#backdoor — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #backdoor, aggregated by home.social.
-
HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel
Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia. -
HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel
Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia. -
CoolClient backdoor goes deeper: Windows kernel rootkit added
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.
Pulse ID: 6a7ef2da146fb06724520eb4
Pulse Link: https://otx.alienvault.com/pulse/6a7ef2da146fb06724520eb4
Pulse Author: AlienVault
Created: 2026-08-14 10:50:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault
-
CoolClient backdoor goes deeper: Windows kernel rootkit added
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.
Pulse ID: 6a7ef2da146fb06724520eb4
Pulse Link: https://otx.alienvault.com/pulse/6a7ef2da146fb06724520eb4
Pulse Author: AlienVault
Created: 2026-08-14 10:50:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
Страховой случай: изучаем инструменты и инфраструктуру новой киберпреступной группировки Malinsure
Аналитики F6 Threat Intelligence обнаружили новую угрозу для российских компаний – Malinsure . Группировка использует собственный бэкдор SafeMostSSH и нестандартные TTPs.
https://habr.com/ru/companies/F6/articles/1070006/
#threat_intelligence #backdoor #safemostssh #malinsure #фишинговые_рассылки #дмс
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.
Pulse ID: 6a7b4a5db787f887767b8a2a
Pulse Link: https://otx.alienvault.com/pulse/6a7b4a5db787f887767b8a2a
Pulse Author: AlienVault
Created: 2026-08-11 16:14:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault
-
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.
Pulse ID: 6a7b4a5db787f887767b8a2a
Pulse Link: https://otx.alienvault.com/pulse/6a7b4a5db787f887767b8a2a
Pulse Author: AlienVault
Created: 2026-08-11 16:14:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
Pulse ID: 6a7c2a8d929a5da66d577e3c
Pulse Link: https://otx.alienvault.com/pulse/6a7c2a8d929a5da66d577e3c
Pulse Author: Tr1sa111
Created: 2026-08-12 08:10:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
Pulse ID: 6a7c2a8d929a5da66d577e3c
Pulse Link: https://otx.alienvault.com/pulse/6a7c2a8d929a5da66d577e3c
Pulse Author: Tr1sa111
Created: 2026-08-12 08:10:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Indicators extracted from public reporting. Source: https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html
Pulse ID: 6a7a02a323143aa437392c7c
Pulse Link: https://otx.alienvault.com/pulse/6a7a02a323143aa437392c7c
Pulse Author: CyberHunter_NL
Created: 2026-08-10 16:56:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Indicators extracted from public reporting. Source: https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html
Pulse ID: 6a7a02a323143aa437392c7c
Pulse Link: https://otx.alienvault.com/pulse/6a7a02a323143aa437392c7c
Pulse Author: CyberHunter_NL
Created: 2026-08-10 16:56:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Wer einen #Router kauft, der vertraut einem Hersteller und seinen Zulieferern sein ganzes Zuhause oder seine Firma an.
Ich habe deswegen einen Selbstbau-Router. Quasi einen PC im 19-Zoll-Format, basierend auf FreeBSD. Ich habe mein Vertrauen auf generische Komponenten und etablierte gemeinnützige Organisationen platziert.
Lest bitte, wer alles schon mal eine #Backdoor gehabt hat (Hinweise auf Vorsatz!). Schaut wie sie vorgehen bei Aktualisierungen. Das ist der reinste "Wilde Westen".
-
Wer einen #Router kauft, der vertraut einem Hersteller und seinen Zulieferern sein ganzes Zuhause oder seine Firma an.
Ich habe deswegen einen Selbstbau-Router. Quasi einen PC im 19-Zoll-Format, basierend auf FreeBSD. Ich habe mein Vertrauen auf generische Komponenten und etablierte gemeinnützige Organisationen platziert.
Lest bitte, wer alles schon mal eine #Backdoor gehabt hat (Hinweise auf Vorsatz!). Schaut wie sie vorgehen bei Aktualisierungen. Das ist der reinste "Wilde Westen".
-
Einordnung: Eine ab Werk eingebaute Hintertür im Router ist so ziemlich der Worst Case. Das Gerät sitzt schließlich direkt am Übergang ins Internet. Wer ein betroffenes Modell nutzt, sollte es bis zu einem nachvollziehbar sauberen Update aus dem Netz nehmen - und bei OEM-Geräten genau auf die Modellnummer schauen.
2/2
-
Einordnung: Eine ab Werk eingebaute Hintertür im Router ist so ziemlich der Worst Case. Das Gerät sitzt schließlich direkt am Übergang ins Internet. Wer ein betroffenes Modell nutzt, sollte es bis zu einem nachvollziehbar sauberen Update aus dem Netz nehmen - und bei OEM-Geräten genau auf die Modellnummer schauen.
2/2
-
Der chinesische Routerhersteller Zbtlink stoppt den Verkauf betroffener Geräte, nachdem Forscher in mehr als 20 Modellen eine versteckte Hintertür gefunden haben. Die Geräte verbinden sich regelmäßig mit einem externen Server. Der Hersteller will Firmware-Updates bereitstellen.
1/2
-
Der chinesische Routerhersteller Zbtlink stoppt den Verkauf betroffener Geräte, nachdem Forscher in mehr als 20 Modellen eine versteckte Hintertür gefunden haben. Die Geräte verbinden sich regelmäßig mit einem externen Server. Der Hersteller will Firmware-Updates bereitstellen.
1/2
-
Chinesische Router sicherer als die aus USA? Nein.
Nein, wer hätte das erwartet! Router aus chinesischer Herstellung enthalten ab Werk Hintertüren genau wie die aus den USA. Der chinesische Hersteller Zbtlink leugnet, dass in seinen WLAN-Routern Hintertüren enthalten seien. Genau diesen Vorwurf hat das Sicherheitsunternehmen VulnCheck über 20 Routermodelle der Firma erhoben. Zbtlink reagiert darauf, indem es veröffentlicht, man habe Sicherheitslücken gefunden. Deshalb sei der Download von Firmware vorerst ausgesetzt, der Verkauf der Geräte gestoppt. Wer Hardware von Zbtlink besitzt, sollte die Hersteller-Firmware raus werfen und durch OpenWrt ... Weiterlesen:
#closedsource #cybercrime #hersteller #hintertür #backdoor #router #sicherheit #vorbeugen #wissen #wlan
-
Chinesische Router sicherer als die aus USA? Nein.
Nein, wer hätte das erwartet! Router aus chinesischer Herstellung enthalten ab Werk Hintertüren genau wie die aus den USA. Der chinesische Hersteller Zbtlink leugnet, dass in seinen WLAN-Routern Hintertüren enthalten seien. Genau diesen Vorwurf hat das Sicherheitsunternehmen VulnCheck über 20 Routermodelle der Firma erhoben. Zbtlink reagiert darauf, indem es veröffentlicht, man habe Sicherheitslücken gefunden. Deshalb sei der Download von Firmware vorerst ausgesetzt, der Verkauf der Geräte gestoppt. Wer Hardware von Zbtlink besitzt, sollte die Hersteller-Firmware raus werfen und durch OpenWrt ... Weiterlesen:
#closedsource #cybercrime #hersteller #hintertür #backdoor #router #sicherheit #vorbeugen #wissen #wlan
-
86,000 exposed servers hide a second, always-on computer, and half are critically flawed
Follow @1ban_news for daily coverage.
-
Encrypted iPhone backups: Apple fights London's demands
Even under the new Labour Prime Minister Burnham, the British state is demanding backdoors from Apple. Its lawyers are trying to fight back.
#Backdoor #iCloud #iOS #iPhone #Mobiles #Netzpolitik #Recht #Security #Verschlüsselung #news
-
Encrypted iPhone backups: Apple fights London's demands
Even under the new Labour Prime Minister Burnham, the British state is demanding backdoors from Apple. Its lawyers are trying to fight back.
#Backdoor #iCloud #iOS #iPhone #Mobiles #Netzpolitik #Recht #Security #Verschlüsselung #news
-
#VulnCheck:
"
ENDLESSDOORS Is Phoning Home. Pick Up.
"
".. continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. .."https://www.vulncheck.com/blog/zbt-endlessdoors
5.8.2026
#Backdoor #China #Cybersicherheit #Cybersecurity #IT #Roouter #Wiflyer #Zbtlink
-
#VulnCheck:
"
ENDLESSDOORS Is Phoning Home. Pick Up.
"
".. continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. .."https://www.vulncheck.com/blog/zbt-endlessdoors
5.8.2026
#Backdoor #China #Cybersicherheit #Cybersecurity #IT #Roouter #Wiflyer #Zbtlink
-
#AndroidAuthority:
"
Maybe the FCC was onto something: These routers are phoning home to China with a secret backdoor
Of course, because they predate the ban, the FCC continues to permit their sale
"
"The FCC is only targeting new routers, while all these super-insecure old Zbtlink models can continue to be sold."https://www.androidauthority.com/routers-china-backdoor-3695345/
8.8.2026
#Amazon #Backdoor #China #Cybersicherheit #Cybersecurity #FCC #IT #Roouter #USA #VulnCheck #Wiflyer #Zbtlink
-
#AndroidAuthority:
"
Maybe the FCC was onto something: These routers are phoning home to China with a secret backdoor
Of course, because they predate the ban, the FCC continues to permit their sale
"
"The FCC is only targeting new routers, while all these super-insecure old Zbtlink models can continue to be sold."https://www.androidauthority.com/routers-china-backdoor-3695345/
8.8.2026
#Amazon #Backdoor #China #Cybersicherheit #Cybersecurity #FCC #IT #Roouter #USA #VulnCheck #Wiflyer #Zbtlink
-
Analysis of a Modular Cyber Espionage Framework
Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a
Pulse ID: 6a75b204c9420179df545451
Pulse Link: https://otx.alienvault.com/pulse/6a75b204c9420179df545451
Pulse Author: AlienVault
Created: 2026-08-07 10:23:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault
-
Analysis of a Modular Cyber Espionage Framework
Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a
Pulse ID: 6a75b204c9420179df545451
Pulse Link: https://otx.alienvault.com/pulse/6a75b204c9420179df545451
Pulse Author: AlienVault
Created: 2026-08-07 10:23:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault
-
Verschlüsselte iPhone-Backups: Apple kämpft gegen Londoner Begehrlichkeiten
Auch unter dem neuen Labour-Premierminister Burnham verlangt der britische Staat Hintertüren von Apple. Dessen Anwälte versuchen, sich zu wehren.
#Backdoor #iCloud #iOS #iPhone #Mobiles #Netzpolitik #Recht #Security #Verschlüsselung #news
-
Verschlüsselte iPhone-Backups: Apple kämpft gegen Londoner Begehrlichkeiten
Auch unter dem neuen Labour-Premierminister Burnham verlangt der britische Staat Hintertüren von Apple. Dessen Anwälte versuchen, sich zu wehren.
#Backdoor #iCloud #iOS #iPhone #Mobiles #Netzpolitik #Recht #Security #Verschlüsselung #news
-
Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages With 1.3 Billion Monthly Downloads
Indicators extracted from public reporting. Source: https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain
Pulse ID: 6a7591439f7119bc3233bc3d
Pulse Link: https://otx.alienvault.com/pulse/6a7591439f7119bc3233bc3d
Pulse Author: CyberHunter_NL
Created: 2026-08-07 08:03:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages With 1.3 Billion Monthly Downloads
Indicators extracted from public reporting. Source: https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain
Pulse ID: 6a7591439f7119bc3233bc3d
Pulse Link: https://otx.alienvault.com/pulse/6a7591439f7119bc3233bc3d
Pulse Author: CyberHunter_NL
Created: 2026-08-07 08:03:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models
Indicators extracted from public reporting. Source: https://www.vulncheck.com/blog/zbt-endlessdoors
Pulse ID: 6a7581aabf7202662d3df797
Pulse Link: https://otx.alienvault.com/pulse/6a7581aabf7202662d3df797
Pulse Author: CyberHunter_NL
Created: 2026-08-07 06:56:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models
Indicators extracted from public reporting. Source: https://www.vulncheck.com/blog/zbt-endlessdoors
Pulse ID: 6a7581aabf7202662d3df797
Pulse Link: https://otx.alienvault.com/pulse/6a7581aabf7202662d3df797
Pulse Author: CyberHunter_NL
Created: 2026-08-07 06:56:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
OctLurk e SilkLurk: la backdoor cinofona che si decifra solo sulla macchina della vittima
Kaspersky svela OctLurk e SilkLurk, due backdoor usate da un attore cinofono per colpire enti governativi e sanitari in Asia Centrale dal 2025. Il payload si decifra solo sul dispositivo del bersaglio, usando il seriale del disco o il nome del computer come chiave, per rendere quasi impossibile l'analisi forense. -
OctLurk e SilkLurk: la backdoor cinofona che si decifra solo sulla macchina della vittima
Kaspersky svela OctLurk e SilkLurk, due backdoor usate da un attore cinofono per colpire enti governativi e sanitari in Asia Centrale dal 2025. Il payload si decifra solo sul dispositivo del bersaglio, usando il seriale del disco o il nome del computer come chiave, per rendere quasi impossibile l'analisi forense. -
This is fun. A Chinese company that makes fairly generic WiFi routers and sells them under its own (multiple) brands as well as white-labelling them for many other companies to sell as "theirs", has shipped a backdoor on what appears to be every version of every model they've sold.
https://www.vulncheck.com/blog/zbt-endlessdoors
The backdoor itself is also laughably insecure, easily taken over by anyone who can intercept packets between the router and its command-and-control server, or who can cause the hardcoded domain names it used to resolve to an IP address under their control. TL;DR: this is very easy to exploit.
It is a deliberate remote root backdoor.
The company says "oh no, there's no security issue, you misunderstand" to the researcher that found this. However, they've taken all their downloadable firmware images offline to be updated for the security issue their PR people say doesn't exist.
And it is definitely, 100% deliberate and done in bad faith. The backdoor processes deliberately mislabel themselves as `kworker` processes to try to make anyone who sees them think they are Linux built-in kernel threads.
Worth a read.
#BackDoor #security #exploit #root #Chinesium #trust #network #hardware
-
This is fun. A Chinese company that makes fairly generic WiFi routers and sells them under its own (multiple) brands as well as white-labelling them for many other companies to sell as "theirs", has shipped a backdoor on what appears to be every version of every model they've sold.
https://www.vulncheck.com/blog/zbt-endlessdoors
The backdoor itself is also laughably insecure, easily taken over by anyone who can intercept packets between the router and its command-and-control server, or who can cause the hardcoded domain names it used to resolve to an IP address under their control. TL;DR: this is very easy to exploit.
It is a deliberate remote root backdoor.
The company says "oh no, there's no security issue, you misunderstand" to the researcher that found this. However, they've taken all their downloadable firmware images offline to be updated for the security issue their PR people say doesn't exist.
And it is definitely, 100% deliberate and done in bad faith. The backdoor processes deliberately mislabel themselves as `kworker` processes to try to make anyone who sees them think they are Linux built-in kernel threads.
Worth a read.
#BackDoor #security #exploit #root #Chinesium #trust #network #hardware
-
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.
Pulse ID: 6a748055fc990bd246b92b6c
Pulse Link: https://otx.alienvault.com/pulse/6a748055fc990bd246b92b6c
Pulse Author: AlienVault
Created: 2026-08-06 12:38:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault
-
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Indicators extracted from public reporting. Source: https://www.vulncheck.com/blog/zbt-endlessdoors
Pulse ID: 6a744cf161d7135a1b2d8743
Pulse Link: https://otx.alienvault.com/pulse/6a744cf161d7135a1b2d8743
Pulse Author: CyberHunter_NL
Created: 2026-08-06 08:59:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL