SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 118

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape
Malware Newsletter
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
UAC-0277: ClickFix on compromised websites to spread LUNEXSTEALER
MALFEX – A malicious npm postinstall no advisory has caught for fourteen months
Canto incognito: tracking the PoeLLM malware
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Sleep, Beacon, Steal, Repeat – The Story of P7 DarkSword Variant
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Never Deleted, Only Re-Pointed: Inside the 17,600-Repo FakeGit Fleet That Re-Arms Overnight
The phone was compromised before the user turned it on: the rise of Midnight Mimosa
ORCAGen: Orchestrating Context-Aware Malware Deception with RAG-Guided Generative AI
MARS: Malware Analysis with Rule-Based Scoring of LLM Claims
An IoT Malware Detection Framework Based on Large Language Models and Deep Learning Techniques
An Explainable Attention-Enhanced Deep Learning Model for Memory-Forensic Malware Detection
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, newsletter)

