Filtered by tag: malware × Clear
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Matched: health
A campaign targeting Cambodia is deploying Spark RAT, an open-source remote access trojan, using lure themes including government notices, public health materials, and real estate content. The attack abuses a vulnerable OPSWAT driver to disable security tools, broadening its potential victim pool across individuals and organizations in the region.
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions
Matched: health
ToxNetV2 is a Linux botnet targeting AArch64 systems that integrates NVIDIA's NIM AI service into its controller to suggest attack commands. The controller feeds system and botnet data to the AI model, parsing structured responses into a queue of proposed actions — including shell commands, SSH access, and file operations — that human operators must approve before execution. The botnet uses a peer-to-peer structure and includes scanning, self-propagation, and 17 network-attack modules. Researchers at JOESecurity noted the malware embeds a jailbreak prompt to reduce AI refusals.
Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access
Matched: health
Scammers are running fake Microsoft-branded security scan websites that display fabricated system warnings and artificially low security scores to frighten visitors. The sites instruct users to uninstall their antivirus software, then collect personal and banking details through a form before redirecting victims to await a callback. During that call, operators request remote access to complete a fake refund, giving criminals direct control of the device. Malwarebytes identified 11 related sites sharing one server.