Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
2026-05-28T07:24:11Z•d90922af3a9fbe813a6892bdc38024125e02af4b02d750e847a070e78f79e3c4
AI‑abuseAnthropic ClaudeBTMOBCISA/KEVCrates.ioDrupalGhost CMSGiteaGlassWormGrandoreiroKnowledgeDeliverLaravel‑LangLazarusLiteSpeedMuddyWaterPackagistPyPIRemotePESharePointTrapDoorcredential‑stealercryptojacking','MFA prompt bombingmalwarenpmsupply-chain
What happened
Pulse of recent security news: multiple active malware and supply-chain campaigns (Grandoreiro, BTMOB, GlassWorm, TrapDoor, Laravel‑Lang compromises, Packagist abuses) are targeting Windows, Android, and developer ecosystems across Latin America, Europe, and globally. Several high‑impact vulnerabilities are being exploited or patched, including Gitea unauthenticated container access, LiteSpeed cPanel RCE (CVE‑2026‑48172) under active exploitation, Ghost CMS SQLi (CVE‑2026‑26980) used to hijack sites, and other disclosed flaws (SharePoint, KnowledgeDeliver, Drupal) with active exploitation and/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d90922af3a9fbe813a6892bdc38024125e02af4b02d750e847a070e78f79e3c4
- Enrichment time
- 2026-05-28T07:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.