Skip to main content
← All Articles

Tag

#Backdoor

25 articles

Advertisement

HIGH
Supply Chain

Head Mare Breaches TrueConf, Trojanizes Client Installers

The Head Mare hacktivist group breached TrueConf video conferencing servers to distribute backdoored client installers, compromising user systems.

Runtime Rebel Intel
4 min read · Aug 8, 2026
HIGH
Supply Chain

Critical Backdoors & Supply Chain Attacks: Zbtlink Routers & QuickFox VPN Compromised

Urgent warning: Zbtlink routers ship with unauthenticated root backdoors, while QuickFox VPN delivers FDMTP implant via supply chain compromise.

Runtime Rebel Intel
5 min read · Aug 7, 2026
Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors
HIGH
Threat Intel

Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors

Ongoing cyberattacks by a suspected Chinese-speaking threat actor target Central Asian governments with OctLurk and SilkLurk backdoors for espionage and data theft.

Runtime Rebel Intel
3 min read · Aug 1, 2026
GigaWiper: Modular Implant Combines Backdoor & Wiper Functions
HIGH
Malware

GigaWiper: Modular Implant Combines Backdoor & Wiper Functions

Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.

Runtime Rebel Intel
5 min read · Jul 13, 2026
CRITICAL
Threat Intel

Roundcube Flaw Exploited by China-Linked Group Against Academics

A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.

Runtime Rebel Intel
4 min read · Jul 8, 2026
HIGH
Threat Intel

New 'Leash' Backdoors Target SOHO Routers: China-Linked APT Update

A China-linked APT group has expanded its toolkit with new 'Leash' backdoors (LongLeash, DogLeash, JarLeash), targeting SOHO routers for persistent access and command…

Runtime Rebel Intel
5 min read · Jul 8, 2026

Advertisement

CVE-2026-11405: Tenda Router Firmware Admin Backdoor Exposed
HIGH
Vulnerabilities

CVE-2026-11405: Tenda Router Firmware Admin Backdoor Exposed

CERT/CC warns of an undocumented admin backdoor, CVE-2026-11405, in Tenda router firmware, enabling full administrative access bypass. Immediate action advised.

Runtime Rebel Intel
5 min read · Jul 7, 2026
China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor
HIGH
Threat Intel

China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor

A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.

Runtime Rebel Intel
4 min read · Jul 1, 2026
ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored
HIGH
Supply Chain

ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored

Attackers compromised ShapedPlugin's distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Jun 23, 2026
HIGH
Malware

CryptoBandits Malware: Tor-Abusing Backdoor & Data Theft

CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.

Runtime Rebel Intel
5 min read · Jun 19, 2026
HIGH
Threat Intel

Outdated REDCap Servers Targeted by China-linked UNC6508

A majority of internet-accessible REDCap servers remain unpatched, making them prime targets for initial access and backdoor deployment by China-linked UNC6508.

Runtime Rebel Intel
5 min read · Jun 18, 2026
SHub Reaper Stealer Backdoors macOS via Spoofed Apps
HIGH
Malware

SHub Reaper Stealer Backdoors macOS via Spoofed Apps

SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.

Runtime Rebel Intel
5 min read · May 19, 2026
HIGH
Malware

SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor

A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.

Runtime Rebel Intel
4 min read · May 19, 2026
Malicious node-ipc Versions Compromise Developer Secrets via Supply Chain
HIGH
Supply Chain

Malicious node-ipc Versions Compromise Developer Secrets via Supply Chain

Three versions of the node-ipc npm package (9.1.6, 9.2.3, 12.0.1) contain stealer/backdoor functionality targeting developer secrets. Urgent update advised.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Malware

Stealthy Quasar Linux (QLNX) Malware Targets Developers

New Quasar Linux (QLNX) malware is infecting developers' Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.

Runtime Rebel Intel
5 min read · May 6, 2026
Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia
HIGH
Threat Intel

Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia

China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.

Runtime Rebel Intel
4 min read · May 4, 2026
HIGH
Vulnerabilities

WordPress Quick Page/Post Redirect Backdoor: Arbitrary Code Injection

A dormant backdoor in the Quick Page/Post Redirect WordPress plugin allowed arbitrary code injection for five years on over 70,000 sites. Learn mitigation.

Runtime Rebel Intel
5 min read · Apr 30, 2026
HIGH
Threat Intel

UNC6692 Targets Microsoft Teams to Deploy Snow Malware

UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.

Runtime Rebel Intel
3 min read · Apr 25, 2026
HIGH
Malware

Firestarter Backdoor Infects Cisco Firewall at US Federal Agency

Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 24, 2026
CRITICAL
Malware

FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall

CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.

Runtime Rebel Intel
6 min read · Apr 23, 2026
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
HIGH
Threat Intel

APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting

China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.

Runtime Rebel Intel
4 min read · Apr 13, 2026
Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack
HIGH
Supply Chain

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack

Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.

Runtime Rebel Intel
3 min read · Apr 10, 2026
Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos
HIGH
Threat Intel

Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos

Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.

Runtime Rebel Intel
4 min read · Mar 27, 2026
HIGH
Supply Chain

Fake Next.js Job Interview Tests Backdoor Developers

Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.

Runtime Rebel Intel
5 min read · Feb 26, 2026