#cyberhunter_nl — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Pulse ID: 6ab82348cdf7f4bb4bc291a7
Pulse Link: https://otx.alienvault.com/pulse/6ab82348cdf7f4bb4bc291a7
Pulse Author: CyberHunter_NL
Created: 2026-09-26 19:55:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Pulse ID: 6ab82348cdf7f4bb4bc291a7
Pulse Link: https://otx.alienvault.com/pulse/6ab82348cdf7f4bb4bc291a7
Pulse Author: CyberHunter_NL
Created: 2026-09-26 19:55:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Pulse ID: 6ab82348cdf7f4bb4bc291a7
Pulse Link: https://otx.alienvault.com/pulse/6ab82348cdf7f4bb4bc291a7
Pulse Author: CyberHunter_NL
Created: 2026-09-26 19:55:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Pulse ID: 6ab82348cdf7f4bb4bc291a7
Pulse Link: https://otx.alienvault.com/pulse/6ab82348cdf7f4bb4bc291a7
Pulse Author: CyberHunter_NL
Created: 2026-09-26 19:55:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Pulse ID: 6ab82348cdf7f4bb4bc291a7
Pulse Link: https://otx.alienvault.com/pulse/6ab82348cdf7f4bb4bc291a7
Pulse Author: CyberHunter_NL
Created: 2026-09-26 19:55:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .
Pulse ID: 6ab67d763984b22f9018e519
Pulse Link: https://otx.alienvault.com/pulse/6ab67d763984b22f9018e519
Pulse Author: CyberHunter_NL
Created: 2026-09-25 13:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .
Pulse ID: 6ab67d763984b22f9018e519
Pulse Link: https://otx.alienvault.com/pulse/6ab67d763984b22f9018e519
Pulse Author: CyberHunter_NL
Created: 2026-09-25 13:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .
Pulse ID: 6ab67d763984b22f9018e519
Pulse Link: https://otx.alienvault.com/pulse/6ab67d763984b22f9018e519
Pulse Author: CyberHunter_NL
Created: 2026-09-25 13:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .
Pulse ID: 6ab67d763984b22f9018e519
Pulse Link: https://otx.alienvault.com/pulse/6ab67d763984b22f9018e519
Pulse Author: CyberHunter_NL
Created: 2026-09-25 13:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .
Pulse ID: 6ab67d763984b22f9018e519
Pulse Link: https://otx.alienvault.com/pulse/6ab67d763984b22f9018e519
Pulse Author: CyberHunter_NL
Created: 2026-09-25 13:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Criminals turn placeholder domain into ClickFix trap
Indicators extracted from public reporting. Source: https://www.manifold.security/blog/third-party-com-placeholder-clickfix
Pulse ID: 6ab66fb56bc0ecf27543eaca
Pulse Link: https://otx.alienvault.com/pulse/6ab66fb56bc0ecf27543eaca
Pulse Author: CyberHunter_NL
Created: 2026-09-25 12:57:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Criminals turn placeholder domain into ClickFix trap
Indicators extracted from public reporting. Source: https://www.manifold.security/blog/third-party-com-placeholder-clickfix
Pulse ID: 6ab66fb56bc0ecf27543eaca
Pulse Link: https://otx.alienvault.com/pulse/6ab66fb56bc0ecf27543eaca
Pulse Author: CyberHunter_NL
Created: 2026-09-25 12:57:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Criminals turn placeholder domain into ClickFix trap
Indicators extracted from public reporting. Source: https://www.manifold.security/blog/third-party-com-placeholder-clickfix
Pulse ID: 6ab66fb56bc0ecf27543eaca
Pulse Link: https://otx.alienvault.com/pulse/6ab66fb56bc0ecf27543eaca
Pulse Author: CyberHunter_NL
Created: 2026-09-25 12:57:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Criminals turn placeholder domain into ClickFix trap
Indicators extracted from public reporting. Source: https://www.manifold.security/blog/third-party-com-placeholder-clickfix
Pulse ID: 6ab66fb56bc0ecf27543eaca
Pulse Link: https://otx.alienvault.com/pulse/6ab66fb56bc0ecf27543eaca
Pulse Author: CyberHunter_NL
Created: 2026-09-25 12:57:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Criminals turn placeholder domain into ClickFix trap
Indicators extracted from public reporting. Source: https://www.manifold.security/blog/third-party-com-placeholder-clickfix
Pulse ID: 6ab66fb56bc0ecf27543eaca
Pulse Link: https://otx.alienvault.com/pulse/6ab66fb56bc0ecf27543eaca
Pulse Author: CyberHunter_NL
Created: 2026-09-25 12:57:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
Pulse ID: 6ab548034e267449f1adb0e4
Pulse Link: https://otx.alienvault.com/pulse/6ab548034e267449f1adb0e4
Pulse Author: CyberHunter_NL
Created: 2026-09-24 15:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
Pulse ID: 6ab548034e267449f1adb0e4
Pulse Link: https://otx.alienvault.com/pulse/6ab548034e267449f1adb0e4
Pulse Author: CyberHunter_NL
Created: 2026-09-24 15:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
Pulse ID: 6ab548034e267449f1adb0e4
Pulse Link: https://otx.alienvault.com/pulse/6ab548034e267449f1adb0e4
Pulse Author: CyberHunter_NL
Created: 2026-09-24 15:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
Pulse ID: 6ab548034e267449f1adb0e4
Pulse Link: https://otx.alienvault.com/pulse/6ab548034e267449f1adb0e4
Pulse Author: CyberHunter_NL
Created: 2026-09-24 15:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
Pulse ID: 6ab548034e267449f1adb0e4
Pulse Link: https://otx.alienvault.com/pulse/6ab548034e267449f1adb0e4
Pulse Author: CyberHunter_NL
Created: 2026-09-24 15:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.