ClickFix campaign spreads MacSync macOS Infostealer via fake AI tool installer

Three different ClickFix campaigns were found to serve as delivery vectors for the deployment of a macOS information stealer called MacSync. Sophos researchers Jagadeesh Chandraiah, Tonmoy Jitu, Dmitry Samosseiko, and Matt Wixey said, “Unlike traditional exploit-based attacks, this technique relies entirely on user interaction (usually in the form of copying and executing commands), making it […]

DRILLAPP backdoor targets Ukraine, exploits Microsoft Edge debugging for stealth espionage

Ukrainian organizations have emerged as targets of a new campaign likely orchestrated by Russian-linked threat actors, according to a report from S2 Grupo’s LAB52 threat intelligence team. This campaign, observed in February 2026, is assessed as a duplicate of a previous campaign launched by Laundry Bear (also known as UAC-0190 or Void Blizzard) targeting the […]

Android 17 blocks non-accessible apps from accessibility APIs to prevent malware abuse

Ravi LakshmananMarch 16, 2026Mobile security/data protection Google is testing a new security feature as part of Android Advanced Protected Mode (AAPM) that prevents certain types of apps from using accessibility services APIs. This change is included in Android 17 Beta 2 and was first reported by Android Authority last week. AAPM was introduced by Google […]

Flaw in OpenClaw AI agent could allow rapid injection and data leakage

Ravi LakshmananMarch 14, 2026Artificial intelligence/endpoint security The China National Computer Network Emergency Response Technology Team (CNCERT) has issued a warning about security stemming from the use of OpenClaw (formerly Clawdbot and Moltbot), an open source, self-hosted autonomous artificial intelligence (AI) agent. In a post shared on WeChat, CNCERT noted that the platform’s “inherently weak default […]

GlassWorm supply chain attack exploits 72 open VSX extensions to target developers

Cybersecurity researchers have warned of a new iteration of the GlassWorm campaign, claiming that it has “significantly expanded” its method of spread through the Open VSX registry. “Rather than requiring loaders to be directly embedded in every malicious list, threat actors are now exploiting extensionPack and extensionDependency to turn extensions that initially appear standalone into […]

Chinese hackers target Southeast Asian militaries with AppleChris and MemFun malware

The suspected China-based cyber espionage operation has targeted military organizations in Southeast Asia as part of a state-sponsored campaign dating back to at least 2020. Palo Alto Networks Unit 42 is tracking threat activity under the designation CL-STA-1087. CL refers to clusters and STA stands for state-backed motives. Security researchers Lior Rochberger and Yoav Zema […]

Meta to end Instagram’s end-to-end encrypted chat support starting May 2026

Ravi LakshmananMarch 13, 2026Encryption/data protection Meta announced plans to discontinue support for end-to-end encryption (E2EE) in Instagram chats after May 8, 2026. “If you have chats that are affected by this change, you will receive instructions on how to download the media and messages you want to keep,” the social media giant said in its […]

Interpol destroys 45,000 malicious IPs and arrests 94 people in global cybercrime investigation

Ravi LakshmananMarch 13, 2026Ransomware/Cybercrime Interpol announced on Friday that it would remove 45,000 malicious IP addresses and servers used in connection with phishing, malware and ransomware campaigns as part of the agency’s ongoing efforts to dismantle criminal networks, thwart new threats and protect victims from fraud. This effort is part of an international law enforcement […]

Storm-2561 spreads Trojan VPN clients and steals credentials via SEO poisoning

Ravi LakshmananMarch 13, 2026VPN Security/Malware Microsoft has revealed details of a credential theft campaign using fake virtual private network (VPN) clients distributed through search engine optimization (SEO) poisoning techniques. “This campaign deploys a digitally signed Trojan horse that redirects users searching for legitimate enterprise software to a malicious ZIP file on an attacker-controlled website and […]

Investigating new clickfix variants

Disclaimer: This report was produced by the Threat Research Center to increase cybersecurity awareness and support strengthening defensive capabilities. This is based on independent research and observations of the current threat landscape available at the time of publication. This content is for informational and preparatory purposes only. Read more blogs on threat intelligence and adversary […]