{"id":525211,"date":"2026-03-15T15:39:08","date_gmt":"2026-03-15T15:39:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/525211\/"},"modified":"2026-03-15T15:39:08","modified_gmt":"2026-03-15T15:39:08","slug":"security-affairs-malware-newsletter-round-88","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/525211\/","title":{"rendered":"SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 88"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 88\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> March 15, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2026\/03\/SecurityAffairs-malware-newsletter-2.png\" alt=\"\"\/><\/p>\n<p>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape<\/p>\n<p>Malware Newsletter<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/c\/boryptgrab-stealer-targets-users-via-deceptive-github-pages.html\" rel=\"nofollow noopener\" target=\"_blank\">New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages<\/a><\/p>\n<p><a href=\"https:\/\/www.nadsec.online\/blog\/coruna#article\" rel=\"nofollow noopener\" target=\"_blank\">Inside Coruna: Reverse Engineering a Nation-State iOS Exploit Kit From JavaScript<\/a>\u00a0<\/p>\n<p><a href=\"https:\/\/cyble.com\/blog\/clipxdaemon-autonomous-x11-clipboard-hijacker\/\" rel=\"nofollow noopener\" target=\"_blank\">ClipXDaemon: Autonomous X11 Clipboard Hijacker Delivered via Bincrypter-Based Loader<\/a><\/p>\n<p><a href=\"https:\/\/www.bluevoyant.com\/blog\/new-a0backdoor-linked-to-teams-impersonation-and-quick-assist-social-engineering\" rel=\"nofollow noopener\" target=\"_blank\">New A0Backdoor Linked to Teams Impersonation and Quick Assist Social Engineering<\/a><\/p>\n<p><a href=\"https:\/\/www.securonix.com\/blog\/voidgeist-stealthy-multi-stage-python-loader\/\" rel=\"nofollow noopener\" target=\"_blank\">VOID#GEIST: Stealthy MultiStage Python Loader with Embedded Runtime Deployment, Startup Persistence, and Fileless Early Bird APC Injection into explorer.exe<\/a>\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-zombie-zip-technique-lets-malware-slip-past-security-tools\/\" rel=\"nofollow noopener\" target=\"_blank\">New \u2018Zombie ZIP\u2019 technique lets malware slip past security tools<\/a><\/p>\n<p><a href=\"https:\/\/blog.lumen.com\/silence-of-the-hops-the-kadnap-botnet\/\" rel=\"nofollow noopener\" target=\"_blank\">Silence of the hops: The KadNap botnet<\/a><\/p>\n<p><a href=\"https:\/\/securelist.com\/beatbanker-miner-and-banker\/119121\/\" rel=\"nofollow noopener\" target=\"_blank\">BeatBanker: A dual\u2011mode Android Trojan<\/a>\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/www.aryaka.com\/docs\/reports\/blacksanta-edr-killer-threat-report.pdf\" rel=\"nofollow noopener\" target=\"_blank\">BlackSanta EDR-Killer A Silent Threat Targeting Recruitment Workflows<\/a>\u00a0<\/p>\n<p><a href=\"https:\/\/www.cyfirma.com\/research\/taxispy-rat-analysis-of-taxispy-rat-russian-banking-focused-android-malware-with-full-remote-control\/\" rel=\"nofollow noopener\" target=\"_blank\">TAXISPY RAT : Analysis of TaxiSpy RAT \u2013 Russian Banking \u2013 Focused Android Malware with Full Remote Control<\/a><\/p>\n<p><a href=\"https:\/\/www.ibm.com\/think\/x-force\/slopoly-start-ai-enhanced-ransomware-attacks\" rel=\"nofollow noopener\" target=\"_blank\">A Slopoly start to AI-enhanced ransomware attacks<\/a>\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/www.certosoftware.com\/insights\/oblivion-the-new-300-android-rat-that-beats-every-major-phone-manufacturers-security\/\" rel=\"nofollow noopener\" target=\"_blank\">Oblivion: The New $300 Android RAT That Beats Every Major Phone Manufacturer\u2019s Security<\/a>\u00a0\u00a0 \u00a0\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/businessinsights.bitdefender.com\/apt36-nightmare-vibeware\" rel=\"nofollow noopener\" target=\"_blank\">APT36: A Nightmare of Vibeware<\/a><\/p>\n<p><a href=\"https:\/\/annex.security\/blog\/pixel-perfect\/\" rel=\"nofollow noopener\" target=\"_blank\">Pixel Perfect: Sold Extension Injects Code Through Pixel<\/a>\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/sednit-reloaded-back-trenches\/\" rel=\"nofollow noopener\" target=\"_blank\">Sednit reloaded: Back in the trenches<\/a><\/p>\n<p><a href=\"https:\/\/zenox.ai\/en\/venon-the-first-brazilian-banker-rat-in-rust\/\" rel=\"nofollow noopener\" target=\"_blank\">VENON: The First Brazilian Banker RAT in Rust<\/a>\u00a0\u00a0<\/p>\n<p><a href=\"https:\/\/arxiv.org\/abs\/2603.03712\" rel=\"nofollow noopener\" target=\"_blank\">Internet malware propagation: Dynamics and control through SEIRV epidemic model with relapse and intervention<\/a><\/p>\n<p><a href=\"https:\/\/arxiv.org\/abs\/2603.09044\" rel=\"nofollow noopener\" target=\"_blank\">Synergistic Directed Execution and LLM-Driven Analysis for Zero-Day AI-Generated Malware Detection<\/a><\/p>\n<p><a href=\"https:\/\/www.mdpi.com\/2076-3417\/16\/6\/2670\" rel=\"nofollow noopener\" target=\"_blank\">Representation-Centric Approach for Android Malware Classification: Interpretability-Driven Feature Engineering on Function Call Graphs<\/a><\/p>\n<p><a href=\"https:\/\/www.mdpi.com\/1424-8220\/26\/6\/1750\" rel=\"nofollow noopener\" target=\"_blank\">Systematic Evaluation of Machine Learning and Deep Learning Models for IoT Malware Detection Across Ransomware, Rootkit, Spyware, Trojan, Botnet, Worm, Virus, and Keylogger<\/a><\/p>\n<p>Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p>(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0newsletter)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 88 Pierluigi Paganini March 15, 2026 Security Affairs Malware newsletter includes a collection&hellip;\n","protected":false},"author":2,"featured_media":525212,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[4,450,4001,5401,4002,5398,451,236546,236547,18482,3,236548,236549,236550,452,453],"class_list":["post-525211","post","type-post","status-publish","format-standard","has-post-thumbnail","category-breaking-news","tag-breaking-news","tag-breakingnews","tag-cybercrime","tag-data-breach","tag-hacking","tag-hacking-news","tag-headlines","tag-information-security-news","tag-it-information-security","tag-malware","tag-news","tag-pierluigi-paganini","tag-security-affairs","tag-security-news","tag-top-stories","tag-topstories"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/525211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=525211"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/525211\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/525212"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=525211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=525211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=525211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}