home.social

#chacha20 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #chacha20, aggregated by home.social.

fetched live
  1. GoSerpent backdoor attacks in Southeast Asia

    Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.

    Pulse ID: 6a590384cb730e14eaafeac5
    Pulse Link: otx.alienvault.com/pulse/6a590
    Pulse Author: AlienVault
    Created: 2026-07-16 16:15:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #ChaCha20 #Cloud #CyberSecurity #Encryption #Government #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #bot #AlienVault

  2. GoSerpent backdoor attacks in Southeast Asia

    Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.

    Pulse ID: 6a590384cb730e14eaafeac5
    Pulse Link: otx.alienvault.com/pulse/6a590
    Pulse Author: AlienVault
    Created: 2026-07-16 16:15:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #ChaCha20 #Cloud #CyberSecurity #Encryption #Government #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #bot #AlienVault

  3. jscrambler npm Package Compromised in Supply Chain Attack

    A malicious release of the jscrambler npm package (version 8.14.0) was published on July 11, 2026, introducing hidden native binaries that execute automatically during installation. The compromised package added an undocumented preinstall hook executing dist/setup.js, which deploys platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. The payload is a Rust-built infostealer targeting cryptocurrency wallets, AI coding assistants, cloud credentials (AWS, GCP, Azure), browser data, and messaging applications. String obfuscation uses per-string ChaCha20-Poly1305 encryption. The threat actor published five malicious versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0) over three hours, evolving delivery methods to evade detection. Version 8.22.0 is confirmed clean. The package receives approximately 15,800 weekly downloads, affecting developer workstations, CI systems, and build pipelines with access to credentials and secrets.

    Pulse ID: 6a52d7f22883fcd1f11046c2
    Pulse Link: otx.alienvault.com/pulse/6a52d
    Pulse Author: AlienVault
    Created: 2026-07-11 23:55:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Browser #ChaCha20 #Cloud #CyberSecurity #Encryption #InfoSec #InfoStealer #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #Rust #SupplyChain #Windows #bot #cryptocurrency #AlienVault

  4. jscrambler npm Package Compromised in Supply Chain Attack

    A malicious release of the jscrambler npm package (version 8.14.0) was published on July 11, 2026, introducing hidden native binaries that execute automatically during installation. The compromised package added an undocumented preinstall hook executing dist/setup.js, which deploys platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. The payload is a Rust-built infostealer targeting cryptocurrency wallets, AI coding assistants, cloud credentials (AWS, GCP, Azure), browser data, and messaging applications. String obfuscation uses per-string ChaCha20-Poly1305 encryption. The threat actor published five malicious versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0) over three hours, evolving delivery methods to evade detection. Version 8.22.0 is confirmed clean. The package receives approximately 15,800 weekly downloads, affecting developer workstations, CI systems, and build pipelines with access to credentials and secrets.

    Pulse ID: 6a52d7f22883fcd1f11046c2
    Pulse Link: otx.alienvault.com/pulse/6a52d
    Pulse Author: AlienVault
    Created: 2026-07-11 23:55:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Browser #ChaCha20 #Cloud #CyberSecurity #Encryption #InfoSec #InfoStealer #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #Rust #SupplyChain #Windows #bot #cryptocurrency #AlienVault

  5. PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault

  6. PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #ChaCha20 #Clipboard #CyberSecurity #Endpoint #InfoSec #InfoStealer #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #RAT #RPC #Rust #SQL #bot #AlienVault

  7. RustDuck: An In-Depth Analysis of a Two-Stage Botnet

    Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

    Pulse ID: 6a4635e7998db450b0ccdee2
    Pulse Link: otx.alienvault.com/pulse/6a463
    Pulse Author: AlienVault
    Created: 2026-07-02 09:56:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #ChaCha20 #CyberSecurity #DDoS #DoS #Encryption #HoneyPot #InfoSec #IoT #Malware #OTX #OpenThreatExchange #PHP #Password #RAT #Rust #SMS #SSH #Telnet #Word #bot #botnet #AlienVault

  8. RustDuck: An In-Depth Analysis of a Two-Stage Botnet

    Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

    Pulse ID: 6a4635e7998db450b0ccdee2
    Pulse Link: otx.alienvault.com/pulse/6a463
    Pulse Author: AlienVault
    Created: 2026-07-02 09:56:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #ChaCha20 #CyberSecurity #DDoS #DoS #Encryption #HoneyPot #InfoSec #IoT #Malware #OTX #OpenThreatExchange #PHP #Password #RAT #Rust #SMS #SSH #Telnet #Word #bot #botnet #AlienVault

  9. Rapid growth and a new ransomware variant

    The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors.

    Pulse ID: 6a42506c95cc259404196a5b
    Pulse Link: otx.alienvault.com/pulse/6a425
    Pulse Author: AlienVault
    Created: 2026-06-29 11:01:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdvancedIPScanner #BackDoor #Brazil #ChaCha20 #China #CyberSecurity #Healthcare #Indonesia #InfoSec #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #RansomwareAsAService #Thailand #VPN #bot #AlienVault

  10. Rapid growth and a new ransomware variant

    The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors.

    Pulse ID: 6a42506c95cc259404196a5b
    Pulse Link: otx.alienvault.com/pulse/6a425
    Pulse Author: AlienVault
    Created: 2026-06-29 11:01:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdvancedIPScanner #BackDoor #Brazil #ChaCha20 #China #CyberSecurity #Healthcare #Indonesia #InfoSec #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #RansomwareAsAService #Thailand #VPN #bot #AlienVault

  11. Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf

    Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...

    #Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware

    sekurak.pl/szyfrowanie-danych-

  12. Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf

    Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...

    #Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware

    sekurak.pl/szyfrowanie-danych-

  13. [Перевод] ChaCha, модификация Salsa20

    ChaCha8 это 256-битный поточный шифр, основанный на 8-раунодовом шифре Salsa20/8. Новшества, привнесенные при работе от Salsa20/8 до ChaCha8, позволили улучшить перемежение бит за раунд, тем самым повысив стойкость к криптоанализу при сохранении, а иногда и уменьшении, времени требуемого на вычисления одного раунда. ChaCha12 и ChaCha20 являются аналогичными модификациями 12-раундового и 20-раундового шифров Salsa20/12 и Salsa20/20. В данной статье описывается семейство шифров ChaCha и объясняется разница между Salsa20 и ChaCha.

    habr.com/ru/articles/784452/

    #chacha20 #daniel_j_bernstein #перевод #перевод_с_английского

  14. [DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)

    [EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.

    #cryptography #shors #grovers #kyber #mceliece #chacha20

  15. [DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)

    [EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.

    #cryptography #shors #grovers #kyber #mceliece #chacha20

  16. CW: research review

    S. Dey et al., "Cryptanalysis of Reduced Round ChaCha- New Attack and Deeper Analysis"¹

    In this paper we present several analyses on ChaCha, a software stream cipher. First, we consider a divide-and-conquer approach on the secret key bits by partitioning them. The partitions are based on multiple input-output differentials to obtain a significantly improved attack on 6-round ChaCha256 with a complexity of 2^{99.48}. It is 2^{40} times faster than the currently best known attack. Note that, this is the first time an attack could be mounted on reduced round ChaCha with a complexity significantly less than 2^{k}{2}, where the secret key is of k bits. Further, we note that all the attack complexities related to ChaCha are theoretically estimated in general and there are several questions in this regard as pointed out by Dey et al. in Eurocrypt 2022. In this regard, we propose a toy version of ChaCha, with a 32-bit secret key, on which the attacks can be implemented completely to verify whether the theoretical estimates are justified. This idea is implemented for our proposed attack on 6 rounds. Finally, we show that it is possible to estimate the success probabilities of these kinds of PNB-based differential attacks more accurately. Our methodology explains how different cryptanalytic results can be evaluated with better accuracy rather than claiming (Aumasson et al., 2008) that the success probability is significantly better than 50%.

    #IACR #ResearchPapers #ARX #ChaCha20 #ProbabilisticNeutralBits #Cryptanalysis #DifferentialAttack #Cryptography
    __
    ¹ eprint.iacr.org/2023/134

  17. Which do you consider to be more secure?

    (Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)

    #AES #CHACHA20 #infosec #cryptography #encryption

  18. Which do you consider to be more secure?

    (Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)

    #AES #CHACHA20 #infosec #cryptography #encryption