malware

AppWizard
September 18, 2026
Cybersecurity experts have identified a new Android malware named RatHat, believed to be operated by Chinese threat actors. RatHat is distributed primarily through smishing and malvertising campaigns, leading users to deceptive download portals. It employs an automated multi-stage infection process and exploits Accessibility features along with a local ADB self-pairing mechanism to escape the Android application sandbox. The malware uses various anti-analysis techniques, including container tampering, manifest bombs, DEX bytecode poisoning, and dual string-encryption. RatHat's architecture consists of a malicious Android application, a Go agent, and an FRP reverse-proxy client, which together enable it to gain critical system permissions and perform various malicious activities such as credential capturing, screen recording, and SMS interception. Even if uninstalled, the malware retains shell access to the device, allowing attackers to reinstall it. RatHat can serialize the device's Accessibility tree to XML and communicate with a Generative AI assistant for tasks like screen coordinate determination and text extraction. The Go Agent, masquerading as a native library, exploits shell access to execute commands and establish a persistent connection to a command-and-control server via the FRP client. The C2 server can issue extensive commands to collect sensitive information, including SMS messages, credentials, files, and keystrokes, and RatHat also features a hardware-level keylogger.
BetaBeacon
September 18, 2026
- Pokémon Infinite Fusion is a standalone game built in RPG Maker XP, using the RGSS scripting layer. - The game is not a ROM, cartridge dump, or console to emulate, but rather a folder of Ruby scripts, tileset graphics, and audio files. - The mainline build of the game reached version 6.7.2 on October 2, 2025, and was updated to version 6.8.2 by August 2026. - The game combines two Pokémon into a single custom sprite and blended stat line, generating the combined artwork procedurally. - The Android-specific performance complaints come from the CPU doing image layering work in real time when compositing fusion sprites on lower-end devices.
AppWizard
September 17, 2026
Security researchers at Zimperium have identified a new strain of Android malware called RatHat, which is linked to threat actors from China and is designed to steal sensitive credentials and banking information. RatHat infiltrates devices through phishing sites, malvertising, and SMS phishing (smishing), tricking users into downloading malicious Android package kits (APKs). The malware uses a dropper to activate its payload, which is hidden in encrypted assets, and employs techniques to bypass Android's security measures. RatHat consists of three main components: a malicious Android application, a Go agent (liblocal-service.so), and an FRP client (libmedia_codec.so). The app collects sensitive information such as banking credentials, notifications, 2FA codes, OTP keys, and screen inputs. It features a generative AI user interface-automation engine that communicates in Mandarin and can perform various tasks like determining screen coordinates and issuing navigation commands. The Go agent acts as a command-and-control executor, executing commands to bypass app-level security and manage system-level tasks. The FRP client maintains a secure reverse tunnel to the attacker's server, allowing ongoing remote access to the device. The architecture of RatHat demonstrates the inadequacy of traditional mobile security measures against such advanced threats.
Tech Optimizer
September 16, 2026
Iranian state-affiliated cyber actors are targeting dissidents, activists, and journalists using fake AI applications, counterfeit antivirus tools, and fabricated MRI scan results, primarily through a spyware family known as CHOSEN BRICK, which is designed for Windows systems. This campaign has been active since at least 2025 and affects individuals globally, including in the UK, US, and Netherlands. The malware establishes persistence via the Windows Registry Run key and communicates through Telegram, utilizing unique Bot IDs for each victim. CHOSEN BRICK is capable of extensive data collection, including capturing screenshots, recording audio, and stealing email content. Personal information from victims has been found on pro-Iranian leak sites, increasing harassment risks. Security measures should include monitoring for suspicious Registry entries and unusual communications, while users are advised to avoid unsolicited software installations and keep their systems updated. The FBI refers to this malware family as HEAVYGRAM.
Tech Optimizer
September 16, 2026
Windows is the only desktop platform where antivirus software is essential. Microsoft has patched many vulnerabilities, but the OS still allows installations from unverified sources and connects to potentially untrustworthy networks. As of 2026, the top antivirus solutions for Windows include: - Norton 360: Best overall, with a full scan time of 13 minutes and 22 seconds, robust firewall, and up to 250 GB cloud backup. - Bitdefender: Best for older PCs, maintaining peak CPU usage at 11% and memory at 183 MB during scans. - Avast One: Best free option for Windows 11, achieving a perfect score in AV-TEST. - NordVPN Threat Protection Pro: Best for VPN users, blocking 90% of malware. - McAfee+: Best for households with multiple devices, offering unlimited coverage but is the slowest scanner. - Microsoft Defender: Best free option included with Windows, awarded Top Product by AV-TEST. Norton 360 has a 99.8% detection rate and offers a 60-day refund window. Bitdefender also has a 99.8% detection rate with low resource usage. Avast's free version is effective, while NordVPN provides integrated malware protection for existing VPN users. McAfee is suitable for large households but has slower performance. Microsoft Defender is adequate for single users practicing safe browsing but lacks multi-device support. Kaspersky is unavailable in the U.S. due to supply chain concerns.
Tech Optimizer
September 15, 2026
Iranian state-sponsored hackers are targeting dissidents, activists, and journalists using deceptive tactics, including malicious applications that impersonate reputable cybersecurity products like Norton Antivirus and KeePass. The FBI and UK authorities issued a warning about these hackers, who establish rapport with targets via social messaging platforms, posing as IT support or known contacts. They convince victims to download files that appear authentic, including AI video creation applications and other software. The spyware, named “Chosen Brick,” infects Windows PCs and has capabilities such as capturing screen content, recording audio, collecting message data, and downloading additional malware. The hackers have exploited this spyware to publish personal details of victims, increasing their harassment. The FBI advises potential victims on detecting the spyware and recommends enabling antivirus software, running regular scans, and avoiding unofficial downloads.
Search