Advertisement
Redtail Malware Exploiting CVE-2024-3400: Technical Analysis
Analysis of the Libredtail variant exploiting Palo Alto Networks CVE-2024-3400 to deploy crypto-miners and establish rootkit persistence.
VECT 2.0 Ransomware Analysis: Encryption Flaws Act as Data Wiper
VECT 2.0 ransomware features a critical flaw in its encryption logic that permanently wipes large files, making data recovery impossible even with a key.
LofyGang Targets Minecraft Players with LofyStealer Malware
Brazilian cybercrime group LofyGang resurfaces after three years, deploying LofyStealer (GrabBot) disguised as a Minecraft 'Slinky' hack to steal player credentials.
VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi
VECT 2.0 ransomware permanently destroys files over 131KB on Windows, Linux, and ESXi systems due to flawed encryption, making data recovery impossible.
GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions
A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.
Firestarter Malware Persists on Cisco Firewalls Post-Update
U.S. and U.K. agencies warn about Firestarter malware exhibiting post-update persistence on Cisco Firepower and Secure Firewalls running ASA/FTD.
Firestarter Backdoor Infects Cisco Firewall at US Federal Agency
Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.
26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis
Researchers discover 26 malicious apps on the Apple App Store impersonating crypto wallets to steal seed phrases via trojanized software and browser redirects.
Trigona Ransomware: Custom Tool for Faster Data Exfiltration
Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.
FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall
CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.
Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption
Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.
CVE-2025-29635: Mirai Exploits EoL D-Link Routers
A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks. Urgent…
Lotus Wiper Malware Targets Venezuelan Energy Sector
Kaspersky researchers uncover Lotus Wiper, a destructive malware targeting Venezuelan energy and utility systems via malicious batch scripts.
Malicious Crypto Apps on Apple App Store Target Private Keys
Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to…
Lotus Data Wiper Targets Venezuelan Energy Utilities
Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.
NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil
Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.
Python Infostealer Targeting Browser Credentials and Discord Tokens
Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.
Malware Delivery via Malicious .WAV Files — Technical Analysis
Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.
Malicious Crypto Wallets Infiltrate China's Apple App Store
26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.
Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions
Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.
Lumma Stealer and Sectop RAT Dual Infection Chain Analysis
Technical breakdown of the Lumma Stealer and Sectop RAT (ArechClient2) infection chain, detailing C2 communication and persistence mechanisms.
PDF JavaScript Exploitation: Analysis of PowerShell Delivery
Technical analysis of malicious PDF documents using embedded JavaScript and /OpenAction triggers to execute PowerShell for initial access and C2 establishment.
Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.
Analyzing ZionSiphon: Malware Targeting Water Treatment OT Systems
Investigate ZionSiphon malware, an OT-specific threat designed to sabotage water treatment and desalination facilities. Understand its impact and critical defense…