Fileless Malware Abuses Google Blogspot to Deploy Infostealer in Memory
2026-07-01T14:52:18Z•ece14d984b52726ecbdf4924822a915a7edfdaa9ea08dea94c8d549b0f7e0aff
Aflac Japan breachChina-linked backdoorClickFixDjinn StealerEDR bypassGentleKillerGoogle BlogspotKDDI breachMDM bypass macOS XPC flawMillenium RATNAIC breachNissan breachOracle PeopleSoft zero-dayOusabanPureLog StealerRMM vulnerabilitySimpleHelpTaskWeaverTelegramTinyRCTVeil#Dropbanking trojanfileless malwareinfostealersocial engineering
What happened
A broad set of high-impact cybersecurity developments: multiple zero-day exploits and supply‑chain attacks are being actively abused (Oracle PeopleSoft, Cisco Catalyst, SimpleHelp RMM), leading to data breaches at large organizations (Nissan, Aflac Japan, NAIC, KDDI) and deployment of information‑stealers and ransomware. Attackers continue to innovate with fileless in-memory infostealers (Veil#Drop delivering PureLog), Telegram-distributed RATs (Millenium), malicious npm packages, and blockchain-hosted malware; macOS and Apple platform weaknesses (XPC EDR/MDM bypass, unpatchable BootROM on A12
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- ece14d984b52726ecbdf4924822a915a7edfdaa9ea08dea94c8d549b0f7e0aff
- Enrichment time
- 2026-07-01T14:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.