Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Analysis of BlueShell Variants Used by APT Groups

released on 2026-07-29 @ 08:57:16 AM
BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.

Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

released on 2026-07-29 @ 08:57:14 AM
Unknown threat actors distributed malicious downloader functionality across multiple npm packages targeting users of Alibaba tools. The campaign used typosquatting tactics by creating unscoped packages impersonating private packages from Alibaba's @ali scope. Malicious functionality was split across a dependency chain including packages like lib-mtop, smart-config-manager, cloud-config-fetcher, and local-config-parser. The attack employed VM sandbox escape techniques and delivered a sophisticated cross-platform RAT capable of data exfiltration, command execution, and lateral movement through DingTalk collaboration tools. The campaign remained undetected for three months, suggesting possible account takeovers and coordinated publishing across multiple npm accounts in late April 2026, specifically targeting Chinese-speaking developers within Alibaba Group companies for industrial espionage purposes.

Shai-Hulud-Style npm Worm Hits

released on 2026-07-29 @ 08:57:14 AM
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity.

Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria

released on 2026-07-29 @ 02:59:35 AM
Since Q1 2026, an emerging botnet named Dysphoria has amassed over 200,000 compromised hosts through rapid technical iterations spanning jackskid and fbot variants. The botnet employs sophisticated blockchain-based command and control infrastructure using ENS and SNS domains, combined with a novel architecture that converts victim hosts into relay/proxy nodes. Dysphoria propagates primarily through Telnet/SSH credential brute-forcing and exploitation of IoT vulnerabilities. Its commercial operation offers tiered DDoS attack packages claiming up to 4 Tbps capacity, targeting victims globally across multiple industries. The botnet demonstrates advanced evasion techniques including modified RC4 encryption, UPnP NAT traversal, and dynamic C2 resolution mechanisms. Daily monitoring shows peak activity of 239,000 overseas bots and 1,801 domestic bots, with 740,000 daily C2 requests, confirming sustained high-volume malicious operations.

Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

released on 2026-07-29 @ 02:59:34 AM
Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.

ClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAV

released on 2026-07-29 @ 02:59:34 AM
A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection.

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

released on 2026-07-28 @ 09:18:54 PM
Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability.

Mirage Kitten targets Middle East and Africa region with new malware

released on 2026-07-28 @ 12:10:28 PM
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.

Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

released on 2026-07-28 @ 03:35:19 AM
Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core

released on 2026-07-28 @ 03:35:17 AM
Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.

AI-Native security platform

released on 2026-07-27 @ 04:59:18 PM
Between May and July 2026, security researchers deployed an unauthenticated Model Context Protocol (MCP) honeypot server to observe how threat actors exploit AI agent infrastructure. Of approximately 1,000 sources that reached the decoy, 596 spoke the protocol and 24 proceeded to actively exploit it. These operators executed 628 shell commands, 255 file reads, and 248 secrets-store lookups, with 19 hunting credentials and 4 attempting container escapes. Activity escalated from 39 tool calls in May to 877 by mid-July. Three stolen credentials were subsequently used against a live AWS account, with two cases involving Bedrock model invocation for LLMjacking. The attacks demonstrated automated reconnaissance, credential harvesting, container escape attempts, backdoor account creation, and Kubernetes enumeration, revealing that exposed MCP servers represent a growing attack surface as AI agent infrastructure proliferates.

Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

released on 2026-07-27 @ 04:45:15 PM
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

Fake Corepack Site Distributes Infostealer and Proxyware to Developers

released on 2026-07-25 @ 07:54:45 AM
A fraudulent website impersonating Corepack, the Node.js package manager tool, is distributing malware to developers. The attackers exploit timing around Corepack's removal from Node.js bundling, targeting developers searching for installation instructions. The site offers Windows executables that deliver OpenShield infostealer and proxyware, enrolling victim machines in bandwidth-sharing networks without consent. The payload steals browser credentials, SSH keys, establishes persistence, and routes third-party traffic through compromised systems. An alternative download path delivers adware and trojan components disguised as OperaGX installer. The site features AI-generated content with obvious errors, including confusing Yarn package manager with textile crafts. The domain has been reported to registrars for takedown after community members identified the threat.

Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

released on 2026-07-24 @ 09:40:32 PM
Check Point has released urgent security updates addressing three critical vulnerabilities affecting Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating systems. The most severe vulnerability, CVE-2026-16232, allows unauthenticated remote attackers to bypass SmartConsole login and gain full administrative access to exposed Management Servers. The vulnerability has been actively exploited against customers with internet-exposed management infrastructure. Successful exploitation enables attackers to modify firewall policies, create administrator accounts, weaken security protections, and establish persistent access. Two additional vulnerabilities were patched: CVE-2026-62144 enabling unauthenticated command execution, and CVE-2026-62145 allowing privilege escalation from read-only to root access. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog with an exceptionally short remediation deadline, reflecting the severity of this authentication bypass...

Security Advisory - Action Required - July 2026 Security Update

released on 2026-07-24 @ 02:24:56 PM
A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices.

June 2026 Threat Trend Report on APT Attacks (South Korea)

released on 2026-07-24 @ 12:34:40 PM
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

Ongoing PLC Exploitation Against Critical U.S. Infrastructure

released on 2026-07-24 @ 12:34:38 PM
Multiple federal agencies have updated a joint advisory warning of active exploitation targeting programmable logic controllers (PLCs) in U.S. critical infrastructure. Attackers scan for internet-exposed industrial control systems and connect using legitimate engineering software with valid credentials, appearing as authorized technicians. Once inside, they alter controller logic and manipulate operator displays to hide anomalies. The campaign has expanded beyond Rockwell Automation to include Schneider Electric and Siemens equipment. Unlike a similar 2023 campaign that caused minimal disruption, this ongoing activity has resulted in confirmed operational disruption and financial losses. Targeted sectors include government facilities, water systems, and energy infrastructure. The exploitation leverages architectural weaknesses rather than software vulnerabilities, with attackers accessing systems through ports 22, 102, 502, 2222, and 44818.

Intercom-client@7.0.4 Harvesting Github Credentials

released on 2026-07-24 @ 01:19:11 AM
The Intercom TypeScript Library version 7.0.4 has been compromised with malicious code that harvests GitHub credentials. Upon installation, the package executes a preinstall hook that downloads the Bun runtime, then runs a payload to extract GitHub credentials using the gh auth token command. The attack employs sophisticated C2 communication by querying GitHub's commit search API for specific strings embedded in public repositories, effectively using legitimate services to evade detection. The attack patterns mirror previous Shai-Hulud compromises, which exhibit worm-like behavior by automatically using stolen credentials to infect additional npm packages. With 361,510 weekly downloads, this compromise poses significant risk for a widespread infection wave similar to November 2025 when over 1,000 packages were affected.

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

released on 2026-07-23 @ 08:59:19 PM
Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

Upgrades MaaS Ecosystem with Modular Tools

released on 2026-07-23 @ 04:30:35 PM
Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.

Email threat landscape: Q2 2026 trends and insights

released on 2026-07-23 @ 04:30:34 PM
During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end.

Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

released on 2026-07-23 @ 04:30:34 PM
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

Zimbra Mailservers Targeted with Half-Click Exploits

released on 2026-07-23 @ 04:30:33 PM
Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

released on 2026-07-23 @ 04:25:24 PM
A large-scale campaign exploited GitHub Actions by compromising repositories to launch distributed attacks against cPanel and WHM servers. The operation began with compromised developer accounts, pushing malicious workflow files that executed on GitHub-hosted runners rather than through traditional package installation. These workflows downloaded Linux payloads from command-and-control infrastructure, scanned internet-facing systems, and exploited CVE-2026-41940 to harvest credentials including AWS keys, GitHub tokens, API credentials, database access, SSH materials, and cloud keys. The campaign affected approximately 6,100 to 16,000 workflow files across unrelated repositories, using ephemeral runners as disposable attack infrastructure. Stolen data was exfiltrated through HTTP POST requests with continuous heartbeat monitoring, enabling near-real-time visibility into exploitation operations across distributed infrastructure.

Global Webmail Espionage

released on 2026-07-23 @ 04:25:24 PM
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

A New Name in the Data Extortion Ecosystem?

released on 2026-07-23 @ 03:25:39 PM
A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

released on 2026-07-23 @ 11:57:14 AM
Cisco Talos discovered msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group. This sophisticated RAT never directly touches the network, instead controlling command-and-control communications exclusively through Chrome DevTools Protocol (CDP). It manipulates browsers via CDP, performs signaling with Cloudflare Workers, and establishes WebRTC DataChannels using Twilio TURN as a relay. The infection chain begins with downloading an MSI file containing the RAT payload. msaRAT hijacks Chrome or Edge browsers in headless mode, injects JavaScript code, and establishes encrypted C2 communications through WebRTC. This design makes all external communications appear to originate from legitimate browser processes, effectively hiding C2 traffic within normal web activity and evading detection by firewalls and network monitoring tools.

JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake

released on 2026-07-23 @ 11:57:14 AM
In mid-April 2026, an exposed directory on an Alibaba Cloud server revealed a comprehensive China-nexus operation targeting government, healthcare, and education sectors across Southeast Asia and Latin America. The investigation uncovered simultaneous intrusions against Vietnamese hospitals, the Malaysian Ministry of Foreign Affairs, Hong Kong educational institutions, and targets in Honduras and Venezuela. At the center is TriBack Loader, a custom malware family using DLL sideloading with signed binaries and Win32 callback APIs to deliver AdaptixC2 and Beagle backdoors. The exposed server contained post-exploitation toolkits, bash history, and victim paths, revealing ongoing operations. Infrastructure analysis showed consistent use of NameSilo registrations, Alibaba hosting, and Cloudflare fronting. Phishing campaigns included fake portals impersonating Venezuelan tax systems and Claude-Pro software. The operation demonstrates shared tooling common across Chinese APT groups, with TTPs overlapping multiple...

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

released on 2026-07-23 @ 07:30:51 AM
Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.

Exploitation in the Wild of wp2shell

released on 2026-07-23 @ 07:30:51 AM
A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

released on 2026-07-23 @ 12:27:49 AM
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

released on 2026-07-22 @ 07:55:39 PM
A newly discovered Windows stealer and remote access trojan called Dolphin X targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. The malware collects credentials ranging from browser logins to SSH keys, .env files, and cloud tokens. A distinctive feature called the AI Profiler automatically scores infected victims based on application usage, browsing activity, and installed software, helping attackers identify high-value targets through daily summaries. The malware builder operates through a remote server that compiles agents and offers optional mutation engines to evade detection. Advertised by a vendor using the alias Kontraktnik, Dolphin X poses significant risk to developers and organizations by potentially exposing access to entire production environments through compromised DevOps credentials.

Inside a TrickBot Variant Using DNS Tunneling for C2

released on 2026-07-22 @ 07:55:37 PM
A TrickBot variant has been identified that uses DNS tunneling for command-and-control communications instead of traditional HTTP protocols. The malware maintains persistence through Windows Task Scheduler, creating disguised tasks that execute at startup and repeat every five minutes. Configuration data is stored in NTFS Alternate Data Streams to evade detection. The malware employs multiple obfuscation techniques including encrypted strings, runtime API resolution via hash-based lookups, and dynamically calculated constants. Its modular architecture supports twelve different control commands enabling capabilities such as module downloads, process injection through hollowing and doppelgänging techniques, PowerShell execution, and raw machine code execution. The variant transfers data through specially crafted DNS queries to public DNS servers, encoding command data in malformed domain names and receiving responses embedded within multiple IPv4 addresses, achieving transfer speeds of approximately 30.7 KB/s.

Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign

released on 2026-07-22 @ 03:17:48 PM
A sophisticated phishing campaign impersonates legitimate business entities including UPS and the Malaysian Inland Revenue Board to distribute Phantom Stealer v3.5.0. The attack begins with convincing emails containing compressed archives housing malicious JavaScript files. Once executed, the JavaScript launches obfuscated PowerShell scripts that operate entirely in memory, deploying multiple stages of encrypted and encoded payloads. The infection chain utilizes Base64 encoding, AES encryption, and XOR ciphering to conceal its activities. The final payload, Phantom Stealer, harvests credentials from browsers, cryptocurrency wallets, messaging applications, and system information before exfiltrating stolen data via SMTP over port 587 using STARTTLS encryption. The multi-layered approach significantly reduces on-disk footprint and employs reflective code loading and process injection into legitimate binaries to evade traditional security defenses.

Inside a Global Procurement-Themed AiTM Phishing Campaign

released on 2026-07-22 @ 12:59:04 AM
A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.

Portugal-focused phishing campaign delivers multistage malware

released on 2026-07-21 @ 04:05:04 PM
An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims.

Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

released on 2026-07-21 @ 11:39:00 AM
VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

From E-Sign to RMM: DocuSign Kit Targets Windows and...

released on 2026-07-21 @ 11:38:34 AM
A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.

New Project CAV3RN .NET Native AOT communication module

released on 2026-07-21 @ 11:19:50 AM
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models

released on 2026-07-21 @ 12:05:23 AM
An advanced threat actor identified as JADEPUFFER has evolved its capabilities, now deploying ENCFORGE, a specialized ransomware targeting AI and ML infrastructure. The actor exploits CVE-2025-3248 in Langflow to gain initial access, then autonomously chains reconnaissance, credential harvesting, and lateral movement. ENCFORGE is a compiled Go binary targeting approximately 180 file extensions specific to AI/ML environments, including model checkpoints, vector databases, training datasets, and embedding indices. The ransomware uses AES-256-CTR with RSA-2048 encryption and cannot be recovered without the attacker's private key. Unlike traditional ransomware, encrypted AI models cannot simply be restored, as rebuilding production-ready models costs between $75,000 to $500,000 per model in compute and engineering time. The operation demonstrates sophisticated autonomous behavior, including real-time container escape toolkit construction when initial payload delivery failed, completing the escape mechanism in ...

Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

released on 2026-07-20 @ 07:44:31 PM
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.

HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels

released on 2026-07-20 @ 07:44:30 PM
A sophisticated espionage campaign has been identified leveraging malware that exploits Microsoft Graph API to transform compromised Microsoft 365 calendars into covert command-and-control infrastructure. The malware creates calendar events dated to 2050 with encrypted attachments to exfiltrate files and receive instructions. A secondary DNS tunneling channel using IPv6 AAAA records refreshes Microsoft Entra ID credentials for authentication. Communications are secured using hybrid RSA and AES-256-GCM encryption with separate key pairs for inbound and outbound channels. Twelve infected systems have been identified, primarily targeting Israeli entities, with only three actively communicating with attackers. The operation demonstrates high technical sophistication and disciplined targeting, suggesting a well-resourced adversary conducting focused espionage operations since at least June 2026.

Targeted Attack on Government Entities in the Middle East | Part 1

released on 2026-07-20 @ 07:29:47 PM
In July 2026, a threat actor with links to East Asia launched sophisticated attacks against government entities in the Middle East. The multi-stage campaign deployed previously undocumented malware including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses Telegram API for command-and-control communication to blend with legitimate traffic, while employing heavy code obfuscation techniques like control flow flattening and mixed boolean arithmetic. MIXEDKEY serves as a reflective loader that uses environmental keying by deriving decryption keys from the victim machine's volume serial number. The threat actor demonstrated advanced tradecraft through DLL sideloading, anti-analysis techniques including hypervisor detection and RAM speed checks, and careful staging to evade detection. Post-compromise activity revealed systematic reconnaissance and persistence establishment between July 7-9, 2026, with operations concentrated during East Asian working hours.

NadMesh Botnet Analysis: Product-Level Threat in the AI Services Era

released on 2026-07-20 @ 02:51:14 PM
In July 2026, a sophisticated Go-based botnet named NadMesh was discovered actively deploying across the internet. Unlike traditional worms, it integrates autonomous scanning, exploitation of 20+ vulnerabilities, and targeted harvesting of AI infrastructure credentials. The botnet specifically targets AI services including ComfyUI, Ollama, and MCP ecosystems using Shodan intelligence to prioritize high-value assets. It features a web-based control panel, multi-stage persistence mechanisms including SSH backdoors and cron watchdogs, and polymorphic builds using Garble obfuscation and UPX compression. The operation demonstrates product-grade engineering with automated feedback loops for task generation, honeypot avoidance, and credential extraction from cloud environments, Kubernetes clusters, and AI model services.

Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service

released on 2026-07-20 @ 09:36:09 AM
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.

Still Circling: Toolkit Keeps Evolving

released on 2026-07-18 @ 11:29:33 AM
Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.

Contagious Interview malware in SVG images: DPRK campaign

released on 2026-07-17 @ 08:08:00 PM
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

Botnet Analysis: A Product-Grade Threat for the AI Service Era

released on 2026-07-17 @ 11:27:49 AM
NadMesh is an industrial-grade Go-based botnet observed in July 2026 that autonomously scans and exploits AI infrastructure and cloud services. The botnet integrates scanning, exploitation, and intelligence harvesting into a single platform targeting over 90 cloud provider address ranges. It employs 20+ exploitation vectors against Redis, Docker, MCP, Kubernetes, and other services, with particular focus on AI platforms like ComfyUI, Ollama, and Gradio discovered via Shodan API. NadMesh features a web-based management panel, polymorphic builds using Garble obfuscation and UPX packing, and redundant persistence mechanisms including SSH backdoors, agent processes, and cron watchdogs. The operation demonstrates clear commercial intent with conversion funnel statistics, canary updates, and automated task supply loops that amplify high-yield subnets. It harvests cloud credentials, Kubernetes tokens, AI model access, and MCP service intelligence.

Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

released on 2026-07-17 @ 11:18:30 AM
A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t...

ACR Stealer: Two observed intrusion chains amid increased threat activity

released on 2026-07-17 @ 01:19:39 AM
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...

The Patch Wars have begun

released on 2026-07-16 @ 09:04:54 PM
Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications while maintaining infrast...

GoSerpent backdoor attacks in Southeast Asia

released on 2026-07-16 @ 04:15:01 PM
Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.

HelloNet campaign: a threat via the ViPNet update system

released on 2026-07-16 @ 04:15:00 PM
An active APT campaign discovered in May 2026 exploits the ViPNet update system to deploy previously unknown tooling against large Russian organizations. Attackers achieve persistence through DLL sideloading, placing malicious wtsapi32.dll in ViPNet directories. The campaign employs multiple components: HelloInjector loader, HelloProxy for traffic proxying and payload delivery, HelloExecutor backdoor for command execution, HelloCleaner for log file sanitization, and HelloBackdoor written in Rust for file manipulation. Attackers conduct reconnaissance activities, establish SSH tunnels using renamed PuTTY utilities, and target government, energy, transport, education, logistics, and industrial sectors. Attribution points to an unknown Chinese-speaking APT group with low confidence based on strings referencing sina.com and Chinese package repositories.

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

released on 2026-07-16 @ 04:06:34 PM
Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

released on 2026-07-16 @ 11:39:24 AM
A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.

Novel Starland RAT and bespoke WLDR C2 implant deployed in financially motivated campaign

released on 2026-07-16 @ 11:34:03 AM
A sophisticated Russian-speaking financially motivated adversary designated UAT-11795 has been conducting malicious operations targeting users in the United States and Europe since June 2025. The campaign delivers a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as the WLDR agent. The actor distributes trojanized installers disguised as legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT through likely ClickFix social engineering techniques. The operation targets victims' credentials and cryptocurrency wallet assets while establishing persistent connections for additional payload delivery. Alternative payloads include CastleStealer and Remcos RAT. The infrastructure utilizes distributed staging and C2 domains, Telegram bots for notifications, and a Polygon smart contract as a fallback mechanism for C2 domain resolution. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine for exe...

ClickLock Stealer: Paste Once, Lose Everything

released on 2026-07-16 @ 11:34:02 AM
A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome's encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive 'locker' technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

released on 2026-07-16 @ 06:59:08 AM
On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

released on 2026-07-16 @ 02:29:56 AM
TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service.

Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

released on 2026-07-16 @ 02:29:55 AM
Chinese cybercrime group GoldenEyeDog has been active since 2015, regularly updating malware and leveraging code-signing certificates to bypass Windows SmartScreen since 2024. A subgroup called CylindricalCanine uses Golden Gh0st Loader and Golden Gh0st RAT, modified versions of the 2008 Gh0st RAT, primarily targeting finance organizations in the Asia Pacific region through phishing campaigns. In April 2026, these actors compromised a DigiCert support member's device and stole code-signing certificates intended for customers, which they used to sign their own malware. The malware uses DLL sideloading, custom WebSocket protocols for command and control, and includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation. Analysis reveals consistent tactics including using legitimate executables to load malicious DLLs that decrypt payloads from files disguised as logs.

Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials

released on 2026-07-15 @ 08:49:52 PM
A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.

Fake crypto scams try to piggyback off SpaceX IPO

released on 2026-07-15 @ 08:49:52 PM
Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.

11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

released on 2026-07-15 @ 04:29:28 PM
Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.

Shared Claude Chats Meet ClickFix

released on 2026-07-15 @ 04:14:15 PM
A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

Miasma Worm Returns to npm

released on 2026-07-15 @ 02:20:02 PM
Four AsyncAPI npm packages were compromised in July 2026, delivering Miasma v3, a new variant of the worm previously found in Red Hat packages. The malicious versions (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) were published through AsyncAPI's legitimate GitHub Actions workflow using npm's OIDC integration, creating packages with valid provenance attestations. Unlike previous variants, this attack triggers when applications load the poisoned library rather than during installation. The payload downloads a second stage from IPFS, establishing a persistent Node.js backdoor with arbitrary shell command execution capabilities. While the codebase contains credential theft, propagation, and AI-tool poisoning modules, this deployment primarily functions as a remote access trojan. The attack began with an unauthorized commit to the repository's release branch, highlighting the importance of branch protection even when using trusted-publisher mechanisms.

June 2026 Infostealer Trend Report

released on 2026-07-15 @ 11:58:14 AM
During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks.

Inside an IoT Botnet Framework With LLM-Assisted Development

released on 2026-07-15 @ 11:58:12 AM
A previously undocumented modular IoT botnet framework has been identified with code partially generated using large language models. The framework consists of C-based bot agents compiled for 17 architectures, a Go-based command-and-control server with DDoS-for-hire panel, and custom exploit capabilities. Bot agents brute-force Telnet access using 1,496 credential pairs and target over 30 IoT device families. While core infection mechanisms function properly, several features are broken due to LLM-generated bugs that were shipped without manual review. The framework includes multiple fallback C2 mechanisms including domain generation algorithms, peer-to-peer gossip, IRC, and DNS TXT queries. Infrastructure analysis links this operation to the Keksec ecosystem through shared dropper servers. Development timeline spans from January 2025 to April 2026, with active C2 infrastructure observed since March 2026.

OkoBot framework infection chain

released on 2026-07-15 @ 11:58:11 AM
In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

released on 2026-07-15 @ 11:58:11 AM
Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.

Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet

released on 2026-07-15 @ 07:23:58 AM
A Russian-speaking threat actor known as 'bandcampro' leveraged Google Gemini CLI to migrate and operate a command-and-control botnet in six minutes, with the AI handling 89% of all work including architecture, coding, deployment, and debugging. Analysis of 200 Gemini CLI session logs from March-April 2026 revealed the actor controlled eight computers in a dental clinic, accessing OpenDental databases. The actor communicated intentions in plain Russian while AI executed technical operations. The entire C&C infrastructure fits in three plain-text files totaling 5KB, making it highly portable and disposable. Beyond botnet operations, the actor used AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly victims in the US and Canada. The AI proactively suggested improvements 59 times unprompted, demonstrating how AI lowers barriers for threat actors by replacing technical skill requirements with simple natural-language instructions.

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

released on 2026-07-15 @ 01:40:06 AM
Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software

released on 2026-07-14 @ 09:17:46 PM
A previously undocumented remote access tool named LabubaRAT has been identified, masquerading as NVIDIA software through fake metadata and runtime artifacts. This Rust-based malware creates persistent footholds enabling hands-on operator activity including host profiling, security tool identification, command execution, file transfers, screenshot capture, and traffic proxying. The implant supports multiple communication methods including HTTPS polling, WebView2-based communication, and DNS tunneling. It uses a configurable framework model with organization, group, server, and API key parameters suggesting a Malware-as-a-Service platform. The malware maintains local state in SQLite databases and provides comprehensive remote access capabilities including PowerShell and JavaScript execution, SOCKS5 proxy support, and user-level persistence through registry autoruns. Infrastructure analysis revealed LabubaPanel branding with associated command and control servers hosted on German providers.

Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries

released on 2026-07-14 @ 09:17:46 PM
In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information.

Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

released on 2026-07-14 @ 04:36:50 PM
Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

Supply Chain Compromise via GitHub Actions

released on 2026-07-14 @ 04:36:49 PM
On July 14, 2026, an attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository through a 'pwn request' vulnerability. The attacker opened 37 pull requests, with one containing obfuscated JavaScript that exfiltrated a highly privileged Personal Access Token belonging to asyncapi-bot. Using the stolen credentials, the attacker published five malicious npm package versions under the @asyncapi namespace, which collectively receive over three million downloads weekly. The malware features a multi-stage payload that establishes persistence and connects to command and control infrastructure, executing on import rather than install. It includes capabilities for credential theft targeting browsers, SSH keys, cloud credentials, and cryptocurrency wallets. The payload shares technical characteristics with the Miasma malware framework but shows unique features including a comprehensive command framework.

​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​

released on 2026-07-14 @ 04:36:40 PM
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025.

The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets

released on 2026-07-14 @ 04:36:39 PM
A sophisticated multi-layered scam operation targets fans seeking tickets for Celine Dion's French tour through two primary vectors. Fraudsters embed themselves in Facebook Groups and Marketplace, using social engineering to create artificial urgency and selling tickets before official presale dates. They exploit Ticketmaster's legitimate transfer feature to resell identical digital tickets to multiple victims, accepting direct bank transfers from compromised accounts. Simultaneously, threat actors deploy fraudulent websites impersonating official distributors like AXS and Ticketmaster, exploiting Shopify's payment infrastructure to appear legitimate. These sites share common technical indicators suggesting use of a recycled phishing kit previously deployed for other major concert events, including Oasis and Taylor Swift tours. The scheme combines emotional manipulation with technical deception to defraud victims desperate for concert access.

Lucide Proxy: Turning Student Web Proxies into DDoS Bots

released on 2026-07-14 @ 04:14:42 PM
A sophisticated campaign deployed 148 malicious npm packages disguised as student web proxy applications under brands like Riverbend Tutoring and Northstar Tutoring. Published by accounts terminal3airport and eerikakirk, these packages weaponized visitor browsers into distributed denial-of-service botnets while generating advertising revenue. The applications functioned as working proxies but secretly executed mutable remote code and high-performance WebSocket traffic generators compatible with the Wisp protocol. During a critical two-week period in May 2026, active deployments launched HTTP floods generating 2GB/s aggregate traffic and control-plane attacks establishing 10,240 socket connections per second against target servers. The campaign abused npm as a content delivery network, affecting users who visited proxy instances rather than through traditional dependency infection.

Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers

released on 2026-07-14 @ 11:51:22 AM
A sophisticated cyber campaign targets Indian government job seekers using fake recruitment advertisements for Senior Field Officer positions in the Cabinet Secretariat. The attack chain begins with a malicious ZIP archive containing a disguised LNK file, PowerShell script, and .NET executable. Attackers abuse the legitimate ControlR remote management tool for persistent access and deploy SheetAgent RAT, a custom .NET malware that uses Google Sheets as a command-and-control channel. The malware employs multiple persistence mechanisms including scheduled tasks and startup folder entries, while incorporating extensive anti-analysis checks to detect virtualized environments. Infrastructure analysis reveals multiple web-based management panels and connections to APT36 based on targeting patterns and tradecraft similarities.

ModHeader Malware: Inside the Chrome Spyware Google Removed

released on 2026-07-14 @ 08:04:44 AM
ModHeader, a popular Chrome developer extension with over 800,000 users, was flagged and removed by Google for containing hidden spyware. Version 7.0.18 included a covert SDK disguised as a date library (dayjs) that harvested visited domain names, encrypted them using AES-GCM, and was configured to upload the data daily to api.stanfordstudies.com. Although the collection remained dormant due to an empty allowlist, the complete exfiltration infrastructure was present and operational. Additionally, the extension displayed active adware behavior, opening affiliate tabs on every update including on enterprise-managed machines. The malicious code shipped with official Chrome Web Store signatures, affecting both Chrome and Edge users. Forensic analysis revealed the extension locally stored 178MB of sensitive HTTP headers from all browsing activity, though no data was successfully exfiltrated from analyzed systems.

CrashStealer: C++ macOS Infostealer Posing as Crash Reporter

released on 2026-07-14 @ 07:59:28 AM
A newly discovered macOS infostealer, implemented in native C++, impersonates Apple's crash-reporting framework to harvest sensitive data. The malware is distributed through a signed and notarized dropper application that bypasses Gatekeeper, then downloads and installs the payload from attacker infrastructure. The stealer validates victim passwords locally using dscl, unlocks the login keychain, and collects browser credentials, cryptocurrency wallet extensions, password manager data, and keychain material. Collected data is encrypted using AES-GCM before being packaged into hidden ZIP archives and exfiltrated to a command-and-control server. The malware establishes persistence by copying itself to a hidden directory and installing a LaunchAgent. It employs control-flow flattening, encrypted strings, and anti-debugging techniques to resist analysis. The campaign uses GitHub for initial staging and multiple fake collaboration software domains as lures.

Tomorrowland 2026, Belgium: People of Tomorrow, Targets of Today

released on 2026-07-14 @ 07:19:35 AM
Tomorrowland Belgium 2026, spanning two weekends in July at De Schorre in Boom, sold out rapidly, creating opportunities for cybercriminals. Investigation uncovered approximately a dozen fraudulent websites impersonating the festival brand to target ticket seekers and travellers. These scams include fake ticket shops mimicking official sales with countdown timers and fraudulent biometric checks, travel sites offering bogus accommodation and transport packages, and affiliate schemes. The operations harvest complete identity data, payment credentials, and personal information through sophisticated social engineering. Victims lose money with no recourse, face identity theft risks, and ultimately receive invalid or non-existent tickets. The scammers exploit high demand, tight supply, and rushed purchasing decisions, with sites registered weeks in advance and pushed hardest when official tickets are sold out.

Defending SaaS-based applications against ShinyHunters OAuth abuse

released on 2026-07-14 @ 02:38:48 AM
Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into authorizing malicious OAuth applications. Supply chain compromises leveraged trusted integrations including Salesloft, Gainsight, and Klue to obtain OAuth tokens for downstream customer access. Misconfigured guest access enabled exploitation of Aura framework functionality for unauthorized data queries. These techniques abused legitimate OAuth relationships to inherit user and application privileges, enabling enumeration and exfiltration of CRM data while evading authentication detections. The campaigns targeted multiple industries including retail, education, and manufacturing, highlighting risks in OAuth-connected applications and third-party integrations.

Threat Actors Achieve Persistence After SQL Injection

released on 2026-07-13 @ 05:23:52 PM
Threat actors gaining initial access through SQL injection exploited a web application vulnerability in a technology sector organization. After compromising an MSSQL instance via inadequate input validation, the attackers deployed base64-encoded PowerShell scripts to conduct reconnaissance using tasklist commands and exfiltrated results to an external server. They established persistence by enabling Remote Desktop Services, creating an administratively privileged user account named adminweb2$, and disabling Windows Defender. The attackers installed BadIIS modules for SEO fraud, deployed XMRig cryptocurrency miner with hidden file attributes, and utilized service creation tools. Multiple PowerShell scripts and batch files were downloaded throughout the attack to facilitate various malicious operations and maintain access.

Update on Attacks by Threat Group APT-C-60 in 2026

released on 2026-07-13 @ 12:54:55 PM
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.

One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators

released on 2026-07-13 @ 10:36:53 AM
A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026.

How WP-SHELLSTORM Exposed 1.4M WordPress Sites

released on 2026-07-13 @ 09:59:50 AM
A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.

Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2

released on 2026-07-12 @ 10:28:11 PM
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.

jscrambler npm Package Compromised in Supply Chain Attack

released on 2026-07-11 @ 11:55:30 PM
A malicious release of the jscrambler npm package (version 8.14.0) was published on July 11, 2026, introducing hidden native binaries that execute automatically during installation. The compromised package added an undocumented preinstall hook executing dist/setup.js, which deploys platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. The payload is a Rust-built infostealer targeting cryptocurrency wallets, AI coding assistants, cloud credentials (AWS, GCP, Azure), browser data, and messaging applications. String obfuscation uses per-string ChaCha20-Poly1305 encryption. The threat actor published five malicious versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0) over three hours, evolving delivery methods to evade detection. Version 8.22.0 is confirmed clean. The package receives approximately 15,800 weekly downloads, affecting developer workstations, CI systems, and build pipelines with access to credentials and secrets.

Sign here… and install an unwanted RMM

released on 2026-07-10 @ 05:25:53 PM
A sophisticated phishing campaign impersonates DocuSign's branding to compromise victims through malicious JavaScript embedded in fraudulent webpages. The attack leverages social engineering to trick users into downloading MSI installers disguised as legitimate DocuSign updates or documents. These payloads establish remote access through legitimate Remote Monitoring and Management tools from Atera Network Ltd and ConnectWise/ScreenConnect. Investigation revealed extensive attacker infrastructure spanning hundreds of domains, with tracking mechanisms via Telegram bots collecting detailed victim telemetry including IP addresses, geolocation, ISP information, and user-agent strings. The campaign targets both Windows and macOS systems, utilizing deployment kits across multiple infrastructures with similar URL patterns and JavaScript mechanisms.

Vishing actors target Entra passkey enrollment

released on 2026-07-10 @ 08:15:24 AM
Since April 2026, threat actors operating under O-UNC-066 have deployed a sophisticated vishing campaign targeting Microsoft 365 passkey enrollment. Attackers register domains containing 'passkey' and call victims to convince them to register new passkeys. Victims are directed to operator-controlled phishing kits that mimic Microsoft's enrollment process while attackers simultaneously register their own passkeys in victim accounts. The kit uses real-time polling and adapts to various MFA requirements including TOTP, push notifications, and SMS OTP. Targeted organizations span food and beverage, technology, healthcare, automotive, construction, and aviation industries. The campaign leverages Microsoft's legitimate passkey registration campaigns as a pretext, with primary motivation being data extortion through the Pink data leak site. Infrastructure is hosted on DDoS-Guard and IQWeb FZ-LLC.

Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics

released on 2026-07-10 @ 03:46:31 AM
A compromised version of the Injective Labs TypeScript SDK npm package was published containing malicious code that exfiltrates cryptocurrency wallet private keys and mnemonic phrases. The malicious version 1.20.21 was published on June 8, 2026, through a compromised developer account with established repository access. The malware hooks key generation functions to capture sensitive wallet data and exfiltrates it via base64-encoded POST requests to legitimate Injective infrastructure endpoints, disguising the traffic. The threat actor amplified impact by publishing 17 additional scoped packages pinned to the malicious version. Though quickly detected and contained within hours, the compromised package received approximately 310 downloads. The package has roughly 50,000 weekly downloads and 87 dependent packages, presenting significant supply chain risk to cryptocurrency wallet implementations.

Fake Banking Rewards, Telegram Delivery and Albiriox: Anatomy of an Android Malware Campaign

released on 2026-07-09 @ 10:16:06 PM
A malicious campaign was detected impersonating an Italian banking brand through a fraudulent domain offering fake financial rewards for installing a mobile application. Users are redirected to a Telegram bot that distributes a malicious Android APK outside official app stores. The APK functions as a dropper containing an embedded second-stage payload identified as Albiriox, an Android banking Remote Access Trojan. This payload exploits Accessibility services, implements overlay attacks, intercepts SMS messages, captures credentials, and enables remote device control through a custom TCP-based command-and-control protocol. The infrastructure uses domain impersonation and social engineering with financial incentives to distribute the malware. Communication occurs via raw TCP sockets to endpoints on ports 5555 and 5552, with JSON messages framed using big-endian length prefixes. Attribution to Albiriox is supported by protocol similarities, behavioral patterns, and comparison with known Albiriox samples.

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

released on 2026-07-09 @ 10:16:05 PM
Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...

Threat Insight: Cybercriminals Abusing Vercel to Deliver Remote Access Malware

released on 2026-07-09 @ 10:16:03 PM
Cybercriminals are conducting phishing campaigns by hosting malicious pages on Vercel, a legitimate website hosting platform. The attack involves sending phishing emails with links to fake Adobe PDF viewer pages that prompt users to download executable files disguised as documents. The malware, distributed as Invoice06092025.exe.bin, automatically installs LogMeIn remote access software upon execution, enabling attackers to remotely control compromised machines. Over a two-month period, more than 28 distinct campaigns have been observed targeting over 1,271 users. The attackers leverage trusted platforms to disguise their malicious activity, making detection more challenging and increasing the likelihood of successful compromise.

Indonesian Banking Sector Threat Landscape

released on 2026-07-09 @ 05:50:08 PM
Indonesia's Banking, Financial Services, and Insurance sector faced significant cyber threats throughout 2026, including multiple alleged data breaches targeting major banking institutions and fintech platforms. Underground forums advertised compromised datasets containing customer information, account details, and sensitive documents, with varying levels of validation. Ransomware groups ICARUS and The Gentleman conducted extortion campaigns against financial organizations. China-linked APT groups including SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, and Shadow Campaigns demonstrated sophisticated capabilities through phishing operations, supply chain compromises, and zero-day exploitation. These state-aligned actors deployed advanced malware such as ValleyRAT, ABCDoor, LOTUSLITE, and custom backdoors for long-term espionage. The expanding digital banking ecosystem and regional financial connectivity have increased attack surfaces, requiring enhanced cyber resilience, continuous monitoring, a...

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

released on 2026-07-09 @ 05:33:05 PM
In October 2025, Microsoft Threat Intelligence discovered GigaWiper, a sophisticated Golang-based backdoor that combines command-and-control capabilities with multiple destructive payloads. This versatile implant consolidates functionality from at least three separate malware families: a standalone wiper operating at physical disk level, a destructive component derived from Crucio ransomware that encrypts files with randomly generated unsaved keys, and a reimplemented version of FlockWiper with enhanced multi-pass secure wiping. The backdoor provides 20 different commands enabling threat actors to maintain control, execute operations, collect system information, and trigger destructive actions on demand. GigaWiper establishes persistence through scheduled tasks, communicates via RabbitMQ and Redis servers, and can perform disk wiping, fake ransomware encryption, screen recording, VNC-like remote control, and system-level sabotage including BSOD triggers and event log clearing.

RedHook Returns with a Dangerous Upgrade

released on 2026-07-09 @ 01:20:35 PM
RedHook is an Android Remote Access Trojan that has re-emerged with significant enhancements, particularly in privilege abuse capabilities. The malware autonomously exploits Android's ADB Wireless Debugging features to obtain shell-level access, integrating the Shizuku framework to execute protected system APIs. Recent activity shows expansion beyond Vietnam to Indonesia, targeting Southeast Asian users through spoofed government and financial websites. Malicious APKs are hosted on trusted platforms like AWS S3 and GitHub repositories. The current version supports 53 distinct server-issued commands and employs sophisticated persistence mechanisms including foreground activity spoofing, silent media playback, and cross-process monitoring. Distribution relies on social engineering via phone calls and messaging applications, tricking victims into downloading malicious APKs and enabling Accessibility services under false pretenses.

CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware

released on 2026-07-09 @ 01:20:34 PM
Between January and June 2026, multiple unrelated organizations experienced nearly identical intrusions following a standardized seven-step attack chain. The attacks exploited CitrixBleed 2 (CVE-2025-5777), a memory-overread vulnerability in NetScaler ADC and Gateway appliances. Attackers sent malformed pre-authentication login requests that leaked NetScaler memory containing valid session tokens, bypassing multi-factor authentication by hijacking active sessions. Following initial access, threat actors consistently escalated privileges to SYSTEM using a registry-symlink exploitation technique targeting the AppMgmt service, created rogue administrator accounts (CtxAppVCOMService, ctxsvc, test), and established persistence through legitimate remote access tools including ScreenConnect and Zoho Assist. The most advanced case culminated in DragonForce ransomware deployment. The highly standardized tradecraft, reused infrastructure, and consistent indicators across unrelated victims suggest a single Initial Ac...

Massive offensive launched on Russian businesses

released on 2026-07-09 @ 12:53:29 PM
In May and June 2026, the Clubfoot Wolf cluster executed a large-scale phishing campaign targeting Russian organizations across manufacturing, retail, e-commerce, agriculture, IT, transportation, healthcare, and science sectors, with primary focus on wholesale distributors of chemical products. Several Belarusian organizations were also compromised. The adversary sent phishing emails disguised as invoices or purchase requests, containing ZIP archives with decoy documents and malicious LNK files. Upon execution, a PowerShell script downloaded and installed NetSupport Manager, a legitimate remote administration tool, which was then used for malicious activities. The attackers employed URL shorteners to hide infrastructure and used multiple decoy files to build victim trust. The campaign demonstrated continuous evolution in delivery methods and infection chains.

GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses

released on 2026-07-09 @ 12:53:28 PM
GodDamn ransomware represents the third iteration of ransomware developed by Hyadina, following Monster (2022) and Beast (2024). A recent attack in June 2026 demonstrates sophisticated tactics including AnyDesk for remote access, NirSoft-based credential harvesting tools, and the PoisonX kernel driver for defense evasion. PoisonX is a malicious driver signed by Microsoft that terminates security processes at the kernel level. Attackers used PsExec for lateral movement, deployed comprehensive credential theft toolkits comprising 14 different tools, and disabled endpoint defenses before encrypting files. The encrypted files were renamed with victim organization names as extensions. The four-day dwell period allowed attackers to stage payloads and conduct reconnaissance before triggering encryption across at least 10 hosts within the targeted organization.

Vidar Infostealer Being Spread through Phishing Emails

released on 2026-07-09 @ 11:27:51 AM
Vidar, a Malware-as-a-Service infostealer first identified in 2018, continues to be distributed through phishing campaigns targeting Korea in the first half of 2026. The threat actor uses phishing emails disguised as job applications and copyright infringement notices, with attachments appearing as Word documents but actually being executables. Vidar employs a Go-based packer, uses Dead Drop Resolver technique via Telegram and Steam profiles to obtain C&C addresses, and implements anti-debugging and anti-VM techniques. The infostealer exfiltrates sensitive information including browser credentials, cookies, browsing history, cryptocurrency wallet data, Discord tokens, Telegram information, Steam data, Azure credentials, and screenshots. Configuration information is downloaded in JSON format, and data collection is performed based on received flags and additional downloaded conditions.

From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations

released on 2026-07-09 @ 11:27:10 AM
A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...

Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories

released on 2026-07-09 @ 08:25:00 AM
A malicious Go module posing as a DNS/subdomain scanner exposed a sophisticated Windows malware staging operation utilizing commit-farming workflows, public dead drops, and protected archives to deploy RAT and infostealer malware. The operation, tracked as 'Muck and Load', leverages a GitHub-based infrastructure comprising 222 confirmed repositories across 190 accounts designed to appear active and legitimate through automated GitHub Actions workflows. The attack chain begins with a deceptive Go module that downloads encoded PowerShell content, which then queries multiple public platforms including Pastebin, Telegram, YouTube, and Instagram as dead drops for encrypted payload locations. The loader retrieves password-protected archives containing AsyncRAT, Quasar, Remcos, and Vidar infostealer payloads, executing them from masqueraded Microsoft-themed directories. At least 14 malware files were confirmed across the repository network.

Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

released on 2026-07-07 @ 11:19:30 PM
Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sophisticated anti-analysis techniques including sandbox detection based on CPU cores and hostname patterns, multi-layer C2 domain obfuscation using XOR encoding, and selective activation gating. Upon execution, the packages exfiltrate environment variables containing API keys, secrets, tokens, and authentication credentials to AWS-hosted infrastructure via an ngrok endpoint. The campaign demonstrates coordinated cross-ecosystem capabilities, proper operational security through varied obfuscation keys, and knowledge of defender technologies, suggesting an organized threat actor with financial motivation.

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

released on 2026-07-07 @ 11:19:29 PM
A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

Continues building ORB networks using new malware

released on 2026-07-07 @ 02:17:46 PM
An advanced persistent threat actor designated UAT-7810 maintains and expands the LapDogs Operational Relay Box network infrastructure. This China-nexus group develops custom malware including SHORTLEASH and its evolved version LONGLEASH, alongside newly discovered tools DOGLEASH (a C-based backdoor), JARLEASH (a JAVA-based administrative backdoor), and LEASHTEST (a testing binary for MIPS devices). The actor exploits known vulnerabilities in unpatched Ruckus wireless routers and ASUS AiCloud devices, targeting networking equipment across multiple hardware platforms including MIPS, ARM, and x64. UAT-7810 establishes relay networks that secondary threat actors leverage for attacks against high-value targets. Infrastructure analysis reveals four command servers hosting malicious payloads, with one located in Hong Kong and others associated with VPS instances across multiple countries.

Phishers Abuse Business Account Manager Service

released on 2026-07-07 @ 02:15:15 PM
An unknown threat actor exploited Meta's Business Account Manager service to send phishing emails from legitimate Meta addresses between November 2025 and June 2026. The attackers manipulated the business partner mechanism by embedding URLs in the business name field, causing emails to appear as legitimate Meta communications. The campaign evolved to incorporate Facebook Messenger chatbots and exfiltrated stolen credentials, MFA codes, phone numbers, and identity documents to a private Telegram channel. The phishing pages impersonated Meta's Agency Partner Program and Verified badge services, targeting businesses to capture account credentials. Meta responded by implementing detections and blocking accounts attempting to use URLs in business names. Vietnamese language elements in the exfiltration process suggest the attackers' possible origin.

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

released on 2026-07-07 @ 02:14:56 PM
A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise.

One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation

released on 2026-07-07 @ 09:24:54 AM
Since May 2026, a suspected China-aligned threat cluster named UNK_MassTraction has been exploiting Roundcube mailservers at physics and engineering departments of US and Canadian universities. The campaigns exploit multiple n-day vulnerabilities including CVE-2024-42009 and CVE-2025-49113 to steal credentials and deploy either a webshell called SquareShell or the VShell backdoor into server memory. The actor uses an initial cross-site scripting vulnerability to execute JavaScript, then deploys IceCube stealer to harvest authentication material before pivoting server-side through deserialization exploits. The operators deliberately crafted their infection chain with mature tooling to avoid detection, using Roundcube servers as pivot points to enter target networks. The targeting focuses on departments with national security ties or those studying astrophysics and particle physics.

Bundled to Steal: The Salat Stealer Campaign

released on 2026-07-06 @ 11:30:04 PM
Salat Stealer is a Go-based information stealer that performs deep system reconnaissance and extracts sensitive data from compromised hosts. It targets browser credentials, cryptocurrency wallets, and communication platforms like Discord and Steam. The malware features advanced surveillance capabilities including desktop streaming, audio/video capture through microphone and webcam, and local file exfiltration. A notable distribution campaign bundled Salat Stealer with Xeno Executor, a gaming utility tool, transforming it into a full compromise vector. The malware employs sophisticated evasion techniques including disabling Windows Defender features through multiple PowerShell scripts, establishing persistence via registry run keys, and using token impersonation of lsass.exe to obtain elevated privileges. Loaders written in batch script and Rust programming language obfuscate deployment and bypass security controls.

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

released on 2026-07-06 @ 02:02:14 PM
Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

The Crown Prince, Nezha

released on 2026-07-03 @ 09:26:03 PM
Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability.

What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign.

released on 2026-07-03 @ 01:02:04 PM
The BabaDeda loader family has undergone significant advancements in its capabilities, particularly in stealth, evasion, and payload flexibility. Discovered during April 2026, this evolved framework continues to conceal malicious payloads within seemingly legitimate installer packages while expanding its functionality. The attack methodology begins with a social engineering exploit known as ClickFix, which encourages users to execute commands via trusted operating system utilities. This initial step transitions into a sophisticated multi-stage loader that employs several tactics, including hidden PowerShell commands, in-memory shellcode, DLL sideloading, and external payload storage.

Armored Likho's new weapon: BusySnake Stealer

released on 2026-07-03 @ 12:13:50 PM
Kaspersky uncovered a sophisticated phishing campaign by the APT group Armored Likho, deploying a previously undocumented Python-based infostealer dubbed BusySnake Stealer. The campaign targets government agencies and electric power sectors across Russia, Brazil, and Kazakhstan through spear-phishing emails containing malicious EXE or LNK attachments. BusySnake Stealer features advanced obfuscation using PyArmor Pro, extracts credentials from browsers using DPAPI and NSS libraries, captures screenshots, logs keystrokes, scrapes cryptocurrency wallets and 2FA tokens, and establishes reverse SSH tunnels for remote access. The threat actor leverages AI-generated code for first-stage payloads and distributes components via GitHub repositories. The stealer maintains persistence through scheduled tasks and communicates with C2 infrastructure to receive commands dynamically, representing a significant evolution in the group's technical capabilities.

Roblox, Minecraft, and the Insidious Internet for Children

released on 2026-07-03 @ 10:55:03 AM
Children are targeted by a sprawling ecosystem of websites exploiting their interest in Roblox and Minecraft through offerwall reward schemes and phishing campaigns. These sites promise free in-game currency in exchange for completing tasks, collecting personal data, enrolling minors in paid subscriptions, and violating platform terms of service that can result in account bans. The infrastructure relies on cheap, disposable hosting with aggressive domain rotation. Using Internet-wide scan data from Censys, this analysis characterizes two categories: offerwall get-paid-to reward sites and credential harvesting generators. The exposed infrastructure handles children's data with minimal security, monetizing their attention at scale through affiliate commissions while presenting significant privacy and security risks.

PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

released on 2026-07-03 @ 02:26:47 AM
PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

released on 2026-07-03 @ 02:26:45 AM
A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.

Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities

released on 2026-07-02 @ 08:59:13 PM
A sophisticated multi-stage phishing campaign delivers a previously undocumented framework called Avalon through spoofed legal documents hosted on Proton Drive. The intrusion begins with password-protected archives containing ISO images that execute malicious MSBuild projects, loading payloads entirely in memory without conventional executable attachments. Avalon consolidates credential theft, lateral movement, recovery disruption, and ransomware capabilities within a single framework, with its encryption component branded as CrownX. The framework demonstrates hallmarks of AI-assisted development, rapidly combining multiple post-exploitation capabilities that previously required sustained development effort. Avalon targets browsers, cryptocurrency wallets, messaging platforms, VPN configurations, and infrastructure systems while implementing extensive defense evasion techniques against major security products. The framework disrupts recovery by eliminating Volume Shadow Copies, Windows Recovery Environment...

Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic

released on 2026-07-02 @ 08:59:13 PM
Scam advertising campaigns have been identified that impersonate trusted brands to redirect consumers to unrelated online gambling sites. These operations utilize paid social media advertisements on platforms like Facebook, Instagram, and TikTok, combined with fake app store pages and Progressive Web Apps. The campaigns target UK consumers primarily, with variants observed in German and Spanish. Scammers impersonate major brands including financial institutions like Monzo, Revolut, and Barclays, as well as household names such as Tesco, Amazon, Netflix, and Facebook. The scheme involves three stages: paid ads claiming brands have launched official casino products, fake landing pages mimicking app stores, and PWAs that redirect to gambling sites through affiliate tracking links. Typical affiliate payouts range from $50 to $350 per depositing player, indicating significant financial motivation behind these operations.

Indirect Prompt Injection in Web Content Targets AI Agents

released on 2026-07-02 @ 08:39:41 PM
AI agents are increasingly vulnerable to indirect prompt injection (IPI) attacks, where malicious instructions are embedded in web content to manipulate AI-driven workflows. Two campaigns were identified that combine SEO poisoning with CSS/HTML abuse to influence AI decision-making. The first campaign uses fake API documentation to trick AI agents into making fraudulent payments for a fake Python library, incorporating hidden instructions in JSON-LD and CSS-concealed content directing payment of $3.00 via Stripe or approximately 0.0012 ETH to attacker wallets. The second campaign employs typosquatting to impersonate DeBank, a cryptocurrency portfolio tracker, embedding hidden prompts to make the fraudulent site appear as an authoritative source. Testing across 26 LLMs revealed 4 models were vulnerable to the payment scam and 2 models misclassified the typosquatting site, demonstrating measurable real-world impact.

GitHub Impersonation Deploys Information Stealer

released on 2026-07-02 @ 04:15:22 PM
An internal security operations team identified a fraudulent GitHub page impersonating a cybersecurity vendor to target customers and the general public. The malicious page appeared legitimate by referencing authentic services and operational requirements. While the GitHub page itself contained non-malicious content, a disguised link led victims to download a ZIP archive containing malicious executables. The attack chain deployed BoryptGrab Stealer information-stealing malware through DLL side-loading techniques. Investigation revealed nearly 300 similar repositories impersonating well-known organizations including Malwarebytes, Bitdefender, and 360 Total Security, using SEO keywords to attract victims. The malicious page has been removed and detection capabilities have been enhanced.

A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

released on 2026-07-02 @ 11:29:27 AM
An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.

RustDuck: An In-Depth Analysis of a Two-Stage Botnet

released on 2026-07-02 @ 09:56:56 AM
Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

Blacksite: New AiTM Phishing Kit Evades URL Scanners via Cloaked.gg

released on 2026-07-02 @ 09:50:33 AM
Blacksite is a newly identified adversary-in-the-middle phishing-as-a-service offering sold alongside Cloaked.gg, a cloaking platform that conceals phishing infrastructure from automated security analysis. The kit operates as a reverse-proxy that intercepts authentication tokens, session cookies, and 2FA codes in real time, enabling full account takeover even against MFA-protected accounts. Cloaked.gg blocks traffic from AWS, Google Cloud, and Azure networks while serving AI-generated decoy pages to suspected scanners, making malicious URLs appear benign during automated analysis. Priced between $600-$1,000 monthly, the service commercializes sophisticated AiTM techniques, lowering technical barriers for attackers. The pairing of credential theft capabilities with anti-detection infrastructure creates a split-view environment where security tools see harmless content while intended victims are routed to live phishing pages targeting consumer, financial, and enterprise identity systems.

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

released on 2026-07-01 @ 09:35:11 PM
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

Iran-Nexus Disseminates MarkiRAT Surveillance Tool

released on 2026-07-01 @ 04:58:02 PM
TAG-182, an Iran-nexus threat cluster, is conducting surveillance operations targeting Iranian citizens both domestically and abroad using MarkiRAT malware. The group distributes fake Android applications masquerading as VPN services and media players through social media platforms, particularly Instagram. Following Iran's partial internet restoration in May 2026 after an 88-day shutdown, these surveillance activities have intensified as Iranian security apparatus seeks to monitor perceived dissidents and anti-government activists. MarkiRAT samples demonstrate tradecraft overlaps with previously documented Ferocious Kitten operations, including use of Background Intelligent Transfer Service (BITS). The group operates infrastructure across multiple autonomous systems, utilizing domains with naming conventions mimicking legitimate services like Microsoft, Google, and Facebook.

How a single ScreenConnect incident exposed a massive campaign

released on 2026-07-01 @ 04:52:44 PM
A massive campaign distributes malicious installer archives hosted on spoofed websites masquerading as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam. Over 90 domain names localized across 10 languages were discovered. The malicious archives bundle a legitimate Microsoft-signed install.exe binary with a rogue install.res.1033.dll library deployed via DLL sideloading. This installs the ScreenConnect remote access service, which then deploys AsyncRAT payloads through PowerShell and VBS scripts. The threat actors leverage SEO techniques to position fraudulent sites at the top of search engine results, targeting both individual users and corporate networks. The infrastructure spans three IP addresses with domains registered between October 2025 and March 2026, creating a global footprint with multi-language support.

Phishing in the Balkans: Fake Traffic Fines, Real Losses

released on 2026-07-01 @ 04:52:36 PM
An active SMS phishing campaign targets Serbian road users by impersonating Putevi Srbije, Serbia's state road authority. Victims receive text messages claiming they have unpaid traffic fines with urgent payment demands. The fraudulent links lead to cloned government websites designed to steal payment card details. The infrastructure employs JavaScript-based obfuscation techniques to evade automated security scanners and uses disposable domains with uncommon TLDs. Technical analysis reveals connections to both Darcula and Phoenix Phishing-as-a-Service platforms, indicating fraudsters are combining tools from multiple PhaaS vendors. The operation demonstrates coordinated roles including infrastructure setup, SMS distribution, and data harvesting. Similar campaigns have targeted victims globally across government bodies, postal services, and financial institutions.

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

released on 2026-07-01 @ 11:58:56 AM
Check Point Research discovered a novel browser-native ransomware technique that emerged from AI-generated code attributed to DeepSeek. The attack leverages the File System Access API in Chromium browsers to encrypt files without requiring native payloads, exploits, or app installations. A malicious sample disguised as an AI image upscaler was analyzed, revealing how LLMs can connect theoretical platform risks to practical attack workflows. The technique is particularly concerning on Android, where Chrome allows web pages to access photo directories after user approval through legitimate permission prompts. By using social engineering with a fake AI enhancement tool, attackers can persuade victims to grant folder-level access, enabling file exfiltration and encryption entirely within the browser. This demonstrates how frontier AI models can autonomously design novel attack chains by reasoning across existing knowledge.

Inside an affiliate panel targeting Microsoft 365

released on 2026-07-01 @ 11:58:54 AM
Cisco Talos discovered ARToken, a sophisticated phishing-as-a-service panel sharing infrastructure and operational patterns with the EvilTokens platform. The panel exposes over 80 API endpoints enabling device code phishing, Primary Refresh Token persistence, email access, business email compromise operations, and SharePoint exfiltration through a React-based dashboard. The platform deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads. ARToken abuses Microsoft's OAuth 2.0 Device Authorization Grant to bypass multi-factor authentication entirely. Analysis reveals post-compromise capabilities including token management across password resets, automated BEC operations, inbox rule manipulation for evidence suppression, cross-account keyword monitoring, and SharePoint file operations. The platform operates as multi-tenant infrastructure with subscription-based affiliate access, representing a complete operations environment rather than simple phish...

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

released on 2026-07-01 @ 01:24:45 AM
LevelBlue has identified two distinct ValleyRAT attack vectors: campaigns using fake installers and malicious email-based campaigns. Detection volume increased significantly from May 2025, nearly doubling in 2026. The fake installer attacks primarily target Chinese-speaking users and employ advanced techniques including Pool Party Variant 7 process injection and BYOVD methods. The malicious email campaigns target both Chinese and Japanese-speaking users, delivering ZIP archives containing EXE and DLL files that leverage DLL sideloading. The malware employs multiple evasion techniques including junk code insertion, memory size checks, sleeping duration checks, process count validation, and fileless execution using Donut-generated shellcode. ValleyRAT establishes persistence through registry modification and enables remote access capabilities for threat actors.

Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs

released on 2026-06-30 @ 04:35:06 PM
The Gentlemen ransomware group, which emerged in July 2025, employed a zero-day vulnerability in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint detection and response systems. During an incident investigated in early April, the group leveraged an obscure third-party driver named ktapi.sys from Kontron to bypass security protections. The sophisticated exploit chains multiple advanced techniques to navigate Windows exploit mitigations, including bypassing Supervisor Mode Access Prevention and Supervisor Mode Execution Prevention. The toolkit enables the attackers to call privileged kernel mode functions from user mode processes, ultimately terminating EDR processes including Windows Defender, ESET, Palo Alto Cortex XDR, and SentinelOne. The vulnerability had no prior public documentation and was previously absent from vulnerable driver blocklists.

Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

released on 2026-06-30 @ 12:07:36 PM
Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.

How access to Gmail accounts is gained

released on 2026-06-30 @ 11:56:30 AM
The ToddyCat APT group developed a sophisticated tool called Umbrij to compromise Gmail corporate accounts through OAuth token theft. The malware exploits Chromium-based browsers by launching them in headless mode with remote debugging enabled, utilizing the Shadow Token via Remote Debug (STRD) technique. Umbrij automates the entire attack chain: it copies user profiles, launches browsers with debugging ports, connects via Puppeteer Sharp library, and manipulates OAuth flows by impersonating legitimate Google Workspace migration tools. The tool specifically targets client IDs for Google Workspace Migration for Microsoft Outlook and Google Workspace Sync applications, requesting extensive permissions for email, calendar, drive, and contacts. ToddyCat deploys Umbrij through DLL sideloading techniques using signed files from Bitdefender, Visual Studio, and Google Desktop Search. This automated approach enables scalable compromise of organizational email communications while evading traditional security monito...

Defence Impairment Olympics

released on 2026-06-30 @ 02:01:10 AM
A sophisticated attack sequence was detected beginning June 7 involving a steganographically hidden webshell on a vulnerable Adobe ColdFusion server. The threat actor executed extensive enumeration commands before deploying approximately a dozen defence impairment techniques. These included disabling IIS logging, tampering with Microsoft Defender, timestomping file metadata, killing Sysmon and Filebeat processes, uninstalling ModSecurity WAF, downgrading WDigest credential protection, and using WMI Event Consumer to clear Windows Event Logs. A batch script named i.bat revealed the complete attack chain, culminating in Mimikatz credential dumping. The attack persisted through multiple remediation attempts when the vulnerable server was prematurely reconnected before complete patching was finished, allowing the threat actor to maintain access and continue operations over several days.

A Djinn in the Machine: TaskWeaver's Node.js Intrusion Chain

released on 2026-06-30 @ 02:01:09 AM
An intrusion was investigated that began with exploitation of CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software. The threat actor obtained unauthorized technician access and deployed two previously undocumented malware samples: TaskWeaver and Djinn Stealer. TaskWeaver is a heavily obfuscated Node.js loader that establishes encrypted communications and delivers additional payloads. Djinn Stealer targets credentials across Windows, macOS, and Linux systems, collecting authentication data for cloud platforms, source control, package registries, AI development assistants, browsers, SSH keys, and cryptocurrency wallets. The attacker leveraged legitimate RMM capabilities to transfer files and execute commands across managed systems. Stolen AI assistant tokens provided extensive access to repositories, databases, and cloud accounts. The intrusion demonstrated how a single authentication bypass in trusted management infrastructure can enable widespread credential theft and p...

India's government and energy sectors targeted with ZOHOMURK and MINIRECON

released on 2026-06-29 @ 08:25:13 PM
Mustang Panda orchestrated two concurrent espionage campaigns targeting Indian government entities and hydropower infrastructure between May and June 2026. The campaigns leveraged DLL sideloading via legitimate executables to deploy newly identified malware including SHARDLOADER, MINIRECON, and ZOHOMURK. MINIRECON represents an evolution of Toneshell with WebSocket-based command-and-control capabilities, while ZOHOMURK abuses Zoho WorkDrive cloud services for C2 communications and data exfiltration. Distribution occurred through spear-phishing with lures themed around India-Taiwan cooperation agreements and hydropower projects. The activity demonstrates code overlaps with previous tooling, infrastructure proximity to known operations, and targeting patterns aligned with Chinese strategic intelligence collection priorities. Multiple compromised government systems were identified, with coordination conducted through CERT-In for victim notification and remediation.

RAT Abuses TON Blockchain to Target Japan's Hotel Industry

released on 2026-06-29 @ 08:24:16 PM
A sophisticated phishing campaign observed in May 2026 targets Japanese accommodation facilities partnering with Booking.com. Attackers impersonate guest complaints and review requests through emails, tricking hotel staff into downloading malicious ZIP files containing shortcut links disguised as photos. The malware, TONResolver, employs The Open Network blockchain platform as a dead drop resolver to dynamically retrieve command-and-control server addresses, making detection and takedown difficult. The attack uses Node.js with VM-based obfuscation and establishes encrypted WebSocket connections using ECDH key exchange and AES-256-CBC encryption. Two delivery methods were identified: bulk phishing and conversational attacks via Gmail that build trust before delivering malicious URLs. Once infected, endpoints maintain persistent Keepalive connections awaiting attacker commands for credential theft and additional malware deployment, with observed follow-on activity targeting browser-stored credentials from Ch...

Chromium extension uses AI‑related branding to redirect browser search

released on 2026-06-29 @ 08:08:25 PM
Microsoft Threat Intelligence identified a malicious Chromium extension spoofing Perplexity AI to deceive users into installation. The extension's primary objective involves search traffic interception and data collection through Manifest Version 3 capabilities and declarativeNetRequest rules. It routes both full search queries and real-time keystrokes through attacker-controlled infrastructure hosted on a typosquatted domain before redirecting to legitimate search providers. The extension overrides browser default search settings, captures user input at keystroke-level, and uses suspicious permissions inconsistent with legitimate AI assistants. The threat demonstrates how actors operationalize AI branding as social engineering vectors. Google removed the extension following responsible disclosure. Organizations should strengthen user awareness training and implement layered security strategies to detect similar threats.

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

released on 2026-06-29 @ 03:46:50 PM
In July 2025, threat actors compromised organizations through SEO poisoning campaigns targeting users searching for legitimate IT management tools. Users downloading trojanized installers for ManageEngine OpManager received Bumblebee malware, granting initial access. The attackers exploited the fact that users executing these IT tools were privileged administrators, enabling rapid lateral movement to domain controllers. They dumped credentials using wbadmin, created backdoor accounts with enterprise admin privileges, and installed RustDesk for persistent access. AdaptixC2 beacons were deployed for command and control. The threat actors conducted extensive reconnaissance, dumped LSASS memory across multiple systems, attempted Veeam credential theft, and exfiltrated data via SFTP using FileZilla. The intrusion culminated in Akira ransomware deployment across both root and child domains within 44 hours, with subsequent re-encryption two days later affecting the child domain.

New customs charges for online orders outside the EU

released on 2026-06-29 @ 03:40:51 PM
With the introduction of charges/taxes on certain items posted from outside the EU, threat actors appear to be leveraging the situation to send fraudulent SMS and email messages impersonating postal services in an attempt to harvest payment details and personal information. The campaign is already being observed targeting Irish users, and I'd like to highlight this activity publicly as part of a LinkedIn post around our Brand Protection, Threat Intelligence, and Domain Takedown capabilities.

Rapid growth and a new ransomware variant

released on 2026-06-29 @ 11:01:01 AM
The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors.

Phishing Campaign PasasteSinTAG - New domain rotation identified associated with the campaign impersonating the PasasteSinTAG portal

released on 2026-06-29 @ 06:35:54 AM
A phishing campaign targeting Chile continues to evolve with significant infrastructure expansion. Security researchers identified 99 new domains impersonating the legitimate PasasteSinTAG portal, with 22 domains confirmed active and 77 registered but not yet activated. The active domains utilize various top-level domains including .click, .cfd, .cyou, .mom, .best, .rest, .top, .help, .sbs, .icu, .life, .xyz, .buzz, .casa, and .pics. The infrastructure is hosted across seven IP addresses. This campaign represents an ongoing threat to Chilean users through brand impersonation tactics, with threat actors maintaining a large reserve of dormant domains for future rotation.

Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages

released on 2026-06-27 @ 01:57:13 AM
A fresh wave of the Miasma Mini Shai-Hulud supply chain campaign compromised legitimate npm packages under the @immobiliarelabs scope on June 26, 2026. The attack targeted Backstage plugins used for GitLab integration and LDAP authentication, affecting 22 package versions across multiple releases. The malware employs sophisticated techniques including hidden payloads that bypass standard package reviews, steals developer credentials and CI/CD secrets, and exploits GitHub Actions workflows for propagation. The campaign appears linked to a compromised upstream GitHub Action (codfish/semantic-release-action) and leverages deployment-triggered workflows for execution. Stolen credentials include npm tokens, GitHub tokens, cloud credentials, SSH keys, and various authentication secrets, which are exfiltrated to attacker-controlled repositories for further propagation across the ecosystem.

Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren't always the most exploited

released on 2026-06-26 @ 09:31:37 PM
On June 25, 2026, the first active exploitation of CVE-2026-55255, a critical CVSS 9.9 Langflow vulnerability, was documented. Langflow is an open-source framework for building AI agents and RAG pipelines. A single operator exploited both CVE-2026-55255 (cross-tenant IDOR) and CVE-2026-33017 (unauthenticated RCE, CVSS 9.3) against the same instance. Despite its lower score, the RCE has been exploited thousands of times and is listed in CISA KEV, while the IDOR showed no prior in-the-wild exploitation. The operator focused primarily on the RCE for code execution and implant delivery, using the IDOR opportunistically for credential theft across tenants. The financially motivated threat actor deployed a scripted loader to harvest AWS keys, environment files, and API credentials. This demonstrates that CVSS scores don't always correlate with real-world exploitation rates, as unauthenticated vulnerabilities require less effort than those needing authorization and disclosed object IDs.

Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment

released on 2026-06-26 @ 12:50:32 PM
A sophisticated China-aligned cyber espionage campaign targeting India's tax infrastructure was identified between May and June 2026. The operation impersonates the Income Tax Department, Ministry of Finance, exploiting the AY2026-27 ITR filing season to target corporate entities, tax professionals, chartered accountants, and taxpayers. The attack employs spear-phishing emails with malicious attachments mimicking legitimate government utilities. The multi-stage infection chain deploys DcRAT through steganographic payload concealment, fileless .NET execution, AMSI bypass, and Windows service persistence. The threat actor demonstrates operational maturity through active payload rotation achieving 0/66 detection rates, encrypted TLS-based C2 communications, and infrastructure hosted across multiple ASNs linked to China. The campaign shows overlaps with the China-nexus threat actor Silver Fox, featuring screen capture capabilities, data exfiltration, and systematic intelligence collection from high-value India...

Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem

released on 2026-06-26 @ 03:57:12 AM
A sophisticated supply chain attack campaign linked to Mini Shai-Hulud, Miasma, and Hades malware has compromised LeoPlatform npm packages, GitHub Actions workflows, and the Verana Blockchain Go module. The attack employs binding.gyp install-time execution, Bun-staged JavaScript malware, and encrypted credential exfiltration targeting developer and CI/CD environments. Malicious packages were published through the czirker and llxlr npm accounts in a coordinated burst on June 24, 2026. The campaign steals credentials including npm tokens, GitHub tokens, cloud provider credentials, SSH keys, and AI coding assistant configurations. Attackers use GitHub as dead-drop infrastructure and inject persistence hooks into repositories through orphan branches and fake dependency-update workflows. The RevokeAndItGoesKaboom marker connects this wave to the codfish/semantic-release-action compromise, indicating shared operational tooling.

Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access

released on 2026-06-26 @ 03:57:12 AM
Since April 2026, a sophisticated multi-stage intrusion campaign has targeted hospitality and hotel organizations across Europe and Asia. The operation uses photo-themed ZIP archives containing malicious shortcut files disguised as images. When executed, these shortcuts initiate an attack chain involving obfuscated PowerShell, Node.js-based implants, and dual registry persistence mechanisms. The threat actor exploits legitimate services like Calendly and Google redirects for phishing delivery, employing authentication laundering to bypass email security controls. The campaign evolved through two waves, introducing .NET DLL compilation, Cloudflare-fronted infrastructure, and refined obfuscation techniques. Post-compromise activities include command-and-control beaconing over non-standard ports, forced shutdowns, and portable executable compilation, suggesting preparation for additional malicious operations.

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

released on 2026-06-25 @ 11:28:29 PM
Google Threat Intelligence Group has identified STOCKSTAY, a .NET backdoor continuously developed and deployed by Russia-linked Turla (FSB Center 16) since December 2022. The multi-component malware communicates via secure WebSocket connections and targets government and military organizations in Ukraine, as well as entities interested in Italian foreign policy. STOCKSTAY shares significant code overlaps with KAZUAR, particularly the K1MORPHER obfuscation mechanism. The threat actor employs academic and diplomatic lures, malicious RDP files, and compromised Ukrainian infrastructure for deployment. STOCKSTAY demonstrates environmental keying for configuration protection and operates at multiple operational stages. The malware's modular architecture separates C2 communication, task orchestration, and execution into distinct components, mirroring KAZUAR's design philosophy and indicating shared development resources within Turla's cyber espionage arsenal.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

released on 2026-06-25 @ 11:11:09 PM
Throughout 2025, Chinese-speaking threat actors tracked as CL-STA-1062 conducted extensive operations against government entities and critical infrastructure in Southeast Asia, specifically targeting state-owned enterprises in energy and government sectors. Active since March 2022, this cluster was previously identified as UAT-7237 in campaigns against Taiwan's web hosting infrastructure. The attackers employ a hybrid toolkit combining open-source tools like SoftEther VPN, Mimikatz, and VNT with a newly discovered custom backdoor called TinyRCT. This .NET-based backdoor provides capabilities including arbitrary command execution, file enumeration and exfiltration, screen capture, and self-destruct mechanisms. The infection chain typically begins with web application exploitation deploying ASPX web shells, followed by credential dumping, lateral movement, and data exfiltration. Between October and December 2025, at least ten organizations across Southeast Asia were compromised, demonstrating sustained regio...

From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy

released on 2026-06-25 @ 06:43:50 PM
A Chinese web-development framework called DCloud Uni-App has become the technical foundation for over 236,000 scam domains since 2022, powering fake cryptocurrency exchanges, pig-butchering operations, wallet drainers, gambling platforms, and brand-impersonation sites. The framework gained prominence after the 2024 RainbowEx cryptocurrency scam in Argentina, which defrauded residents of San Pedro. Similar operations include the Lightning Shared Scooter Co. (LSSC) scam in the United States, which caused millions in losses across multiple states, and the currently-active Yuechi Sharing Technology Ltd. bicycle-sharing investment scam. These operations use legitimate hosting providers, with approximately 6% utilizing bulletproof hosting, particularly CTG Server. The scams target victims globally through WhatsApp, Telegram, and social media, converting victims into recruiters for pyramid-style operations. Enterprise exposure reaches over 985 distinct organizations across 25 industry verticals, with over five m...

Millenium: A RAT Rewritten, A Threat Multiplied

released on 2026-06-25 @ 06:43:49 PM
Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone significant architectural changes from .NET to native C++, while continuing to leverage Telegram Bot API for command and control without requiring dedicated server infrastructure. The malware is distributed as Malware-as-a-Service by developer 'ShinyEnigma' for $50-90 USD. Active exploitation campaigns are conducted by threat actor cluster 'Y2K Operators' using social engineering tactics including fraudulent utilities, hacking toolkits, software cracks, gaming lures, and trojanized cybercrime tools. The trojan enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 compromised endpoints across more than 160 countries have been identified, with 39,730 infections occurring in Q1 2026 alone, demonstrating accelerating infection rates.

Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond

released on 2026-06-25 @ 03:26:35 PM
Between June 16 and 19, 2026, a sophisticated adversary-in-the-middle phishing campaign targeted AWS console users through three domains registered within 48 hours and hosted on Cloudflare. The campaign impersonated AWS login pages and captured credentials along with real-time multi-factor authentication codes through email, SMS, and authenticator apps. Phishing emails were delivered through legitimate platforms like SendGrid and Nimbu to bypass spam filters. The kit employed JavaScript-based credential harvesting with victim validation through encrypted URL parameters, preventing sandbox analysis. Targets were primarily US-based software engineers and engineering leadership, suggesting a curated target list rather than mass phishing. The same kit was linked to concurrent SendGrid impersonation campaigns and previous cryptocurrency wallet targeting since July 2025. The small sample of fewer than 50 targeted email addresses indicates highly selective targeting of technical personnel with AWS access.

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

released on 2026-06-25 @ 03:21:09 PM
In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access.

ClickFix campaign delivers macOS infostealer via DMG

released on 2026-06-25 @ 03:01:33 PM
A new macOS ClickFix campaign employs fake CAPTCHA pages to deceive users into executing malicious Terminal commands. The attack chain downloads and invisibly mounts a DMG file containing a self-signed information-stealer application bundle. This payload, assessed as belonging to the AMOS (Atomic macOS Stealer) lineage—specifically the Odyssey variant—prompts users for passwords through fake System Preferences dialogs. The stealer harvests extensive data including browser credentials, cryptocurrency wallet information from 13 standalone applications and 201 browser extensions, messaging app data, Apple Notes, Safari cookies, and macOS keychain entries. Exfiltrated data is compressed and sent to two command-and-control servers. The malware establishes persistence via LaunchAgent and trojanizes legitimate cryptocurrency applications including Ledger Live and Trezor Suite, replacing them with compromised versions downloaded from attacker infrastructure.

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor

released on 2026-06-25 @ 02:55:44 PM
Prinz Eugen is a newly discovered Go-based ransomware family first observed in April 2026, attributed to an actor known as ROOTBOY. The encryptor employs sophisticated techniques including ChaCha20-Poly1305 encryption, prioritizes recently modified files to maximize pressure on victims, and implements anti-forensic measures such as memory scrubbing and self-deletion. Unlike typical ransomware, it leaves no ransom note on disk, conducting all extortion communications out-of-band through leak sites and direct contact. The threat actor gains initial access through compromised RDP credentials, uses legitimate RMM tools like RemotePC for persistence, and creates backdoor admin accounts. Victims span multiple countries and sectors, with notable incidents including Standard Bank Group in South Africa and Transitions Pro Centre Val de Loire in France.

FIFA 2026 Security Alert: Cybercriminals Exploit Fan Excitement with Mass Phishing

released on 2026-06-25 @ 02:07:34 PM
Threat actors are exploiting anticipation for the FIFA World Cup 2026 through sophisticated phishing campaigns targeting fans seeking tickets, hospitality packages, and tournament information. Attackers have deployed FIFA-themed domains and mobile-optimized phishing infrastructure resolving to specific IP addresses, designed to harvest credentials and payment information. The campaigns feature convincing fake ticketing portals that mimic official FIFA services, collecting personal details including names, emails, phone numbers, and payment card data. Some variants redirect victims to online gambling platforms after credential theft. The infrastructure leverages third-party payment services like KOIpay and EBpay, with JavaScript redirecting users to external payment gateways. Victims face risks including fraudulent account creation, credential stuffing attacks, email account takeover, and unauthorized financial access. This operation represents part of a larger fraud ecosystem targeting the tournament.

KimJongRAT Continues to Evolve by Leveraging LOTS

released on 2026-06-25 @ 05:07:47 AM
In May 2026, security researchers observed an attack campaign distributing KimJongRAT through GitHub and other legitimate services. KimJongRAT, used by the North Korean APT group Kimsuky since 2013, combines information stealing and remote access capabilities. The infection chain begins with phishing emails containing shortened URLs redirecting to GitHub Releases hosting malicious ZIP files. Victims execute LNK files that download HTA files from GitHub, which then retrieve subsequent payloads from Google Drive. Recent variants demonstrate significant evolution: they now dynamically fetch C2 addresses from external sources rather than hardcoding them, enabling operators to maintain persistent access despite infrastructure takedowns. Additionally, new versions include MeshAgent RMM installation for redundant access. The campaign exemplifies Living Off Trusted Sites (LOTS) techniques, abusing legitimate platforms like GitHub, Google Drive, and Dropbox to evade detection.

LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

released on 2026-06-24 @ 11:43:16 PM
LokiBot, an infostealer first advertised in May 2015, continues to operate after more than a decade with numerous variants. The malware targets credentials from over a hundred software products including browsers, cryptocurrency wallets, password managers, email and FTP clients. A recent campaign delivers LokiBot through malspam with JScript email attachments, executing a multi-stage infection chain involving PowerShell loaders and .NET injectors protected by ConfuserEx. The final payload uses process injection into aspnet_compiler.exe, employing API hashing techniques to evade detection. While LokiBot maintains extensive credential theft capabilities, recent samples exhibit broken persistence mechanisms due to patched decryption subroutines. The malware communicates with C2 servers to exfiltrate compressed stolen data and await further commands, demonstrating continued evolution despite reduced activity in recent years.

Operation Endgame disrupts Amadey and Stealc

released on 2026-06-24 @ 06:53:01 PM
ESET Research contributed to a global disruption operation targeting the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings. The operation, coordinated by Microsoft Digital Crimes Unit, BitSight, Lumen, and MBSD, impacted approximately 50 domains and nearly 200 active IP-based command and control servers. ESET provided technical analyses, statistical information, C&C server lists, encryption keys, campaign identifiers, and affiliate-level insights gathered from three years of tracking. Both malware families operate through affiliate networks where operators deploy their own infrastructure, making disruption efforts particularly challenging. Amadey primarily functions as a modular loader distributing additional payloads, while Stealc focuses on credential theft from browsers, crypto wallets, and applications. The largest Amadey botnet cluster accounted for 34% of all samples and distributed an average of 14 payloads per victim, operating a pay-per-install model that monetized compromi...

New Backdoor May be Linked to Ransomware Access Broker

released on 2026-06-24 @ 01:40:02 PM
A stealthy new backdoor called Mistic has been deployed in cybercrime intrusions since April 2026, potentially linked to Woodgnat, an initial access broker associated with multiple ransomware operations including Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta. Mistic was deployed alongside ModeloRAT in at least one case, a tool developed by Woodgnat. The backdoor uses sideloading techniques through legitimate Microsoft files and executes payloads in memory without writing to disk. It includes typical backdoor capabilities plus a self-delete kill switch for enhanced stealth. Targeting appears opportunistic across insurance, education, IT and professional services sectors. Woodgnat operates as an IAB, establishing durable remote access within enterprises and selling this access to ransomware affiliates, using various social-engineering techniques including ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites.

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

released on 2026-06-24 @ 01:40:01 PM
Infostealers remain among the most pervasive cybercrime threats, silently harvesting passwords, cookies, and session tokens that enable enterprise breaches. StealC is a malware-as-a-service infostealer written in C++ that collects credentials from browsers, cryptocurrency wallets, messaging applications, email clients, and gaming platforms while functioning as a secondary loader. Amadey operates as a modular backdoor loader active since 2018, delivering downstream payloads including StealC, Lumma Stealer, and ransomware through various backdoor commands. Both operate on commodity rental models where stolen credentials flow through underground markets to access brokers who resell enterprise access. On June 24, 2026, Microsoft's Digital Crimes Unit coordinated with Europol to disrupt over 200 malicious command-and-control domains supporting these operations, using AI-assisted analysis tools including Microsoft Copilot for binary analysis and configuration extraction.

StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon

released on 2026-06-24 @ 01:38:55 PM
A previously undocumented malware family named SharkLoader has been discovered delivering Cobalt Strike Beacon to targets worldwide. The threat actor deploys SharkLoader through exploitation of internet-facing applications including Microsoft Exchange, SharePoint, and Openfire Server, as well as through malicious droppers disguised as legitimate software. SharkLoader employs sophisticated techniques including Perfect DLL Hijacking to bypass Windows loader locks, multi-stage decryption using Blowfish and AES encryption, and extensive API hooking via Microsoft Detours and MinHook libraries. Victims include government entities and software development companies across Taiwan, Indonesia, Hong Kong, Lebanon, Syria, Colombia, Macedonia, Nepal, and Serbia. Post-compromise activities focus on Active Directory enumeration, credential dumping, and system reconnaissance. The campaign demonstrates both targeted and opportunistic characteristics, with potential cyber-espionage objectives, though attribution remains unc...

Ukraine's UAV Supply Chain Targeted With Besomar-Themed Malware Chain

released on 2026-06-24 @ 09:03:29 AM
A newly identified threat group, designated as GhostShell, has been conducting cyber operations against Ukraine's unmanned aerial vehicle supply chain since February 2026. The attackers employ malicious archives containing decoy documents that impersonate Besomar, a Ukrainian manufacturer of high-precision interceptor drones, to compromise defense and procurement networks. The attack chain deploys three distinct payloads: a custom backdoor (122.exe) utilizing mTLS client certificates for screen capture and command execution, an in-memory stager (update.exe) disguised as a Windows Health Service that fetches next-stage payloads via Telegram, and a proxy launcher (22.exe) that tunnels traffic through Xray Core to deploy the Vidar v2 information stealer. The targeting strongly suggests a Russian cyber operation, though analysts employ the SOLBIT framework to avoid attribution based on easily forgeable indicators.

Skill Marketplace and the Emerging AI Supply Chain Threat

released on 2026-06-24 @ 03:38:22 AM
Between February and May 2026, researchers identified five malicious skills on ClawHub, OpenClaw's AI agent marketplace, that evaded detection by VirusTotal and ClawScan. The threats included two macOS infostealers communicating with command-and-control infrastructure, one skill using file padding to bypass scanner thresholds, and two novel agentic threats exploiting the AI supply chain for financial gain. The infostealers delivered payloads including AMOS malware through Base64-encoded droppers and paste-site redirects. One skill implemented runtime affiliate injection by forcing agents to recommend products through malicious referral links, while another orchestrated a front-running scheme using coordinated AI agents to manipulate cryptocurrency token launches. These attacks demonstrate how malicious actors exploit semantic instruction hijacking and the lack of isolation between skill logic and agent authority to compromise AI agent ecosystems.

Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory

released on 2026-06-24 @ 03:38:21 AM
FortiBleed is a large-scale credential compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. The operation employs a sophisticated credential pipeline utilizing credential stuffing, password spraying, configuration harvesting, offline cracking, and post-authentication capture processing. Reverse engineering of the CyberStrike Harvester v1.5 binary revealed a comprehensive workflow converting FortiGate access into multi-protocol credential extraction, hash cracking via Hashcat/Hashtopolis GPU clusters, VPN-bound Active Directory and SMB access, and file-share exfiltration. The campaign affected devices across 194 countries and uses a seven-VM Kali lab infrastructure with automated tooling including FortiGate Sniffer panels, Telegram-orchestrated cracking bots, and Python/Impacket-based lateral movement tools. One documented exfiltration operation collected 121.43 GB from internal file shares. The operation appears to function as initial-access brokerage wi...

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

released on 2026-06-24 @ 03:38:21 AM
A sophisticated Rust-based macOS implant named macOS.Gaslight has been discovered, featuring a novel 3.5 KB prompt-injection payload containing 38 fabricated system messages designed to disrupt LLM-assisted malware analysis. The backdoor communicates via Telegram Bot API with AES-GCM encrypted payloads over certificate-pinned TLS and includes self-redaction capabilities to hide its bot token from logs. It provides operators with an interactive shell, system information collection, and credential stealing capabilities through a bundled Python script that targets browser data, keychains, and command histories. The implant uses runtime-fetched CPython interpreters and establishes persistence through a LaunchAgent masquerading as an Apple system service. This threat is assessed with high confidence to be aligned with DPRK activity and represents a significant evolution in adversarial techniques targeting security analysts rather than sandbox environments.

Observed activity associated with Sidewinder APT. Lure document: No.9374.docx, 64f2681ad0940e6c2c9c76e6834117bf. Observed C2 infrastructure: update[.]ms-office[.]app

released on 2026-06-24 @ 03:26:21 AM
Recent activity has been detected linked to the Sidewinder advanced persistent threat group. The campaign utilizes a malicious document named No.9374.docx with the hash value 64f2681ad0940e6c2c9c76e6834117bf as a lure mechanism. The infrastructure supporting command and control operations includes the domain update[.]ms-office[.]app. This observation indicates ongoing operations by Sidewinder, a threat actor known for targeting specific regions and sectors. The use of weaponized documents and deceptive domains mimicking legitimate Microsoft services demonstrates continued sophisticated social engineering tactics employed by this group.

"Ghost" Code Phishing Analysis

released on 2026-06-23 @ 10:03:16 PM
EvilTokens is a sophisticated phishing kit that conceals critical components of its attack through browser-side AES-GCM encryption, creating visibility gaps for traditional static URL analysis. The kit exploits Microsoft's legitimate device login flow through OAuth device-code phishing to gain account access without directly stealing passwords. Targeting organizations primarily in the United States and Europe, EvilTokens focuses on managed security services, technology, manufacturing, education, banking, and consulting sectors. The encrypted landing page only reveals its malicious content after browser decryption, requiring dynamic analysis to uncover the complete attack chain. The kit uses multiple stages including gate checks, user code requests, and session monitoring to complete Microsoft 365 account takeovers while appearing legitimate through final redirects to OneDrive.

Observed phishing URLs delivering RMM payload

released on 2026-06-23 @ 07:59:58 PM
ScreenConnect is used in phishing URLs to deliver RMM payload. DocuSign has been observed to be the common theme in these phishing emails.

The #APT36 cluster can't stop, won't stop

released on 2026-06-23 @ 07:23:17 PM
They just added #CVE-2026-21509 and #CVE-2026-21513 (borrowed from APT28) onto their delivery chain, pushing updated FIREPOWER via weaponized RTF and LNKs against 🇮🇳 targets. Separately, fresh SheetCreep + a shiny new CrystalShell-Slack variant co-dropped on a Kashmir target, because one implant is never enough. The vibeware factory is running three shifts: Crystal, .NET and PowerShell.

A Multi-Stage Steganographic Loader Campaign Deploying Diverse Payloads Globally

released on 2026-06-23 @ 05:35:20 PM
A sophisticated phishing campaign was identified distributing multiple malware families through a multi-stage loader utilizing steganography and fileless techniques. The infection chain begins with archive attachments containing files disguised as financial documents, primarily targeting Indian organizations using names related to GST, NEFT, RTGS, and IMPS transactions. The loader employs in-memory execution to avoid disk-based artifacts and uses embedded .NET Bitmap objects to conceal payloads. Various malware families have been deployed including Remcos RAT, Agent Tesla, MassLogger, Phantom Stealer, Dark Cloud, Red Line Stealer, Snake keyloggers, Formbook, and xworm. The final payloads establish persistence through registry Run keys, perform process hollowing, steal browser credentials, record audio and webcam, and exfiltrate data to command-and-control infrastructure. The campaign exhibits characteristics of a loader-as-a-service operation serving multiple threat actors globally.

From PostCSS Masquerading to Windows RAT

released on 2026-06-23 @ 05:20:30 PM
A sophisticated supply chain attack leverages typosquatting of the legitimate postcss-selector-parser npm package, which receives over 150 million weekly downloads. Three malicious packages published by user 'abdrizak' masquerade as PostCSS utilities while delivering a multi-stage Windows RAT. The infection chain begins with encoded JavaScript that drops PowerShell scripts, which then download a bundled Python runtime containing Nuitka-compiled modules. The final payload implements comprehensive RAT capabilities including HTTP C2 communication with RC4 encryption, registry persistence, VM detection, remote shell execution, file transfer, and Chrome credential theft using DPAPI and app-bound decryption. The attack demonstrates how build tooling dependencies can serve as delivery mechanisms for sophisticated Windows malware targeting developer environments.

Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware

released on 2026-06-23 @ 04:41:50 PM
An initial access broker linked to Payouts King ransomware is deploying Edgecution, a sophisticated malware utilizing a malicious Microsoft Edge browser extension. The attack begins through social engineering via Microsoft Teams, impersonating IT staff and directing victims to fake Microsoft websites offering supposed Outlook updates. Edgecution comprises two components: a browser extension that communicates with command-and-control servers via websockets, and a Python-based backdoor. The extension abuses Chrome native messaging protocol to escape browser sandbox restrictions, enabling direct host access. This allows attackers to manipulate the filesystem, launch processes, and execute arbitrary code. The malware operates in a headless browser, remaining invisible to users. Deployment methods include AutoHotKey scripts, Windows batch scripts, and PowerShell scripts. The Python backdoor supports various commands including system information collection, filesystem access, and arbitrary code execution.

Customer CRM Data Accessed in Supply Chain Incident

released on 2026-06-23 @ 04:31:05 PM
LastPass experienced a security incident through Klue, a third-party market intelligence platform integrated with its Salesforce and Gong systems. On June 12, 2026, LastPass was notified that an unauthorized actor exploited stolen OAuth tokens held by Klue to access customer relationship management data within LastPass's Salesforce environment. The exposed information includes customer names, email addresses, phone numbers, physical addresses, support case data, and sales records. Multiple Klue customers were affected by this supply chain attack. LastPass confirmed no Gong data was accessed, and customer vaults, master passwords, and encrypted vault data remain unaffected. The company has terminated Klue access, rotated compromised API tokens, and is cooperating with law enforcement while warning customers about potential phishing attempts using the exposed contact information.

Artifact scanner detects npm package 'node-fetch-utils' using external dependency resolution with remote tarball dependency from GitHub

released on 2026-06-23 @ 12:11:59 PM
A malicious npm package named 'node-fetch-utils' was discovered masquerading as a legitimate fetch helper utility. The package declares a remote tarball dependency from GitHub that executes upon installation. It runs an obfuscated postinstall script targeting Windows systems, which downloads a bundled Python runtime and drops it as Microsoft\EdgeBroker\pythonw.exe for persistence. The dropper then uses this disguised runtime to execute a fileless Python implant decrypted in memory and launched hidden via wscript. The dropper scripts self-delete while the disguised runtime remains active on the compromised system, establishing command and control communications.

PHISH ALERT: From a Simple Phishing Email to a Full Attack Arsenal: The Evolution of "ClickFix"

released on 2026-06-23 @ 12:11:54 PM
A sophisticated phishing campaign leverages evolved ClickFix techniques to bypass modern endpoint security through victim-assisted execution. Targets receive emails with urgent OneDrive document lures containing malicious ZIP attachments. The attack uses LNK shortcuts that redirect victims to landing pages, silently injecting PowerShell commands into their clipboard. Through social engineering, victims are tricked into manually executing commands via Win+R, circumventing traditional security filters. The campaign employs DNS TXT records for payload staging, avoiding HTTP detection. The threat infrastructure hosts multiple malicious components including obfuscated scripts, fake MSI installers masquerading as legitimate software like ConnectWise, and ISO images with spyware for persistent access. This represents a shift toward long-game tactics focused on establishing full post-compromise environmental control.

Detecting the Klue supply chain attack in Salesforce instances

released on 2026-06-22 @ 08:21:12 PM
On June 11, 2026, the Icarus threat group compromised Klue's backend systems, a market intelligence platform used by hundreds of enterprises to sync competitive battlecard data with CRM environments. The attackers exploited a dormant credential from an abandoned prototype integration to harvest OAuth tokens for Salesforce and Gong. Through automated API calls using Python scripts, the group exfiltrated CRM data including business contacts, price quotes, and sales communications from multiple customer Salesforce organizations. Klue detected the anomalous activity on June 12 and revoked OAuth credentials on June 13. The attackers subsequently launched an extortion campaign starting June 16, demanding victims contact them via Session Messenger within 48 hours.

An unknown actor distributes malicious VBS scripts via WhatsApp

released on 2026-06-22 @ 11:01:01 AM
An active malware campaign has been discovered distributing malicious VBScript files through WhatsApp direct messages since June 2026. The operation affects users across multiple countries, with Malaysia experiencing the highest concentration of victims. Attackers compromise WhatsApp accounts and send weaponized VBS files disguised as business and financial documents to contacts. The multi-stage infection chain ultimately deploys legitimate ManageEngine Endpoint Central RMM software, providing persistent remote access to compromised systems. The scripts employ heavy obfuscation, Chinese-language comments, and modify Windows UAC settings. Infrastructure overlaps with ValleyRAT and Gh0st RAT operations suggest possible Chinese-speaking operators, though attribution remains uncertain. The campaign primarily targets individual users through opportunistic rather than focused methods, exploiting social engineering techniques with localized filenames in multiple languages.

3CXDesktopApp Intrusion Campaign Prevention

released on 2026-06-22 @ 06:28:53 AM
A sophisticated supply chain attack compromised the legitimate 3CXDesktopApp softphone application across Windows, macOS, and Linux platforms. The malicious activity involved trojanized signed installers that deployed a compromised ffmpeg.dll binary, establishing HTTPS beacons to attacker-controlled infrastructure and enabling second-stage payload deployment. Analysis revealed the attack utilized specific beacon structures and encryption keys matching infrastructure patterns, with hands-on-keyboard activity observed in targeted cases. The operation affected multiple platforms through signed MSI installers containing malicious components. The attack demonstrated advanced tradecraft through abuse of trusted software distribution channels, requiring immediate removal of affected versions and deployment of behavioral detection capabilities to identify malicious beaconing activity.

Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind

released on 2026-06-19 @ 06:47:21 PM
An exposed attacker server has unveiled FortiBleed, a large-scale credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. This operation involved credential harvesting through reuse, brute force, and hash cracking using a distributed GPU infrastructure with approximately 36 rented GPUs via Hashtopolis. The exposed directory contained 319 files revealing scanning tools, cracking infrastructure, credential databases, post-exploitation toolkits, and active VPN configurations. While initially reported as affecting 21,632 domains, analysis of the attacker's own tooling reveals only 918 organizations showed evidence of internal network compromise, with merely 148 confirmed cases where credentials were fully cracked. The operation ultimately aimed to sell initial access to compromised networks, with victims spanning 194 countries, predominantly India, United States, and Taiwan.

Threat Actors Weaponizing RAR Archives to Target Thailand's Healthcare Sector

released on 2026-06-19 @ 02:27:26 PM
An active malware campaign is targeting Thailand's healthcare sector, including Ministry of Health personnel and affiliated organizations. The operation leverages healthcare-themed spear-phishing lures distributed through malicious RAR archives containing obfuscated batch scripts and executable payloads. The infection chain employs multiple stages of obfuscation, GitHub-hosted payload delivery, and persistence mechanisms. The final payload is a Python-based information stealer designed to harvest browser credentials, session data, and cookies, with exfiltration attempts through Telegram Bot API. The campaign demonstrates sophisticated tradecraft including Rouki-obfuscated batch loaders, Startup folder persistence, and bundled Python interpreters. Active operational window spans from April to June 2026, with all samples uploaded from Thailand.

Operation Poisson – Analyzing a Cybercriminal’s Entire Operation

released on 2026-06-19 @ 11:24:44 AM
A comprehensive analysis of 339 commands issued by a French-speaking threat actor nicknamed 'Poisson' over 33 days, targeting a French automotive small business and four French individuals. The attacker utilized a multi-stage fileless attack deploying a 70-line Python keylogger to harvest banking and email credentials. The operation leveraged free-tier infrastructure including Havoc C2 framework, Backblaze B2 storage, and DuckDNS. Most significantly, the attacker installed OpenSSH and Tailscale VPN on victim machines, creating persistent access that survived C2 server takedown. When the C2 went offline for 18 days, the attacker's access remained intact through the VPN mesh, demonstrating that VPN-mesh-based persistence is actively used in real-world intrusions and that traditional C2 takedown is insufficient for remediation.

Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088

released on 2026-06-19 @ 04:31:49 AM
A campaign exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 has been actively targeting Ukraine since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden PowerShell stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes.

OXLOADER: new loader evading detection to drop infostealer

released on 2026-06-19 @ 12:03:23 AM
A previously undocumented Windows loader designated as OXLOADER delivers the CASTLESTEALER infostealer through malicious Google Ads campaigns, achieving remarkably low detection rates. The loader employs multiple obfuscation layers including control-flow flattening, opaque predicates, and mixed Boolean-Arithmetic techniques, along with self-modifying decryption stubs and abuse of the Windows .reloc section for shellcode staging. Distribution occurs via malvertising impersonating Node.js installations, redirecting victims through intermediary domains to Storj-hosted batch scripts. The loader implements five anti-VM and language checks, including CIS-region and Russian-language exclusions, suggesting a financially motivated Russian-speaking threat actor. OXLOADER uses DonutLoader to deliver the .NET-based CASTLESTEALER payload in memory, evading traditional detection mechanisms through deliberate engineering choices.

Operation FlutterBridge: The FlutterShell macOS Backdoor

released on 2026-06-19 @ 12:03:22 AM
FlutterShell is a macOS backdoor campaign active from December 2025 to March 2026, identified as cluster CL-CRI-1089 under Operation FlutterBridge. The threat actors deliberately misused the Flutter framework to deliver malware through malvertising campaigns on Google and YouTube. The malware employs a two-component architecture: a thin Mach-O launcher and a large Flutter payload dylib. Across three generations, the operators rotated Apple Developer certificates, implemented progressive Dart obfuscation, and renamed bridge commands to evade detection. The backdoor uses a WKWebView to load attacker-controlled JavaScript from C2 servers, implementing a conditional execution model where commands are delivered at runtime via a JavaScript-to-native bridge called flutterInvoke. The primary impact includes Chrome browser hijacking to inject sinterfumesco[.]com as the default search provider and persistent infection through silent Sparkle framework updates.

Popa: From Sourcing to Distribution

released on 2026-06-18 @ 07:31:57 PM
An Android proxyware SDK named Popa enrolls consumer devices including phones, tablets, and streaming boxes into a commercial residential proxy network. Operating since at least 2020, Popa and its variants (Loopop, Neupop, and Moneytiser) are distributed inside consumer streaming, IPTV, and utility applications. The SDK begins relaying third-party traffic at host-app launch without displaying informed-consent prompts in analyzed samples. Multiple variants communicate directly with NetNut SDK endpoints, sharing operational infrastructure and telemetry. Controlled testing showed traffic from Popa-enrolled devices egressing through NetNut's commercial gateway. The SDK uses encrypted Google Drive files to resolve relay servers in later versions. Analysis of over 20 publishers revealed significant links to piracy-related applications, with none observed requesting user consent despite later builds including this capability.

Okendo Reviews Supply Chain Attack

released on 2026-06-18 @ 03:00:37 PM
On May 14, 2026, a supply chain attack was discovered targeting the Okendo Reviews widget, a customer review platform used by over 18,000 brands. The threat actor injected malicious JavaScript code into the legitimate widget, which is deployed on high-traffic e-commerce pages including storefronts and product pages. The compromised JavaScript acted as a staged loader, using obfuscation, localStorage tracking, User-Agent filtering, and XOR-based decoding to conceal next-stage infrastructure. The attack employed ClickFix-style social engineering to deceive users into executing malicious commands, ultimately delivering remote access trojans like NetSupport and Remcos, or information stealers such as StealC. Affected websites received hundreds of thousands to millions of monthly visitors, with nearly 15,000 blocks recorded in a single day.

May 2026 Infostealer Trend Report

released on 2026-06-18 @ 02:53:54 PM
This analysis covers infostealer distribution trends observed during May 2026, based on automated collection systems and diagnostic logs. Distribution occurred primarily through illegal software disguised as cracks and keygens, as well as email campaigns. ACRStealer, Remus, and LummaC2 were most prevalent, with distribution via domains including Mediafire and AWS S3 buckets. Microsoft was the most impersonated company, followed by Auslogics and NVIDIA. EXE files represented 78.9% of execution types, while DLL side-loading accounted for 21.1%. macOS environments saw ClickFix techniques and malicious Bash scripts, with 142 scripts and 12 C2 domains identified. Email campaigns distributed AgentTesla and DarkCloud. Remus showed significant growth, comprising 36% of distributions. LummaC2 remained the most prevalent overall variant.

Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation

released on 2026-06-18 @ 02:53:54 PM
Global law enforcement, including agencies from the Netherlands, Canada, United States, and Germany, coordinated Operation Endgame to disrupt TA569, a prominent cybercriminal group tracked since 2018. The operation targeted SocGholish infrastructure, taking down over 100 servers and domains while remediating 14,971 compromised websites. TA569 pioneered web inject techniques using fake browser updates to distribute malware, often leading to ransomware attacks. The group compromised high-traffic websites across multiple industries, affecting millions of visitors globally. Their attack chains involved traffic distribution systems like Keitaro TDS and ParrotTDS, delivering GhoLoader payloads that could lead to ransomware deployment in enterprise environments. Law enforcement actions included server disruption and website disinfection, significantly impacting the threat actor's operations, infrastructure, and reputation within the cybercriminal ecosystem.

Operation Endgame vs. SocGholish Fake Updates

released on 2026-06-18 @ 02:53:53 PM
A multinational law enforcement operation called Operation Endgame has successfully disrupted SocGholish, a malware framework operated by threat actor TA569 since 2017. The operation took down 106 servers and domains and remediated nearly 15,000 compromised WordPress websites. SocGholish uses fake browser update prompts on compromised websites to trick victims into downloading malicious JScript payloads, providing initial access to corporate networks for ransomware deployment and data breaches. Analysis revealed that 55% of Infoblox cloud customers were exposed to SocGholish in 2026, demonstrating widespread impact across multiple industries including government, education, and healthcare. The framework employs domain shadowing techniques and operates through a four-stage attack chain involving traffic acquisition, filtering, fake update lures, and on-device implant execution. SocGholish infrastructure has facilitated access for various ransomware families and has been extensively used by the notorious Evi...

GitBait: Phishing targeting the Mexican financial sector

released on 2026-06-18 @ 10:09:53 AM
A sophisticated, modular phishing infrastructure has been identified targeting at least 12 Mexican financial institutions over a three-year period. The operation leverages GitHub Pages for hosting and SheetBest API for credential exfiltration, eliminating the need for dedicated backend infrastructure. Attackers employ obfuscated JavaScript, randomized paths, and dynamic brand selection panels to impersonate legitimate banking portals. Over 100 associated domains were identified, each hosting multiple phishing pages across different paths. Credentials are collected through multi-stage forms mimicking authentic banking authentication flows and exfiltrated in real-time to attacker-controlled Google Sheets. An alternative exfiltration method via Telegram bot was also observed. The campaign demonstrates operational persistence with multiple operator accounts maintaining the infrastructure through continuous commits and updates.

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign

released on 2026-06-18 @ 10:09:51 AM
Cybercriminals orchestrated a sophisticated malvertising operation leveraging Google Ads to impersonate popular AI developer tools including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains. Over seven weeks spanning April to June 2026, attackers deployed 106 unique malicious hostnames across six distinct waves, initially hosting ClickFix social engineering pages on GitLab infrastructure before pivoting to weaponize claude.ai's legitimate shared chat feature. The campaign targeted technically proficient users searching for AI development tools, tricking them into executing terminal commands that deployed the MacSync infostealer. This credential-harvesting malware collected browser data, SSH keys, and cryptocurrency wallets. The Asia-Pacific region sustained the heaviest impact with 67.2% of over 2,000 victims, particularly concentrated in Taiwan. Anthropic responded by banning malicious accounts and implementing additional abuse mitigations.

From package to postinstall payload: Inside the Mastra npm supply chain compromise

released on 2026-06-18 @ 05:41:52 AM
Microsoft Threat Intelligence discovered a large-scale npm supply chain attack compromising over 140 packages in the mastra and @mastra scopes. The attack originated from takeover of the ehindero npm maintainer account, which published poisoned package versions introducing easy-day-js, a malicious typosquat of the popular dayjs library. The malicious package executed a postinstall hook that deployed an obfuscated dropper script, disabled TLS certificate verification, contacted command-and-control infrastructure at 23.254.164.92 and 23.254.164.123, and downloaded a second-stage payload. This 41KB cross-platform Node.js implant installed persistence mechanisms, performed cryptocurrency wallet inventory, exfiltrated browser history and host reconnaissance data, and on Windows performed reflective .NET assembly injection for fileless in-memory code execution. Any developer workstation or CI/CD pipeline executing npm install after compromise was potentially exposed regardless of code usage.

Twitter Feed - nextronresearch - 17-06-2026

released on 2026-06-18 @ 03:19:07 AM
SideCopy, also tracked as APT36 or Transparent Tribe, has launched a new attack campaign targeting Indian defense personnel using a fake 'Minutes Of Meeting' document as lure. The attack employs an identical playbook to previous operations: a double-extension Minutes Of Meeting.docx.lnk file executes a PowerShell stager (pdfdocs.bat) from a nested pdfdocs folder while displaying a clean decoy document. The chain deploys a Remote Access Trojan (pdfdocs) that establishes persistence through the HKCU Run key. The staged components demonstrate low detection rates at initial delivery, with the decoy document scoring 0/66, the stager 1/61, and only the final executable reaching 35/71 detections.

Klue Integration Abused in Salesforce Data Theft | Threat Spotlight

released on 2026-06-18 @ 03:14:23 AM
In June 2026, a compromised Klue competitive-intelligence platform integration was exploited to exfiltrate customer relationship management data from enterprise Salesforce environments. Attackers authenticated through compromised Klue service accounts, generated OAuth tokens, and executed automated Python scripts to conduct bulk data extraction via Salesforce REST API queries over approximately 24 hours. The activity included concentrated bursts of nearly a thousand queries within 15 minutes and sustained extraction windows exceeding 6 hours. This incident follows similar third-party OAuth-abuse campaigns targeting Salesforce through Salesloft Drift and Gainsight integrations throughout 2025 and 2026. While the tactics resemble operations attributed to ShinyHunters and UNC6395 threat groups, attribution remains uncertain. The initial access vector, full scope of exfiltration, and attacker intent are still under investigation, with no extortion demands observed to date.

Crypto Clipper uses Tor and worm-like propagation for persistence and control

released on 2026-06-18 @ 03:14:20 AM
A Windows-based cryptocurrency clipper has been actively targeting users since February 2026, employing sophisticated techniques to steal digital assets. The malware propagates through malicious shortcut files on USB devices, creating a worm-like infection chain. Once deployed, it utilizes Windows Script Host and ActiveX to launch a bundled Tor proxy client, enabling anonymous communication with hidden-service command and control servers. The clipper performs high-frequency clipboard monitoring to intercept cryptocurrency wallet addresses, seed phrases, and private keys, replacing them with attacker-controlled alternatives. Additionally, it captures screenshots for context and maintains persistent access through scheduled tasks. The threat demonstrates advanced capabilities including remote code execution, making it more than a simple stealer by functioning as a lightweight backdoor. The malware employs multiple defense evasion techniques including multi-layer obfuscation, anti-analysis checks, and local S...

Invisible Sting: Over 4000 Outdated Routers Compromised by AryStinger, Becoming Global Attack Springboards for Hackers

released on 2026-06-17 @ 10:48:57 PM
AryStinger is a sophisticated botnet targeting legacy routers based on RTL819X chipsets and NAS devices through vulnerabilities disclosed over a decade ago, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. The malware exists in two versions: a C-based RTL819X variant for resource-constrained routers and a Go-based Standard version for NAS devices. Both communicate with command-and-control servers using Protobuf-encoded, XOR-encrypted traffic. Infected devices function as Executors in a distributed infrastructure, performing reconnaissance activities including port scanning, subdomain enumeration, and service identification. The botnet supports traffic tunneling, remote access via Dropbear or gs-netcat, and can execute payloads in Go, Java, and Python. Over 4,300 routers globally have been confirmed infected, predominantly D-Link models, with concentrations in South Korea, China, and Sweden. The infrastructure serves as both a concealment layer and attack platform for cyber espionage and intrusio...

ClickFix Campaign Generated Via AI Delivers SmartRAT

released on 2026-06-17 @ 06:20:55 PM
In March 2026, threat actors leveraged AI-powered website builders to create typosquatting domains impersonating a Brazilian bank. The campaign employed ClickFix techniques, presenting victims with fake CAPTCHA and BSOD screens to trick them into executing malicious PowerShell commands. This delivered SmartRAT, a PowerShell-based banking trojan with capabilities including encrypted C2 communications, remote control of screen/keyboard/mouse, credential theft through keylogging and banking overlays, and QR code interception for transaction fraud. The malware establishes persistence via scheduled tasks and Windows services, and targets Brazilian financial institutions, payment platforms, and cryptocurrency exchanges. The threat actors' C2 panel contained critical authentication flaws allowing client-side bypass, suggesting deployment without adequate security review.

More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers

released on 2026-06-17 @ 06:13:27 PM
Security researchers discovered AryStinger, a botnet targeting legacy routers and NAS devices to build reconnaissance and attack infrastructure. The malware exploits vulnerabilities from 2013-2025 to compromise over 4,300 devices globally, primarily D-Link routers using RTL819X chips. AryStinger communicates via HTTP/HTTPS using Protobuf encoding and XOR encryption, supporting tasks including network scanning, traffic proxying, command execution, and persistent backdoor deployment through dropbear or gs-netcat. Two versions exist: RTL819X in C for routers, and Standard in Go for NAS devices with expanded capabilities including integration of fscan, ksubdomain, and httpx tools. Infected devices serve as distributed scanning nodes and attack proxies, effectively hiding attacker identities while conducting footprinting activities. The campaign shows extremely low detection rates in mainstream security engines, with evidence suggesting operations possibly began in 2024.

140+ npm Packages Compromised in Coordinated Supply Chain Attack

released on 2026-06-17 @ 01:38:33 PM
More than 140 Mastra npm packages were compromised through a supply chain attack that injected a typosquatted dependency called easy-day-js. A single npm account published malicious versions within a short timeframe, affecting packages including @mastra/core with over 918K weekly downloads. The attack executes during npm install via a postinstall hook, deploying a two-stage payload. The first stage disables TLS validation and downloads a second-stage implant that installs cross-platform persistence on Windows, macOS, and Linux. This implant functions as a command-and-control client that steals cryptocurrency wallet inventories from 166+ browser extensions, harvests browser history, and can execute arbitrary code sent by operators. The malicious code executes before developers import packages, compromising systems during installation.

From emerging threat to top-tier ransomware-as-a-service: The evolution of INC ransomware

released on 2026-06-17 @ 01:38:13 PM
INC has evolved from an emerging ransomware-as-a-service operation into one of the most active groups in 2026, claiming over 800 victims since 2023. The disruption of LockBit and BlackCat's shutdown created opportunities for INC to expand as affiliates migrated. Both Windows and Linux/ESXi encryptors have been rewritten in Rust, enabling cross-platform development and increasing analysis complexity. Recent incidents reveal updated tooling, including a modified credential dumper targeting newer Veeam backup deployments with support for salted DPAPI encryption. INC's influence extends beyond its operations; following the 2024 source code sale for $300,000, related families like Lynx and Sinobi emerged. United States organizations account for over 65% of victims, with legal services, manufacturing, construction, technology, and healthcare among the most targeted sectors.

New APT-Q-27 sample spotted

released on 2026-06-17 @ 08:46:02 AM
A new campaign has been identified utilizing a valid digital signature from a Chinese technology company that remains unrevoked. The attack chain employs a dropper that retrieves an extension-based module list from command and control infrastructure. The malicious payloads exploit DLL Side-Loading techniques through a legitimate Tencent-signed executable to achieve code execution. The infrastructure includes Google Cloud Storage and a dedicated domain for command and control operations. Multiple components have been identified including an EXE dropper, DLL loader, DAT payload, and the legitimate Tencent executable used for side-loading purposes.

Bluekit Phishing as a Service (PhaaS)

released on 2026-06-16 @ 11:44:00 PM
BlueKit operates as a mature commercial Phishing-as-a-Service platform offering 87 ready-made phishing kits targeting banks, cloud services, cryptocurrency exchanges, and global brands. The platform features subscription-based access, automated account takeover capabilities, peer-to-peer infrastructure for stealth, and integrated anti-detection tooling. BlueKit supports credential harvesting, session hijacking, and automated post-compromise workflows including password resets and passkey enrollment. The platform includes bulk SMS phishing capabilities, Telegram notifications, hardware wallet seed phrase harvesting, and integration with anti-detect browsers. Operating through Tor and clearnet domains with cryptocurrency payments, BlueKit employs a reseller model enabling white-label redistribution. The platform significantly lowers technical barriers for cybercriminals while providing enterprise-grade phishing infrastructure, posing critical threats to financial institutions, cloud environments, and cryptoc...

Attackers Weaponize Microsoft Teams Relays to Stay Hidden

released on 2026-06-16 @ 02:44:33 PM
Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei's HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce's evolution into a highly capable ransomware cartel with advanced operational maturity.

Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack

released on 2026-06-16 @ 02:27:52 PM
A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.

Android Banker with Complete Device Takeover Capabilities

released on 2026-06-16 @ 02:27:52 PM
A newly identified Android banking trojan named Rokarolla has been discovered, distributed through malicious websites masquerading as popular applications like TikTok or Google Chrome. The malware targets 217 distinct cryptocurrency and banking applications using 137 sophisticated commands for device control. Capabilities include harvesting lock screen credentials, exfiltrating contact lists and SMS data, deploying keyloggers, blocking calls, creating fraudulent screen overlays, and disabling Google Play Protect. The infection begins with a dropper impersonating Google Play Protect that installs a secondary payload. Rokarolla communicates with C2 infrastructure via HTTPS, uses overlays to steal banking credentials and device unlock patterns, silently monitors WhatsApp contacts, hijacks SMS and calls, manipulates clipboard content for cryptocurrency theft, and employs snapshot-based screen surveillance. It maintains persistence by hiding its icon, muting device audio, and keeping screens active indefinitely.

Gamers beware: malicious wallpapers on Steam found stealing accounts

released on 2026-06-16 @ 09:50:13 AM
Since late 2025, cybercriminals have been exploiting Wallpaper Engine, a popular live wallpaper application on Steam, to distribute malware through Steam Workshop. Attackers target primarily Chinese and Russian gamers by embedding malicious code within application wallpapers shared on the platform. These compromised wallpapers deliver various malware types including infostealers, backdoors, crypto miners, and ransomware. One analyzed sample dropped DarkKomet backdoor while hijacking Steam sessions to steal account credentials. The malware modifies system libraries to locate Steam installations and exfiltrate data to attacker-controlled servers. Compromised accounts are then used to upload additional malicious wallpapers. The diverse malware families suggest multiple independent hacking groups are exploiting this distribution method. Infected wallpapers received thousands of downloads before removal, with 89% of infections occurring in China.

Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis

released on 2026-06-16 @ 05:29:40 AM
An investigation revealed a malicious email campaign directing victims to download a ZIP file from MediaFire. The infection chain began with a Python setup executable (Setu.exe) that side-loaded a malicious 400 MB python37.dll containing repeated byte padding. The DLL performed process injection into dllhost.exe, establishing communication with a C2 server at 138.124.186.2:7000. The threat actor deployed three persistence mechanisms: a PowerShell-based path, a fake EdgeUpdate Python executable with scheduled task, and NetSupport RMM as a third access method. The analysis highlights the importance of comparing file timestamps during triage to identify malicious artifacts within compressed archives.

WebAssembly Malware Found in Trojanized Open VSX Extensions

released on 2026-06-16 @ 04:27:32 AM
Trojanized Visual Studio Code extensions distributed via the Open VSX marketplace deliver a sophisticated WebAssembly-based attack chain. The extensions ship ChaCha20-encrypted TinyGo-compiled WebAssembly modules that poll the Solana blockchain for command-and-control instructions embedded in transaction memos. This novel dead-drop technique allows attackers to rotate infrastructure without hardcoded servers. Once activated, the modules read attacker instructions from a monitored Solana wallet address, then execute platform-specific download-and-execute commands via Node.js child_process to deploy second-stage payloads. The campaign impersonates legitimate extensions on Open VSX, exploiting cross-registry trust gaps to target VSCodium, Cursor, Windsurf, and other VS Code forks. Attribution points to GlassWorm-associated tradecraft with medium confidence, representing a new WebAssembly-based variant of previously documented supply chain compromise techniques.

How attackers are jailbreaking LLMs with CTF framing and how to catch them

released on 2026-06-15 @ 07:33:13 PM
Threat actors are bypassing AI model safety guardrails by framing exploit requests as legitimate security research, such as capture-the-flag challenges or CVE-hunting exercises. This technique manipulates upstream LLMs into generating working exploit code that attackers deploy against real targets. Multiple independent operators have been observed targeting five applications—PraisonAI, LiteLLM, FastGPT, Open-WebUI, and Gotenberg—using CVE-templated User-Agent strings and similar framing across multiple fields including passwords and AWS session names. The jailbreak framing leaks into every LLM-generated field because the model incorporates the prompt context into its output. This pattern represents a shift from manually written scanners to LLM-assisted exploit generation, creating detectable fingerprints across request headers, account aliases, and IAM session names that legitimate traffic rarely exhibits.

Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

released on 2026-06-15 @ 07:33:12 PM
A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection requirements.

How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches

released on 2026-06-15 @ 02:58:19 PM
SearchJack represents a coordinated campaign comprising 23 deceptive Chrome browser extensions that silently hijack users' default search engines, redirecting queries through monetization middleware before delivering results. These extensions masquerade as various productivity tools, satellite imagery viewers, maps, and news readers while their actual purpose is generating search affiliate revenue. The campaign affects approximately 758,000 users across 22 unique publishers and leverages at least 8 distinct monetization brokers, primarily routing traffic through Yahoo Hosted Search affiliate programs. The extensions employ manifest-only wrappers using chrome_settings_overrides to hijack search settings, with some implementing runtime obfuscation to evade static analysis. Several extensions feature false privacy claims, anomalous review patterns, and anonymous publishers with fictional corporate identities, enabling operators to monetize user search behavior while maintaining zero accountability.

Inside OnyxC2: The New Stealer Targeting 210 Apps

released on 2026-06-15 @ 02:58:18 PM
OnyxC2 emerged in early 2026 as a malware-as-a-service stealer sold on cybercrime networks for $250 monthly. The platform includes a web panel, payload builder, and tiered pricing structure with refund guarantees. Written in C++ with assembly for direct syscalls, it targets approximately 210 applications across nine categories: 45 browsers, 109 extensions including 2FA tools, 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, 5 email clients, and VPN/messaging applications. The stealer achieves 99% detection evasion through mutated builds and delivers via DLL sideloading using signed binaries. Higher tiers unlock remote access capabilities including HVNC, LSASS dumping, reverse SOCKS5 proxy, keylogging, and reverse shell. Distribution occurs through fake installers delivered as password-protected archives, with C2 communication over Cloudflare-fronted HTTPS to akmuniverstall.top.

Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

released on 2026-06-15 @ 02:58:18 PM
A sophisticated Python-based RAT targeting Korean users through spear phishing emails disguised as Microsoft security alerts. The attack chain employs LNK files embedded in ZIP archives, BAT-based obfuscation, and multi-stage loaders culminating in NarwhalRAT deployment. This advanced malware features keylogging, screen capture, microphone recording, and USB data collection capabilities. It utilizes a dual C2 infrastructure combining Korean relay servers (daehoat.com, novel21.co.kr) with pCloud API as a dead-drop resolver. The malware creates encrypted configuration files, implements anti-VM techniques, and establishes persistence through scheduled tasks. It operates as a manually-controlled RAT with selective function activation via C2 commands, employing in-memory execution to evade file-based detection.

Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years: How Cybercriminals Are Targeting Travelers in 2026

released on 2026-06-15 @ 02:53:05 PM
The hospitality and travel sector experienced a dramatic surge in cyberattacks, with organizations facing an average of 2,291 weekly attacks in May 2026, representing a 24% year-over-year increase and a cumulative 122% rise since 2023. Cybercriminals registered 47,318 travel-related domains in May 2026 alone, with one in every 112 classified as malicious or suspicious. Three coordinated bulk-registration campaigns were identified, including sequential hotel-lure domains, American Express and Lloyds Travel Choice impersonations, and widespread Fora Travel brand abuse across 108 TLDs. Active phishing operations target major platforms including Booking.com, Airbnb, and Skyscanner through lookalike domains designed to harvest credentials and payment information. These attacks deliberately intensify during peak summer booking season when travelers are distracted and eager for deals, exploiting the industry's high volume of personal and financial data processing.

The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed

released on 2026-06-15 @ 02:53:04 PM
On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.

OptinMonster supply chain attack hits 1.2 million sites

released on 2026-06-14 @ 02:55:34 PM
An active supply-chain attack targeted over 1.2 million WordPress sites using OptinMonster, TrustPulse, and PushEngage plugins operated by Awesome Motive. Attackers injected malicious JavaScript into legitimate files served through Awesome Motive's CDN endpoints. The malware activates when a logged-in administrator accesses the site, creating backdoor admin accounts (developer_api1 and randomized dev_xxxxxx accounts) and installing a self-hiding PHP plugin. The backdoor provides unauthenticated code execution through a web shell and eval endpoint. Stolen credentials are exfiltrated to tidio.cc, a lookalike domain mimicking the legitimate tidio.com. The breach likely originated from compromised Awesome Motive servers or their BunnyNet CDN account. The campaign began in late April 2026 and remained active through mid-June, affecting OptinMonster (over 1 million installations), TrustPulse, and PushEngage users.

The Package That Never Shipped: Following a USPS Smishing Kit Through DNS Data

released on 2026-06-13 @ 02:59:22 AM
A sophisticated smishing campaign impersonates United States Postal Service (USPS) package delivery notifications via SMS. The kit serves genuine USPS production HTML, CSS, fonts, and images verbatim, including live Google Analytics tags firing to USPS infrastructure. It captures victim card data in real-time through WebSocket connections, streaming keystrokes, performing server-side BIN lookups, and pushing routing decisions back to victim browsers. Starting from a single lure hostname, passive DNS analysis revealed 682 unique lookalike domains across seven Tencent Cloud hosts. A parallel UPS-themed campaign runs on the same infrastructure, with both variants sharing the internal theme name us_post_ups in cookies. The operation spans two distinct backends (GoFrame and Spring Boot) while maintaining identical real-time exfiltration mechanics and Caddy reverse proxy architecture.

Interlock and Rhysida within the Ransomware Ecosystem

released on 2026-06-12 @ 09:29:01 PM
This analysis examines over two years of observations on the ransomware ecosystem surrounding Interlock and Rhysida threat groups. Hive0163 (Interlock) employs custom malware including NodeSnake, InterlockRAT, JunkFiction downloader, Supper, and Interlock ransomware, with identified links to TAG-124. Rhysida actors utilize Endico downloader, Broomstick, Supper, and Tomb crypter, showing relationships with IceNova operators and ITG23. Strong code overlaps between NodeSnake, JunkFiction downloader, InterlockRAT and Supper indicate shared codebases or common developers. Both groups primarily target U.S. organizations across multiple sectors, using trojanized installers, ClickFix campaigns, and traffic distribution systems for initial access. Analysis of post-exploitation payloads reveals broad, adaptable toolsets including custom WDAC policies, credential phishing tools, and various privilege escalation exploits, demonstrating sophisticated ransomware operations.

How to defend ARM64 cloud infrastructure

released on 2026-06-12 @ 04:57:59 PM
ITScape (CVE-2026-46316) is a guest-to-host escape vulnerability in the vGIC-ITS emulation within KVM/arm64, disclosed by researcher Hyunwoo Kim. The flaw stems from a race condition in the vgic_its_invalidate_cache() function causing a double-put use-after-free, enabling host kernel code execution. Since the bug exists in in-kernel KVM rather than QEMU user-space, successful exploitation grants host kernel privileges, posing significant risk to multi-tenant ARM64 cloud environments. The vulnerability can be chained with local privilege escalation when guest root access is unavailable. Affected kernels range from commit 8201d1028caa through 13031fb6b835, when the patch was applied. Two YARA rules have been developed for detection: one targeting hardcoded constants from the proof-of-concept, another identifying behavioral patterns in privilege drop sequences.

UNC1151/Ghostwriter phishing campaign targeting Gmail accounts

released on 2026-06-12 @ 04:57:58 PM
The UNC1151/Ghostwriter group is conducting high-intensity phishing campaigns targeting Gmail accounts of Polish citizens since March 2026. The campaigns primarily target individuals in political and public life, prominent positions, researchers, journalists, public administration and law enforcement employees, and their associates. Attackers use fraudulent emails impersonating Gmail administrators, claiming suspicious activity or policy violations to pressure victims into verifying their accounts. The phishing infrastructure captures login credentials and two-factor authentication codes through fake login panels. The group utilizes dedicated domains, Netlify subdomains, and compromised websites to host phishing pages. Campaigns run primarily on weekdays with new domains appearing almost daily, demonstrating persistent operational tempo against Polish targets.

Akira, LimeWire, and the Sour Taste of Data Exfiltration

released on 2026-06-12 @ 04:57:57 PM
In a recent ransomware attack, threat actors accessed a victim's hypervisor and created a new virtual machine to stage and launch Akira ransomware. The forensic investigation revealed the attackers disabled Microsoft Defender immediately, installed WinRAR for data staging, and used Easyupload.io, a file transfer website owned by LimeWire, for data exfiltration. The threat actor also utilized WinSCP and enumerated Active Directory users and computers. The newly instantiated VM lacked security tooling, allowing the attacker to operate uninhibited. Analysis of the VHDX file provided clear evidence of the attack progression, showing the threat actor moved quickly through their operations without employing sophisticated anti-forensics techniques. The incident highlights the need for organizations to monitor environments for unusual access and new endpoint creation.

Defending the Digital Pitch: World Cup 2026 Cyber Threats

released on 2026-06-11 @ 09:09:40 PM
The 2026 FIFA World Cup presents a concentrated attack surface spanning three nations, 16 cities, and billions of viewers. Cybercriminals have already launched phishing campaigns, fraudulent ticket sales, and brand impersonation schemes targeting governments, sponsors, broadcasters, transportation providers, and telecommunications companies. Financially motivated actors are exploiting tournament-related interest through credential theft and payment fraud. Hacktivist and state-aligned groups, including pro-Iranian actors like Handala and CyberAv3ngers, may conduct DDoS attacks, website defacements, or espionage operations amid heightened geopolitical tensions involving Iran, the United States, and Russia. Ransomware groups such as Qilin, DragonForce, Akira, and Play may target organizations reliant on continuous service availability. Thousands of FIFA-themed domains have been registered, many exhibiting characteristics associated with fraud campaigns. Organizations throughout the ecosystem face elevated ris...

World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat

released on 2026-06-11 @ 09:09:40 PM
Threat intelligence has uncovered a significant increase in digital scams and phishing campaigns exploiting the FIFA World Cup 2026, specifically targeting mobile users. Three primary attack campaigns have been identified: The first uses typosquatting and institutional spoofing with fake domains like fifa-tickets[.]vip to deceive ticket buyers. The second mimics major sports retailers such as Nike and Adidas, hiding infrastructure behind Cloudflare to steal payment credentials. The third campaign, dubbed OffsideHire, exploits tournament hiring through sophisticated recruitment fraud using an Adversary-in-the-Middle platform targeting corporate Google Workspace accounts with real-time MFA bypass capabilities. These campaigns leverage emotional urgency, ticket scarcity, and mobile device usage patterns to bypass traditional security controls, posing risks to both individuals and enterprise environments through credential harvesting and session hijacking.

Targets Education Sector with Oracle PeopleSoft Exploit

released on 2026-06-11 @ 09:09:39 PM
Between May 27 and June 9, 2026, UNC6240 (ShinyHunters) conducted an active compromise and extortion campaign targeting Oracle PeopleSoft application infrastructure. The threat actor exploited CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component, as a zero-day before Oracle's June 10, 2026 advisory. Over 100 organizations were potentially affected, with 68 percent operating in higher education and most based in the United States. Attackers deployed customized MeshCentral agents masquerading as Microsoft Azure services, established C2 infrastructure at azurenetfiles.net, and used lateral movement scripts to propagate across internal networks. The campaign culminated in data exfiltration and publication of stolen data on the ShinyHunters Data Leak Site on June 9, 2026. Compromised systems received defacement markers and extortion notices.

Affidavit in Support of Application for Criminal Complaint

released on 2026-06-11 @ 09:09:38 PM
An FBI investigation identified Denis Nikolayevich Obrezko, a Russian national, as facilitating cyber intrusions conducted by the Russia-aligned threat group Void Blizzard. Between June and July 2024, multiple U.S. companies across various sectors were targeted in a large-scale cyber espionage campaign involving mass email harvesting and unauthorized access. The threat actors utilized stolen session tokens, proxy services, and VPNs to authenticate to victim Office 365 environments and exfiltrate data. Obrezko allegedly obtained critical infrastructure including a virtual private server and domain registration used in these attacks. FBI investigation linked Obrezko through cryptocurrency transactions, email accounts, phone numbers, and IP addresses to domains and infrastructure used in the intrusion campaign. Eleven U.S. companies have confirmed unauthorized access, representing only a fraction of suspected victims nationwide.

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

released on 2026-06-11 @ 04:31:57 PM
A sophisticated malware campaign exploits growing interest in artificial intelligence by distributing malicious files disguised as AI-related learning resources and technical guides. The attack employs an exceptionally complex multi-stage infection chain beginning with compressed archives containing LNK shortcuts and hidden PDF files. Through multiple layers of obfuscation involving PowerShell scripts, batch files, and AutoHotkey loaders, the campaign establishes persistent access and deploys two distinct .NET Remote Access Trojans including AsyncRAT. The intermediate scripts extensively use Simplified Chinese variable names and exhibit coding patterns suggesting AI-assisted development, with cultural references to Chinese mythology used as symbolic aliases for Windows API calls. The attack implements advanced techniques including process hollowing, reflective DLL injection, and scheduled task persistence while actively disabling Windows Defender exclusions to facilitate execution.

How Lookalike Domains Exploit Human Judgment

released on 2026-06-11 @ 04:31:57 PM
Lookalike attacks exploit human cognitive shortcuts rather than technical vulnerabilities, designing domain names that resemble legitimate services to bypass security controls. These attacks leverage predictable patterns in how people read and process text, using techniques including homographs, typosquatting, domain embedding, and keyword association. The domain name itself embeds targeting intent, making attacks visible in DNS infrastructure before malicious activity occurs. Attackers face deliberate tradeoffs between plausibility and uniqueness, often maintaining domains in dormant states between campaigns to evade takedown. DNS provides early structural signals about attacker intent and brand targeting, though ambiguity remains inherent as legitimate services often exhibit similar patterns. Effective detection requires separating targets from imposters and understanding that domain-based analysis surfaces risk rather than definitive verdicts.

Threat Actors Target FIFA World Cup 2026

released on 2026-06-11 @ 04:31:36 PM
A sophisticated Chinese-origin fraud operation is targeting FIFA World Cup 2026 attendees through pixel-perfect website clones and a multi-tenant phishing infrastructure. The actors deploy typosquatted domains and a commercially developed administrative system to mimic legitimate FIFA ticketing platforms. Technical analysis reveals high-fidelity brand cloning, real-time card skimming capabilities, and a distributed reseller ecosystem supporting at least 15 active operator instances. The platform functions as an active Man-in-the-Middle framework intercepting payment card details and bypassing SMS-based two-factor authentication in real time. Traffic is primarily driven through Facebook and Instagram in-app browsers. Simplified Chinese localizations and operator geolocations from IP addresses in China indicate PRC-based actors. The core payment routing hub tbpay[.]uk lacks financial regulatory authorization and has historical malicious patterns.

Cyber-Enabled Maritime Sanctions Evasion

released on 2026-06-11 @ 04:08:08 PM
Iranian and Russian shadow fleet vessels are utilizing sophisticated online infrastructure consisting of over 36 inauthentic websites to facilitate sanctions evasion. These websites impersonate ship registries, national maritime administrations, seafarer training organizations, protection and indemnity clubs, and classification societies from jurisdictions including Comoros, Benin, Bhutan, Cameroon, Chad, Equatorial Guinea, Gambia, Haiti, Malawi, Nicaragua, and Zambia. The infrastructure operates through three identified clusters designated Alpha, Bravo, and Charlie, which demonstrate technical overlaps suggesting a broader ecosystem supporting multiple sanctions evasion networks. Operators employ tactics including automated document generation, typosquatting, identity spoofing, and mutual endorsement loops between fraudulent entities. Attribution includes links to Indian web development company Oceaniek Technologies and two Syrian nationals. The infrastructure has documented connections to seventeen vesse...

From external espionage to domestic targeting

released on 2026-06-11 @ 02:15:47 PM
Analysis of OceanLotus activities from 2024-2026 reveals a strategic shift toward domestic espionage within Vietnam. The Vietnam-aligned APT group conducted two distinct campaigns using the SPECTRALVIPER backdoor: a supply-chain attack compromising FireAnt Metakit stock trading platform from October 2025 to March 2026, and a prolonged intrusion into a Vietnamese infrastructure and transport construction corporation from mid-2024 through January 2026. The FireAnt compromise exploited the platform's insecure update mechanism, targeting stock investors with selective deployment. This operational pivot coincides with Vietnam's Blazing Furnace anti-corruption campaign, suggesting possible alignment with domestic investigative efforts against financial crime. The group continues demonstrating sophisticated tactics despite public exposure of its front company in 2020, maintaining technical innovation in tooling and infrastructure.

Targeted espionage against Cambodian government entities

released on 2026-06-11 @ 11:50:23 AM
Acronis Threat Research Unit identified two espionage campaigns targeting Cambodian government entities in defense and public works sectors, attributed to a cluster tracked as Khmer Shadow. Both campaigns delivered a custom C++ loader named NIGHTFORGE through government-themed lures in self-extracting archives. NIGHTFORGE employs sophisticated evasion techniques including NTDLL unhooking and Hell's Gate syscall resolution to decrypt and execute a Havoc Demon payload in memory. The loader utilizes DLL sideloading through a legitimate VMware-signed binary (VMwareNamespaceCmd.exe) and establishes persistence via COM-based scheduled tasks. Despite advanced technical capabilities, the actor demonstrated poor operational security by reusing identical payloads and infrastructure across targets. The campaigns targeted Cambodia's Information Collection Bureau and Ministry of Public Works and Transport using meeting-themed social engineering lures.

Sniper's Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud

released on 2026-06-11 @ 11:49:42 AM
An investigation into phishing activity targeting users across the Middle East and North Africa uncovered SniperDz, a centralized Push-Notification-as-a-Service and Phishing-as-a-Service platform. The operation uses fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations to promote fake offers including free mobile internet packages and financial compensation. Victims are redirected through trusted link-aggregation services like Linktree and Linkbio to evade detection. SniperDz provides 80 phishing templates mimicking over 30 global brands across financial services, social media, streaming, and gaming platforms. The infrastructure employs browser notification abuse, history manipulation creating a back-button prison, premium SMS subscriptions, premium-rate calls, investment scams, and affiliate marketing for monetization. Analysis revealed over 900 suspicious domains linked to shared hosting infrastructure and a recurring VAPID public key connecting multiple campai...

China-Linked Fake Consulting Sites Targeting US Clearance Holders Seized

released on 2026-06-11 @ 07:23:06 AM
US Federal authorities have seized 13 domains allegedly used in a Chinese intelligence-linked operation to recruit Americans with access to classified government information. The websites posed as legitimate consulting firms, offering vague consultancy and advisory roles to current and former US government employees, military personnel, and security clearance holders. The operation, which began in November 2023, used fake company websites, online job postings, and social media recruiting to approach potential targets. Recruiters offered paid consulting work, then pressured candidates to share confidential insider information. The campaign employed false personas, stolen identities, AI-generated profile photos, encrypted messaging, cryptocurrency, and fake contracts to appear legitimate. Job postings appeared on platforms including Upwork, Expertia AI, and Hubstaff Talent, covering topics aligned with Chinese government interests.

Fake Software Tutorials on TikTok Spread Vidar Stealer

released on 2026-06-10 @ 04:22:44 PM
Threat actors are leveraging TikTok and Instagram Reels to distribute the Vidar infostealer through fake software tutorials. Two distinct campaigns use short-form videos disguised as tutorials for unlocking premium software like Spotify. The first campaign uses accounts mimicking official Windows profiles with AI-voiced clips instructing users to run PowerShell commands that download Vidar from lookalike domains. One video achieved over 100,000 views. The second campaign uses ordinary accounts posting music-backed clips that bait users in comments to receive malicious links via direct message. These campaigns exploit platform recommendation algorithms by encouraging saves and shares. Vidar is sold as a service for $300 lifetime license and harvests credentials, financial data and authentication tokens.

Ransomware Analysis: Go Binary and Fast Encryption

released on 2026-06-10 @ 11:58:43 AM
The Gentlemen is a Ransomware-as-a-Service operation, tracked as Storm-2697, that emerged in mid-2025 after splitting from Qilin ransomware following a payment dispute. Operating as a highly structured syndicate with at least 9 core operators, the group has compromised over 1,570 organizations across 70+ countries, with approximately 71-78% paying ransoms and never appearing on public leak sites. The operation uses custom Go and C-compiled cross-platform lockers featuring partial encryption modes (0.3%-9% per file), built-in lateral movement via WMI and PowerShell remoting, aggressive defense evasion including Windows Defender disabling and event log clearing, and self-propagation capabilities. A formal partnership with BreachForums in May 2026 expanded distribution through integrated affiliate onboarding. Despite sophisticated encryption using X25519 key exchange and XChaCha20, a critical CWE-244 implementation flaw allows key recovery from process memory dumps.

SilabRAT, What's Your Power?

released on 2026-06-10 @ 11:58:30 AM
SilabRAT is an advanced Remote Access Trojan offered as Malware-as-a-Service on Darkweb forums since late 2025, developed by threat actor o1oo1 and sold for $5,000 monthly. This financially-motivated tool focuses on credential theft and cryptocurrency operations, featuring Hidden Virtual Network Computing for invisible remote control, browser profile cloning to bypass session protections, and automated cryptocurrency wallet password cracking. The RAT bypasses Chrome App-Bound Encryption, performs session hijacking, and includes keylogging, clipboard monitoring, and remote desktop capabilities. Distributed through phishing and ClickFix campaigns with operator-hosted infrastructure, SilabRAT uses ChaCha20-Poly1305 encryption for command-and-control communications. The developer also offers AsmCrypt, a companion crypter service, creating a complete malware bundle from evasion to execution and remote control.

PHISH ALERT: Press Play for Compromise — Voicemail Phishing Kit Bundles SSO Hijacking, Credential Theft, and RMM Delivery

released on 2026-06-10 @ 10:57:37 AM
An advanced voicemail-themed phishing campaign is utilizing HTML attachments to hijack Microsoft 365 sessions through silent OAuth exploitation. Emails arrive spoofing legitimate businesses with fake voicemail notifications containing embedded HTML files. When victims click the play button, the kit triggers a rogue OAuth 2.0 request using the prompt=none parameter to steal authentication tokens from active M365 sessions. If no active session exists, victims are redirected to credential harvesters hosted on compromised infrastructure, specifically a Turkish domain hosting over 100 active campaign directories. The operation includes multiple attack vectors: fake login portals mimicking DocuSign, Outlook and Google, OAuth device code phishing interfaces, and RMM deployment disguised as document viewers. This represents a sophisticated Phishing-as-a-Service operation deploying concurrent attack types from consolidated infrastructure.

Technical Analysis of MLTBackdoor

released on 2026-06-09 @ 08:11:50 PM
In May 2026, a new malware family named MLTBackdoor was identified, likely leveraged by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains targeting automotive-related web pages, this backdoor employs sophisticated obfuscation techniques including Mixed Boolean-Arithmetic and Control Flow Flattening. MLTBackdoor features indirect system calls, API hashing, and extensive anti-analysis checks that detect debuggers and sandboxed environments. Its capabilities include filesystem operations and a powerful Beacon Object File loader that dynamically expands functionality. The malware uses custom encrypted binary protocols over TLS with Elliptic-Curve Diffie-Hellman key exchange for command-and-control communications. Additionally, it implements a deterministic date-based Domain Generation Algorithm to maintain persistence when hardcoded C2 domains become unreachable, demonstrating advanced resilience against takedown attempts.

Phishing Attacks Leverage TikTok, Instagram Reels

released on 2026-06-09 @ 08:11:49 PM
Threat actors are exploiting short-form video platforms like TikTok and Instagram Reels to conduct social engineering attacks. Two distinct campaign methods have been identified: professional-looking fake tutorials with AI-generated voiceovers promising free premium software, and casual videos showcasing premium features to generate engagement through comments. Both approaches direct victims to malicious websites hosting infostealer malware, particularly Vidarstealer. The campaigns leverage platform algorithms through high engagement rates including saves, shares, and comments. Attackers use multiple accounts with Windows-themed branding and manipulate PowerShell commands to download malicious executables. These techniques are difficult to counter as creators can delete warning comments and platform reporting mechanisms prove ineffective. The attacks target non-technical users seeking free access to premium services like Spotify, Microsoft Office, and other software, making social media feeds an emerging p...

From Fake Amazon Security Alert to HarborWatch Agent: ClickFix Delivery of a Custom Monitoring RAT

released on 2026-06-09 @ 03:50:23 PM
A sophisticated phishing campaign exploits Amazon's brand reputation through spoofed security alerts to deliver HarborWatch Agent, a custom remote access trojan. The attack chain begins with emails impersonating Amazon security notifications about suspicious account activity, directing victims to lookalike domains. Users are presented with fake CAPTCHA verification pages that employ ClickFix social engineering techniques, instructing them to execute PowerShell commands on their own systems. The multi-stage infection downloads mysql.exe from compromised infrastructure, which communicates with a Chinese-language command and control panel branded Harbor Sentinel. The RAT collects extensive system information including OS details, architecture, CPU count, disk usage, memory status, and network configurations, exfiltrating data through API endpoints to the threat actor's monitoring infrastructure.

Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)

released on 2026-06-09 @ 03:50:15 PM
A critical authentication bypass vulnerability affecting Remote Access VPN and Mobile Access deployments has been actively exploited in the wild. The vulnerability exploits a logic flaw in certificate validation within the deprecated IKEv1 key exchange protocol, allowing attackers to establish VPN sessions without valid passwords. Exploitation has been observed since May 7, 2026, targeting several dozen organizations globally. One confirmed incident involved post-compromise activity linked to Qilin ransomware operations. The threat actor appears financially motivated and operates dedicated VPS infrastructure across multiple hosting providers. An additional related vulnerability affecting site-to-site VPN communications was discovered through AI-assisted code analysis, though no active exploitation has been observed. Immediate patching is strongly recommended for affected systems using IKEv1 protocol.

From Malspam to Fileless .NET Loader

released on 2026-06-09 @ 03:50:14 PM
A sophisticated malspam campaign delivers a multi-stage .NET loader through an elaborate chain beginning with HTML email attachments. The attack routes through legitimate Google DoubleClick infrastructure to evade detection, then deploys a dynamically personalized phishing kit that pulls victim company branding in real-time. The infection chain progresses through JavaScript, PowerShell, and multiple .NET components, executing primarily in-memory while actively patching AMSI and ETW to blind Windows telemetry. The loader performs extensive anti-analysis checks, terminates or reboots upon detecting sandboxes or debugging tools, and establishes persistence through registry keys and scheduled tasks disguised as NVIDIA components. It targets Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe for process injection, maintains C2 communications over non-standard ports using AES-encrypted protobuf messages, and profiles victim systems including specific GPU enumeration potentially for cryptocurrency min...

Fighting Spyware: An Update

released on 2026-06-09 @ 07:07:35 AM
WhatsApp successfully identified and disrupted spear phishing attempts linked to NSO Group, a spyware firm blacklisted by the US government. The company is requesting the court to hold NSO in contempt for violating a permanent injunction that prohibited them from targeting WhatsApp and its users. The attacks involved social engineering attempts to trick users into clicking malicious links, as well as creating test accounts and groups on the platform. WhatsApp emphasizes that spyware represents a national security threat and is supporting the Spyware Accountability Initiative through significant contributions. The company continues to protect users through end-to-end encryption and encourages reporting suspicious activity while maintaining updated applications and devices.

A First Look at a New Post-Exploitation Red Team Tool

released on 2026-06-09 @ 06:15:00 AM
A new post-exploitation red team tool named Splinter has been discovered on customer systems through Advanced WildFire's memory scanning capabilities. Developed in Rust programming language, Splinter is exceptionally large at around 7MB due to statically linked libraries. The tool uses a JSON configuration structure containing implant ID, C2 server details, and operational parameters. It operates through a task-based model with capabilities including Windows command execution, remote process injection, file upload/download, cloud service information gathering, and self-deletion. Communication with the C2 server occurs via HTTPS using specific URL paths for task synchronization, heartbeat connections, and file transfers. While not as sophisticated as Cobalt Strike, Splinter represents a growing variety of penetration testing tools that could potentially be misused by threat actors.

Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels

released on 2026-06-08 @ 07:36:05 PM
A sophisticated supply chain attack campaign has expanded to 471 affected artifacts across npm and PyPI, targeting developers through malicious packages. The campaign uses three distinct delivery methods: executable .pth startup hooks, trojanized native .abi3.so extensions that execute at import time, and a split loader-payload architecture that searches Python's sys.path. Twenty-three newly identified PyPI packages masquerade as bioinformatics tools, AI frameworks, and popular libraries like requests and Flask. The attack deploys heavily obfuscated JavaScript stealers via Bun runtime, harvesting high-value credentials including GitHub tokens, npm registry access, cloud credentials, SSH keys, and CI/CD secrets. The malware employs anti-analysis techniques with fake LLM prompt-injection headers designed to disrupt AI-assisted security scanners, while targeting developer workstations and automated build environments.

AI brands as bait: How threat actors are using the AI hype in social engineering

released on 2026-06-08 @ 07:36:04 PM
Threat actors are increasingly leveraging the global interest in artificial intelligence by impersonating popular AI platforms such as ChatGPT, Copilot, DeepSeek, and Claude in social engineering campaigns. These operations span phishing attacks, malvertising, and search engine optimization-driven tactics that ultimately lead to credential theft, financial fraud, or malware infections. Observed campaigns include ChatGPT-themed phishing collecting credit card data targeting South Africa, Claude-themed adversary-in-the-middle attacks harvesting credentials and access tokens, malvertising campaigns distributing Vidar stealer through fake AI plugin downloads, and fraudulent DeepSeek V4 installers on GitHub. The initial access broker Storm-3075 has been identified employing AI-themed malvertising, while the financially motivated actor Fox Tempest provides malware-signing-as-a-service to enhance payload legitimacy. These campaigns combine traditional social engineering tactics with AI branding to improve success...

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open

released on 2026-06-08 @ 10:30:31 AM
Two Russia-aligned campaigns continue exploiting CVE-2025-8088, a WinRAR path traversal vulnerability patched in July 2025, against Ukrainian organizations through April 2026. SHADOW-EARTH-066 deploys an evolved GIFTEDCROOK information stealer using in-memory DLL loading via direct NT system calls, harvesting browser credentials, session cookies, and documents across 35 file extensions before self-deleting. Earth Dahu employs an HTA-based infection chain delivering espionage modules through Cloudflare Workers infrastructure. Both campaigns leverage the same CVE-2025-8088 exploit but use distinct tooling: SHADOW-EARTH-066 relies on compiled C++ with RC4-encrypted C&C communication, while Earth Dahu uses script-based approaches with Dynamic DNS. The persistent exploitation nearly a year post-patch demonstrates how unmanaged software lacking centralized update mechanisms creates enduring attack surfaces that threat actors deliberately target.

Hacktivists are broadening their scope beyond political motivation

released on 2026-06-08 @ 10:30:30 AM
Kaspersky researchers uncovered interconnected hacktivist campaigns attributed to groups including 4BID, Hakerskii Kit, and C.A.S., targeting organizations primarily in Russia and Belarus, but expanding to Kazakhstan, UAE, Syria, and Egypt. Attackers exploited ProxyShell vulnerabilities in Microsoft Exchange servers to deploy fd.aspx web shells and various post-exploitation frameworks including Sliver, Havoc, Mythic Apollo, AdaptixC2, and a custom BlackSalt backdoor. The campaigns deployed ransomware including ClearWater and updated versions of Blackout Locker, alongside EDR killers using BYOVD techniques. Attackers leveraged legitimate RMM tools like AnyDesk, Panorama9, and Tactical RMM for persistence, with AI-generated scripts showing varying quality. The geographical expansion and increased use of ransomware suggest a shift from purely political motivation toward financial gain.

Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency

released on 2026-06-08 @ 10:05:37 AM
Between April and May 2026, a likely North Korean threat actor conducted phishing campaigns targeting developers across nearly 100 organizations in finance, cryptocurrency, education, and technology sectors. The attacks used recruitment and code review themes, delivering emails with links to actor-controlled GitHub repositories hosting malicious scripts. The infection chain exploited Visual Studio Code workflows and deployed malicious Visual Studio Extensions (VSIX) requiring minimal user interaction. Cross-platform malware was executed on macOS, Linux, and Windows systems, including the open-source Overlord framework. The campaigns specifically targeted developer assets including API tokens, cryptocurrency wallets, and credentials. Attackers employed fake company personas and professional-looking repositories masquerading as legitimate cryptocurrency and blockchain projects to establish credibility and lure victims.

Miasma Worm Campaign Spreads with New PyPI Wave

released on 2026-06-07 @ 11:21:59 AM
A coordinated PyPI compromise campaign involving 37 malicious wheel artifacts across 19 packages was detected, utilizing Python startup hooks to execute credential-stealing payloads. The attack leverages .pth files for automatic execution during Python interpreter startup, downloads the Bun JavaScript runtime, and runs obfuscated JavaScript payloads. The malware targets high-value developer and CI/CD credentials including GitHub, npm, PyPI, cloud providers (AWS, GCP, Azure), Kubernetes, Vault, SSH keys, and AI tool tokens. This represents a PyPI branch of the Shai-Hulud/Miasma campaign family, using a Hades-themed variant for GitHub exfiltration. Compromised packages included established bioinformatics tools with significant download counts, stemming from apparent maintainer account takeover. The payload employs multi-layer obfuscation, AES-GCM encryption, and exfiltrates data through GitHub repositories with distinctive markers. The campaign demonstrates cross-runtime attack capabilities and ecosystem-spe...

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

released on 2026-06-05 @ 06:07:51 PM
From January through May 2026, a financially motivated data theft extortion campaign executed by threat cluster UNC3753 targeted dozens of organizations across professional, legal, and financial services in the United States. The threat actors leverage voice phishing and social engineering techniques, posing as IT support to convince targets to host screen-sharing sessions and download remote monitoring and management utilities. Once inside environments, they conduct searches to locate and exfiltrate highly sensitive data including proprietary legal agreements, personally identifiable information, and financial records for subsequent extortion demands. The entire attack sequence often occurs within a single business day, with recent incidents showing data theft initiated in under an hour. Notably, threat actors have also accessed victims' systems in person, with individuals posing as IT technicians entering corporate offices to attempt direct exfiltration using USB storage media.

Agentic AI Uncovers New China-Linked Cluster OP-512

released on 2026-06-05 @ 06:07:51 PM
A newly identified China-linked espionage cluster designated OP-512 has been discovered targeting Internet Information Services (IIS) servers through advanced AI-driven detection. The operation involves deploying a sophisticated custom web shell framework consisting of three components: a file manager with command-and-control notification channel and two cryptographically authenticated command handlers. Each deployment is cryptographically unique, utilizing RSA and RC4 encryption alongside timestomping techniques to evade signature-based detection. The attacker maintained persistence for 75 days before rapid deployment of multiple access paths, privilege escalation tools including BadPotato, SweetPotato, and EfsPotato, and establishment of dual notification channels through DNS and HTTP. The framework employs hex-encoded subdomain queries for self-reporting and automated builder-generated code with randomized variables. This represents the fourth China-linked cluster documented targeting legacy IIS infrast...

VerdantBamboo: Just Another BRICKSTORM in the Firewall

released on 2026-06-05 @ 06:07:50 PM
Chinese threat actor VerdantBamboo compromised a victim organization and its Managed Services Provider over an 18-month period, deploying malware on network edge devices lacking EDR coverage. The initial breach involved an Egnyte Storage Sync system, where attackers exploited a sudo misconfiguration for privilege escalation and installed BRICKSTORM backdoor and AGENTPSD fallback implant. Investigation revealed the MSP's pfSense firewall was also compromised with a FreeBSD variant of BRICKSTORM. After remediation, VerdantBamboo regained access through stolen firewall credentials, enabling custom VPN access and deploying PLENET backdoor on a Synology NAS. The threat actor leveraged compromised systems as proxies to access Microsoft 365 environments while evading security controls. VerdantBamboo demonstrated operational discipline by targeting appliances without EDR capabilities and using sophisticated malware including PLENET, compiled with .NET Native AOT to hinder analysis.

Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

released on 2026-06-05 @ 05:40:45 PM
An unidentified threat actor is actively exploiting CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway components. The flaw allows unauthorized attackers to circumvent security controls and initiate VPN connections. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on May 29, 2026. Exploitation activity has been detected targeting GlobalProtect, with a small portion of probed devices successfully establishing VPN sessions. No post-access behavior or lateral movement has been identified. Organizations are advised to hunt for indicators including specific IP addresses, suspicious host IDs, and MAC addresses. Palo Alto Networks recommends following security advisory guidance, implementing available workarounds, and upgrading to patched versions.

Operation TaxShadow: Multi-Region Tax Phishing & In-Memory Malware Campaign

released on 2026-06-04 @ 10:52:21 PM
A sophisticated multi-stage malware campaign targets victims through tax-themed phishing emails impersonating Indian and Japanese government authorities. The operation leverages social engineering, fraudulent tax notifications, and trusted third-party email delivery services to distribute ZIP archives containing three staged payloads. The malware implements advanced evasion techniques including DLL Search Order Hijacking, API hooking, token manipulation, Mersenne Twister-based execution logic, COM callback execution, mutated RC4 encryption, and reflective PE loading. Execution occurs primarily in memory, significantly reducing forensic artifacts. The malware establishes persistent WebSocket-based command-and-control communication through HTTP protocol upgrades, allowing malicious traffic to blend with legitimate activity. Chinese-language artifacts were observed throughout the infrastructure and code, though attribution remains at moderate confidence. The campaign demonstrates characteristics of a mature, ...

ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery

released on 2026-06-04 @ 10:52:19 PM
A multi-stage phishing campaign emerged in early May 2026, impersonating LinkedIn and Indeed through typosquatted domains to deliver malicious payloads. The attack chain begins with fake CAPTCHA pages distributed via Google Ads, leveraging the legacy Finger protocol and native Windows utilities. Victims are tricked into executing commands that deploy portable Python runtimes (CPython or IronPython), which then execute in-memory shellcode. The campaign delivers CastleLoader, a Malware-as-a-Service framework using ChaCha20 and RC4 encryption for C2 communications, followed by a Python-based remote access trojan. The RAT provides interactive shell control, in-memory payload execution, and persistence mechanisms. The campaign represents an evolution of browser-based social engineering, combining Living-off-the-Land binaries with Python-based delivery to maintain a fileless footprint and evade detection through legitimate system utilities.

Latest goon squad to use fake helpdesk calls to steal creds

released on 2026-06-04 @ 10:52:19 PM
A new extortion group called Pink, tracked as cluster CL-CRI-1147, employs voice phishing and fake IT helpdesk impersonation to compromise organizations. The gang steals employee credentials, bypasses multi-factor authentication, and exfiltrates data from cloud storage platforms like SharePoint and OneDrive. Pink threatens to leak stolen information unless ransom demands are met, setting 72-hour deadlines. The group's data-leak site launched on May 31, 2026. This approach mirrors tactics popularized by Lapsus$, Scattered Spider, and ShinyHunters. Incident responders link Pink to The Com, a loosely connected network of English-speaking hackers and extortionists. Attackers use compromised victim accounts and internal Teams messages for extortion communications, reusing domains across multiple targets.

Matryoshka #3/3: Gamaredon's Gammasteel Infostealer

released on 2026-06-04 @ 01:57:26 PM
This analysis examines Gamaredon's (UAC-0010, Armagedon) advanced espionage operations targeting Ukrainian government, military, and critical infrastructure. The FSB-operated group deploys GammaSteel, a sophisticated stealer operating almost entirely from memory using Windows DPAPI encryption and storing 71 distinct payload functions in the HKCU\Printers registry key. The malware employs three concurrent data acquisition mechanisms: timed drive scans, USB monitoring for air-gapped systems, and real-time file surveillance. Exfiltration occurs via legitimate S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled servers. The infection chain extensively uses VBScript for evasion, Dead Drop Resolvers on platforms like Telegram and Mastodon for C2 configuration, and includes bidirectional backdoor capabilities enabling arbitrary remote code execution. Infrastructure demonstrates high automation with servers rotated approximately every 24 hours.

Argamal: Malware hidden in hentai games

released on 2026-06-04 @ 09:19:53 AM
In April 2026, researchers discovered a malware campaign targeting players of adult-themed games. The infected games install a previously unknown implant called Argamal that downloads and executes a RAT after several days, resulting in full system compromise. The malware uses COM hijacking to persist, replacing the InprocServer32 entry for Windows Color System Calibration Loader DLL. Delivery occurs through trojanized games distributed via dedicated websites and torrent trackers, containing modified FFmpeg DLLs that load malicious components. The RAT provides broad functionality including system control, surveillance, file operations, and reconnaissance capabilities. Hundreds of victims have been identified primarily in Russia, Brazil, Germany, and Vietnam. Attribution suggests a Spanish-speaking developer, with infrastructure pointing to ASN 11664 and multiple C2 domains.

Preinstall to persistence: Inside the npm Miasma credential-stealing campaign

released on 2026-06-04 @ 09:19:14 AM
Microsoft Threat Intelligence discovered a large-scale npm supply chain attack compromising 32 malicious packages across over 90 versions under the @redhat-cloud-services scope. The compromise originated from the RedHatInsights/javascript-clients CI/CD pipeline, enabling attackers to publish trojanized packages through legitimate GitHub Actions OIDC workflows with authentic provenance signatures. The malicious packages executed a heavily obfuscated 4.29 MB dropper via npm preinstall hooks, which downloaded the Bun JavaScript runtime and launched payloads designed to harvest credentials from GitHub, npm, AWS, Azure, GCP, HashiCorp Vault, Kubernetes, and developer systems. The malware scraped GitHub Actions runner memory for secrets, escalated privileges using passwordless sudo, exfiltrated stolen data through GitHub infrastructure, and propagated by compromising additional maintainer packages with forged SLSA provenance. The campaign marker "Miasma: The Spreading Blight" was embedded throughout the malicious

Browser Spy-Ons: Threat Actor's Extension Hijack Your AI Conversations

released on 2026-06-04 @ 02:46:49 AM
Multiple malicious Chrome extensions are exploiting the growing use of AI platforms by disguising themselves as legitimate productivity tools while secretly stealing user conversations and personal data. Extensions including Urban VPN, Smart Sidebar, and AI Assistant/Chat AI collectively reach millions of users but contain hidden scripts that intercept communications with popular AI platforms like ChatGPT, Claude, DeepSeek, Gemini, and others. These extensions inject malicious JavaScript that overrides network requests, monitors DOM elements for chat interactions, and exfiltrates sensitive data including conversation content, session identifiers, and timestamps to remote servers. The threat is particularly concerning as users frequently share confidential personal, medical, and corporate information with AI platforms, making intercepted conversations highly valuable for threat actors.

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

released on 2026-06-03 @ 10:14:24 PM
A new Gafgyt botnet variant named C0XMO has been discovered that spreads by exploiting a stack buffer overflow vulnerability in DD-WRT router firmware. Unlike earlier versions, this malware separates its lateral movement capabilities into a standalone Python script, enabling more efficient targeting of various system architectures including ARM, MIPS, PowerPC, and x86. The malware establishes persistence through cron jobs and shell profile modifications, eliminates competing botnets, and supports 19 different DDoS attack methods. Its scanner component performs weak-credential brute-force attacks on Telnet and SSH services while also exploiting multiple HTTP-based vulnerabilities and Android Debug Bridge unauthorized access. The malware connects to command-and-control infrastructure and demonstrates significantly more sophisticated architecture compared to traditional IoT botnets.

The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP

released on 2026-06-03 @ 10:14:23 PM
Cybercriminals in Brazil are exploiting the country's electronic invoice system (Nota Fiscal eletrônica) to deliver Havoc framework implants. The campaign surfaced during May 2026, coinciding with tax season when accountants routinely process invoice-related emails. Attackers distribute malicious ZIP files disguised as legitimate invoices, containing VBScript droppers that download MSI installers from Google Cloud Storage. These installers deploy a fake Microsoft Defender DLP module (endpointdlp.dll) alongside a legitimate signed executable. The stager DLL downloads Havoc demon shellcode from command-and-control infrastructure at runtime, never writing the final payload to disk. Analysis reveals nine stager variants originating from a single builder, distributed through multiple channels including Brazilian NF-e-themed lures and Malaysia-registered domains. The implant establishes persistence through the rarely-monitored UserInitMprLogonScript registry key and employs advanced anti-forensic techniques incl...

PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network

released on 2026-06-03 @ 05:43:40 PM
PCPJack operators compromised 230 cloud Linux servers across AWS, GCP, and Azure to build a covert SMTP relay network for email-based attacks. Researchers discovered exposed directories on infrastructure at 213.136.80[.]73 containing complete deployment toolkits including Chisel binaries, Python deployers, and operational state files. The campaign deployed Sliver C2 beacons and established reverse SOCKS5 tunnels on compromised hosts, testing each for SMTP relay capability. Three deployment versions showed operational evolution from 50 to 230 nodes, with verified proxies synchronized every five minutes to a downstream aggregation server. The operation targeted cloud-hosted web applications, exploiting them to gain initial access, then establishing persistence through systemd services and cron jobs disguised as system utilities. Victims included small to medium businesses across multiple regions running containerized and traditional workloads.

Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem

released on 2026-06-03 @ 05:42:56 PM
A large-scale operation impersonates open-source and freeware projects to capture search traffic, targeting tools such as Ghidra, dnSpy, and SpiderFoot. The professionally designed sites load CloudFront-hosted JavaScript that converts download button clicks into handoffs to a Traffic Distribution System (TDS), which enforces strict gating including first-visit state, click confirmation, anti-bot logic, VPN filtering, and frequency capping. The ecosystem appears primarily built for traffic acquisition and monetization using legitimate ad-tech, but downstream redirect chains repeatedly led selected users to malware delivery infrastructure. The observed payloads include SessionGate (a multi-stage loader with heavy obfuscation delivering potentially unwanted applications), RemusStealer (an infostealer targeting over 20 browsers and hundreds of extensions), and AnimateClipper (a cryptocurrency clipper supporting 20+ blockchain ecosystems). Over 5,000 VirusTotal submissions indicate substantial reach across the ...

FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad

released on 2026-06-03 @ 01:18:24 PM
Gamaredon, an FSB-operated cyberespionage group, continues targeting Ukrainian government, military, and critical infrastructure through sophisticated multi-stage infection chains. This analysis examines GammaLoad, a collection of VBScript loaders that establish continuous access through three distinct stages. The malware leverages Dead Drop Resolvers on legitimate platforms including Telegram, Telegraph, and Check-Host to maintain persistent C2 communications while storing configurations in Windows registry keys. Each stage employs different techniques: the first fingerprints hosts and uses failover mechanisms, the second writes payloads to Alternate Data Streams and establishes persistence via scheduled tasks, and the third executes obfuscated PowerShell to deliver the final GammaSteel payload. This matryoshka architecture enables operators to deploy arbitrary payloads while remaining largely invisible by abusing trusted Windows features and cloud platforms.

Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages

released on 2026-06-03 @ 01:18:23 PM
A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes.

Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT

released on 2026-06-03 @ 01:18:23 PM
DesckVB RAT emerged in February 2026 through a sophisticated malspam campaign utilizing a dynamic delivery kit that personalizes lures on-the-fly by extracting victim email addresses and pulling company logos in real-time. The attack chain routes through Google's DoubleClick domain to evade email gateways before delivering a five-stage infection: HTML redirect, JScript loader, PowerShell dropper, .NET loader, and finally the RAT itself. The malware employs extensive anti-analysis techniques including sandbox detection, forced reboots upon detection, and in-memory execution via .NET reflection. Once established, it patches AMSI and ETW at the native API level, injects into legitimate Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe, and establishes persistence through registry keys and scheduled tasks. The RAT communicates with DDNS-based C2 infrastructure on non-standard ports, performs system reconnaissance including GPU enumeration possibly for crypto mining, and can deliver additional payl...

TA4922: The Suspected Chinese Crime Group is Going Global

released on 2026-06-03 @ 12:55:40 PM
TA4922 is a highly sophisticated Chinese-speaking threat actor demonstrating rapid operational tempo and continually evolving malware capabilities. Initially targeting East Asia, particularly Japan, the group has expanded globally to Europe and Africa. The actor deploys multiple malware families including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0), alongside legitimate remote management tools like AnyDesk and SyncFuture. Campaigns use localized lures themed around HR, payroll, tax, and invoicing, targeting hundreds to thousands of recipients per campaign. TA4922 conducts credential phishing, fraud operations including credit card theft, and attempts to shift communications to out-of-band channels like LINE, WhatsApp, and Microsoft Teams. The group leverages legitimate cloud hosting services and trusted software for delivery and persistence, combining advanced tradecraft with financially motivated objectives such as data theft, fraud, access resale, and persistent remote access.

Espionage Campaign Targeted Stock Exchange Executive for Five Months

released on 2026-06-03 @ 12:55:40 PM
Unknown attackers conducted a five-month espionage campaign against a senior executive at a major global stock exchange, systematically stealing the victim's Outlook mailbox in incremental batches. The attackers demonstrated sophisticated operational discipline by using legitimate cloud services like Dropbox and OneDrive Personal for exfiltration and command-and-control infrastructure. They employed an Aspose-based mailbox stealer to extract OST files in date-range windows, beginning with historical emails from August 2025 and continuing with regular two-to-four-week intervals through February 2026. The intrusion maintained persistence through masquerading binaries and scheduled tasks themed around legitimate Adobe and Lenovo services. By extracting mailbox data incrementally and routing traffic through trusted cloud platforms, the attackers avoided detection while building a comprehensive intelligence picture of the executive's communications and organizational activities.

From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services

released on 2026-06-02 @ 07:07:01 PM
A significant expansion of the Kali365 phishing-as-a-service operation has been observed, now targeting multiple platforms beyond Microsoft 365. The operator abuses OAuth 2.0 device authorization flows to bypass MFA and steal authentication tokens. Key discoveries include a live command-and-control panel infrastructure, a phishing campaign impersonating MAX Messenger (Russia's state-backed messaging platform with 110 million users) through fake prize-claim flows, and a cluster of 126 malicious hosts impersonating services including Microsoft Outlook, Okta SSO, Xerox DocuShare, Mail.ru, Yandex Disk, and Odnoklassniki. The operation demonstrates a deliberate focus on Russian consumer platforms alongside Western enterprise targets, utilizing Telegram bots for credential exfiltration and employing a multi-tenant phishing platform distributed through Telegram channels.

Iran Expands Handala Brand to Physical Threats

released on 2026-06-02 @ 02:38:54 PM
Iran's Ministry of Intelligence has broadened its Handala brand beyond cyber operations to include physical threats and influence campaigns targeting US and Israeli interests. The expansion encompasses multiple personas: Handala Popular Resistance Front claiming physical attacks inside Israel, VIPEmployment recruiting proxies globally for espionage and sabotage, and MOISIRAN conducting surveillance operations. These entities engage in coordinated amplification across platforms, soliciting individuals to conduct attacks for financial rewards. The consolidation creates a multi-domain threat combining hacktivist activities with physical operations, espionage recruitment, and influence campaigns. This approach leverages Handala Hack Team's recognition to amplify recruitment efforts while increasing risks to law enforcement, military, intelligence personnel, and critical infrastructure across targeted regions.

Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

released on 2026-06-02 @ 02:33:50 PM
A financially-motivated cybercrime cluster designated CL-CRI-1089 has launched Operation FlutterBridge, deploying FlutterShell backdoor malware targeting macOS systems through malvertising. Built with the Flutter framework, FlutterShell masquerades as legitimate applications including podcast players and PDF viewers, delivering adware with full backdoor capabilities such as shell command execution and file system manipulation. The malware uses a WebView-based architecture with JavaScript-to-native bridge, allowing attackers to dynamically modify behavior without recompiling. Distribution occurs through hundreds of Google-verified advertisements controlled by shell companies including AdsParkPro LTD and Advantage Web Marketing LLC. The campaign primarily targets Anglophone and Western European markets. All samples were signed with valid Apple Developer IDs and successfully passed notarization, achieving zero detections on VirusTotal initially. The malware hijacks Google Chrome browsers, redirecting traffic ...

A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites

released on 2026-06-01 @ 07:32:48 PM
A sophisticated threat actor named DriveSurge operates as an Initial Access Broker using a Pay-Per-Install model to deliver malware at scale. The actor compromises thousands of legitimate websites and uses zTDS (Traffic Distribution System) to silently redirect visitors to malicious content. Victims encounter either FakeUpdates campaigns that impersonate browser update prompts for 11 different browsers, or ClickFix attacks that trick users into executing malicious commands through fake error messages. DriveSurge's infrastructure utilizes bulletproof hosting services, primarily NiceNIC registrar, and has been operating since at least 2015. The campaigns target both Windows and macOS systems, employing sophisticated obfuscation techniques and clipboard hijacking to achieve infection. Eight technical fingerprints have been identified to track this actor's infrastructure and activities.

Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages

released on 2026-06-01 @ 07:31:27 PM
A supply chain attack compromised multiple @redhat-cloud-services npm packages, executing malicious payloads automatically during installation via preinstall hooks. The attack uses AES-GCM encrypted payloads and obfuscated JavaScript loaders to harvest GitHub Actions secrets, npm tokens, cloud credentials (AWS, Azure, GCP), Kubernetes and Vault material, SSH keys, Git credentials, and cryptocurrency wallet files. The payload can daemonize on developer workstations, includes Russian-locale avoidance mechanisms, and exfiltrates stolen data through encrypted HTTPS channels with GitHub API fallback mechanisms. The campaign employs tactics similar to the publicly released Shai-Hulud toolkit, though attribution remains unclear due to the availability of open-source attack tooling.

FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm

released on 2026-06-01 @ 07:31:21 PM
Gamaredon, a cyberespionage group operated by Russia's FSB, conducts long-term intrusion operations targeting Ukrainian government, military, and critical infrastructure. This analysis documents their 2026 infection chain, which uses HTML smuggling with weaponized xHTML files delivering RAR archives that exploit CVE-2025-8088 to extract HTA files into Windows Startup directories. The chain deploys GammaPhish for initial access, GammaLoad for staging, GammaWorm for propagation via USB and network drives, and GammaSteal for exfiltration. The architecture is nearly fileless, leveraging NTFS Alternate Data Streams to conceal modules and using Dead Drop Resolvers on legitimate platforms like Telegram and Cloudflare for C2 infrastructure. Every stage functions as an independent backdoor capable of executing arbitrary VBScript, representing a shift from their historical Pteranodon framework to a modular ecosystem designed for persistent espionage.

A stealthy RAT burrowing deep into Android devices

released on 2026-05-31 @ 11:32:45 PM
BTMOB is an Android remote access trojan that evolved from SpySolr malware and poses significant threats beyond traditional banking trojans. The malware combines phishing-led delivery with an APK builder interface that enables rapid payload generation without coding skills. Distributed through fake app stores impersonating streaming services, cryptocurrency platforms, and government agencies, BTMOB abuses Android Accessibility Services to gain elevated permissions. Marketed as malware-as-a-service with a reported $5,000 lifetime license, it provides adversaries with capabilities to exfiltrate sensitive data, capture screenshots, record device activity, and establish remote control. The tool's customizable phishing lures have been adapted for specific regions, including campaigns impersonating Argentine tax authorities, making it a rapidly evolving threat with global reach.