Security researchers have identified a sophisticated malware named CoffeeLoader, designed to download and execute additional payloads while evading security detection. The malware uses techniques including call stack spoofing and sleep obfuscation to bypass protection. CoffeeLoader, distributed via another malware family, SmokeLoader, also uses a packer named Armoury that executes code on a system’s GPU to hinder analysis in virtual environments.

Hackers Scanning From 24,000 IP’s to Gain Access to Palo Alto Networks
Researchers observed a significant increase in malicious scanning of Palo Alto Networks’ GlobalProtect VPN portals, with nearly 24,000 unique IP addresses targeting the systems. This