Jul 25, 2025
Cyware Daily Threat Intelligence, July 25, 2025
A browser tweak here, a fake mod there, and suddenly your crypto wallet spills its secrets. In a new campaign, the Scavenger trojan exploits DLL Search Order Hijacking to infiltrate password managers and wallets like MetaMask, Bitwarden, and Exodus. Delivered via fake game mods and malicious sites, the trojan uses multi-stage loaders and obfuscation.
Not every scam needs sophistication, sometimes all it takes is a lonely heart and a convincing profile picture. SarangTrap, a massive mobile spyware campaign, is luring victims on Android and iOS through fake dating apps. With over 250 malicious APKs and nearly 90 phishing domains, the campaign uses emotional manipulation and search engine indexing to appear credible.
Fire Ant doesn’t crash through the front door, it slips in quietly, sets up shop, and rewires the building. This advanced China-linked actor is targeting VMware ESXi and vCenter servers using old vulnerabilities to establish espionage footholds. The attackers extract credentials, deploy stealthy backdoors, and tamper with logs to stay hidden.