Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

2026-05-28T07:24:11Zd90922af3a9fbe813a6892bdc38024125e02af4b02d750e847a070e78f79e3c4
AI‑abuseAnthropic ClaudeBTMOBCISA/KEVCrates.ioDrupalGhost CMSGiteaGlassWormGrandoreiroKnowledgeDeliverLaravel‑LangLazarusLiteSpeedMuddyWaterPackagistPyPIRemotePESharePointTrapDoorcredential‑stealercryptojacking','MFA prompt bombingmalwarenpmsupply-chain

What happened

Pulse of recent security news: multiple active malware and supply-chain campaigns (Grandoreiro, BTMOB, GlassWorm, TrapDoor, Laravel‑Lang compromises, Packagist abuses) are targeting Windows, Android, and developer ecosystems across Latin America, Europe, and globally. Several high‑impact vulnerabilities are being exploited or patched, including Gitea unauthenticated container access, LiteSpeed cPanel RCE (CVE‑2026‑48172) under active exploitation, Ghost CMS SQLi (CVE‑2026‑26980) used to hijack sites, and other disclosed flaws (SharePoint, KnowledgeDeliver, Drupal) with active exploitation and/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
d90922af3a9fbe813a6892bdc38024125e02af4b02d750e847a070e78f79e3c4
Enrichment time
2026-05-28T07:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.