Advertisement
Malicious Chrome Wallpaper Extensions Distribute Adware
Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts. Learn to identify…
MSI Malware Detection: Statistical Analysis for Base64 Payloads
Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.
Lumma Stealer Distributed via Fake EditPro AI Image Generator
Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.
The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties
Analysis of The Gentlemen ransomware reveals its worm-like propagation, double extortion tactics, and operational ties to LockBit, Qilin, and Medusa RaaS schemes…
OnyxC2 Stealer: Enterprise-Grade Info-Theft for $250/Month
OnyxC2 stealer targets over 200 applications and extensions, using encrypted payloads, DLL sideloading, and in-memory execution to evade detection.
Infostealers: Millions of Devices Compromised for Credential Theft
Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.
Miasma Worm Source Code Briefly Leaked on GitHub
Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks. Understand…
Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware
Researchers demonstrate an autonomous AI worm using local open-weight LLMs to navigate networks and replicate without human intervention or cloud services.
Python-Based Infostealer Masked as PDF Targets Browser Credentials
Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.
NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks
Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.
Excel VBA Macro Obfuscation: How to Detect Hidden Payloads
Learn how to analyze and detect obfuscated VBA macros in Excel files using oledump.py. Technical guide on character substitution and string reversal techniques.
C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation
C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.
Asin Android Spyware Targets Arabic Users via Fake War Maps
ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.
MSI-Branded Image Steganography: Analysis of WeTransfer Phishing
Analysis of a recurring phishing campaign using steganography in MSI-branded images to deliver malicious payloads via WeTransfer links and bypass security.
Weedhack MaaS Campaign Targets Minecraft Users via CountLoader
McAfee Labs reports the Weedhack campaign spreading CountLoader and cryptominers through fake Minecraft mods on YouTube. Learn detection and mitigation.
AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery
New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.
NetSupport RAT Infection: How to Detect Unidentified Loader Exploits
Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.
ChatGPT Share Link Abuse: Fake Outages Deliver Malware
Threat actors leverage ChatGPT share links to host deceptive outage pages, prompting users to download malware disguised as an official desktop app.
BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover
BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.
Akira Ransomware Kill Chain: Log Analysis for Early Detection
Analyze Akira Ransomware kill chain stages using perimeter and endpoint logs to detect initial access, privilege escalation, and pre-encryption activity.
SEO Poisoning and AI Chatbots Spread GPU Mining Malware
Threat actors are using SEO poisoning and manipulated AI chatbot recommendations to distribute persistent GPU mining malware to high-performance systems.
ACR Stealer Distributed via Fake Claude AI Desktop Site
Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.
Analyzing Microsoft Access VBA Macros for Malware Detection
Learn how threat actors use Microsoft Access .accdb files to execute malicious VBA code and how to analyze these OLE streams for incident response.
Obfuscating Strings in C++ Implants: Detection and Analysis
Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.