The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

CrashStealer: How Native macOS Malware Is Raising the Bar

Jul 20, 2026 2:18:45 PM / by The Hivemind posted in Threat Bulletin, MacOS malware, macOS infostealer, Apple Keychain theft, browser credential theft, cryptocurrency wallet malware, CrashStealer, CrashStealer malware

0 Comments

Executive Summary

Industry researchers have identified CrashStealer, a newly active macOS infostealer that combines a signed and notarized delivery mechanism with sophisticated credential theft, cryptocurrency wallet targeting, and extensive anti-analysis techniques. Unlike many existing macOS stealers that rely on AppleScript or Objective-C wrappers, CrashStealer is implemented primarily in native C++, reflecting an increasingly mature approach to macOS malware development. The malware abuses trusted Apple technologies to bypass user protections, validates stolen credentials locally before collection, encrypts harvested data using AES-256-GCM, and establishes persistence through LaunchAgents while masquerading as legitimate Apple components. The campaign demonstrates that macOS ecosystems are no longer niche targets.

Read More

GigaWiper: Inside a Modular Cyberweapon

Jul 17, 2026 2:51:19 PM / by The Hivemind posted in Threat Bulletin, modular malware, Microsoft threat intelligence, GigaWiper, BLUERABBIT, Crucio ransomware, Zebrocy, Golang malware, FlockWiper

0 Comments

Related Families: GigaWiper, Crucio, FlockWiper, Zebrocy

Executive Summary

Industry researchers identified GigaWiper, a sophisticated Golang-based malware platform that combines remote administration, persistence, reconnaissance, surveillance, and multiple destructive payloads within a single modular implant. Rather than deploying separate malware families for different objectives, the threat actor consolidated disk wiping, irreversible file encryption, secure data destruction, and extensive command-and-control (C2) functionality into one flexible backdoor.

Read More

BusySnake Stealer: Inside Armored Likho's AI-Assisted Malware Operation

Jul 13, 2026 1:09:43 PM / by The Hivemind posted in Threat Bulletin, Infostealer, Spear Phishing, Python Malware, credential theft, Armored Likho, BusySnake Stealer, AI-assisted malware, Eagle Werewolf, reverse SSH tunnel

0 Comments

Verticals Targeted: Government, Electric, Energy, Critical Infrastructure
Regions Targeted: Russia, Kazakhstan, Brazil
Related Threat Actors: Armored Likho
Related Families: BusySnake

Executive Summary

Researchers have identified an active phishing campaign introducing a previously undocumented Python-based infostealer dubbed BusySnake Stealer. Targeting government agencies and electric power organizations across Russia, Kazakhstan, and Brazil, the campaign combines AI-assisted first-stage loaders, modular malware, GitHub-hosted payload delivery, and advanced credential theft capabilities. The operation demonstrates the group's continued technical evolution and highlights how increasingly modular malware can complicate traditional signature-based detection while reinforcing the importance of behavioral analytics and threat intelligence.

Read More

JADEPUFFER: Agentic Ransomware Signals a New Era of AI-Driven Cyber Operations

Jul 10, 2026 11:24:05 AM / by The Hivemind posted in Threat Bulletin, AI-powered ransomware, AI-generated malware, autonomous cyber attacks, JADEPUFFER, autonomous malware, agentic ransomware, LLM malware

0 Comments


Executive Summary

Industry researchers recently documented JADEPUFFER, a ransomware operation they assess to be the first publicly documented example of agentic ransomware. Unlike traditional ransomware operations that rely on manually operated toolkits or prebuilt malware, JADEPUFFER reportedly leveraged a large language model (LLM) to autonomously perform reconnaissance, credential theft, lateral movement, persistence, and database extortion. Although the campaign primarily abused well-known vulnerabilities and insecure configurations rather than novel exploits, its ability to adapt to operational failures and generate new task-specific payloads demonstrates how AI may significantly lower the barrier to conducting sophisticated cyberattacks while creating new challenges for defenders.

Read More

When Disaster Strikes, Cybercriminals Follow: The Persistent Threat of Disaster-Themed Fraud Campaigns

Jul 6, 2026 2:47:54 PM / by The Hivemind posted in Threat Bulletin, Phishing Campaigns, disaster phishing, charity fraud, natural disaster cyber threats, disaster-themed cyber campaigns, fake charities, cyber fraud

0 Comments

Executive Summary

Natural disasters create opportunities not only for emergency responders and humanitarian organizations to do good, but also for cybercriminals seeking to exploit public fear, urgency, and generosity. Following the June 2026 Venezuela earthquake, researchers observed hundreds of newly registered disaster-themed domains, highlighting how quickly threat actors and opportunistic scammers can capitalize on breaking events. This activity reflects a broader pattern observed after major disasters worldwide, where fraudulent websites, phishing campaigns, and fake charities emerge alongside legitimate relief efforts, complicating efforts to distinguish trusted resources from malicious infrastructure.

Read More

SharkLoader Emerges as Stealthy Cobalt Strike Delivery Framework

Jul 2, 2026 9:31:24 AM / by The Hivemind posted in Threat Bulletin, Cobalt Strike, malware loader, DLL sideloading, SharkLoader, StrikeShark

0 Comments

Verticals Targeted: Government, Diplomatic Organizations, Software Development
Regions Targeted: Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, Serbia
Related Families: SharkLoader, Cobalt Strike

Executive Summary

Researchers have identified a previously undocumented malware loader named SharkLoader, used by an intrusion cluster tracked as StrikeShark to deploy Cobalt Strike Beacon against organizations across multiple countries and industries. The campaign has leveraged exploitation of vulnerable internet-facing applications alongside custom droppers disguised as legitimate software installers to establish initial access. Confirmed victims include government-related organizations, diplomatic entities, software development companies, and organizations in additional sectors spanning Asia, Europe, the Middle East, and Latin America.

Read More

Mistic: New Malware May Signal Evolution in Access Broker Tooling

Jun 29, 2026 3:02:43 PM / by The Hivemind posted in Threat Bulletin, initial access broker, Mistic, Backdoor.Mistic, ModeloRAT, MLTBackdoor, Woodgnat, KongTuke

0 Comments

Verticals Targeted: Insurance, Education, Information Technology
Related Families: Mistic, ModeloRAT

Read More

Beyond Banking Trojans: Rokarolla Expands the Android Fraud Playbook

Jun 26, 2026 2:32:36 PM / by The Hivemind posted in Threat Bulletin, Android Malware, Android banking trojan, mobile banking fraud, cryptocurrency malware, Rokarolla, banking malware, Android phishing overlays

0 Comments

Verticals Targeted: Financial, Cryptocurrency
Regions Targeted: Global
Related Families:
Rokarolla

Executive Summary

Researchers have identified Rokarolla, a newly discovered Android banking trojan distributed through malicious websites impersonating trusted applications such as TikTok, Google Chrome, and Google Play Protect. The malware targets at least 217 banking and cryptocurrency applications and leverages Android Accessibility Services, phishing overlays, SMS interception, keylogging, screen monitoring, and call blocking to facilitate financial fraud. Rokarolla exposes at least 137 operator commands and employs multiple persistence and evasion mechanisms, allowing attackers to maintain extensive control over infected devices while minimizing user awareness and intervention.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts