Skip to main content
← All Articles

Tag

#Persistence

18 articles

Advertisement

HIGH
Malware

Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence

CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.

Runtime Rebel Intel
5 min read · Jul 23, 2026
CRITICAL
Vulnerabilities

CVE-2026-50522: SharePoint RCE Exploitation to Steal Machine Keys

Critical CVE-2026-50522 in Microsoft SharePoint is actively exploited to steal machine keys, enabling persistent access. Understand the threat and mitigation.

Runtime Rebel Intel
4 min read · Jul 21, 2026
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
HIGH
Malware

ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops

ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.

Runtime Rebel Intel
3 min read · Jul 16, 2026
HIGH
Malware

Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT

Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.

Runtime Rebel Intel
3 min read · Jun 23, 2026
Junior Hacker's Tailscale & OpenSSH Post-C2 Persistence
HIGH
Threat Intel

Junior Hacker's Tailscale & OpenSSH Post-C2 Persistence

Analysis of a junior hacker's TTPs, leveraging Tailscale and OpenSSH for persistent access to a French automotive business after their Havoc C2 server went offline.

Runtime Rebel Intel
4 min read · Jun 17, 2026
OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
HIGH
Vulnerabilities

OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence

Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.

Runtime Rebel Intel
4 min read · May 19, 2026

Advertisement

MEDIUM
Identity & Access

Active Directory Post-Breach Persistence: Why Password Resets Fail

Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.

Runtime Rebel Intel
4 min read · May 11, 2026
HIGH
Threat Intel

UNC6692 Targets Microsoft Teams to Deploy Snow Malware

UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.

Runtime Rebel Intel
3 min read · Apr 25, 2026
FIRESTARTER Backdoor Exploits Cisco Firepower ASA Software
HIGH
Threat Intel

FIRESTARTER Backdoor Exploits Cisco Firepower ASA Software

CISA and NCSC reveal FIRESTARTER, a persistent backdoor targeting Cisco Firepower devices running ASA software, used in federal agency compromises.

Runtime Rebel Intel
4 min read · Apr 25, 2026
HIGH
Malware

Firestarter Backdoor Infects Cisco Firewall at US Federal Agency

Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 24, 2026
CRITICAL
Malware

FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall

CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.

Runtime Rebel Intel
6 min read · Apr 23, 2026
Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
HIGH
Malware

Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion

Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.

Runtime Rebel Intel
5 min read · Apr 17, 2026
HIGH
Threat Intel

Detecting Malicious Web Shells: Analysis of Persistence and TTPs

Discover how attackers use deceptive naming and pre-set credentials in web shells to maintain persistence and how to detect these malicious files on servers.

Runtime Rebel Intel
4 min read · Apr 8, 2026
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
HIGH
Malware

WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems

Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…

Runtime Rebel Intel
5 min read · Apr 1, 2026
Telecom Sleeper Cells and LLM Jailbreak Trends: Weekly Analysis
HIGH
Threat Intel

Telecom Sleeper Cells and LLM Jailbreak Trends: Weekly Analysis

An analysis of long-term persistence in telecom networks, LLM jailbreak methodologies, and regulatory shifts in UK age verification for Apple users.

Runtime Rebel Intel
3 min read · Mar 30, 2026
HIGH
Malware

GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact

Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.

Runtime Rebel Intel
3 min read · Mar 20, 2026
Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access
HIGH
Malware

Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access

The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.

Runtime Rebel Intel
4 min read · Mar 12, 2026
BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement
MEDIUM
Malware

BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement

An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining…

Runtime Rebel Intel
2 min read · Feb 23, 2026