Organizations in Western and Central Europe have been targeted by Russian state-backed threat operation APT28 with webhook-based macro malware as part of the Operation MacroMaze attack campaign that ran between September 2025 and January 2026, The Hacker News reports.
Crypto wallet-, browser-targeting infostealer spread via bogus CAPTCHAs Fake CAPTCHAs have been leveraged to facilitate the deployment of information-stealing malware targeting multiple cryptocurrency wallets and credentials stored across over two dozen web browsers as part of a new ClickFix attack campaign, according to HackRead.
Cybernews reports that threat actors have launched the information-stealing MacSync malware in a new malvertising campaign that weaponized at least 35 breached Google Ads accounts promoting law firms, hotels, and other legitimate businesses around the world to push over 200 illicit ads spoofing widely used macOS software, including 7-Zip, LibreOffice, Notepad++, and Final Cut Pro.