SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 70

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

SesameOp: Novel backdoor uses OpenAI Assistants API for command and control  

Weaponized Military Documents Deliver Advanced SSH-Tor Backdoor to Defense Sector  

Gootloader Returns: What Goodies Did They Bring? 

Ransomvibing appears in VS Code extensions 

Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities

Investigation Report: Android/BankBot-YNRK Mobile Banking Trojan 

LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices

Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation

DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant

Curly COMrades: Evasion and Persistence via Hidden Hyper-V Virtual Machines

Adversarially Robust and Interpretable Magecart Malware Detection

Android Malware Detection: A Machine Leaning Approach

Legacy Code, Live Risk: Empirical Evidence of Malware Detection Gaps

MemCatcher: An In-Depth Analysis Approach to Detect In-Memory Malware

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)