# VirusTotal

Published articles for VirusTotal.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

DevFeed: [When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts](<https://devfeed.tech/articles/when-scanners-miss-the-attack-how-cloudflare-client-side-security-protects-storefronts-31481.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/client-side-security-finds-4-malicious-campaigns/>)

Author: Denzil Correa

Published: 2026-09-16T20:06:17Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Security](<https://devfeed.tech/topics/security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [client-side-security](<https://devfeed.tech/tags/client-side-security.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer-platform](<https://devfeed.tech/tags/developer-platform.md>), [developers](<https://devfeed.tech/tags/developers.md>), [ecommerce](<https://devfeed.tech/tags/ecommerce.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [malicious-javascript](<https://devfeed.tech/tags/malicious-javascript.md>), [page-shield](<https://devfeed.tech/tags/page-shield.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [workers-ai](<https://devfeed.tech/tags/workers-ai.md>)

### AI overview

Cloudflare describes how its Client-Side Security machine learning model detected four malicious JavaScript operations involving eight payloads in live storefront traffic. The post says humans verified the findings after automated detection, while most payloads were absent from VirusTotal and received no malicious verdict from URLScan.

### Source excerpt

A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation.

## The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

DevFeed: [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](<https://devfeed.tech/articles/the-state-of-ai-enabled-malware-august-2026-from-brand-abuse-to-agentic-execution-7744.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/>)

Author: Sara McBroom

Published: 2026-08-25T10:00:57Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [dataset](<https://devfeed.tech/topics/dataset.md>), [data](<https://devfeed.tech/topics/data.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [article](<https://devfeed.tech/tags/article.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [code](<https://devfeed.tech/tags/code.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [data](<https://devfeed.tech/tags/data.md>), [dll-hijacking](<https://devfeed.tech/tags/dll-hijacking.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Unit 42 analyzes 405 malware samples incorporating AI through mechanisms such as brand impersonation, LLM-generated code, and agentic execution loops. The research finds that most samples remain proof-of-concept or sandbox activity, while existing behavioral detection, cloud sandboxing, and endpoint analytics can detect the threats that reach operational environments.

### Source excerpt

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

## Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond

DevFeed: [Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond](<https://devfeed.tech/articles/behind-the-console-an-aitm-phishing-kit-harvesting-aws-console-credentials-and-beyond-8279.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/>)

Author: Datadog

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Adversary-in-the-middle (AiTM)](<https://devfeed.tech/topics/adversary-in-the-middle-aitm.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [Batch file](<https://devfeed.tech/topics/batch-file.md>), [cURL](<https://devfeed.tech/topics/curl.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [aws](<https://devfeed.tech/tags/aws.md>), [batch](<https://devfeed.tech/tags/batch.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [dns](<https://devfeed.tech/tags/dns.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [security](<https://devfeed.tech/tags/security.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Datadog Security Research analyzes a June 2026 campaign using cloned AWS console login pages and adversary-in-the-middle techniques to harvest credentials and MFA codes. The article details the phishing infrastructure, delivery methods, VirusTotal artifact, and JavaScript-based credential-harvesting flow.

### Source excerpt

Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.

## macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

DevFeed: [macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox](<https://devfeed.tech/articles/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox-8318.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/>)

Author: Phil Stokes

Published: 2026-06-23T21:59:42Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [apple](<https://devfeed.tech/tags/apple.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [data](<https://devfeed.tech/tags/data.md>), [llm](<https://devfeed.tech/tags/llm.md>), [logs](<https://devfeed.tech/tags/logs.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [rust](<https://devfeed.tech/tags/rust.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [tls](<https://devfeed.tech/tags/tls.md>), [update](<https://devfeed.tech/tags/update.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

SentinelLABS analyzes macOS.Gaslight, a Rust implant whose embedded prompt injection attempts to derail LLM-assisted malware triage. The report describes Telegram Bot API command and control, encrypted communications, token redaction, and a suspected DPRK-linked activity cluster.

### Source excerpt

DPRK-linked implant embeds 38 fabricated system messages that spoof an LLM triage harness, hiding a credential stealer and Telegram C2 underneath.

## FishMonger's arsenal upgraded: SprySOCKS for Windows

DevFeed: [FishMonger's arsenal upgraded: SprySOCKS for Windows](<https://devfeed.tech/articles/fishmonger-s-arsenal-upgraded-sprysocks-for-windows-8368.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/>)

Author: ESET Research

Published: 2026-06-16T08:54:04Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [china](<https://devfeed.tech/tags/china.md>), [communication](<https://devfeed.tech/tags/communication.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [government](<https://devfeed.tech/tags/government.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET reports two previously undocumented Windows variants of the SprySOCKS backdoor attributed to FishMonger. The variants use TCP, UDP, and WebSocket communications; WIN_DRV uses a kernel driver to conceal artifacts and redirect specially crafted TCP traffic.

### Source excerpt

ESET researchers have discovered SprySOCKS for Windows, FishMonger's backdoor weaponizing a kernel driver for advanced stealthiness

## ESET APT Activity Report Q4 2025-Q1 2026

DevFeed: [ESET APT Activity Report Q4 2025-Q1 2026](<https://devfeed.tech/articles/eset-apt-activity-report-q4-2025-q1-2026-8362.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/>)

Author: Jean-Ian Boutin

Published: 2026-05-28T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [china](<https://devfeed.tech/tags/china.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [iran](<https://devfeed.tech/tags/iran.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

ESET's report summarizes selected APT activity from October 2025 through March 2026, including China-aligned espionage, activity targeting government and strategic-technology entities, and changes in Iran-aligned activity during the war in Iran.

### Source excerpt

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

## Backdoored Cemu release linked to TanStack and Mistral supply chain campaign

DevFeed: [Backdoored Cemu release linked to TanStack and Mistral supply chain campaign](<https://devfeed.tech/articles/backdoored-cemu-release-linked-to-tanstack-and-mistral-supply-chain-campaign-8277.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/>)

Author: Martin McCloskey, Sebastian Obregoso, Rory McCune

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Python](<https://devfeed.tech/topics/python.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [payload](<https://devfeed.tech/topics/payload.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [github](<https://devfeed.tech/tags/github.md>), [linux](<https://devfeed.tech/tags/linux.md>), [payload](<https://devfeed.tech/tags/payload.md>), [python](<https://devfeed.tech/tags/python.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

A coordinated supply chain campaign compromised npm and PyPI packages and backdoored the official Cemu GitHub release. The malicious Linux AppImage reached nearly 20,000 users before detection, while investigation linked the payload across the affected ecosystems.

### Source excerpt

We investigate how a coordinated supply chain campaign that compromised npm and PyPI packages also backdoored the official Cemu Nintendo Wii U emulator GitHub release, reaching nearly 20,000 Linux users.

## PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

DevFeed: [PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale](<https://devfeed.tech/articles/pcpjack-cloud-worm-evicts-teampcp-and-steals-credentials-at-scale-8311.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/>)

Author: Alex Delamotte

Published: 2026-05-07T10:00:17Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [pcpjack](<https://devfeed.tech/topics/pcpjack.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [MongoDB](<https://devfeed.tech/topics/mongodb.md>), [Redis](<https://devfeed.tech/topics/redis.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [database](<https://devfeed.tech/tags/database.md>), [docker](<https://devfeed.tech/tags/docker.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pcpjack](<https://devfeed.tech/tags/pcpjack.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [redis](<https://devfeed.tech/tags/redis.md>), [security](<https://devfeed.tech/tags/security.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

SentinelLABS describes PCPJack as a credential-theft framework that spreads across exposed cloud infrastructure, removes TeamPCP-related artifacts, harvests credentials from cloud, container, developer, productivity, and financial services, and exfiltrates the data. The framework targets services including Docker, Kubernetes, Redis, MongoDB, and vulnerable web applications, with suspected monetization through fraud, spam, extortion, or resale of stolen access rather than cryptomining.

### Source excerpt

Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.

## Hugging Face and VirusTotal collaborate to strengthen AI security

DevFeed: [Hugging Face and VirusTotal collaborate to strengthen AI security](<https://devfeed.tech/articles/hugging-face-and-virustotal-collaborate-to-strengthen-ai-security-7557.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/virustotal>)

Author: Adrien Carreira; Bernardo Quintero

Published: 2025-10-22T00:00:00Z

Content type: article

Language: en

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [hugging face](<https://devfeed.tech/topics/hugging-face.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source Models & Datasets](<https://devfeed.tech/topics/open-source-models-datasets.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [ai-models](<https://devfeed.tech/tags/ai-models.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [hub](<https://devfeed.tech/tags/hub.md>), [hugging-face](<https://devfeed.tech/tags/hugging-face.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [partnerships](<https://devfeed.tech/tags/partnerships.md>), [security](<https://devfeed.tech/tags/security.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Hugging Face and VirusTotal are collaborating to continuously scan public model and dataset repositories on the Hugging Face Hub. The integration checks file hashes against VirusTotal intelligence without sharing raw file contents, providing malware detections, threat relationships, and related campaign context. Organizations can also use the checks in CI/CD and deployment workflows to reduce the risk of distributing malicious assets.

### Source excerpt

We're on a journey to advance and democratize artificial intelligence through open source and open science.