Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Source: The Hacker News Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the Read original

August 26, 2026 Updated: October 8, 2026 1 min

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning Source: The Hacker News Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike g Read original

August 24, 2026 Updated: October 8, 2026 1 min

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning Source: The Hacker News Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike g Read original

August 24, 2026 Updated: October 8, 2026 1 min

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Source: The Hacker News Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stea Read original