Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

SalatStealer Malware: Inside a Credential Stealer Built for Repeat Use

SalatStealer is a Go-based infostealer family first observed in August 2026, built for x86 Windows environments and focused on credential theft. Its documented capabilities include stealing authentication credentials, hiding executing code, and degrading security software.

MovieReaper Malware: From Movie Download to Malware Infection

MovieReaper is a malware family first observed in September 2026 that combines remote-access trojan and loader functionality in a modular, multi-stage framework. It targets x86-64 systems and is built to reach remote machines, install additional components, persist across reboots, and exfiltrate data while resisting analysis through anti-sandbox, anti-VM, and AV-evasion features.

Noodle RAT: A Recipe for Cross Platform Espionage

Noodle RAT—also known as ANGRYREBEL or Nood RAT—is a modular remote access trojan (RAT) with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. It was previously misclassified as variants of Gh0st RAT or Rekoobe but is now recognized as a unique backdoor family.

Pikabot Malware: Delivery Methods, Evasion, and Impact

Originating in early 2023, Pikabot emerged as a significant malware loader. Over the past year, ThreatLabz has diligently monitored its development and operational methods. Notably, there was a surge in Pikabot’s usage in the latter part of 2023, attributed to a BlackBasta ransomware affiliate adopting Pikabot post the FBI-led Qakbot takedown. However, Pikabot’s activity ceased shortly after Christmas 2023, with version 1.1.19 marking its endpoint.

PoshC2 Explained: Capabilities, Indicators, and Detection

PoshC2 version 6.0, an open-source command and control framework, is notable for its robust capabilities in managing compromised hosts. Accompanying its release, a comprehensive list of Indicators of Compromise (IoCs) and a dedicated GitHub repository have been provided. These resources are designed to assist cybersecurity teams in detecting PoshC2, especially when deployed with its default settings, which less sophisticated attackers often utilize.

What Is gh0st RAT? How It Works, Spreads, and Steals Data

Ghost RAT (Remote Access Trojan) is a type of sophisticated malicious software that operates covertly, enabling unauthorized remote access and control of a victim’s computer system. Often deployed with malicious intent by cybercriminals, Ghost RATs are designed to evade detection and provide the attacker with a range of powerful capabilities, such as data theft, system manipulation, and surveillance.

Havoc Malware: Techniques, Targets, and Threat Overview

Security analysts have noticed a trend among threat actors shifting towards adopting a novel open-source command and control (C2) framework called Havoc as an alternative to paid solutions like Cobalt Strike and Brute Ratel. Developed in the C language and introduced in 2022, Havoc’s Main branch received updates in 2023.

SparkKitty Malware: An Emerging Threat to Mobile Users

SparkKitty is a newly uncovered cross-platform information stealer, designed to exfiltrate sensitive data—particularly cryptocurrency wallet seed phrases—by leveraging advanced optical character recognition (OCR) techniques on both Android and iOS devices. The malware, discovered by Kaspersky in early 2024 and publicly detailed in June 2025, appears to be a direct evolution of a previous stealer known as SparkCat.

WannaCry Ransomware: Infection, Impact, and Prevention

WannaCry, also known as WannaCrypt, is a notorious ransomware strain that gained global attention in May 2017 due to its widespread and damaging impact. It belongs to the category of malware known as ransomware, which encrypts a victim’s files and demands a ransom payment, usually in cryptocurrency, in exchange for a decryption key that can unlock the files.