Advertisement
Faronics Deploy Abused by Phishing Actors to Install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint management tool to gain remote access and install ScreenConnect via malicious installers.
TerminalFix: PowerShell Weaponization in Enterprise Attacks
Analysis of 'TerminalFix' campaign, detailing PowerShell weaponization, multistage attack chain, and reverse tunnels into enterprise networks.
DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files
Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.
Entra Log Analysis: Detecting Password Spray Attacks with PowerShell
Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.
Auditing Entra ID MFA Gaps with PowerShell and Microsoft Graph
A new PowerShell script helps security teams identify Microsoft Entra ID users not registered for MFA or using weaker authentication methods.
PowerShell and WMI Detection: Analyzing Suspicious Command Lines
Learn to detect obfuscated PowerShell commands and malicious WMI activity through advanced command-line monitoring and log analysis for security teams.
Advertisement
Analyzing Remcos RAT Delivery via Malicious LNK Files
Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.
Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell
Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.
Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT
Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.
NetSupport RAT Infection: How to Detect Unidentified Loader Exploits
Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.
Weaponized Trust: Analyzing the Abuse of Administrative Utilities
Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.
PowMix Botnet Targets Czech Workers via Randomized C2 Traffic
Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.
DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea
North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.
SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives
Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.
InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers
The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.
XWorm RAT Delivery: Analyzing Multi-Stage Infection Chains
New XWorm malware waves utilize multi-technology delivery involving LNK files and PowerShell. Learn how to detect and mitigate XWorm RAT infections.
Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell
Security researchers identify a malware campaign using trojanized gaming tools to deliver a Java-based RAT using PowerShell and portable Java runtimes.