Advertisement
Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth
Cheap Android TV boxes are pre-installed with Fuyao malware, impersonating phones for ad fraud and turning devices into residential proxy nodes.
Astaroth's Spambot Component: Expanding Phishing and Exfiltration
Analysis of Astaroth trojan's new spambot component, detailing its capabilities for email harvesting, spam distribution, and data exfiltration tactics.
SSH Botnet Reconnaissance Before Linux Cryptominer Deployment
An SSH botnet performs extensive hardware and system reconnaissance on Linux targets before deploying an optimized cryptocurrency miner. Weak credentials exploited.
Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service
Analysis of the 'Flying Eagle' mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…
Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence
The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.
Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay
Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.
Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience
Dysphoria IoT botnet evolves with blockchain-based C2 and victim relays after JackSkid disruption, posing new challenges for defenders.
SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly
The SourTrade malvertising operation bypasses security controls by using the victim's browser to assemble malicious Bun runtime executables in real-time.
JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses
Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.
Dolphin X Malware: AI-Driven Target Prioritization & Defense
Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…
Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware
A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.
Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence
CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.
Brazilian Banking Trojan Expansion into Portugal Targets Businesses
Portuguese businesses face increased risk from Brazilian banking trojans leveraging shared language for phishing and credential theft.
msaRAT Malware Hijacks Browser Debugging for Stealthy C2 Traffic
Chaos ransomware operators deploy msaRAT, a new backdoor using Chromium-based browser debugging features to proxy C2 traffic and evade network security.
Ransomware Attack Freezes Japanese Food Supply Chain Operations
A ransomware attack on a Japanese food and logistics firm severely disrupted frozen food supply to thousands of clients, including KFC. Analyze the impact.
Fake Bahrain Alert Apps Deploy Android Surveillance Malware
Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…
FakeGit Campaign Leverages 7,600 GitHub Repos to Distribute SmartLoader, StealC
Analysis of the FakeGit campaign distributing SmartLoader and StealC malware via over 7,600 deceptive GitHub repositories, impacting millions of downloads.
Anubis Ransomware Targets Fairlife, Threatens Data Leak
The Anubis ransomware gang claims responsibility for a cyberattack on Coca-Cola's Fairlife, threatening a data leak. Learn about their TTPs and mitigation.
ENCFORGE Ransomware Targets AI Systems via Langflow RCE
New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.
FakeGit Campaign Exploits GitHub for SmartLoader Malware
Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.
HollowGraph Malware Uses Microsoft Graph for Stealthy C2
HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.
AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment
An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.
ACR Stealer Campaign Targets Microsoft Enterprise Credentials
Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.