SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 57

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN 

The State of Ransomware – Q2 2025 

Malware 101: a comprehensive guide 

Behind Random Words: DoubleTrouble Mobile Banking Trojan Revealed

ToxicPanda: The Android Banking Trojan Targeting Europe   

“CAPTCHAgeddon” Unmasking the Viral Evolution of the ClickFix Browser-Based Threat 

Project Ire autonomously identifies malware at scale 

Unmasking SocGholish: Silent Push Untangles the Malware Web Behind the “Pioneer of Fake Updates” and Its Operator, TA569

11 Malicious Go Packages Distribute Obfuscated Remote Payloads 

New Infection Chain and ConfuserEx-Based Obfuscation for DarkCloud Stealer

WinRAR zero-day exploited to plant malware on archive extraction     

ranDecepter: Real-time Identification and Deterrence of Ransomware Attacks

MalFlows: Context-aware Fusion of Heterogeneous Flow Semantics for Android Malware Detection

Hybrid Analysis Model for Detecting Fileless Malware 

Germany’s top court holds that police can only use spyware to investigate serious crimes   

FraudOnTok

Updated UAC-0099 toolkit: MATCHBOIL, MATCHWOK, DRAGSTARE

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, NEWSLETTER)