Advertisement
Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT
Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.
Defending Against ClickOnce Abuse for Persistence and Initial Access
Learn how adversaries abuse Microsoft ClickOnce for stealthy persistence and how to secure Windows environments against malicious deployment manifests.

Junior Hacker's Tailscale & OpenSSH Post-C2 Persistence
Analysis of a junior hacker's TTPs, leveraging Tailscale and OpenSSH for persistent access to a French automotive business after their Havoc C2 server went offline.

OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks. Patching guidance
UNC6692 Targets Microsoft Teams to Deploy Snow Malware
UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.
Firestarter Backdoor Infects Cisco Firewall at US Federal Agency
Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.

Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.

WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting

Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access
The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.

BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement
An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining yield.