Find notable cyber news and cases, enriched with sources, timelines, and signals.

GRIMWEDGE JavaScript backdoor with persistent C2 polling

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The GRIMWEDGE JavaScript backdoor is being deployed with a persistent C2 loop, giving operators host reconnaissance, file and process management, command execution, and payload delivery on compromised systems. It polls ocr.opusaccel[.]top for instructions and executes them in memory via eval(). The activity increases the risk of follow-on tooling and deeper hands-on-keyboard abuse after the initial foothold.

Related Happenings

ErrTraffic and Cruciferra ClickFix BYOVD malware activity

Malware Activity
H score72 First: 20.08.2026 20:23 Last: 20.08.2026 20:23 Sources 1

About this happening: The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....

Google DeepMind launches Gemini 3.5 Flash Cyber via CodeMender for vulnerability discovery and patching

Security Tool/Service
H score26 First: 21.07.2026 18:09 Last: 21.07.2026 18:09 Sources 1

About this happening: Google DeepMind released Gemini 3.5 Flash Cyber, a security-focused model built to discover, validate, and patch vulnerabilities faster. The capability is being delive...

ClickLock ClickFix macOS targeting campaign

Campaign
H score33 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...

DEEP#DOOR Python backdoor framework

Malware Activity
H score28 First: 30.04.2026 15:36 Last: 30.04.2026 15:36 Sources 1

About this happening: DEEP#DOOR is a newly disclosed Python-based backdoor framework that can keep persistent access to compromised Windows hosts while stealing browser, SSH, and cloud cred...

Transparent Tribe AI-assisted implant campaign targeting India

Campaign
H score32 First: 06.03.2026 17:11 Last: 06.03.2026 17:11 Sources 1

About this happening: Transparent Tribe (APT36) is running an evolving campaign that now includes PATCHCORD and SHEETCORD alongside earlier AI-assisted implants. The newer activity targ...

Latest development: 13.08.2026 18:00

Transparent Tribe, assessed with moderate confidence as APT36, is targeting Afghan telecom providers, Indian government IT networks, and South Asian critical infrastructure with PATCHCORD and SHEETCORD. The implants are delivered through fake Afghan Telecom lures, Telecom_TMS.zip, and nic-support[.]site, then use browser-shortcut hijacking or the Windows Startup folder for persistence, Google Sheets or GitHub Gists for C2, and infrastructure tied to CVE-2024-6387 exploit material.

Timeline

  1. 15.09.2026 08:31 1 articles · 2h ago

    Spear-phishing campaign deploys GRIMWEDGE against multiple NGOs

    Campaign Scope Update

    A Chinese threat actor targeted multiple non-governmental organizations with spear-phishing emails that used a reflected XSS redirect from a U.S.-based university website into a multi-stage Chrome-Windows exploit chain, delivering the GRIMWEDGE JavaScript backdoor on September 1, 2026.

    Show sources
  2. 15.09.2026 08:31 2 articles · 2h ago

    GRIMWEDGE polls ocr.opusaccel[.]top for in-memory commands

    Technical Analysis Update

    GRIMWEDGE enters a persistent command loop that polls ocr.opusaccel[.]top, receives instructions, and executes them in memory via eval(); the backdoor supports host reconnaissance, file and process management, directory operations, command execution, and payload delivery on compromised Windows hosts.

    Show sources