Skip to content

project

VirusTotal

VirusTotal, part of Google, scans submitted files and URLs against dozens of antivirus engines and offers threat-intelligence and hunting tools.

Known aliases

  • VirusTotal Intelligence
  • VirusTotal Livehunt
  • VT

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

Fake Zoom installer talks macOS users past Gatekeeper to drop CloudSyncD backdoor

Jamf Threat Labs reported CloudSyncD, a new macOS backdoor that spreads through a fake Zoom installer and beacons to its server every 8 to 16 seconds. First caught as a VirusTotal sample that looked unfinished, it now appears in builds that connect to live infrastructure in what Jamf calls an active campaign.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 70%
Investor
Investor 5%

Reality

Evidence70
Adoption15
Hype gap+15
Incentives
Insufficient
Confidence68
security3 publishers

Card-present fraud without the card: WindRelay relays NFC from the victim's own phone

Group-IB says a 13-minute call ended with a loan in the victim's name and card data streaming to a fake merchant terminal, every transaction approved with the victim's own PIN.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 63%
Investor
Investor 10%

Reality

Evidence62
Adoption20
Hype gap+10
Incentives40
Confidence65
security3 publishers

SLEEPWALKER: a backdoor that ships its own 23-instruction language, and nothing to block until it wakes

Dominik Reichel's write-up describes a passive Windows implant with no listening port and no embedded payload. Recovering its AES key still leaves you holding bytecode for an interpreter only it understands.

Publishers:r136a1.devscworld.comthehackernews.com

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 52%
Investor
Investor 5%

Reality

Evidence58
Adoption10
Hype gap+6
Incentives35
Confidence68

Earlier coverage

  1. RevStealer spread via fake free Claude Opus 5 desktop build on GitHub

    Security · September 1, 2026 · 2 publishers

  2. Georgia Tech found malware could move money unassisted in 35 of 159 banking apps it tested

    Invest · August 27, 2026 · 1 publisher

  3. Unit 42 counted 405 AI malware samples. Twelve reached a real endpoint.

    Science · August 27, 2026 · 1 publisher

  4. A fake internet, not a tighter cage: catching a trojan that waits for DNS

    Build · August 25, 2026 · 1 publisher

  5. PavinLoader: the lures keep changing, the MSBuild stage does not

    Security · August 24, 2026 · 1 publisher

  6. PyInstaller exits zero, then the real work starts: notarization traps that report success

    Build · August 21, 2026 · 1 publisher

  7. Exposed MCP servers are now a scanned entry point, and N4D's agent calls the tools itself

    Science · August 21, 2026 · 1 publisher

  8. ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload

    Security · August 20, 2026 · 2 publishers