Multiple sophisticated malware campaigns have been identified targeting organizations and individuals across various regions, utilizing advanced loader techniques and evasion tactics. Notable threats include AuraStealer, a malware-as-a-service infostealer distributed via social media scams and cracked software, capable of stealing data from a wide range of browsers and applications, and employing anti-analysis features such as geolocation checks and virtual machine detection. CloudEyE, another malware-as-a-service downloader and cryptor, has seen a dramatic increase in detections, serving as a delivery mechanism for other malware like Rescoms, Formbook, and Agent Tesla, and leveraging multi-stage delivery tactics to avoid detection. Additionally, a commodity loader has been used in targeted email campaigns against manufacturing and government sectors, employing weaponized documents, steganography, and multi-layered evasion pipelines to distribute remote access trojans and infostealers.
The Tuoni C2 malware framework was used in a stealthy attack against a major U.S. real estate firm, utilizing AI-generated code, steganography, and memory-only execution to evade detection and maintain long-term access for credential theft and potential ransomware deployment. These campaigns highlight a trend toward modular, evasive malware delivery systems that leverage commodity loaders, steganography, and malware-as-a-service models, enabling threat actors to efficiently compromise targets while minimizing forensic footprints. Security researchers emphasize the need for advanced detection and prevention strategies to counter these evolving threats, as traditional security layers are increasingly bypassed by modern malware techniques.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers published technical analysis of AuraStealer, a malware-as-a-service infostealer for Windows that steals data from browsers, applications, extensions, and cryptocurrency wallets. The report described its anti-analysis features, customizable theft options, underground promotion, and recent expansion from Russian-only to English language support.
Researchers identified a targeted email campaign against manufacturing and government organizations in Italy, Finland, and Saudi Arabia using a shared commodity loader. The attacks delivered RATs and information stealers through weaponized Office files, SVGs, and ZIP/LNK chains with steganography and fileless execution techniques.
Morphisec Threat Labs discovered a sophisticated intrusion targeting a major U.S. real estate company using the Tuoni command-and-control framework. The malware used AI-generated code, steganography, and memory-only execution to steal credentials, maintain persistence, and prepare for possible ransomware deployment while evading detection for weeks or months.
ESET Research observed more than 100,000 CloudEyE detections in the second half of 2025 and reported a thirtyfold increase in activity within six months. The malware was used to distribute payloads including Rescoms, Formbook, and Agent Tesla.
Businesses across Central and Eastern Europe were targeted in September and October 2025 by localized phishing emails delivering the CloudEyE malware-as-a-service downloader and cryptor. The messages often impersonated routine business communications and sometimes came from compromised legitimate business accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.