Advertisement
SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT
Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT. Learn about RAT capabilities and general mitigation…
FBI Seeks Victims of Malicious Steam Games Stealing Credentials
The FBI is investigating eight malicious games on Steam that stole user credentials from tens of thousands of players. Learn how to identify and report compromised…
AI-Generated Slopoly Malware Linked to Interlock Ransomware Attacks
Analysis of the AI-generated Slopoly malware and its role in Interlock ransomware operations, including technical details and detection strategies.
Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access
The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.
VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks
A new Rust-based malware called VENON is targeting 33 Brazilian banks with credential-stealing overlays, signaling a shift in Latin American cybercrime TTPs.
BeatBanker Android Malware: Starlink Impersonation & Device Hijack
New BeatBanker Android malware impersonates the Starlink app on fake app stores to hijack devices, targeting unsuspecting users. Learn detection & mitigation.
BlackSanta Malware Targets HR Workflows to Disable EDR Systems
Russian-speaking threat actors deploy BlackSanta malware via hijacked HR workflows to terminate EDR agents and facilitate undetected data exfiltration.
KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network
The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.
KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet
KadNap malware has compromised over 14,000 edge devices, primarily Asus routers, to create a massive proxy botnet for anonymizing malicious traffic.
Quasar RAT Delivery via Malicious PDF and LNK Files
Technical analysis of a multi-stage infection chain using PDF lures and LNK files to deploy Quasar RAT, including detection and mitigation strategies.
InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers
The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.
VOID#GEIST Malware: Multi-Stage Delivery of AsyncRAT and XWorm
Securonix identifies VOID#GEIST, a stealthy multi-stage malware campaign using obfuscated batch scripts to deliver XWorm, AsyncRAT, and Xeno RAT payloads.
Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers
Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.
Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto
The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.
Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits
Google's GTIG identified Coruna (CryptoWaters), a powerful iOS exploit kit leveraging 23 exploits across 5 chains to target iOS 13.0-17.2.1. Update immediately.
XWorm RAT Delivery: Analyzing Multi-Stage Infection Chains
New XWorm malware waves utilize multi-technology delivery involving LNK files and PowerShell. Learn how to detect and mitigate XWorm RAT infections.
Analyzing Embedded ZIP Payloads in RTF Documents for Malware Analysis
Learn how to detect ZIP files in RTF documents and extract hex-encoded binary payloads using specialized forensic tools to identify hidden malware threats.
QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware
Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.
Phishing Campaign Leverages Donut Loader via Spoofed FedEx Alerts
Analysis of a phishing campaign using fake FedEx delivery notifications to deliver the Donut loader framework for in-memory shellcode execution.
CISA Warns of RESURGE Malware Persistence on Ivanti Devices
CISA details RESURGE, a sophisticated implant exploiting CVE-2025-0282 in Ivanti Connect Secure, capable of remaining dormant to bypass detection and recovery.
Aeternum Loader Employs Polygon Blockchain for Resilient C2
Analysis of the Aeternum botnet loader, which utilizes Polygon smart contracts to host decentralized command-and-control infrastructure for resilience.
Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell
Security researchers identify a malware campaign using trojanized gaming tools to deliver a Java-based RAT using PowerShell and portable Java runtimes.
Aeternum C2 Leverages Polygon Blockchain for Command-and-Control
Aeternum C2 loader uses the Polygon blockchain to store encrypted instructions, creating a decentralized infrastructure resilient to traditional takedowns.
Arkanix Stealer: Rapid Disappearance of C++ & Python Malware
Arkanix Stealer, a C++ and Python-based info-stealer, emerged briefly, exfiltrating system data, browser credentials, and files before vanishing. Analysis of its TTPs.