Category: Viruses

  • Malware in the Open Source Supply Chain Is Now the Default

    Malware in the Open Source Supply Chain Is Now the Default

    The malicious npm package, the typosquatted PyPI release, the compromised Docker image. The pattern has matured. The frequency has increased. The defence has not kept up.

  • Modern Phishing as a Service Is Boring (And That Is Why It Works)

    Modern Phishing as a Service Is Boring (And That Is Why It Works)

    Phishing in 2026 is not a clever technical exploit. Phishing in 2026 is a service industry, a well oiled business, and the most reliable way into a corporate network. Here is why it works.

  • The Incident Responder’s Playbook When Malware Hits

    The Incident Responder’s Playbook When Malware Hits

    The first 60 minutes of a malware incident decide the next 60 days. Here is what the responder actually does, in order, with the tooling that holds up under pressure.

  • Wipers, Not Ransomware, Are the New Normal

    Wipers, Not Ransomware, Are the New Normal

    Picture the standard ransomware playbook. Attacker breaches the network, encrypts the data, posts the ransom note. Victim pays, gets the decryption key, restores, files the insurance claim, moves on. That last part is the part that is breaking. A growing share of attackers are taking the ransom and refusing to hand over the key. The…

  • What a Modern Remote Access Trojan Actually Does

    What a Modern Remote Access Trojan Actually Does

    The RAT has changed. The 2015 RAT was a toy. The 2026 RAT is a mature criminal product with persistence, evasion, and operator UX. Here is what is actually running on the compromised endpoint.

  • The Loader Economy: How Initial Access Brokers Work

    The Loader Economy: How Initial Access Brokers Work

    The loader economy is the supply chain of ransomware. Initial access brokers buy the footholds, sell the footholds, and let the ransomware crews focus on the encryption. Here is how it works in 2026.

  • Ransomware Double Extortion Has Stopped Working

    Ransomware Double Extortion Has Stopped Working

    Double extortion ransomware was the dominant pattern from 2020 to 2024. The attacker encrypted the data and exfiltrated a copy, the victim paid the ransom to get both the decryption key and the non disclosure. By 2026 the pattern has stopped working, for three reasons that have less to do with the attacker and more…

  • The State of Viruses in 2026: A Clear-Eyed Look at Modern Malware

    The State of Viruses in 2026: A Clear-Eyed Look at Modern Malware

    Around 450,000 new malicious programs are detected every day. That number has been roughly stable for three years. What is changing is the distribution.