Threat actors are impersonating employers on the Indeed job board to distribute malicious Android applications disguised as interview tools to unsuspecting job seekers. Once installed, these fake apps deliver spyware capable of compromising victim devices. This campaign exploits the trust job applicants place in legitimate recruitment platforms to gain initial access.
A previously unknown Windows backdoor called SLEEPWALKER has been discovered by an independent researcher, featuring a dormant-until-triggered mechanism that activates only upon receipt of a specially crafted network packet. Once activated, the unsigned 64-bit DLL executes commands using a custom 23-instruction bytecode language, designed for side-loading into legitimate processes. This stealthy approach allows the malware to remain undetected in memory until explicitly triggered by an attacker.
A malware campaign discovered by Cato Networks exploits sponsored search ads to direct macOS users to a fake OpenAI Codex download page, where victims are socially engineered into pasting malicious commands directly into Terminal. The attack uses a variation of the ClickFix technique, which manipulates users into executing the infection themselves rather than opening a malicious file, with the campaign beginning through sponsored search results for queries like "codex macos download."
Researchers have identified a novel command-and-control technique where threat actors exploit FTP banners as dead drop resolvers to deliver two previously unreported RATs named E4del and PINHOLE. This approach leverages legitimate FTP services to obscure malware communications and point to additional C2 infrastructure while evading detection.