Advertisement
Malicious Crypto Wallets Infiltrate China's Apple App Store
26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.
Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions
Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.
Lumma Stealer and Sectop RAT Dual Infection Chain Analysis
Technical breakdown of the Lumma Stealer and Sectop RAT (ArechClient2) infection chain, detailing C2 communication and persistence mechanisms.
PDF JavaScript Exploitation: Analysis of PowerShell Delivery
Technical analysis of malicious PDF documents using embedded JavaScript and /OpenAction triggers to execute PowerShell for initial access and C2 establishment.
Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.
Analyzing ZionSiphon: Malware Targeting Water Treatment OT Systems
Investigate ZionSiphon malware, an OT-specific threat designed to sabotage water treatment and desalination facilities.
Advertisement
Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware
Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.
SVG File Phishing: How Attackers Hide Malicious JavaScript in Images
Discover how attackers use Scalable Vector Graphics (SVG) to embed malicious JavaScript for phishing and credential theft while bypassing security filters.
AgingFly Malware: Credential Theft Operations Against Ukraine
Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…
Signed Software Abuse: How Malicious Scripts Disable EDR and AV
Analysis of signed adware being used to deploy antivirus-killing scripts with SYSTEM privileges across government and healthcare sectors.
Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse
Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.
Mirax Android RAT: Bypassing Security via Malicious Meta Ads
Mirax Android RAT targets 220,000 users via Meta Ads, turning devices into SOCKS5 proxies. Learn to detect and mitigate this emerging mobile threat.
JanelaRAT Malware Analysis: 14,000+ Attacks Target Latin American Banks
Analyze the JanelaRAT campaign targeting Brazil and Mexico. Learn how this BX RAT variant steals financial data and how to detect JanelaRAT attacks.
Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide
Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.
Storm Infostealer: Bypassing Local Decryption for Session Hijacking
Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.
Detect Obfuscated JavaScript Phishing Delivered via RAR Archives
Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.
LucidRook Malware Targets Taiwan NGOs via DLL Side-Loading
Analysis of the Lua-based LucidRook malware targeting Taiwanese NGOs and universities through spear-phishing and sophisticated DLL side-loading techniques.
Magecart Skimmer Hides in Pixel-Sized SVG on Magento Stores
A sophisticated Magecart campaign targets nearly 100 Magento stores, concealing credit card-stealing JavaScript within tiny, pixel-sized SVG images.
Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns
The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.
Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy
A new variant of Chaos malware targets misconfigured cloud deployments, leveraging SOCKS proxy capabilities to expand botnet infrastructure beyond edge devices.
Masjesu Botnet: Stealthy DDoS Malware Targets Linux IoT Devices
Masjesu is a highly evasive DDoS botnet targeting Linux IoT devices. It prioritizes persistence and avoids critical infrastructure to remain undetected.
Medusa Ransomware: Rapid Vulnerability Weaponization and Analysis
An analysis of Medusa ransomware's rapid exploitation of vulnerabilities and Zero-Day bugs to exfiltrate and encrypt data within days of initial access.
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.
SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases
A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.