Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Anthropic Claude Opus 5 on AWS boosts cybersecurity capabilities
July 27, 2026
Critical WalletService Flaw (CVE-2024-XXXX) Lets Attackers Control Windows Systems
July 27, 2026
Top 10 Malware Threats Observed July 20-26, 2026
July 27, 2026
Home/CyberSecurity News/Top 10 Malware Threats Observed July 20-26, 2026
CyberSecurity News

Top 10 Malware Threats Observed July 20-26, 2026

Key Takeaways Information stealers and Remote Access Trojans (RATs) continue to dominate the threat landscape, driven by accessible Malware-as-a-Service (MaaS) offerings. Vidar, AsyncRAT, and XWorm...

David kimber
David kimber
July 27, 2026 7 Min Read
2 0

Key Takeaways

  • Information stealers and Remote Access Trojans (RATs) continue to dominate the threat landscape, driven by accessible Malware-as-a-Service (MaaS) offerings.
  • Vidar, AsyncRAT, and XWorm were the most frequently observed malware families, with XWorm and Formbook showing increased activity.
  • Phishing remains the primary infection vector, often leveraging legitimate infrastructure and “living off the land” binaries (LOLBins) to bypass traditional defenses.
  • Key vulnerabilities exploited include CVE-2017-11882 in Microsoft Equation Editor and CVE-2025-8088 in WinRAR.
  • Organizations must implement layered security, including robust email filtering, patch management, process monitoring, and user behavior controls, to mitigate these pervasive threats.

Overview of Malware Trends: July 20-26, 2026

The latest analysis of malware submissions to public sandboxes reveals a consistent pattern in the tools most frequently encountered by cybersecurity professionals. This week’s data, spanning July 20-26, 2026, highlights the persistent threat posed by information stealers and Remote Access Trojans (RATs), underscoring the widespread availability and utility of Malware-as-a-Service (MaaS) offerings in the cybercriminal underground.

Table Of Content

  • Key Takeaways
  • Overview of Malware Trends: July 20-26, 2026
  • Top 10 Malware Families by Uploads (July 20-26, 2026)
  • Threat Family Profiles
  • Vidar Stealer
  • AsyncRAT
  • XWorm
  • Remcos RAT
  • Stealc
  • Lumma Stealer
  • Formbook
  • Quasar RAT
  • AgentTesla
  • DonutLoader
  • Known Infection Vectors
  • Known Tools and Living-off-the-Land Binaries Abused
  • Targeted Industries
  • Common Vulnerabilities Exploited (CVEs)
  • Indicators of Compromise (IOCs)
  • File Hashes
  • Malicious Domains and URLs
  • IP Addresses

Info-stealers such as Vidar, Stealc, and Lumma, alongside RATs like AsyncRAT, XWorm, Remcos, and Quasar, constitute the majority of observed threats. This dominance reflects a market where sophisticated malicious capabilities are readily accessible, enabling a broad range of cyberattacks.

Vidar led the weekly rankings with 235 total uploads, despite a decrease of 47 samples from the previous period. AsyncRAT was a close second, registering 214 uploads, a reduction of 60. Conversely, XWorm saw a notable uptick with 205 uploads, marking a rare weekly increase of 13 samples, which suggests renewed or expanded campaign activity.

Formbook and XWorm were the only malware families to exhibit an upward trend in upload counts this week. This rise is a critical indicator for defenders, as increasing submission rates often precede a surge in active campaigns exploiting new vulnerabilities or employing novel lures.

In contrast, AgentTesla and DonutLoader experienced the most significant declines, with 59 and 58 fewer samples, respectively. Despite these drops, both families remain prevalent components of commodity phishing kits, indicating their continued use in initial access operations.

Top 10 Malware Families by Uploads (July 20-26, 2026)

Rank Malware Family Type Total Uploads Weekly Change
1 Vidar Infostealer 235 -47
2 AsyncRAT RAT 214 -60
3 XWorm RAT 205 +13
4 Remcos RAT/Surveillanceware 158 -36
5 Stealc Infostealer 126 -44
6 Lumma Infostealer 121 -21
7 Formbook Infostealer 113 +41
8 Quasar RAT 109 -6
9 AgentTesla Infostealer/Keylogger 108 -59
10 DonutLoader Loader 99 -58

Threat Family Profiles

Vidar Stealer

Vidar, an information stealer derived from Arkei, operates as a malware-as-a-service (MaaS) offering. Its primary function is to harvest sensitive data, including browser credentials, cookies, two-factor authentication information, Tor Browser configurations, and cryptocurrency wallet details. Recent campaigns in 2026 have seen Vidar distributed through malvertising, leading to fake cracked-software downloads, and via trojanized GitHub repositories masquerading as legitimate developer tools. The payloads are often cleverly embedded within JPEG and TXT files for in-memory execution. A notable parallel campaign involves Vidar being delivered alongside the XMRig cryptominer, employing DLL sideloading through a Go-compiled fake MpClient.dll to evade detection.

AsyncRAT

AsyncRAT is a widely exploited open-source Remote Access Trojan (RAT) that enables adversaries to execute commands remotely, exfiltrate data, and conduct covert surveillance on Windows systems. Current campaigns abuse legitimate infrastructure, such as Dropbox links and TryCloudflare tunnels. The infection chain typically initiates with an LNK file, followed by JavaScript and batch scripts that ultimately deploy Python-based loaders while displaying a deceptive invoice PDF. Persistence is achieved via startup-folder batch scripts and code injection into explorer.exe. Regional campaigns have observed C2 traffic utilizing TCP ports 6606, 7707, and 8808.

XWorm

XWorm is a modular RAT, available through MaaS channels since 2022, offering a range of malicious capabilities including credential theft, keylogging, webcam access, DDoS attacks, and ransomware deployment plugins. The 2026 infection chain typically starts with phishing emails containing ZIP attachments, often disguised as payment confirmations. These attachments extract a malicious JavaScript loader that establishes persistence in the Startup folder and retrieves a Base64-encoded DLL appended to a JPEG file hosted on public image services. The payload is then injected into MSBuild.exe or Aspnet_compiler.exe via process hollowing for fileless execution. Newer variants have been observed exploiting the WinRAR flaw CVE-2025-8088 and CVE-2018-0802 in Excel to bypass detection.

Remcos RAT

Initially a legitimate remote administration tool, Remcos has been extensively misused as a surveillance-as-a-service RAT. Its capabilities include live webcam streaming, real-time keylogging, credential theft, and screen capture. The primary infection vector remains phishing emails containing malicious ZIP or LNK attachments, followed by text-based staging and the abuse of legitimate Microsoft Living-off-the-Land Binaries (LOLBins) like MSBuild.exe to evade detection. Education, professional services, and finance sectors in Latin America (Colombia, Brazil) and the U.S. are the most frequent targets, with C2 traffic often routed through Dynamic DNS providers such as DuckDNS. Additional insights into Remcos’ evolution can be found in Lumu’s analysis.

Stealc

Stealc is a modular, MaaS infostealer designed to target a wide array of sensitive data, including information from browsers, FTP clients, messaging applications, email clients, gaming platforms, and cryptocurrency wallets. Its V2 iteration introduced RC4 encryption for stolen data, enhancing its stealth. It propagates through various channels, including phishing attachments, malvertising, drive-by downloads, and compromised cracked software/keygen sites. Stealc is frequently observed bundled with other cybercrime services, such as Amadey.

Lumma Stealer

Lumma (LummaC2), a subscription-based MaaS infostealer, has re-emerged with more sophisticated tactics following a law enforcement takedown of its core infrastructure. Current delivery methods include deceptive CAPTCHA “ClickFix” pages that trick victims into executing malicious PowerShell commands via the Windows Run dialog. Other vectors involve trojanized GitHub repositories featuring AI-generated README files promoting game cheats, and coordinated YouTube video campaigns linking to malicious downloads. Trend Micro provides further details on Lumma Stealer’s return.

Formbook

Formbook is a long-standing data stealer and form-grabber, sold as MaaS since 2016. It offers capabilities such as keylogging, screenshot capture, credential theft, and the ability to stage additional malware. Recent campaigns leverage phishing emails with RAR attachments that abuse DLL sideloading, or obfuscated JavaScript embedded in PDFs. Older campaigns exploited CVE-2017-11882 in Microsoft Equation Editor through malicious Word documents. Aerospace, defense contractors, and manufacturing sectors in the U.S. and South Korea have been disproportionately targeted. More information on Formbook campaigns is available from Google Cloud.

Quasar RAT

Quasar is an open-source, C#-based RAT that provides attackers with extensive remote control over compromised systems, including registry editing, keylogging, password theft, and file exfiltration. It is commonly delivered via malicious RTF or Office documents that trigger PowerShell payload downloads. Newer variants utilize dual DLL sideloading techniques to drop and execute payloads without triggering standard detection mechanisms.

AgentTesla

AgentTesla is a .NET-based RAT and advanced keylogger that has been active since 2014. Its functionalities include clipboard logging, screen capture, and the theft of stored browser and email credentials. It is primarily delivered through phishing emails that exploit Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2017-8570. Exfiltrated data is typically sent via SMTP, FTP, or Telegram bot channels.

DonutLoader

DonutLoader is a shellcode-based loader that utilizes the “Donut” fileless execution framework to deploy secondary payloads, such as the PureLogs stealer, directly into memory. This approach helps avoid disk-based artifacts, enhancing stealth. Recent campaigns have employed “ClickFix”-style spoofed licensing websites, tricking victims into executing malicious PowerShell commands. These actions establish TCP-based C2 communications for data exfiltration and configuration retrieval. Further details on the Canndelta ClickFix campaign are available from Gurucul.

Known Infection Vectors

Phishing remains the most pervasive common denominator across all ten malware families, though the specific lures and payload staging techniques vary significantly depending on the malware family.

Infection Vector Malware Families Using It
Phishing email with ZIP/RAR archive attachment AsyncRAT, XWorm, Remcos, Formbook
Malicious Office document (macro/exploit) AgentTesla, Quasar, Formbook, Snake Keylogger
Malvertising / fake cracked software Vidar, Stealc, Lumma
Trojanized GitHub repositories Vidar, Lumma
Fake CAPTCHA / ClickFix PowerShell execution Lumma, DonutLoader
LNK/JS/BAT multi-stage script chains AsyncRAT, XWorm
PDF or image (JPEG) steganographic payloads XWorm, Vidar
Dropbox/TryCloudflare abused infrastructure AsyncRAT

Known Tools and Living-off-the-Land Binaries Abused

Threat actors are increasingly leveraging legitimate, signed Windows utilities, known as Living-off-the-Land Binaries (LOLBins), to camouflage malicious activities within normal system operations and bypass signature-based detection.

  • MSBuild.exe: Abused by XWorm and Remcos for reflective DLL injection and payload execution.
  • Aspnet_compiler.exe: Utilized by XWorm for in-memory reflective DLL injection, as detailed by Trellix research.
  • PowerShell (-nop, -ep bypass): Employed across XWorm, DonutLoader, and Lumma ClickFix chains for staged payload decryption and execution.
  • wscript.exe / mshta.exe: Used to trigger JavaScript and HTA loaders in XWorm and Remcos campaigns.
  • RegAsm.exe / RegSvcs.exe / InstallUtil.exe: Abused via process hollowing/injection by AgentTesla and Snake Keylogger.
  • explorer.exe: A target for code injection in AsyncRAT campaigns, as highlighted in Trend Micro’s analysis.
  • Python interpreter (legitimate installer): Deployed by AsyncRAT operators to run malicious scripts under a trusted runtime. Further details can be found in Trend Micro’s MDR analysis.
  • Donut shellcode framework: Leveraged by DonutLoader for fileless, in-memory .NET assembly loading, as discussed by Gurucul.

Targeted Industries

Industry Malware Families Observed Notes
Education & nonprofits Remcos Underfunded IT security, high-value data. See Lumu’s report.
Financial services Remcos, AgentTesla Credential and wire-fraud targeting. More insights from Lumu.
Aerospace & defense contractors Formbook High-value IP theft campaigns in US/South Korea. Referenced by Google Cloud.
Manufacturing Formbook Targeted via archive-based phishing. Additional information from Google Cloud.
Retail & hospitality Snake Keylogger Payment card and loyalty credential theft. RH-ISAC provides details.
Professional services & technology Remcos, Stealc MaaS-driven credential harvesting.
Government (regional) AsyncRAT, general loaders Hijacked government sites used as delivery channels.
SMBs and consumer users Vidar, Lumma, Stealc Malvertising and cracked-software targeting broad consumer base.

Common Vulnerabilities Exploited (CVEs)

CVE Vulnerability Exploited By
CVE-2017-11882 Microsoft Equation Editor stack buffer overflow (RCE) AgentTesla, Formbook
CVE-2017-8570 Microsoft Office RCE via OLE object AgentTesla
CVE-2018-0802 Microsoft Office Equation Editor memory corruption XWorm
CVE-2025-8088 WinRAR path traversal leading to arbitrary code execution XWorm

Beyond these documented CVEs, most malware families rely on social engineering and the abuse of legitimate tools rather than novel zero-day exploits. This trend emphasizes that patch management alone is insufficient; robust user-behavior controls and strict macro/script restrictions are equally crucial for effective defense.

Indicators of Compromise (IOCs)

File Hashes

Malware Hash Type Value
AsyncRAT SHA1 (zip) 55724b766dd1fe8bf9dd4cb7094b83b88d57d945
AsyncRAT SHA1 (url) 4483561a49791a7cd684258e9f1623fe7dfba772
AsyncRAT SHA1 (lnk) 0aa1b8fba8d7bd19a0064edfdf86c027da253644
XWorm MD5 (weaponized archive) 2074283c9ccc441185cba631fcc8a234
Stealc MD5 (sample) 9f34ab1c9d9351f59826b8d5c458a3d3
Quasar SHA-256 cf7a24c9f2f9d85cc1ba4a11890087b82e38f39c8d194e808e9e6d82a188d3f0
Quasar SHA-256 14b573b7e3ff8ad4e1489a5c039532f16f9eff34ead1d299f97fb0badf0affdc
Formbook SHA1 (MalVirt loader) 15DB79699DCEF4EB5D731108AAD6F97B2DC0EC9C
Formbook SHA1 (0onfirm .NET assembly) 655D0B6F6570B5E07834AA2DD8211845B4B59200
Formbook SHA-256 (order0087.docx) 93CF566C0997D5DCD1129384420E4CE59764BD86FDABAAA8B74CAF5318BA9184
AgentTesla MD5 (VBS file) e2a4a40fe8c8823ed5a73cdc9a8fa9b9
AgentTesla SHA256 (VBS file) e7a157ba1819d7af9a5f66aa9e161cce68d20792d117a90332ff797cbbd8aaa5
AgentTesla MD5 (final payload) dd94daef4081f63cf4751c3689045213
AgentTesla MD5 (COVID doc sample) 527142E25A8229D1DC910AF23CDB5256
DonutLoader SHA-256 0099deccd390e229895d0c508882632569f9533e42d33a675885ee7f4f5164f3
DonutLoader SHA-256 61b453cfedc6c67d9744b963bc3cabbee33f53606fdbf80da04bc3d4c93eb4fb
DonutLoader SHA-256 9bb96fa6aee45120d14660506320932691310adef4353e684775f590a17c22fc
Snake Keylogger MD5 c79d8b7c07b992c6aa435e4101770f99
Snake Keylogger MD5 (ageless.exe) f8410bcd14256d6d355d7076a78c074f
Snake Keylogger MD5 (ageless.vbs) 77f8db41b320c0ba463c1b9b259cfd1b
Quasar (ISO sample) MD5 e4eb623a0f675960acb002d225c6f1d6
Quasar (eBill loader) MD5 B625C18E177D5BEB5A6F6432CCF46FB3

Malicious Domains and URLs

Malware Domain / URL
AsyncRAT inventory-card-thumbzilla-ip[.]trycloudflare[.]com
AsyncRAT mercy-synopsis-notify-motels[.]trycloudflare[.]com/ma[.]zip
AsyncRAT sufficiently-points-est-minimize[.]trycloudflare[.]com/ma[.]zip
AsyncRAT (regional) ck44jili[.]com, mail.emb666[.]com
XWorm kolanga[.]cc
Remcos Nrmlogistics[.]ro (loader)
Remcos Dentalux202[.]ydns[.]eu (C2)
Lumma futureddospzmvq[.]shop, writerospzm[.]shop, mennyudosirso[.]shop
Lumma deallerospfosu[.]shop, quialitsuzoxm[.]shop, complaintsipzzx[.]shop
Formbook www.togsfortoads[.]com, www.popimart[.]xyz
Snake Keylogger varders[.]kozow[.]com:8081, aborters[.]duckdns[.]org:8081
Snake Keylogger anotherarmy[.]dns[.]army:8081
DonutLoader canndelta[.]com
DonutLoader 158.94.208.104/x7GkP2mQ9zL4/my_new_l.bin
Formbook (image relay) www2[.]0zz0[.]com/2025/02/02/10/709869215.png

IP Addresses

Malware IP Address
XWorm 204.10.160.190 (C2, TCP port 7003)
Remcos 107.172.139.23, 193.230.215.22, 94.198.96.165
Lumma 144.76.173[.]247, 45.9.74[.]78, 77.73.134[.]68
Lumma 82.117.255[.]127, 82.118.23[.]50
AgentTesla 79.110.48[.]52, 193.42.33.51
Snake Keylogger 89[.]208[.]29[.]130, 69[.]55[.]5[.]

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEExploitMalwarePatchphishingransomwareSecurityThreatVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Claude AI Vulnerability Exposes Local Files to Malicious Repositories

Next Post

Critical WalletService Flaw (CVE-2024-XXXX) Lets Attackers Control Windows Systems

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Windows 11 File Explorer Speeds Up Large File Deletions
July 27, 2026
SparkKitty Malware Steals Crypto Seed Phrases From iOS and Android Photos
July 27, 2026
Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
July 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us