#alienvault — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #alienvault, aggregated by home.social.
-
CoolClient backdoor goes deeper: Windows kernel rootkit added
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.
Pulse ID: 6a7ef2da146fb06724520eb4
Pulse Link: https://otx.alienvault.com/pulse/6a7ef2da146fb06724520eb4
Pulse Author: AlienVault
Created: 2026-08-14 10:50:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault
-
CoolClient backdoor goes deeper: Windows kernel rootkit added
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.
Pulse ID: 6a7ef2da146fb06724520eb4
Pulse Link: https://otx.alienvault.com/pulse/6a7ef2da146fb06724520eb4
Pulse Author: AlienVault
Created: 2026-08-14 10:50:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.
Pulse ID: 6a7da6ccbbdd8552713c76a1
Pulse Link: https://otx.alienvault.com/pulse/6a7da6ccbbdd8552713c76a1
Pulse Author: AlienVault
Created: 2026-08-13 11:13:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.
Pulse ID: 6a7da6ccbbdd8552713c76a1
Pulse Link: https://otx.alienvault.com/pulse/6a7da6ccbbdd8552713c76a1
Pulse Author: AlienVault
Created: 2026-08-13 11:13:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
Pulse ID: 6a7d8cc2109e73821519b31d
Pulse Link: https://otx.alienvault.com/pulse/6a7d8cc2109e73821519b31d
Pulse Author: AlienVault
Created: 2026-08-13 09:22:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
Pulse ID: 6a7d8cc2109e73821519b31d
Pulse Link: https://otx.alienvault.com/pulse/6a7d8cc2109e73821519b31d
Pulse Author: AlienVault
Created: 2026-08-13 09:22:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault
-
Inside a Ukrainian IP Camera Toolkit
Two open directories hosted on Russian bulletproof infrastructure revealed coordinated operations targeting Ukrainian IP cameras, routers, and government websites. The first server exposed tools exploiting SQL injection against a Ukrainian e-commerce site, used as a proxy for Tor-routed attacks against government councils and military domains. A custom Docker platform named 'camview' cataloged 58 compromised Ukrainian cameras using known Hikvision and Dahua vulnerabilities. The second server deployed similar techniques across 15 European countries, converting compromised edge devices into SOCKS5 proxies. Both operations utilized the open-source Ingram scanner, focused on frontline Ukrainian cities including Kramatorsk, Slavyansk, Odessa, and Kherson, and employed Russian-language scripts. Evidence suggests potential linkage to drone operator infrastructure through role-based access controls, though direct military ties remain unconfirmed.
Pulse ID: 6a7d8d2b3a8a65f2b1dc0cda
Pulse Link: https://otx.alienvault.com/pulse/6a7d8d2b3a8a65f2b1dc0cda
Pulse Author: AlienVault
Created: 2026-08-13 09:23:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Docker #Edge #Europe #Government #InfoSec #Military #OTX #OpenThreatExchange #Proxy #RAT #RCE #Russia #SQL #UK #Ukr #Ukrainian #bot #socks5 #AlienVault
-
Inside a Ukrainian IP Camera Toolkit
Two open directories hosted on Russian bulletproof infrastructure revealed coordinated operations targeting Ukrainian IP cameras, routers, and government websites. The first server exposed tools exploiting SQL injection against a Ukrainian e-commerce site, used as a proxy for Tor-routed attacks against government councils and military domains. A custom Docker platform named 'camview' cataloged 58 compromised Ukrainian cameras using known Hikvision and Dahua vulnerabilities. The second server deployed similar techniques across 15 European countries, converting compromised edge devices into SOCKS5 proxies. Both operations utilized the open-source Ingram scanner, focused on frontline Ukrainian cities including Kramatorsk, Slavyansk, Odessa, and Kherson, and employed Russian-language scripts. Evidence suggests potential linkage to drone operator infrastructure through role-based access controls, though direct military ties remain unconfirmed.
Pulse ID: 6a7d8d2b3a8a65f2b1dc0cda
Pulse Link: https://otx.alienvault.com/pulse/6a7d8d2b3a8a65f2b1dc0cda
Pulse Author: AlienVault
Created: 2026-08-13 09:23:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Docker #Edge #Europe #Government #InfoSec #Military #OTX #OpenThreatExchange #Proxy #RAT #RCE #Russia #SQL #UK #Ukr #Ukrainian #bot #socks5 #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Cl0p Ransomware: Attack Pattern in Threat Intelligence
A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.
Pulse ID: 6a7ca263ee7777102409724c
Pulse Link: https://otx.alienvault.com/pulse/6a7ca263ee7777102409724c
Pulse Author: AlienVault
Created: 2026-08-12 16:42:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault
-
Cl0p Ransomware: Attack Pattern in Threat Intelligence
A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.
Pulse ID: 6a7ca263ee7777102409724c
Pulse Link: https://otx.alienvault.com/pulse/6a7ca263ee7777102409724c
Pulse Author: AlienVault
Created: 2026-08-12 16:42:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault
-
Inside Multi-Stage Phishing Redirection Chains
Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
Pulse ID: 6a7ce26b7815e336e5eee192
Pulse Link: https://otx.alienvault.com/pulse/6a7ce26b7815e336e5eee192
Pulse Author: AlienVault
Created: 2026-08-12 21:15:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #Cloud #CyberSecurity #EDR #HTML #InfoSec #OTX #OpenThreatExchange #Phishing #Rust #bot #AlienVault
-
Inside Multi-Stage Phishing Redirection Chains
Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
Pulse ID: 6a7ce26b7815e336e5eee192
Pulse Link: https://otx.alienvault.com/pulse/6a7ce26b7815e336e5eee192
Pulse Author: AlienVault
Created: 2026-08-12 21:15:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #Cloud #CyberSecurity #EDR #HTML #InfoSec #OTX #OpenThreatExchange #Phishing #Rust #bot #AlienVault
-
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.
Pulse ID: 6a7c6340682f0dc9b225d8d6
Pulse Link: https://otx.alienvault.com/pulse/6a7c6340682f0dc9b225d8d6
Pulse Author: AlienVault
Created: 2026-08-12 12:12:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #GroupIB #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Slovenia #SocialEngineering #SpyNote #Troll #bot #AlienVault
-
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.
Pulse ID: 6a7c6340682f0dc9b225d8d6
Pulse Link: https://otx.alienvault.com/pulse/6a7c6340682f0dc9b225d8d6
Pulse Author: AlienVault
Created: 2026-08-12 12:12:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #GroupIB #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Slovenia #SocialEngineering #SpyNote #Troll #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Fake popular sites offer a free app, instead take over PCs
A campaign uses fake websites impersonating CNN, Stremio, and Avast to distribute legitimate remote administration software O&O Syspectr pre-linked to attacker accounts. The lookalike sites closely mimic authentic homepages and trick Windows users into downloading installers that appear legitimate but grant attackers remote access to victim computers. Additional fake sites use cryptocurrency mining game lures to distribute the same tool. All installers are digitally signed legitimate software, making antivirus detection difficult. The campaign uses multiple Syspectr account IDs embedded in filenames, with CNN, Avast, and Stremio lures sharing one account while crypto-mining lures use another. O&O Software responded by disabling Remote Desktop and Remote Console access for free accounts and suspending the abusive accounts.
Pulse ID: 6a7c2827f67f1ff14996237e
Pulse Link: https://otx.alienvault.com/pulse/6a7c2827f67f1ff14996237e
Pulse Author: AlienVault
Created: 2026-08-12 08:00:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #Windows #bot #cryptocurrency #AlienVault
-
Fake popular sites offer a free app, instead take over PCs
A campaign uses fake websites impersonating CNN, Stremio, and Avast to distribute legitimate remote administration software O&O Syspectr pre-linked to attacker accounts. The lookalike sites closely mimic authentic homepages and trick Windows users into downloading installers that appear legitimate but grant attackers remote access to victim computers. Additional fake sites use cryptocurrency mining game lures to distribute the same tool. All installers are digitally signed legitimate software, making antivirus detection difficult. The campaign uses multiple Syspectr account IDs embedded in filenames, with CNN, Avast, and Stremio lures sharing one account while crypto-mining lures use another. O&O Software responded by disabling Remote Desktop and Remote Console access for free accounts and suspending the abusive accounts.
Pulse ID: 6a7c2827f67f1ff14996237e
Pulse Link: https://otx.alienvault.com/pulse/6a7c2827f67f1ff14996237e
Pulse Author: AlienVault
Created: 2026-08-12 08:00:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #Windows #bot #cryptocurrency #AlienVault
-
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.
Pulse ID: 6a7b4a5db787f887767b8a2a
Pulse Link: https://otx.alienvault.com/pulse/6a7b4a5db787f887767b8a2a
Pulse Author: AlienVault
Created: 2026-08-11 16:14:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault
-
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.
Pulse ID: 6a7b4a5db787f887767b8a2a
Pulse Link: https://otx.alienvault.com/pulse/6a7b4a5db787f887767b8a2a
Pulse Author: AlienVault
Created: 2026-08-11 16:14:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault
-
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
Pulse ID: 6a7c183cfe509b035144c5a6
Pulse Link: https://otx.alienvault.com/pulse/6a7c183cfe509b035144c5a6
Pulse Author: AlienVault
Created: 2026-08-12 06:52:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault
-
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
Pulse ID: 6a7c183cfe509b035144c5a6
Pulse Link: https://otx.alienvault.com/pulse/6a7c183cfe509b035144c5a6
Pulse Author: AlienVault
Created: 2026-08-12 06:52:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault
-
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack
The provided document does not contain an intelligence report. Instead, it appears to be a webpage notification indicating that JavaScript needs to be enabled in the browser to proceed with viewing content. The page includes a verification mechanism to confirm that the user is not an automated bot. No threat intelligence information, malicious activity, threat actors, malware campaigns, attack techniques, or cybersecurity-related content is present in the provided material. Therefore, no meaningful analysis of threat activity, targeted countries, industries, or technical indicators can be extracted from this content.
Pulse ID: 6a7b8b7a783979ea34063bad
Pulse Link: https://otx.alienvault.com/pulse/6a7b8b7a783979ea34063bad
Pulse Author: AlienVault
Created: 2026-08-11 20:52:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Java #JavaScript #Malware #OTX #OpenThreatExchange #ZeroDay #bot #AlienVault
-
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack
The provided document does not contain an intelligence report. Instead, it appears to be a webpage notification indicating that JavaScript needs to be enabled in the browser to proceed with viewing content. The page includes a verification mechanism to confirm that the user is not an automated bot. No threat intelligence information, malicious activity, threat actors, malware campaigns, attack techniques, or cybersecurity-related content is present in the provided material. Therefore, no meaningful analysis of threat activity, targeted countries, industries, or technical indicators can be extracted from this content.
Pulse ID: 6a7b8b7a783979ea34063bad
Pulse Link: https://otx.alienvault.com/pulse/6a7b8b7a783979ea34063bad
Pulse Author: AlienVault
Created: 2026-08-11 20:52:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Java #JavaScript #Malware #OTX #OpenThreatExchange #ZeroDay #bot #AlienVault
-
Fake CCleaner installs GhostDesk Chrome spyware
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.
Pulse ID: 6a7b8dab529ad28b12d29796
Pulse Link: https://otx.alienvault.com/pulse/6a7b8dab529ad28b12d29796
Pulse Author: AlienVault
Created: 2026-08-11 21:01:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault
-
Fake CCleaner installs GhostDesk Chrome spyware
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.
Pulse ID: 6a7b8dab529ad28b12d29796
Pulse Link: https://otx.alienvault.com/pulse/6a7b8dab529ad28b12d29796
Pulse Author: AlienVault
Created: 2026-08-11 21:01:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault
-
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.
Pulse ID: 6a7bdb051d6a41c7ea440061
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb051d6a41c7ea440061
Pulse Author: AlienVault
Created: 2026-08-12 02:31:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault
-
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.
Pulse ID: 6a7bdb051d6a41c7ea440061
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb051d6a41c7ea440061
Pulse Author: AlienVault
Created: 2026-08-12 02:31:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
Pulse ID: 6a7bdb4167c384aad06f1253
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb4167c384aad06f1253
Pulse Author: AlienVault
Created: 2026-08-12 02:32:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
Pulse ID: 6a7bdb4167c384aad06f1253
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb4167c384aad06f1253
Pulse Author: AlienVault
Created: 2026-08-12 02:32:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault
-
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...
Pulse ID: 6a7b3ff969397d537e5d24fa
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ff969397d537e5d24fa
Pulse Author: AlienVault
Created: 2026-08-11 15:30:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault
-
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...
Pulse ID: 6a7b3ff969397d537e5d24fa
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ff969397d537e5d24fa
Pulse Author: AlienVault
Created: 2026-08-11 15:30:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
Project CAV3RN is a sophisticated modular espionage framework targeting entities in Israel. Recent analysis uncovered advanced C2 capabilities using DNS A-record responses to dynamically select between direct HTTPS and Google Apps Script relay channels for each transaction. The framework employs DNS infrastructure to validate and rotate Google Apps Script deployment IDs. A local broker component discovers and loads DLL modules, routes inter-component messages, and supports runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay that forwards requests to actor-controlled infrastructure. The framework demonstrates increasing sophistication through legitimate service abuse, making network detection difficult while maintaining operational flexibility through modular architecture.
Pulse ID: 6a7b022f15eb07ffe06f79e1
Pulse Link: https://otx.alienvault.com/pulse/6a7b022f15eb07ffe06f79e1
Pulse Author: AlienVault
Created: 2026-08-11 11:06:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #Troll #bot #AlienVault
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
Project CAV3RN is a sophisticated modular espionage framework targeting entities in Israel. Recent analysis uncovered advanced C2 capabilities using DNS A-record responses to dynamically select between direct HTTPS and Google Apps Script relay channels for each transaction. The framework employs DNS infrastructure to validate and rotate Google Apps Script deployment IDs. A local broker component discovers and loads DLL modules, routes inter-component messages, and supports runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay that forwards requests to actor-controlled infrastructure. The framework demonstrates increasing sophistication through legitimate service abuse, making network detection difficult while maintaining operational flexibility through modular architecture.
Pulse ID: 6a7b022f15eb07ffe06f79e1
Pulse Link: https://otx.alienvault.com/pulse/6a7b022f15eb07ffe06f79e1
Pulse Author: AlienVault
Created: 2026-08-11 11:06:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #Troll #bot #AlienVault
-
Fake popular sites offer a free app, instead take over PCs
A sophisticated campaign uses lookalike websites impersonating CNN, Avast, and Stremio to distribute legitimate remote administration software O&O Syspectr that's pre-linked to attacker-controlled accounts. Victims believe they're downloading legitimate apps from trusted brands but instead install genuine, digitally signed remote-access tools that grant attackers full control over Windows computers. Additional fake sites promote cryptocurrency mining browser games with the same objective. The installers share common account identifiers, linking them to the same operators. Since the software is legitimate and digitally signed, traditional antivirus may not detect it. O&O Software responded by disabling remote features on free accounts and suspending abusive accounts after notification.
Pulse ID: 6a7b022f777f143eca0c8ee5
Pulse Link: https://otx.alienvault.com/pulse/6a7b022f777f143eca0c8ee5
Pulse Author: AlienVault
Created: 2026-08-11 11:06:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Rust #Troll #Windows #bot #cryptocurrency #AlienVault
-
Fake popular sites offer a free app, instead take over PCs
A sophisticated campaign uses lookalike websites impersonating CNN, Avast, and Stremio to distribute legitimate remote administration software O&O Syspectr that's pre-linked to attacker-controlled accounts. Victims believe they're downloading legitimate apps from trusted brands but instead install genuine, digitally signed remote-access tools that grant attackers full control over Windows computers. Additional fake sites promote cryptocurrency mining browser games with the same objective. The installers share common account identifiers, linking them to the same operators. Since the software is legitimate and digitally signed, traditional antivirus may not detect it. O&O Software responded by disabling remote features on free accounts and suspending abusive accounts after notification.
Pulse ID: 6a7b022f777f143eca0c8ee5
Pulse Link: https://otx.alienvault.com/pulse/6a7b022f777f143eca0c8ee5
Pulse Author: AlienVault
Created: 2026-08-11 11:06:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Rust #Troll #Windows #bot #cryptocurrency #AlienVault