> SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
[AUTHOR: Pierluigi Paganini]
[DATE: 27/09/2026 15:05]
[LANGUAGE: EN]
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape
Malware Newsletter
Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
ChainScript: Tracing a Node.js RAT Through the Blockchain
North Korean “WaterPlum,” commonly referred to as “Contagious Interview,” Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe
npm ‘btree’ Malware Campaign Affects Millions of Downloads, No Need for Install Script
Malicious npm campaign targets developers integrating Twilio
The Closed Quorum: Inside the first reported autonomous AI C2 implant
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
RemControl: AI Built the Overlays. Victims Lose their PINs
Graphalgo campaign spreads to Terraform providers and Go Modules
Inside Corp MDM, the Android spyware targeting logistics companies
ClickFix Malware Report
MacSync under the microscope: new delivery methods and a new payload
CARBONATO: a botnet built around an AI agent
The Psychedelic Stealer: When a CAPTCHA Becomes an Installer
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework
HFS-SVE: A Hybrid Feature Selection and Soft Voting Ensemble for Android Malware Detection
A Data-Driven Analysis of Infostealer Malware Victims
Classifier-Dependent Benefits of Pseudo-Labeling for Semi-Supervised Android Malware Attribution
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, newsletter)