SECURITY Affairs’ MALWARE NEWSLETTER ROUND 117, published on 04 October 2026, compiles a curated set of malware-related research and threat intelligence from across the international landscape. The feature highlights a slate of recent analyses and disclosures, spanning information stealers, ransomware, backdoors, and attacker techniques.
Notable items include Lunex Unmasked, described as a new information stealer deployed through BYOVD, and Storm-3168, which discusses agentic-driven cloud attacks that leverage compromised service principals. The round also points to TraderTraitor backdoors resurfacing on victims without crypto ties, a malicious npm campaign named PhantomSub that secretly adds users to WhatsApp spam channels, and Warlock ransomware continuing to exploit older SharePoint flaws to target critical infrastructure.
Additional items explore the delivery and execution of payloads via AI-assisted and API-centric attack chains, including demonstrations of backdoors and RATs via AI or GPT-based workflows.
The roundup then surfaces further research and developments, such as CloudSyncD—a two-stage macOS backdoor that hides a phished password in zero-width Unicode—and other prominent notes on malware delivery techniques, phishing refinements, and security advisories. The newsletter functions as a digest of recent security research and incident patterns, linking to in-depth analyses from vendors and researchers.
Readers are invited to follow the cited sources for full technical details and evidence behind each claim, with the publication emphasising the ongoing evolution of malware ecosystems and the need for vigilant monitoring of new attack vectors and supply-chain compromises.