hacker-news · Crawled Jul 23, 2026

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

5 IoCs 4 Malware
Read original article ↗

AI Summary

Recent cyber threats include malicious npm and PyPI packages delivering infostealers, counterfeit VS Code extensions exfiltrating machine data, and Android spyware disguised as legitimate safety apps. Iranian-affiliated actors are targeting PLC systems in critical infrastructure, while attackers leverage AI models for prompt injection and malware development. Campaigns also involve malvertising distributing SectopRAT and MarkiRAT, DNS tunneling by TrickBot for C2 communication, and exploitation of trust in legitimate platforms to deliver malware.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 5 extracted

Type Value Detail
Package @copilot-mcp/apex Details →
Package @apexfdn/apex Details →
Filename ClaudeDesktop.exe Details →
Domain attacker-controlled domain Details →
IP hardcoded IP Details →

MITRE ATT&CK TTPs 15 techniques