home.social

Search

1000 results for “alien”

  1. Beep Boop: Alien hates doing #selfPromo so made a bot to do it instead!

    You can buy my hand block printed art over on ko-fi!
    ko-fi.com/alien_sunset/shop

    check out alien-sunset.neocities.org for all the cool things I do!

  2. Beep Boop: Alien hates doing #selfPromo so made a bot to do it instead!

    You can buy my hand block printed art over on ko-fi!
    ko-fi.com/alien_sunset/shop

    check out alien-sunset.neocities.org for all the cool things I do!

  3. Beep Boop: Alien hates doing #selfPromo so made a bot to do it instead!

    You can buy my hand block printed art over on ko-fi!
    ko-fi.com/alien_sunset/shop

    check out alien-sunset.neocities.org for all the cool things I do!

  4. Beep Boop: Alien hates doing #selfPromo so made a bot to do it instead!

    You can buy my hand block printed art over on ko-fi!
    ko-fi.com/alien_sunset/shop

    check out alien-sunset.neocities.org for all the cool things I do!

  5. Beep Boop: Alien hates doing #selfPromo so made a bot to do it instead!

    You can buy my hand block printed art over on ko-fi!
    ko-fi.com/alien_sunset/shop

    check out alien-sunset.neocities.org for all the cool things I do!

  6. PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

    PCPJack is a sophisticated credential theft framework that propagates across exposed cloud infrastructure while systematically removing artifacts linked to TeamPCP, a threat actor behind notable 2026 supply chain compromises. The toolset harvests credentials from cloud platforms, containers, developer tools, productivity applications, and financial services, exfiltrating data through attacker-controlled infrastructure. It targets exposed Docker, Kubernetes, Redis, MongoDB, RayML services and vulnerable web applications, enabling external propagation and lateral movement. Unlike typical cloud malware, PCPJack deploys no cryptominers, focusing instead on credential theft for monetization through fraud, spam campaigns, extortion, or access resale. The framework uses modular Python scripts orchestrated by a central component, employs Common Crawl data for target selection, and utilizes Telegram for command and control communications.

    Pulse ID: 69fd0520d3687243cca2f973
    Pulse Link: otx.alienvault.com/pulse/69fd0
    Pulse Author: AlienVault
    Created: 2026-05-07 21:33:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CryptoMiner #CyberSecurity #Docker #Extortion #InfoSec #Malware #OTX #OpenThreatExchange #Python #RAT #Redis #Spam #SupplyChain #Telegram #Troll #Worm #bot #AlienVault

  7. Threat Actors Weaponize Tiflux RMMs in Malspam Attacks

    Since late February, there has been an uptick in incidents involving Tiflux, a lesser-known Brazilian commercial remote management tool being weaponized by threat actors. The attack chain begins with phishing emails containing fake document lures that deliver a malicious MSI installer. Once executed, the installer deploys multiple remote access tools including UltraVNC, Splashtop, and ScreenConnect for persistent access. The Tiflux installer contains concerning components such as outdated VNC versions from 2014, expired certificates, hardcoded passwords, and a vulnerable HwRwDrv.sys driver known for privilege escalation abuse. The threat actors leverage these tools to establish persistence, capture screenshots, and collect system profiling information. This campaign exemplifies the continuing pattern of adversaries abusing legitimate remote management software for stealthy access to victim environments while chaining multiple tools together to maintain control.

    Pulse ID: 69fd4f31a337de81bfb907d5
    Pulse Link: otx.alienvault.com/pulse/69fd4
    Pulse Author: AlienVault
    Created: 2026-05-08 02:49:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CyberSecurity #Email #InfoSec #MalSpam #OTX #OpenThreatExchange #Password #Passwords #Phishing #ScreenConnect #Spam #VNC #Word #bot #AlienVault

  8. 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer

    Five malicious NuGet packages published under account bmrxntfj impersonate Chinese .NET libraries to deploy an infostealer targeting browser credentials, cryptocurrency wallets, SSH keys, and local files. The packages typosquat legitimate Chinese UI and infrastructure libraries, grafting .NET Reactor-protected payloads onto decompiled legitimate code. The campaign uses version rotation to evade hash-based detection, with 219 of 224 total versions unlisted but fetchable. The stealer targets 12 browsers, 8 desktop crypto wallets, and 5 browser wallet extensions, exfiltrating data to a newly-registered C2 domain. With approximately 65,000 downloads across all versions, the campaign puts tens of thousands of developer workstations and CI/CD build servers at risk. The payload executes through .NET module initializers, hooks the CLR JIT compiler, and supports cross-platform infection including Linux and macOS infrastructure.

    Pulse ID: 69fcc64069bf35be793669dd
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chinese #CyberSecurity #InfoSec #InfoStealer #Linux #Mac #MacOS #NET #NuGet #OTX #OpenThreatExchange #RAT #SSH #bot #cryptocurrency #AlienVault

  9. ClickFix campaign uses fake macOS utilities lures to deliver infostealers

    Threat actors are leveraging ClickFix-style social engineering tactics to distribute infostealers targeting macOS users through fake system utility lures. Attackers host malicious Terminal commands on blog sites and content platforms, disguised as troubleshooting advice for macOS issues. When executed, these commands download infostealers including Macsync, Shub Stealer, and AMOS, which exfiltrate browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign has evolved to use Terminal-based script execution that bypasses Gatekeeper verification. Three distinct campaigns employ different tradecraft, with some replacing legitimate cryptocurrency wallet applications with trojanized versions and establishing persistence through LaunchAgents and LaunchDaemons that masquerade as legitimate services.

    Pulse ID: 69fb97e43f09a3b9ae3a39b9
    Pulse Link: otx.alienvault.com/pulse/69fb9
    Pulse Author: AlienVault
    Created: 2026-05-06 19:35:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #Browser #Cloud #CyberSecurity #ICS #InfoSec #InfoStealer #Mac #MacOS #OTX #OpenThreatExchange #RAT #ScriptExecution #SocialEngineering #Trojan #bot #cryptocurrency #AlienVault

  10. Donuts and Beagles: Fake Claude site spreads backdoor

    A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.

    Pulse ID: 69fcc63f1dce161fc2f8380c
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CrowdStrike #CyberSecurity #Encryption #InfoSec #Malvertising #OTX #OpenThreatExchange #PlugX #SentinelOne #SideLoading #Trellix #ZIP #bot #AlienVault

  11. Fake call logs, real payments: How CallPhantom tricks Android users

    ESET researchers discovered 28 fraudulent Android applications on Google Play, collectively named CallPhantom, that falsely claimed to provide call histories, SMS records, and WhatsApp logs for any phone number. These apps were downloaded over 7.3 million times before removal, primarily targeting users in India and the Asia-Pacific region. The apps generate fabricated data using hardcoded names and random phone numbers, displaying this fake information only after payment. CallPhantom employs three payment methods, with some bypassing Google Play's official billing system through third-party UPI payments or direct card entry, making refunds difficult. The scam exploits user curiosity about private information, charging between €5 and $80 for worthless subscriptions that deliver entirely fabricated communication data.

    Pulse ID: 69fcc63f67fc5f79f089ed5c
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Asia #CyberSecurity #ESET #Google #GooglePlay #India #InfoSec #OTX #OpenThreatExchange #RAT #SMS #WhatsApp #bot #iOS #AlienVault

  12. TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

    A sophisticated Brazilian banking trojan named TCLBANKER has been identified, representing a significant evolution of the MAVERICK/SORVEPOTEL malware family. The campaign employs a trojanized Logitech installer that deploys two .NET Reactor-protected modules through DLL side-loading. The banking trojan monitors 59 Brazilian financial institutions using UI Automation and features a WPF-based full-screen overlay framework for operator-driven social engineering attacks, including credential harvesting and fake system screens. A secondary worm module enables self-propagation through WhatsApp session hijacking and Outlook COM automation, sending phishing messages from victims' own accounts. The malware implements robust anti-analysis capabilities including environment-gated payload decryption, comprehensive watchdog systems, and ETW patching. Infrastructure is hosted on Cloudflare Workers, with evidence suggesting the campaign was detected in early operational stages.

    Pulse ID: 69fb97e531a95b262c4925aa
    Pulse Link: otx.alienvault.com/pulse/69fb9
    Pulse Author: AlienVault
    Created: 2026-05-06 19:35:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Cloud #CredentialHarvesting #CyberSecurity #ELF #InfoSec #Malware #NET #OTX #OpenThreatExchange #Outlook #Phishing #RAT #SocialEngineering #Trojan #WatchDog #WhatsApp #Worm #bot #AlienVault

  13. Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution

    A buffer overflow vulnerability in the User-ID Authentication Portal of PAN-OS software allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. Limited exploitation has been observed starting April 9, 2026, by a likely state-sponsored threat cluster. Attackers successfully achieved remote code execution by injecting shellcode into nginx worker processes. Post-exploitation activities included deployment of EarthWorm and ReverseSocks5 tunneling tools, Active Directory enumeration using compromised firewall credentials, and systematic log destruction to evade detection. The attackers demonstrated operational discipline with intermittent interactive sessions over multiple weeks, using open-source tools instead of proprietary malware to minimize detection. The vulnerability poses elevated risk when the portal is exposed to untrusted networks or the public internet.

    Pulse ID: 69fc45baaffc99649cda5385
    Pulse Link: otx.alienvault.com/pulse/69fc4
    Pulse Author: AlienVault
    Created: 2026-05-07 07:56:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Malware #Nginx #Nim #OTX #OpenThreatExchange #RAT #RCE #RemoteCodeExecution #Rust #ShellCode #Vulnerability #Worm #ZeroDay #bot #socks5 #AlienVault

  14. Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam's Military Telecom & Philippine Healthcare

    A sophisticated spear phishing campaign dubbed Operation GriefLure targeted senior executives of Viettel Group, Vietnam's largest military-owned telecommunications provider, and St. Luke's Medical Center in the Philippines. The operation weaponized authentic legal documents from a genuine data breach dispute involving a Vietnamese citizen and Viettel, alongside fabricated whistleblower complaints targeting Philippine healthcare administrators. Attackers delivered malicious Windows LNK files within nested RAR archives, abusing native ftp.exe as a Living-off-the-Land dropper. Upon execution, the payload assembled polymorphic implants directly on disk from chunked .doc files, establishing persistence while displaying legitimate decoy PDFs. The malware enabled remote access through process injection, credential harvesting from browsers and remote access tools, screenshot capture, and file exfiltration via HTTPS C2 communication to infrastructure hosted on bulletproof Hong Kong servers.

    Pulse ID: 69fc841d0cbc4c199d708315
    Pulse Link: otx.alienvault.com/pulse/69fc8
    Pulse Author: AlienVault
    Created: 2026-05-07 12:22:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CredentialHarvesting #CyberSecurity #DataBreach #HTTP #HTTPS #Healthcare #HongKong #InfoSec #LNK #Malware #Military #OTX #OpenThreatExchange #PDF #Philippines #Phishing #RAT #SpearPhishing #Telecom #Telecommunication #UK #Vietnam #Windows #bot #AlienVault

  15. Beware Of Deceptive Government Reports About To Be Released! | Perry Stone

    Beware Of Deceptive Government Reports About To Be Released! | Perry Stone

    What Is It?

    The YouTube video Beware Of Deceptive Government Reports About To Be Released! | Perry Stone by the YouTube channel Perry Stone:

    https://www.youtube.com/watch?v=37FQQdqvgCE

    Description:

    Product offer: https://perrystone.org/offer-153/

    Join Perry on a tour of Israel!

    https://perrystone.org/israel/

    Check out our Social Media Pages Here: https://linktr.ee/PerryStoneMinistries

    Perry Stone or anyone from our ministry will never comment on YouTube asking for money.

    If you see someone do this, it is a SCAM, and please report it to YouTube directly. Thank you!

    perrystone mannafest prophecy america christianity jesus jesuschrist revival prayer voiceofevangelism christiantelevision voe BibleTeaching propheticmessages HebraicRoots Evangelism hebrewroots

    My Thoughts

    I forgot about Perry Stone!

    I used to watch some of his sermons back in the day.

    He was among my favorite preachers because he talked about interesting topics like this.

    So it was quite the surprise to learn about this video.

    Thanks to several UFO / UAP / alien / non-human / semi-human-themed YouTube channels that I follow.

    Hopefully the government, et cetera, will start to reveal more of this information to the public finally.

    After all these years.

    Something or several things have been going on.

    The question is which combination of things is true.

    And what can / should we do about it?

    The end,

    • John Jr
    #Alien #BewareOfDeceptiveGovernmentReportsAboutToBeReleasedPerryStone #Bible #Christian #Christianity #Disclosure #Extraterrestrial #Government #Pastor #Religion #UAP #UFO #Video #YouTube
  16. Beware Of Deceptive Government Reports About To Be Released! | Perry Stone

    Beware Of Deceptive Government Reports About To Be Released! | Perry Stone

    What Is It?

    The YouTube video Beware Of Deceptive Government Reports About To Be Released! | Perry Stone by the YouTube channel Perry Stone:

    https://www.youtube.com/watch?v=37FQQdqvgCE

    Description:

    Product offer: https://perrystone.org/offer-153/

    Join Perry on a tour of Israel!

    https://perrystone.org/israel/

    Check out our Social Media Pages Here: https://linktr.ee/PerryStoneMinistries

    Perry Stone or anyone from our ministry will never comment on YouTube asking for money.

    If you see someone do this, it is a SCAM, and please report it to YouTube directly. Thank you!

    perrystone mannafest prophecy america christianity jesus jesuschrist revival prayer voiceofevangelism christiantelevision voe BibleTeaching propheticmessages HebraicRoots Evangelism hebrewroots

    My Thoughts

    I forgot about Perry Stone!

    I used to watch some of his sermons back in the day.

    He was among my favorite preachers because he talked about interesting topics like this.

    So it was quite the surprise to learn about this video.

    Thanks to several UFO / UAP / alien / non-human / semi-human-themed YouTube channels that I follow.

    Hopefully the government, et cetera, will start to reveal more of this information to the public finally.

    After all these years.

    Something or several things have been going on.

    The question is which combination of things is true.

    And what can / should we do about it?

    The end,

    • John Jr
    #Alien #BewareOfDeceptiveGovernmentReportsAboutToBeReleasedPerryStone #Bible #Christian #Christianity #Disclosure #Extraterrestrial #Government #Pastor #Religion #UAP #UFO #Video #YouTube
  17. Beware Of Deceptive Government Reports About To Be Released! | Perry Stone

    Beware Of Deceptive Government Reports About To Be Released! | Perry Stone

    What Is It?

    The YouTube video Beware Of Deceptive Government Reports About To Be Released! | Perry Stone by the YouTube channel Perry Stone:

    https://www.youtube.com/watch?v=37FQQdqvgCE

    Description:

    Product offer: https://perrystone.org/offer-153/

    Join Perry on a tour of Israel!

    https://perrystone.org/israel/

    Check out our Social Media Pages Here: https://linktr.ee/PerryStoneMinistries

    Perry Stone or anyone from our ministry will never comment on YouTube asking for money.

    If you see someone do this, it is a SCAM, and please report it to YouTube directly. Thank you!

    perrystone mannafest prophecy america christianity jesus jesuschrist revival prayer voiceofevangelism christiantelevision voe BibleTeaching propheticmessages HebraicRoots Evangelism hebrewroots

    My Thoughts

    I forgot about Perry Stone!

    I used to watch some of his sermons back in the day.

    He was among my favorite preachers because he talked about interesting topics like this.

    So it was quite the surprise to learn about this video.

    Thanks to several UFO / UAP / alien / non-human / semi-human-themed YouTube channels that I follow.

    Hopefully the government, et cetera, will start to reveal more of this information to the public finally.

    After all these years.

    Something or several things have been going on.

    The question is which combination of things is true.

    And what can / should we do about it?

    The end,

    • John Jr
    #Alien #BewareOfDeceptiveGovernmentReportsAboutToBeReleasedPerryStone #Bible #Christian #Christianity #Disclosure #Extraterrestrial #Government #Pastor #Religion #UAP #UFO #Video #YouTube