how suspected Chinese operators are quietly reading university mailboxes- 285

July 9, 2026 A suspected Chinese espionage group has spent months breaking into the email accounts of physics and engineering
2 min read
03
Aug
When cybercrime borrows a spy's toolkit: the UAT-11795 campaign hiding inside everyday software- 292

When cybercrime borrows a spy's toolkit: the UAT-11795 campaign hiding inside everyday software- 292

July 18, 2026 A financially motivated, Russian-speaking hacking crew has spent over a year quietly trojanizing the installers of
5 min read
20
Jul
Trust as the Attack Surface: Inside the ClickFix Campaigns Powering ACR Stealer- 258

Trust as the Attack Surface: Inside the ClickFix Campaigns Powering ACR Stealer- 258

July 19, 2026 No vulnerability was patched, no exploit chain engineered, in the campaigns Microsoft disclosed distributing ACR Stealer through
2 min read
19
Jul
North Korea just made its malware payload host itself on the blockchain- 252

North Korea just made its malware payload host itself on the blockchain- 252

July 5, 2026 North Korean threat actors behind the long-running Contagious Interview campaign have distributed more than 100 malicious
3 min read
19
Jul
The worm that infects the tools developers trust to catch it- 246

The worm that infects the tools developers trust to catch it- 246

April 30, 2026 TeamPCP's Mini Shai-Hulud campaign has spent the past 48 hours poisoning official npm and
2 min read
05
Jul
The Worm in the Toolchain: How TeamPCP Built a Credential Extraction Economy Inside Open Source- 201

The Worm in the Toolchain: How TeamPCP Built a Credential Extraction Economy Inside Open Source- 201

June 23, 2026 The most consequential credential theft does not happen when a user clicks a phishing link. It happens
4 min read
14
Nov
Gootloader malware back for the attack, serves up ransomware- 97

Gootloader malware back for the attack, serves up ransomware- 97

November 6, 2025 The resurgence of Gootloader malware illustrates the evolution of cyber threats where established tactics like SEO poisoning
2 min read