#alienvault — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #alienvault, aggregated by home.social.
-
Fake iPhone Duo preorder scam triggers DarkSword attack
Scammers have weaponized fake iPhone Duo preorder pages to deploy the DarkSword exploit chain against vulnerable iPhones. The fraudulent pages mimic Apple's design and offer a $500 voucher to lure victims, but simply opening the page in Safari triggers an exploitation attempt without requiring user interaction. The attack targets iPhones running unpatched iOS versions, attempting to bypass security protections and deploy a payload designed to steal saved credentials, cryptocurrency wallet data, notes, messages, contacts, and other sensitive information. The exploit leverages vulnerabilities previously disclosed by Google in March 2026 and patched by Apple. If successful, the payload establishes communication with command-and-control servers and can execute additional commands remotely while attempting to cover its tracks by deleting diagnostic reports.
Pulse ID: 6abbc428d397735970a34334
Pulse Link: https://otx.alienvault.com/pulse/6abbc428d397735970a34334
Pulse Author: AlienVault
Created: 2026-09-29 13:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Fake iPhone Duo preorder scam triggers DarkSword attack
Scammers have weaponized fake iPhone Duo preorder pages to deploy the DarkSword exploit chain against vulnerable iPhones. The fraudulent pages mimic Apple's design and offer a $500 voucher to lure victims, but simply opening the page in Safari triggers an exploitation attempt without requiring user interaction. The attack targets iPhones running unpatched iOS versions, attempting to bypass security protections and deploy a payload designed to steal saved credentials, cryptocurrency wallet data, notes, messages, contacts, and other sensitive information. The exploit leverages vulnerabilities previously disclosed by Google in March 2026 and patched by Apple. If successful, the payload establishes communication with command-and-control servers and can execute additional commands remotely while attempting to cover its tracks by deleting diagnostic reports.
Pulse ID: 6abbc428d397735970a34334
Pulse Link: https://otx.alienvault.com/pulse/6abbc428d397735970a34334
Pulse Author: AlienVault
Created: 2026-09-29 13:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Fake iPhone Duo preorder scam triggers DarkSword attack
Scammers have weaponized fake iPhone Duo preorder pages to deploy the DarkSword exploit chain against vulnerable iPhones. The fraudulent pages mimic Apple's design and offer a $500 voucher to lure victims, but simply opening the page in Safari triggers an exploitation attempt without requiring user interaction. The attack targets iPhones running unpatched iOS versions, attempting to bypass security protections and deploy a payload designed to steal saved credentials, cryptocurrency wallet data, notes, messages, contacts, and other sensitive information. The exploit leverages vulnerabilities previously disclosed by Google in March 2026 and patched by Apple. If successful, the payload establishes communication with command-and-control servers and can execute additional commands remotely while attempting to cover its tracks by deleting diagnostic reports.
Pulse ID: 6abbc428d397735970a34334
Pulse Link: https://otx.alienvault.com/pulse/6abbc428d397735970a34334
Pulse Author: AlienVault
Created: 2026-09-29 13:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Fake iPhone Duo preorder scam triggers DarkSword attack
Scammers have weaponized fake iPhone Duo preorder pages to deploy the DarkSword exploit chain against vulnerable iPhones. The fraudulent pages mimic Apple's design and offer a $500 voucher to lure victims, but simply opening the page in Safari triggers an exploitation attempt without requiring user interaction. The attack targets iPhones running unpatched iOS versions, attempting to bypass security protections and deploy a payload designed to steal saved credentials, cryptocurrency wallet data, notes, messages, contacts, and other sensitive information. The exploit leverages vulnerabilities previously disclosed by Google in March 2026 and patched by Apple. If successful, the payload establishes communication with command-and-control servers and can execute additional commands remotely while attempting to cover its tracks by deleting diagnostic reports.
Pulse ID: 6abbc428d397735970a34334
Pulse Link: https://otx.alienvault.com/pulse/6abbc428d397735970a34334
Pulse Author: AlienVault
Created: 2026-09-29 13:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Fake iPhone Duo preorder scam triggers DarkSword attack
Scammers have weaponized fake iPhone Duo preorder pages to deploy the DarkSword exploit chain against vulnerable iPhones. The fraudulent pages mimic Apple's design and offer a $500 voucher to lure victims, but simply opening the page in Safari triggers an exploitation attempt without requiring user interaction. The attack targets iPhones running unpatched iOS versions, attempting to bypass security protections and deploy a payload designed to steal saved credentials, cryptocurrency wallet data, notes, messages, contacts, and other sensitive information. The exploit leverages vulnerabilities previously disclosed by Google in March 2026 and patched by Apple. If successful, the payload establishes communication with command-and-control servers and can execute additional commands remotely while attempting to cover its tracks by deleting diagnostic reports.
Pulse ID: 6abbc428d397735970a34334
Pulse Link: https://otx.alienvault.com/pulse/6abbc428d397735970a34334
Pulse Author: AlienVault
Created: 2026-09-29 13:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
ASEC identified a phishing campaign targeting organizations in Korea through emails impersonating company employees. The emails contain malicious XLS files disguised as project material purchase request forms. When opened, the documents exploit CVE-2017-0199, an OLE2Link vulnerability in Microsoft Office, to download HTA files from a C2 server. The HTA file executes an obfuscated PowerShell script that downloads a steganographic PNG file containing a Base64-encoded .NET loader. This loader subsequently deploys Remcos RAT, which performs keylogging, screen capture, file manipulation, and exfiltrates system information to command and control infrastructure. The attack chain demonstrates sophisticated social engineering combined with multiple layers of obfuscation and encoding techniques.
Pulse ID: 6abbbd28cb7e4cac7c679e36
Pulse Link: https://otx.alienvault.com/pulse/6abbbd28cb7e4cac7c679e36
Pulse Author: AlienVault
Created: 2026-09-29 13:29:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
ASEC identified a phishing campaign targeting organizations in Korea through emails impersonating company employees. The emails contain malicious XLS files disguised as project material purchase request forms. When opened, the documents exploit CVE-2017-0199, an OLE2Link vulnerability in Microsoft Office, to download HTA files from a C2 server. The HTA file executes an obfuscated PowerShell script that downloads a steganographic PNG file containing a Base64-encoded .NET loader. This loader subsequently deploys Remcos RAT, which performs keylogging, screen capture, file manipulation, and exfiltrates system information to command and control infrastructure. The attack chain demonstrates sophisticated social engineering combined with multiple layers of obfuscation and encoding techniques.
Pulse ID: 6abbbd28cb7e4cac7c679e36
Pulse Link: https://otx.alienvault.com/pulse/6abbbd28cb7e4cac7c679e36
Pulse Author: AlienVault
Created: 2026-09-29 13:29:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
ASEC identified a phishing campaign targeting organizations in Korea through emails impersonating company employees. The emails contain malicious XLS files disguised as project material purchase request forms. When opened, the documents exploit CVE-2017-0199, an OLE2Link vulnerability in Microsoft Office, to download HTA files from a C2 server. The HTA file executes an obfuscated PowerShell script that downloads a steganographic PNG file containing a Base64-encoded .NET loader. This loader subsequently deploys Remcos RAT, which performs keylogging, screen capture, file manipulation, and exfiltrates system information to command and control infrastructure. The attack chain demonstrates sophisticated social engineering combined with multiple layers of obfuscation and encoding techniques.
Pulse ID: 6abbbd28cb7e4cac7c679e36
Pulse Link: https://otx.alienvault.com/pulse/6abbbd28cb7e4cac7c679e36
Pulse Author: AlienVault
Created: 2026-09-29 13:29:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
ASEC identified a phishing campaign targeting organizations in Korea through emails impersonating company employees. The emails contain malicious XLS files disguised as project material purchase request forms. When opened, the documents exploit CVE-2017-0199, an OLE2Link vulnerability in Microsoft Office, to download HTA files from a C2 server. The HTA file executes an obfuscated PowerShell script that downloads a steganographic PNG file containing a Base64-encoded .NET loader. This loader subsequently deploys Remcos RAT, which performs keylogging, screen capture, file manipulation, and exfiltrates system information to command and control infrastructure. The attack chain demonstrates sophisticated social engineering combined with multiple layers of obfuscation and encoding techniques.
Pulse ID: 6abbbd28cb7e4cac7c679e36
Pulse Link: https://otx.alienvault.com/pulse/6abbbd28cb7e4cac7c679e36
Pulse Author: AlienVault
Created: 2026-09-29 13:29:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
ASEC identified a phishing campaign targeting organizations in Korea through emails impersonating company employees. The emails contain malicious XLS files disguised as project material purchase request forms. When opened, the documents exploit CVE-2017-0199, an OLE2Link vulnerability in Microsoft Office, to download HTA files from a C2 server. The HTA file executes an obfuscated PowerShell script that downloads a steganographic PNG file containing a Base64-encoded .NET loader. This loader subsequently deploys Remcos RAT, which performs keylogging, screen capture, file manipulation, and exfiltrates system information to command and control infrastructure. The attack chain demonstrates sophisticated social engineering combined with multiple layers of obfuscation and encoding techniques.
Pulse ID: 6abbbd28cb7e4cac7c679e36
Pulse Link: https://otx.alienvault.com/pulse/6abbbd28cb7e4cac7c679e36
Pulse Author: AlienVault
Created: 2026-09-29 13:29:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The "VPN for X" Proxy Farm — Risky Plugins
A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection.
Pulse ID: 6abb5c0df118a53bf415b0bd
Pulse Link: https://otx.alienvault.com/pulse/6abb5c0df118a53bf415b0bd
Pulse Author: AlienVault
Created: 2026-09-29 06:34:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The "VPN for X" Proxy Farm — Risky Plugins
A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection.
Pulse ID: 6abb5c0df118a53bf415b0bd
Pulse Link: https://otx.alienvault.com/pulse/6abb5c0df118a53bf415b0bd
Pulse Author: AlienVault
Created: 2026-09-29 06:34:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The "VPN for X" Proxy Farm — Risky Plugins
A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection.
Pulse ID: 6abb5c0df118a53bf415b0bd
Pulse Link: https://otx.alienvault.com/pulse/6abb5c0df118a53bf415b0bd
Pulse Author: AlienVault
Created: 2026-09-29 06:34:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The "VPN for X" Proxy Farm — Risky Plugins
A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection.
Pulse ID: 6abb5c0df118a53bf415b0bd
Pulse Link: https://otx.alienvault.com/pulse/6abb5c0df118a53bf415b0bd
Pulse Author: AlienVault
Created: 2026-09-29 06:34:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The "VPN for X" Proxy Farm — Risky Plugins
A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection.
Pulse ID: 6abb5c0df118a53bf415b0bd
Pulse Link: https://otx.alienvault.com/pulse/6abb5c0df118a53bf415b0bd
Pulse Author: AlienVault
Created: 2026-09-29 06:34:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Threat actors are exploiting ChatGPT Custom GPTs and Google Sites to deliver remote access trojans through a sophisticated multi-stage attack chain. The campaign uses sponsored Google search results to direct victims to attacker-created Custom GPTs that impersonate legitimate ChatGPT models. Victims are then redirected to a malicious Google Sites page presenting a fake CloudFlare CAPTCHA that deploys a ClickFix lure, tricking users into executing PowerShell commands. This initiates an eight-stage infection chain involving obfuscated scripts, malicious MSI installers, and DLL sideloading through legitimately signed Canon or Stardock executables. The payload establishes dual persistence mechanisms and deploys a full-featured RAT with capabilities including remote desktop access, credential harvesting from seventeen browsers, file management, and payload deployment. Huntress investigators responded to at least 40 related incidents with two confirmed Custom GPT-driven infections.
Pulse ID: 6abb0c55e0fed2d6a1f7e51a
Pulse Link: https://otx.alienvault.com/pulse/6abb0c55e0fed2d6a1f7e51a
Pulse Author: AlienVault
Created: 2026-09-29 00:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Threat actors are exploiting ChatGPT Custom GPTs and Google Sites to deliver remote access trojans through a sophisticated multi-stage attack chain. The campaign uses sponsored Google search results to direct victims to attacker-created Custom GPTs that impersonate legitimate ChatGPT models. Victims are then redirected to a malicious Google Sites page presenting a fake CloudFlare CAPTCHA that deploys a ClickFix lure, tricking users into executing PowerShell commands. This initiates an eight-stage infection chain involving obfuscated scripts, malicious MSI installers, and DLL sideloading through legitimately signed Canon or Stardock executables. The payload establishes dual persistence mechanisms and deploys a full-featured RAT with capabilities including remote desktop access, credential harvesting from seventeen browsers, file management, and payload deployment. Huntress investigators responded to at least 40 related incidents with two confirmed Custom GPT-driven infections.
Pulse ID: 6abb0c55e0fed2d6a1f7e51a
Pulse Link: https://otx.alienvault.com/pulse/6abb0c55e0fed2d6a1f7e51a
Pulse Author: AlienVault
Created: 2026-09-29 00:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Threat actors are exploiting ChatGPT Custom GPTs and Google Sites to deliver remote access trojans through a sophisticated multi-stage attack chain. The campaign uses sponsored Google search results to direct victims to attacker-created Custom GPTs that impersonate legitimate ChatGPT models. Victims are then redirected to a malicious Google Sites page presenting a fake CloudFlare CAPTCHA that deploys a ClickFix lure, tricking users into executing PowerShell commands. This initiates an eight-stage infection chain involving obfuscated scripts, malicious MSI installers, and DLL sideloading through legitimately signed Canon or Stardock executables. The payload establishes dual persistence mechanisms and deploys a full-featured RAT with capabilities including remote desktop access, credential harvesting from seventeen browsers, file management, and payload deployment. Huntress investigators responded to at least 40 related incidents with two confirmed Custom GPT-driven infections.
Pulse ID: 6abb0c55e0fed2d6a1f7e51a
Pulse Link: https://otx.alienvault.com/pulse/6abb0c55e0fed2d6a1f7e51a
Pulse Author: AlienVault
Created: 2026-09-29 00:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Threat actors are exploiting ChatGPT Custom GPTs and Google Sites to deliver remote access trojans through a sophisticated multi-stage attack chain. The campaign uses sponsored Google search results to direct victims to attacker-created Custom GPTs that impersonate legitimate ChatGPT models. Victims are then redirected to a malicious Google Sites page presenting a fake CloudFlare CAPTCHA that deploys a ClickFix lure, tricking users into executing PowerShell commands. This initiates an eight-stage infection chain involving obfuscated scripts, malicious MSI installers, and DLL sideloading through legitimately signed Canon or Stardock executables. The payload establishes dual persistence mechanisms and deploys a full-featured RAT with capabilities including remote desktop access, credential harvesting from seventeen browsers, file management, and payload deployment. Huntress investigators responded to at least 40 related incidents with two confirmed Custom GPT-driven infections.
Pulse ID: 6abb0c55e0fed2d6a1f7e51a
Pulse Link: https://otx.alienvault.com/pulse/6abb0c55e0fed2d6a1f7e51a
Pulse Author: AlienVault
Created: 2026-09-29 00:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Threat actors are exploiting ChatGPT Custom GPTs and Google Sites to deliver remote access trojans through a sophisticated multi-stage attack chain. The campaign uses sponsored Google search results to direct victims to attacker-created Custom GPTs that impersonate legitimate ChatGPT models. Victims are then redirected to a malicious Google Sites page presenting a fake CloudFlare CAPTCHA that deploys a ClickFix lure, tricking users into executing PowerShell commands. This initiates an eight-stage infection chain involving obfuscated scripts, malicious MSI installers, and DLL sideloading through legitimately signed Canon or Stardock executables. The payload establishes dual persistence mechanisms and deploys a full-featured RAT with capabilities including remote desktop access, credential harvesting from seventeen browsers, file management, and payload deployment. Huntress investigators responded to at least 40 related incidents with two confirmed Custom GPT-driven infections.
Pulse ID: 6abb0c55e0fed2d6a1f7e51a
Pulse Link: https://otx.alienvault.com/pulse/6abb0c55e0fed2d6a1f7e51a
Pulse Author: AlienVault
Created: 2026-09-29 00:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis is a modular post-compromise malware family deployed in limited targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, the malware is typically deployed after threat actors have established access, serving to maintain long-term persistence and support follow-on operations. Its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components enabling operators to evade analysis and extend functionality. The malware employs DLL sideloading, WebSockets-based command-and-control communications, and RC4 encryption. Activity aligns with China-based threat actors, with Storm-3069 identified as one operator using NeedyMantis following the DAEMON Tools supply chain compromise.
Pulse ID: 6abac5fd70758a52b56cb48e
Pulse Link: https://otx.alienvault.com/pulse/6abac5fd70758a52b56cb48e
Pulse Author: AlienVault
Created: 2026-09-28 19:54:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis is a modular post-compromise malware family deployed in limited targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, the malware is typically deployed after threat actors have established access, serving to maintain long-term persistence and support follow-on operations. Its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components enabling operators to evade analysis and extend functionality. The malware employs DLL sideloading, WebSockets-based command-and-control communications, and RC4 encryption. Activity aligns with China-based threat actors, with Storm-3069 identified as one operator using NeedyMantis following the DAEMON Tools supply chain compromise.
Pulse ID: 6abac5fd70758a52b56cb48e
Pulse Link: https://otx.alienvault.com/pulse/6abac5fd70758a52b56cb48e
Pulse Author: AlienVault
Created: 2026-09-28 19:54:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis is a modular post-compromise malware family deployed in limited targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, the malware is typically deployed after threat actors have established access, serving to maintain long-term persistence and support follow-on operations. Its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components enabling operators to evade analysis and extend functionality. The malware employs DLL sideloading, WebSockets-based command-and-control communications, and RC4 encryption. Activity aligns with China-based threat actors, with Storm-3069 identified as one operator using NeedyMantis following the DAEMON Tools supply chain compromise.
Pulse ID: 6abac5fd70758a52b56cb48e
Pulse Link: https://otx.alienvault.com/pulse/6abac5fd70758a52b56cb48e
Pulse Author: AlienVault
Created: 2026-09-28 19:54:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis is a modular post-compromise malware family deployed in limited targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, the malware is typically deployed after threat actors have established access, serving to maintain long-term persistence and support follow-on operations. Its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components enabling operators to evade analysis and extend functionality. The malware employs DLL sideloading, WebSockets-based command-and-control communications, and RC4 encryption. Activity aligns with China-based threat actors, with Storm-3069 identified as one operator using NeedyMantis following the DAEMON Tools supply chain compromise.
Pulse ID: 6abac5fd70758a52b56cb48e
Pulse Link: https://otx.alienvault.com/pulse/6abac5fd70758a52b56cb48e
Pulse Author: AlienVault
Created: 2026-09-28 19:54:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis is a modular post-compromise malware family deployed in limited targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, the malware is typically deployed after threat actors have established access, serving to maintain long-term persistence and support follow-on operations. Its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components enabling operators to evade analysis and extend functionality. The malware employs DLL sideloading, WebSockets-based command-and-control communications, and RC4 encryption. Activity aligns with China-based threat actors, with Storm-3069 identified as one operator using NeedyMantis following the DAEMON Tools supply chain compromise.
Pulse ID: 6abac5fd70758a52b56cb48e
Pulse Link: https://otx.alienvault.com/pulse/6abac5fd70758a52b56cb48e
Pulse Author: AlienVault
Created: 2026-09-28 19:54:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...
Pulse ID: 6abaccf85f7a199ca2ad50c6
Pulse Link: https://otx.alienvault.com/pulse/6abaccf85f7a199ca2ad50c6
Pulse Author: AlienVault
Created: 2026-09-28 20:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...
Pulse ID: 6abaccf85f7a199ca2ad50c6
Pulse Link: https://otx.alienvault.com/pulse/6abaccf85f7a199ca2ad50c6
Pulse Author: AlienVault
Created: 2026-09-28 20:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...
Pulse ID: 6abaccf85f7a199ca2ad50c6
Pulse Link: https://otx.alienvault.com/pulse/6abaccf85f7a199ca2ad50c6
Pulse Author: AlienVault
Created: 2026-09-28 20:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...
Pulse ID: 6abaccf85f7a199ca2ad50c6
Pulse Link: https://otx.alienvault.com/pulse/6abaccf85f7a199ca2ad50c6
Pulse Author: AlienVault
Created: 2026-09-28 20:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...
Pulse ID: 6abaccf85f7a199ca2ad50c6
Pulse Link: https://otx.alienvault.com/pulse/6abaccf85f7a199ca2ad50c6
Pulse Author: AlienVault
Created: 2026-09-28 20:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Rise of the Jev-Clones
Following the launch of TypeSafe AI's Jev API, numerous fraudulent storefronts emerged selling access to the legitimate API at inflated prices ranging from 3 to 11.5 times the official cost. Within three days of launch, lookalike domains were registered and ranked higher than the official site in search results. At least six sites operated identical code, with operators quickly reskinning platforms for trending AI models. Certificate transparency logs revealed approximately 670 new domains containing "jev" registered within eight days of launch. These storefronts route customer prompts through third-party servers before reaching TypeSafe's API, creating security and privacy risks. While not illegal, these operations exploit brand confusion and charge excessive markups for direct API access.
Pulse ID: 6aba80800986c7309a31cc76
Pulse Link: https://otx.alienvault.com/pulse/6aba80800986c7309a31cc76
Pulse Author: AlienVault
Created: 2026-09-28 14:58:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Rise of the Jev-Clones
Following the launch of TypeSafe AI's Jev API, numerous fraudulent storefronts emerged selling access to the legitimate API at inflated prices ranging from 3 to 11.5 times the official cost. Within three days of launch, lookalike domains were registered and ranked higher than the official site in search results. At least six sites operated identical code, with operators quickly reskinning platforms for trending AI models. Certificate transparency logs revealed approximately 670 new domains containing "jev" registered within eight days of launch. These storefronts route customer prompts through third-party servers before reaching TypeSafe's API, creating security and privacy risks. While not illegal, these operations exploit brand confusion and charge excessive markups for direct API access.
Pulse ID: 6aba80800986c7309a31cc76
Pulse Link: https://otx.alienvault.com/pulse/6aba80800986c7309a31cc76
Pulse Author: AlienVault
Created: 2026-09-28 14:58:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Rise of the Jev-Clones
Following the launch of TypeSafe AI's Jev API, numerous fraudulent storefronts emerged selling access to the legitimate API at inflated prices ranging from 3 to 11.5 times the official cost. Within three days of launch, lookalike domains were registered and ranked higher than the official site in search results. At least six sites operated identical code, with operators quickly reskinning platforms for trending AI models. Certificate transparency logs revealed approximately 670 new domains containing "jev" registered within eight days of launch. These storefronts route customer prompts through third-party servers before reaching TypeSafe's API, creating security and privacy risks. While not illegal, these operations exploit brand confusion and charge excessive markups for direct API access.
Pulse ID: 6aba80800986c7309a31cc76
Pulse Link: https://otx.alienvault.com/pulse/6aba80800986c7309a31cc76
Pulse Author: AlienVault
Created: 2026-09-28 14:58:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Rise of the Jev-Clones
Following the launch of TypeSafe AI's Jev API, numerous fraudulent storefronts emerged selling access to the legitimate API at inflated prices ranging from 3 to 11.5 times the official cost. Within three days of launch, lookalike domains were registered and ranked higher than the official site in search results. At least six sites operated identical code, with operators quickly reskinning platforms for trending AI models. Certificate transparency logs revealed approximately 670 new domains containing "jev" registered within eight days of launch. These storefronts route customer prompts through third-party servers before reaching TypeSafe's API, creating security and privacy risks. While not illegal, these operations exploit brand confusion and charge excessive markups for direct API access.
Pulse ID: 6aba80800986c7309a31cc76
Pulse Link: https://otx.alienvault.com/pulse/6aba80800986c7309a31cc76
Pulse Author: AlienVault
Created: 2026-09-28 14:58:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Rise of the Jev-Clones
Following the launch of TypeSafe AI's Jev API, numerous fraudulent storefronts emerged selling access to the legitimate API at inflated prices ranging from 3 to 11.5 times the official cost. Within three days of launch, lookalike domains were registered and ranked higher than the official site in search results. At least six sites operated identical code, with operators quickly reskinning platforms for trending AI models. Certificate transparency logs revealed approximately 670 new domains containing "jev" registered within eight days of launch. These storefronts route customer prompts through third-party servers before reaching TypeSafe's API, creating security and privacy risks. While not illegal, these operations exploit brand confusion and charge excessive markups for direct API access.
Pulse ID: 6aba80800986c7309a31cc76
Pulse Link: https://otx.alienvault.com/pulse/6aba80800986c7309a31cc76
Pulse Author: AlienVault
Created: 2026-09-28 14:58:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Telerik UI 취약점을 악용한 웹쉘 설치 및 스캐너 실행 공격 사례
Multiple attack campaigns exploiting CVE-2019-18935, a remote code execution vulnerability in unpatched Telerik UI for ASP.NET AJAX servers, have been identified. The first case involved exploiting the vulnerability to execute a reverse shell connecting to 206.82.6.22, attempting privilege escalation using Potato-family tools like SweetPotato, and installing a Godzilla-style memory-based web shell that operates within the w3wp.exe process without requiring separate ASPX files. The second case deployed a Rust-based scanner tool that searches for exposed WordPress installation pages across target systems and reports findings via Telegram. Both attacks targeted Windows IIS servers, enabling attackers to maintain persistent access, collect system information, and identify additional targets for future campaigns.
Pulse ID: 6aba1398c736673eae22c865
Pulse Link: https://otx.alienvault.com/pulse/6aba1398c736673eae22c865
Pulse Author: AlienVault
Created: 2026-09-28 07:13:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Telerik UI 취약점을 악용한 웹쉘 설치 및 스캐너 실행 공격 사례
Multiple attack campaigns exploiting CVE-2019-18935, a remote code execution vulnerability in unpatched Telerik UI for ASP.NET AJAX servers, have been identified. The first case involved exploiting the vulnerability to execute a reverse shell connecting to 206.82.6.22, attempting privilege escalation using Potato-family tools like SweetPotato, and installing a Godzilla-style memory-based web shell that operates within the w3wp.exe process without requiring separate ASPX files. The second case deployed a Rust-based scanner tool that searches for exposed WordPress installation pages across target systems and reports findings via Telegram. Both attacks targeted Windows IIS servers, enabling attackers to maintain persistent access, collect system information, and identify additional targets for future campaigns.
Pulse ID: 6aba1398c736673eae22c865
Pulse Link: https://otx.alienvault.com/pulse/6aba1398c736673eae22c865
Pulse Author: AlienVault
Created: 2026-09-28 07:13:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Telerik UI 취약점을 악용한 웹쉘 설치 및 스캐너 실행 공격 사례
Multiple attack campaigns exploiting CVE-2019-18935, a remote code execution vulnerability in unpatched Telerik UI for ASP.NET AJAX servers, have been identified. The first case involved exploiting the vulnerability to execute a reverse shell connecting to 206.82.6.22, attempting privilege escalation using Potato-family tools like SweetPotato, and installing a Godzilla-style memory-based web shell that operates within the w3wp.exe process without requiring separate ASPX files. The second case deployed a Rust-based scanner tool that searches for exposed WordPress installation pages across target systems and reports findings via Telegram. Both attacks targeted Windows IIS servers, enabling attackers to maintain persistent access, collect system information, and identify additional targets for future campaigns.
Pulse ID: 6aba1398c736673eae22c865
Pulse Link: https://otx.alienvault.com/pulse/6aba1398c736673eae22c865
Pulse Author: AlienVault
Created: 2026-09-28 07:13:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Telerik UI 취약점을 악용한 웹쉘 설치 및 스캐너 실행 공격 사례
Multiple attack campaigns exploiting CVE-2019-18935, a remote code execution vulnerability in unpatched Telerik UI for ASP.NET AJAX servers, have been identified. The first case involved exploiting the vulnerability to execute a reverse shell connecting to 206.82.6.22, attempting privilege escalation using Potato-family tools like SweetPotato, and installing a Godzilla-style memory-based web shell that operates within the w3wp.exe process without requiring separate ASPX files. The second case deployed a Rust-based scanner tool that searches for exposed WordPress installation pages across target systems and reports findings via Telegram. Both attacks targeted Windows IIS servers, enabling attackers to maintain persistent access, collect system information, and identify additional targets for future campaigns.
Pulse ID: 6aba1398c736673eae22c865
Pulse Link: https://otx.alienvault.com/pulse/6aba1398c736673eae22c865
Pulse Author: AlienVault
Created: 2026-09-28 07:13:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Telerik UI 취약점을 악용한 웹쉘 설치 및 스캐너 실행 공격 사례
Multiple attack campaigns exploiting CVE-2019-18935, a remote code execution vulnerability in unpatched Telerik UI for ASP.NET AJAX servers, have been identified. The first case involved exploiting the vulnerability to execute a reverse shell connecting to 206.82.6.22, attempting privilege escalation using Potato-family tools like SweetPotato, and installing a Godzilla-style memory-based web shell that operates within the w3wp.exe process without requiring separate ASPX files. The second case deployed a Rust-based scanner tool that searches for exposed WordPress installation pages across target systems and reports findings via Telegram. Both attacks targeted Windows IIS servers, enabling attackers to maintain persistent access, collect system information, and identify additional targets for future campaigns.
Pulse ID: 6aba1398c736673eae22c865
Pulse Link: https://otx.alienvault.com/pulse/6aba1398c736673eae22c865
Pulse Author: AlienVault
Created: 2026-09-28 07:13:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Exploits Oracle PeopleSoft Vulnerability CVE-2026-35273 in New Attack Wave
Pulse ID: 6aba4306545d3f90103c576e
Pulse Link: https://otx.alienvault.com/pulse/6aba4306545d3f90103c576e
Pulse Author: AlienVault
Created: 2026-09-28 10:35:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Exploits Oracle PeopleSoft Vulnerability CVE-2026-35273 in New Attack Wave
Pulse ID: 6aba4306545d3f90103c576e
Pulse Link: https://otx.alienvault.com/pulse/6aba4306545d3f90103c576e
Pulse Author: AlienVault
Created: 2026-09-28 10:35:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Exploits Oracle PeopleSoft Vulnerability CVE-2026-35273 in New Attack Wave
Pulse ID: 6aba4306545d3f90103c576e
Pulse Link: https://otx.alienvault.com/pulse/6aba4306545d3f90103c576e
Pulse Author: AlienVault
Created: 2026-09-28 10:35:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Exploits Oracle PeopleSoft Vulnerability CVE-2026-35273 in New Attack Wave
Pulse ID: 6aba4306545d3f90103c576e
Pulse Link: https://otx.alienvault.com/pulse/6aba4306545d3f90103c576e
Pulse Author: AlienVault
Created: 2026-09-28 10:35:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Exploits Oracle PeopleSoft Vulnerability CVE-2026-35273 in New Attack Wave
Pulse ID: 6aba4306545d3f90103c576e
Pulse Link: https://otx.alienvault.com/pulse/6aba4306545d3f90103c576e
Pulse Author: AlienVault
Created: 2026-09-28 10:35:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables. The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection. The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends. The payload targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data. It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion. Persistence is established through registry Run keys and scheduled tasks. All stolen data is packaged into in-memory ZIP archives and exfiltrated via attacker-controlled webhooks, following a scalable affiliate model.
Pulse ID: 6aba46a2a513094d63bf1bd1
Pulse Link: https://otx.alienvault.com/pulse/6aba46a2a513094d63bf1bd1
Pulse Author: AlienVault
Created: 2026-09-28 10:51:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables. The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection. The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends. The payload targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data. It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion. Persistence is established through registry Run keys and scheduled tasks. All stolen data is packaged into in-memory ZIP archives and exfiltrated via attacker-controlled webhooks, following a scalable affiliate model.
Pulse ID: 6aba46a2a513094d63bf1bd1
Pulse Link: https://otx.alienvault.com/pulse/6aba46a2a513094d63bf1bd1
Pulse Author: AlienVault
Created: 2026-09-28 10:51:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables. The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection. The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends. The payload targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data. It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion. Persistence is established through registry Run keys and scheduled tasks. All stolen data is packaged into in-memory ZIP archives and exfiltrated via attacker-controlled webhooks, following a scalable affiliate model.
Pulse ID: 6aba46a2a513094d63bf1bd1
Pulse Link: https://otx.alienvault.com/pulse/6aba46a2a513094d63bf1bd1
Pulse Author: AlienVault
Created: 2026-09-28 10:51:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables. The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection. The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends. The payload targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data. It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion. Persistence is established through registry Run keys and scheduled tasks. All stolen data is packaged into in-memory ZIP archives and exfiltrated via attacker-controlled webhooks, following a scalable affiliate model.
Pulse ID: 6aba46a2a513094d63bf1bd1
Pulse Link: https://otx.alienvault.com/pulse/6aba46a2a513094d63bf1bd1
Pulse Author: AlienVault
Created: 2026-09-28 10:51:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables. The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection. The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends. The payload targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data. It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion. Persistence is established through registry Run keys and scheduled tasks. All stolen data is packaged into in-memory ZIP archives and exfiltrated via attacker-controlled webhooks, following a scalable affiliate model.
Pulse ID: 6aba46a2a513094d63bf1bd1
Pulse Link: https://otx.alienvault.com/pulse/6aba46a2a513094d63bf1bd1
Pulse Author: AlienVault
Created: 2026-09-28 10:51:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.