home.social

#backdoor — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #backdoor, aggregated by home.social.

fetched live
  1. China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business

    Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.

    Pulse ID: 6a7da6cbe879002fadce7e53
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault

  2. China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business

    Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.

    Pulse ID: 6a7da6cbe879002fadce7e53
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault

  3. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

    Pulse ID: 6a7daa9c80273555f3d3ccd1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault

  4. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

    Pulse ID: 6a7daa9c80273555f3d3ccd1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault

  5. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  6. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  7. Страховой случай: изучаем инструменты и инфраструктуру новой киберпреступной группировки Malinsure

    Аналитики F6 Threat Intelligence обнаружили новую угрозу для российских компаний – Malinsure . Группировка использует собственный бэкдор SafeMostSSH и нестандартные TTPs.

    habr.com/ru/companies/F6/artic

    #threat_intelligence #backdoor #safemostssh #malinsure #фишинговые_рассылки #дмс

  8. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  9. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  10. CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

    An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.

    Pulse ID: 6a7b4a5db787f887767b8a2a
    Pulse Link: otx.alienvault.com/pulse/6a7b4
    Pulse Author: AlienVault
    Created: 2026-08-11 16:14:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault

  11. CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

    An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.

    Pulse ID: 6a7b4a5db787f887767b8a2a
    Pulse Link: otx.alienvault.com/pulse/6a7b4
    Pulse Author: AlienVault
    Created: 2026-08-11 16:14:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault

  12. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    Pulse ID: 6a7c2a8d929a5da66d577e3c
    Pulse Link: otx.alienvault.com/pulse/6a7c2
    Pulse Author: Tr1sa111
    Created: 2026-08-12 08:10:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  13. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    Pulse ID: 6a7c2a8d929a5da66d577e3c
    Pulse Link: otx.alienvault.com/pulse/6a7c2
    Pulse Author: Tr1sa111
    Created: 2026-08-12 08:10:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  14. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.

    Pulse ID: 6a7b3ea2ac324259cbd21dc6
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault

  15. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.

    Pulse ID: 6a7b3ea2ac324259cbd21dc6
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault

  16. ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    Indicators extracted from public reporting. Source: thehackernews.com/2026/08/week

    Pulse ID: 6a7a02a323143aa437392c7c
    Pulse Link: otx.alienvault.com/pulse/6a7a0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 16:56:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  17. ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    Indicators extracted from public reporting. Source: thehackernews.com/2026/08/week

    Pulse ID: 6a7a02a323143aa437392c7c
    Pulse Link: otx.alienvault.com/pulse/6a7a0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 16:56:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  18. Wer einen #Router kauft, der vertraut einem Hersteller und seinen Zulieferern sein ganzes Zuhause oder seine Firma an.

    Ich habe deswegen einen Selbstbau-Router. Quasi einen PC im 19-Zoll-Format, basierend auf FreeBSD. Ich habe mein Vertrauen auf generische Komponenten und etablierte gemeinnützige Organisationen platziert.

    Lest bitte, wer alles schon mal eine #Backdoor gehabt hat (Hinweise auf Vorsatz!). Schaut wie sie vorgehen bei Aktualisierungen. Das ist der reinste "Wilde Westen".

  19. Wer einen #Router kauft, der vertraut einem Hersteller und seinen Zulieferern sein ganzes Zuhause oder seine Firma an.

    Ich habe deswegen einen Selbstbau-Router. Quasi einen PC im 19-Zoll-Format, basierend auf FreeBSD. Ich habe mein Vertrauen auf generische Komponenten und etablierte gemeinnützige Organisationen platziert.

    Lest bitte, wer alles schon mal eine #Backdoor gehabt hat (Hinweise auf Vorsatz!). Schaut wie sie vorgehen bei Aktualisierungen. Das ist der reinste "Wilde Westen".

  20. Einordnung: Eine ab Werk eingebaute Hintertür im Router ist so ziemlich der Worst Case. Das Gerät sitzt schließlich direkt am Übergang ins Internet. Wer ein betroffenes Modell nutzt, sollte es bis zu einem nachvollziehbar sauberen Update aus dem Netz nehmen - und bei OEM-Geräten genau auf die Modellnummer schauen.

    2/2

    #Router #Backdoor #Netzwerksicherheit #KuketzAugust

  21. Einordnung: Eine ab Werk eingebaute Hintertür im Router ist so ziemlich der Worst Case. Das Gerät sitzt schließlich direkt am Übergang ins Internet. Wer ein betroffenes Modell nutzt, sollte es bis zu einem nachvollziehbar sauberen Update aus dem Netz nehmen - und bei OEM-Geräten genau auf die Modellnummer schauen.

    2/2

    #Router #Backdoor #Netzwerksicherheit #KuketzAugust

  22. Der chinesische Routerhersteller Zbtlink stoppt den Verkauf betroffener Geräte, nachdem Forscher in mehr als 20 Modellen eine versteckte Hintertür gefunden haben. Die Geräte verbinden sich regelmäßig mit einem externen Server. Der Hersteller will Firmware-Updates bereitstellen.

    reuters.com/world/asia-pacific

    1/2

    #Router #Backdoor #ITSicherheit #KuketzAugust

  23. Der chinesische Routerhersteller Zbtlink stoppt den Verkauf betroffener Geräte, nachdem Forscher in mehr als 20 Modellen eine versteckte Hintertür gefunden haben. Die Geräte verbinden sich regelmäßig mit einem externen Server. Der Hersteller will Firmware-Updates bereitstellen.

    reuters.com/world/asia-pacific

    1/2

    #Router #Backdoor #ITSicherheit #KuketzAugust

  24. Chinesische Router sicherer als die aus USA? Nein.

    Nein, wer hätte das erwartet! Router aus chinesischer Herstellung enthalten ab Werk Hintertüren genau wie die aus den USA. Der chinesische Hersteller Zbtlink leugnet, dass in seinen WLAN-Routern Hintertüren enthalten seien. Genau diesen Vorwurf hat das Sicherheitsunternehmen VulnCheck über 20 Routermodelle der Firma erhoben. Zbtlink reagiert darauf, indem es veröffentlicht, man habe Sicherheitslücken gefunden. Deshalb sei der Download von Firmware vorerst ausgesetzt, der Verkauf der Geräte gestoppt. Wer Hardware von Zbtlink besitzt, sollte die Hersteller-Firmware raus werfen und durch OpenWrt ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #closedsource #cybercrime #hersteller #hintertür #backdoor #router #sicherheit #vorbeugen #wissen #wlan

  25. Chinesische Router sicherer als die aus USA? Nein.

    Nein, wer hätte das erwartet! Router aus chinesischer Herstellung enthalten ab Werk Hintertüren genau wie die aus den USA. Der chinesische Hersteller Zbtlink leugnet, dass in seinen WLAN-Routern Hintertüren enthalten seien. Genau diesen Vorwurf hat das Sicherheitsunternehmen VulnCheck über 20 Routermodelle der Firma erhoben. Zbtlink reagiert darauf, indem es veröffentlicht, man habe Sicherheitslücken gefunden. Deshalb sei der Download von Firmware vorerst ausgesetzt, der Verkauf der Geräte gestoppt. Wer Hardware von Zbtlink besitzt, sollte die Hersteller-Firmware raus werfen und durch OpenWrt ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #closedsource #cybercrime #hersteller #hintertür #backdoor #router #sicherheit #vorbeugen #wissen #wlan

  26. #VulnCheck:
    "
    ENDLESSDOORS Is Phoning Home. Pick Up.
    "
    ".. continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. .."

    vulncheck.com/blog/zbt-endless

    5.8.2026

    #Backdoor #China #Cybersicherheit #Cybersecurity #IT #Roouter #Wiflyer #Zbtlink

  27. #VulnCheck:
    "
    ENDLESSDOORS Is Phoning Home. Pick Up.
    "
    ".. continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. .."

    vulncheck.com/blog/zbt-endless

    5.8.2026

    #Backdoor #China #Cybersicherheit #Cybersecurity #IT #Roouter #Wiflyer #Zbtlink

  28. #AndroidAuthority:
    "
    Maybe the FCC was onto something: These routers are phoning home to China with a secret backdoor
    Of course, because they predate the ban, the FCC continues to permit their sale
    "
    "The FCC is only targeting new routers, while all these super-insecure old Zbtlink models can continue to be sold."

    androidauthority.com/routers-c

    8.8.2026

    #Amazon #Backdoor #China #Cybersicherheit #Cybersecurity #FCC #IT #Roouter #USA #VulnCheck #Wiflyer #Zbtlink

  29. #AndroidAuthority:
    "
    Maybe the FCC was onto something: These routers are phoning home to China with a secret backdoor
    Of course, because they predate the ban, the FCC continues to permit their sale
    "
    "The FCC is only targeting new routers, while all these super-insecure old Zbtlink models can continue to be sold."

    androidauthority.com/routers-c

    8.8.2026

    #Amazon #Backdoor #China #Cybersicherheit #Cybersecurity #FCC #IT #Roouter #USA #VulnCheck #Wiflyer #Zbtlink

  30. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  31. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  32. Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages With 1.3 Billion Monthly Downloads

    Indicators extracted from public reporting. Source: elastic.co/security-labs/shai-

    Pulse ID: 6a7591439f7119bc3233bc3d
    Pulse Link: otx.alienvault.com/pulse/6a759
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 08:03:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL

  33. Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages With 1.3 Billion Monthly Downloads

    Indicators extracted from public reporting. Source: elastic.co/security-labs/shai-

    Pulse ID: 6a7591439f7119bc3233bc3d
    Pulse Link: otx.alienvault.com/pulse/6a759
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 08:03:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL

  34. Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models

    Indicators extracted from public reporting. Source: vulncheck.com/blog/zbt-endless

    Pulse ID: 6a7581aabf7202662d3df797
    Pulse Link: otx.alienvault.com/pulse/6a758
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 06:56:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  35. Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models

    Indicators extracted from public reporting. Source: vulncheck.com/blog/zbt-endless

    Pulse ID: 6a7581aabf7202662d3df797
    Pulse Link: otx.alienvault.com/pulse/6a758
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 06:56:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  36. OctLurk e SilkLurk: la backdoor cinofona che si decifra solo sulla macchina della vittima

    Kaspersky svela OctLurk e SilkLurk, due backdoor usate da un attore cinofono per colpire enti governativi e sanitari in Asia Centrale dal 2025. Il payload si decifra solo sul dispositivo del bersaglio, usando il seriale del disco o il nome del computer come chiave, per rendere quasi impossibile l'analisi forense.

    insicurezzadigitale.com/octlur

  37. OctLurk e SilkLurk: la backdoor cinofona che si decifra solo sulla macchina della vittima

    Kaspersky svela OctLurk e SilkLurk, due backdoor usate da un attore cinofono per colpire enti governativi e sanitari in Asia Centrale dal 2025. Il payload si decifra solo sul dispositivo del bersaglio, usando il seriale del disco o il nome del computer come chiave, per rendere quasi impossibile l'analisi forense.

    insicurezzadigitale.com/octlur

  38. This is fun. A Chinese company that makes fairly generic WiFi routers and sells them under its own (multiple) brands as well as white-labelling them for many other companies to sell as "theirs", has shipped a backdoor on what appears to be every version of every model they've sold.

    vulncheck.com/blog/zbt-endless

    The backdoor itself is also laughably insecure, easily taken over by anyone who can intercept packets between the router and its command-and-control server, or who can cause the hardcoded domain names it used to resolve to an IP address under their control. TL;DR: this is very easy to exploit.

    It is a deliberate remote root backdoor.

    The company says "oh no, there's no security issue, you misunderstand" to the researcher that found this. However, they've taken all their downloadable firmware images offline to be updated for the security issue their PR people say doesn't exist.

    And it is definitely, 100% deliberate and done in bad faith. The backdoor processes deliberately mislabel themselves as `kworker` processes to try to make anyone who sees them think they are Linux built-in kernel threads.

    Worth a read.

    #BackDoor #security #exploit #root #Chinesium #trust #network #hardware

  39. This is fun. A Chinese company that makes fairly generic WiFi routers and sells them under its own (multiple) brands as well as white-labelling them for many other companies to sell as "theirs", has shipped a backdoor on what appears to be every version of every model they've sold.

    vulncheck.com/blog/zbt-endless

    The backdoor itself is also laughably insecure, easily taken over by anyone who can intercept packets between the router and its command-and-control server, or who can cause the hardcoded domain names it used to resolve to an IP address under their control. TL;DR: this is very easy to exploit.

    It is a deliberate remote root backdoor.

    The company says "oh no, there's no security issue, you misunderstand" to the researcher that found this. However, they've taken all their downloadable firmware images offline to be updated for the security issue their PR people say doesn't exist.

    And it is definitely, 100% deliberate and done in bad faith. The backdoor processes deliberately mislabel themselves as `kworker` processes to try to make anyone who sees them think they are Linux built-in kernel threads.

    Worth a read.

    #BackDoor #security #exploit #root #Chinesium #trust #network #hardware

  40. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases

    A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.

    Pulse ID: 6a748055fc990bd246b92b6c
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:38:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault

  41. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases

    A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.

    Pulse ID: 6a748055fc990bd246b92b6c
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:38:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault

  42. Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    Indicators extracted from public reporting. Source: vulncheck.com/blog/zbt-endless

    Pulse ID: 6a744cf161d7135a1b2d8743
    Pulse Link: otx.alienvault.com/pulse/6a744
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 08:59:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  43. Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    Indicators extracted from public reporting. Source: vulncheck.com/blog/zbt-endless

    Pulse ID: 6a744cf161d7135a1b2d8743
    Pulse Link: otx.alienvault.com/pulse/6a744
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 08:59:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  44. Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

    On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.

    Pulse ID: 6a73cac4902afff959b758aa
    Pulse Link: otx.alienvault.com/pulse/6a73c
    Pulse Author: AlienVault
    Created: 2026-08-05 23:44:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault

  45. Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

    On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.

    Pulse ID: 6a73cac4902afff959b758aa
    Pulse Link: otx.alienvault.com/pulse/6a73c
    Pulse Author: AlienVault
    Created: 2026-08-05 23:44:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault

  46. ENDLESSDOORS Is Phoning Home. Pick Up.

    Zbtlink routers, manufactured by Shenzhen Zhibotong Electronics and sold globally under multiple brand names including Wiflyer, contain a pre-installed backdoor implant named ENDLESSDOORS. This implant, based on the open-source rctl tool, runs as disguised userland processes named 'kworker' and continuously attempts to contact command and control servers. The backdoor provides unauthenticated remote root access through plaintext communication on ports 7000 and 7001, allowing attackers to execute arbitrary commands or spawn interactive shells without any verification. Twenty different router models are confirmed affected, all phoning home to four primary endpoints including zbtctl.epplink.net and hardcoded IP addresses hosted on Alibaba Cloud. The vulnerability is assigned CVE-2026-66747. No fixed firmware exists as the backdoor appears intentionally embedded by the manufacturer across multiple firmware versions spanning several years.

    Pulse ID: 6a734a554923448bd690f87e
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #Endpoint #ICS #InfoSec #NET #OTX #OpenThreatExchange #RCE #Vulnerability #bot #AlienVault

  47. ENDLESSDOORS Is Phoning Home. Pick Up.

    Zbtlink routers, manufactured by Shenzhen Zhibotong Electronics and sold globally under multiple brand names including Wiflyer, contain a pre-installed backdoor implant named ENDLESSDOORS. This implant, based on the open-source rctl tool, runs as disguised userland processes named 'kworker' and continuously attempts to contact command and control servers. The backdoor provides unauthenticated remote root access through plaintext communication on ports 7000 and 7001, allowing attackers to execute arbitrary commands or spawn interactive shells without any verification. Twenty different router models are confirmed affected, all phoning home to four primary endpoints including zbtctl.epplink.net and hardcoded IP addresses hosted on Alibaba Cloud. The vulnerability is assigned CVE-2026-66747. No fixed firmware exists as the backdoor appears intentionally embedded by the manufacturer across multiple firmware versions spanning several years.

    Pulse ID: 6a734a554923448bd690f87e
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #Endpoint #ICS #InfoSec #NET #OTX #OpenThreatExchange #RCE #Vulnerability #bot #AlienVault

  48. QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

    Indicators extracted from public reporting. Source: fortinet.com/blog/threat-resea

    Pulse ID: 6a72de9544036c10bb5df1e3
    Pulse Link: otx.alienvault.com/pulse/6a72d
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 06:56:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SupplyChain #Trojan #Windows #bot #CyberHunter_NL

  49. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    Pulse ID: 6a72c0e8b782034f5d99d595
    Pulse Link: otx.alienvault.com/pulse/6a72c
    Pulse Author: Tr1sa111
    Created: 2026-08-05 04:49:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #CyberSecurity #Edge #Espionage #InfoSec #MiddleEast #OTX #OpenThreatExchange #bot #Tr1sa111