FortiGuard Labs Threat Research

FortiGuard Labs Threat Research

Malicious NPM Packages Targeting PayPal Users

FortiGuard Labs has recently discovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. Learn more.

By Jenna Wang April 11, 2025

FortiGuard Labs Threat Research

RolandSkimmer: Silent Credit Card Thief Uncovered

FortiGuard Labs recently observed a new wave of credit card skimming attacks leveraging malicious browser extensions across Chrome, Edge, and Firefox. Learn more.

By Cara Lin April 02, 2025

FortiGuard Labs Threat Research

Real-Time Anti-Phishing: Essential Defense Against Evolving Cyber Threats

FortiGuard Labs reveals critical insights into the nature of recent phishing trends. Learn more.

FortiGuard Labs Threat Research

Fortinet Identifies Malicious Packages in the Wild: Insights and Trends from November 2024 Onward

FortiGuard Labs analyzes malicious software packages detected from November 2024 to the present and has identified various techniques used to exploit system vulnerabilities. Learn more.

By Jenna Wang March 10, 2025

FortiGuard Labs Threat Research

Havoc: SharePoint with Microsoft Graph API turns into FUD C2

ForitGuard Lab reveals a modified Havoc deployed by a ClickFix phishing campaign. The threat actor hides each stage behind SharePoint and also uses it as a C2. Learn more.

By Yurren Wan March 03, 2025

FortiGuard Labs Threat Research

Winos 4.0 Spreads via Impersonation of Official Email to Target Users in Taiwan

FortiGuard Labs uncovers an attack targeting companies in Taiwan with WinOS4.0 that spreads via official email impersonation. Learn more.

By Pei Han Liao February 27, 2025

FortiGuard Labs Threat Research

FortiSandbox 5.0 Detects Evolving Snake Keylogger Variant

Explore how FortiSandbox 5.0 detected this malware, the behavioral indicators it leveraged for identification, and Snake Keylogger's technique to evade detection and analysis.

By Kevin Su February 18, 2025

FortiGuard Labs Threat Research

Ransomware Roundup – Lynx

Get insights into the Lynx ransomware, which is considered the successor to the INC ransomware. This double-extortion ransomware has threatened more than 90 organizations worldwide, including those in the healthcare and energy sectors. Learn more.

By Shunichi Imano and Fred Gutierrez February 14, 2025

FortiGuard Labs Threat Research

Analyzing ELF/Sshdinjector.A!tr with a Human and Artificial Analyst

FortiGuard Labs reverse engineers a malware’s binaries to look into what the malware is actually doing.

By Axelle Apvrille February 04, 2025

FortiGuard Labs Threat Research

Coyote Banking Trojan: A Stealthy Attack via LNK Files

FortiGuard Labs observes a threat actor using a LNK file to deploy Coyote attacks, unleashing malicious payloads and escalating the risk to financial cybersecurity.

By Cara Lin January 30, 2025