Advertisement
BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover
BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.
Akira Ransomware Kill Chain: Log Analysis for Early Detection
Analyze Akira Ransomware kill chain stages using perimeter and endpoint logs to detect initial access, privilege escalation, and pre-encryption activity.
SEO Poisoning and AI Chatbots Spread GPU Mining Malware
Threat actors are using SEO poisoning and manipulated AI chatbot recommendations to distribute persistent GPU mining malware to high-performance systems.
ACR Stealer Distributed via Fake Claude AI Desktop Site
Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.
Analyzing Microsoft Access VBA Macros for Malware Detection
Learn how threat actors use Microsoft Access .accdb files to execute malicious VBA code and how to analyze these OLE streams for incident response.
Obfuscating Strings in C++ Implants: Detection and Analysis
Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.
Advertisement
Analysis of Cross-Platform NPM Stealer Using Discord Webhooks
Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.
Malicious PDF Structure Analysis and Obfuscation Detection
Learn how to detect malicious PDF obfuscation and analyze internal structures like /OpenAction and /JS streams to identify hidden malware payloads.
SHub Reaper Stealer Backdoors macOS via Spoofed Apps
SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.
Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests
Researchers reveal the Trapdoor ad fraud scheme, involving 455 Android apps and 183 C2 domains generating over 600 million daily fraudulent bid requests.
Abuse of MSHTA in Stealthy Malware Delivery Chains
Attackers are abusing the legacy Windows MSHTA utility to deliver malware silently via phishing and fake downloads, bypassing EDR through LOLBIN techniques.
SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor
A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.
Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments
The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.
Malware Evolution: How New Libraries and Languages Bypass EDR
Attackers are adopting Go, Rust, and custom libraries to evade static signatures. Learn how to adapt your detection engineering for modern malware binaries.
Malicious Windows 11 ISOs Deliver Vidar Infostealer — Analysis
Security researchers warn of fake Windows 11 ISO installers delivering Vidar and RedLine infostealers through sophisticated DLL side-loading techniques.
TrickMo Android Trojan Uses TON Blockchain for Covert C2
TrickMo Android banking malware adopts The Open Network (TON) blockchain for decentralized C2, targeting European users via accessibility service abuse.
TCLBANKER Malware: Brazilian Trojan Spreads via WhatsApp and Outlook
TCLBANKER (REF3076) targets 59 financial platforms using the SORVEPOTEL worm. Learn how to detect and mitigate this evolving Brazilian banking trojan.
Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks
A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.
Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215
Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.
PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments
PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.
TCLBanker Malware Targets Fintech via WhatsApp and Outlook
TCLBanker malware uses trojanized Logitech AI installers to target 59 banking apps and spreads automatically via WhatsApp and Outlook messages.
PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access
New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.
PCPJack Credential Stealer: Cloud System Exploitation & Spread
PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…
Mirai-Based xlabs_v1 Botnet Hijacks IoT Devices via ADB
Learn how the xlabs_v1 botnet exploits Android Debug Bridge (ADB) on port 5555 to enroll IoT devices into a DDoS network and how to secure your hardware.