home.social

#cyberhunter_nl — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.

  1. Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

    Pulse ID: 6ab82348cdf7f4bb4bc291a7
    Pulse Link: otx.alienvault.com/pulse/6ab82
    Pulse Author: CyberHunter_NL
    Created: 2026-09-26 19:55:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CAPTCHA #Clickfix #MaaS #OTX #CyberHunter_NL

  2. Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

    Pulse ID: 6ab82348cdf7f4bb4bc291a7
    Pulse Link: otx.alienvault.com/pulse/6ab82
    Pulse Author: CyberHunter_NL
    Created: 2026-09-26 19:55:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CAPTCHA #Clickfix #MaaS #OTX #CyberHunter_NL

  3. Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

    Pulse ID: 6ab82348cdf7f4bb4bc291a7
    Pulse Link: otx.alienvault.com/pulse/6ab82
    Pulse Author: CyberHunter_NL
    Created: 2026-09-26 19:55:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CAPTCHA #Clickfix #MaaS #OTX #CyberHunter_NL

  4. Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

    Pulse ID: 6ab82348cdf7f4bb4bc291a7
    Pulse Link: otx.alienvault.com/pulse/6ab82
    Pulse Author: CyberHunter_NL
    Created: 2026-09-26 19:55:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CAPTCHA #Clickfix #MaaS #OTX #CyberHunter_NL

  5. Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

    Pulse ID: 6ab82348cdf7f4bb4bc291a7
    Pulse Link: otx.alienvault.com/pulse/6ab82
    Pulse Author: CyberHunter_NL
    Created: 2026-09-26 19:55:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CAPTCHA #Clickfix #MaaS #OTX #CyberHunter_NL

  6. PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

    Pulse ID: 6ab699862ec3e91c17fbcb55
    Pulse Link: otx.alienvault.com/pulse/6ab69
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 15:55:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #MacOS #JavaScript #Malware #OTX #CyberHunter_NL

  7. PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

    Pulse ID: 6ab699862ec3e91c17fbcb55
    Pulse Link: otx.alienvault.com/pulse/6ab69
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 15:55:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #MacOS #JavaScript #Malware #OTX #CyberHunter_NL

  8. PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

    Pulse ID: 6ab699862ec3e91c17fbcb55
    Pulse Link: otx.alienvault.com/pulse/6ab69
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 15:55:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #MacOS #JavaScript #Malware #OTX #CyberHunter_NL

  9. PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

    Pulse ID: 6ab699862ec3e91c17fbcb55
    Pulse Link: otx.alienvault.com/pulse/6ab69
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 15:55:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #MacOS #JavaScript #Malware #OTX #CyberHunter_NL

  10. Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection

    Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .

    Pulse ID: 6ab67d763984b22f9018e519
    Pulse Link: otx.alienvault.com/pulse/6ab67
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 13:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Clickfix #OTX #CyberHunter_NL

  11. Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection

    Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .

    Pulse ID: 6ab67d763984b22f9018e519
    Pulse Link: otx.alienvault.com/pulse/6ab67
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 13:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Clickfix #OTX #CyberHunter_NL

  12. Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection

    Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .

    Pulse ID: 6ab67d763984b22f9018e519
    Pulse Link: otx.alienvault.com/pulse/6ab67
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 13:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Clickfix #OTX #CyberHunter_NL

  13. Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection

    Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .

    Pulse ID: 6ab67d763984b22f9018e519
    Pulse Link: otx.alienvault.com/pulse/6ab67
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 13:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Clickfix #OTX #CyberHunter_NL

  14. Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection

    Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a victim encounters. In the cases examined, it arrived at the end of attack chains built around deception rather than a newly disclosed software flaw. Some victims faced ClickFix […] The post Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection appeared first on Cyber Security News .

    Pulse ID: 6ab67d763984b22f9018e519
    Pulse Link: otx.alienvault.com/pulse/6ab67
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 13:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Clickfix #OTX #CyberHunter_NL

  15. Criminals turn placeholder domain into ClickFix trap

    Indicators extracted from public reporting. Source: manifold.security/blog/third-p

    Pulse ID: 6ab66fb56bc0ecf27543eaca
    Pulse Link: otx.alienvault.com/pulse/6ab66
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 12:57:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #OTX #CyberHunter_NL

  16. Criminals turn placeholder domain into ClickFix trap

    Indicators extracted from public reporting. Source: manifold.security/blog/third-p

    Pulse ID: 6ab66fb56bc0ecf27543eaca
    Pulse Link: otx.alienvault.com/pulse/6ab66
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 12:57:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #OTX #CyberHunter_NL

  17. Criminals turn placeholder domain into ClickFix trap

    Indicators extracted from public reporting. Source: manifold.security/blog/third-p

    Pulse ID: 6ab66fb56bc0ecf27543eaca
    Pulse Link: otx.alienvault.com/pulse/6ab66
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 12:57:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #OTX #CyberHunter_NL

  18. Criminals turn placeholder domain into ClickFix trap

    Indicators extracted from public reporting. Source: manifold.security/blog/third-p

    Pulse ID: 6ab66fb56bc0ecf27543eaca
    Pulse Link: otx.alienvault.com/pulse/6ab66
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 12:57:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #OTX #CyberHunter_NL

  19. Criminals turn placeholder domain into ClickFix trap

    Indicators extracted from public reporting. Source: manifold.security/blog/third-p

    Pulse ID: 6ab66fb56bc0ecf27543eaca
    Pulse Link: otx.alienvault.com/pulse/6ab66
    Pulse Author: CyberHunter_NL
    Created: 2026-09-25 12:57:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #OTX #CyberHunter_NL

  20. Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    Indicators extracted from public reporting. Source: arcticwolf.com/resources/blog/

    Pulse ID: 6ab548034e267449f1adb0e4
    Pulse Link: otx.alienvault.com/pulse/6ab54
    Pulse Author: CyberHunter_NL
    Created: 2026-09-24 15:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #Ukrainian #OTX #CyberHunter_NL

  21. Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    Indicators extracted from public reporting. Source: arcticwolf.com/resources/blog/

    Pulse ID: 6ab548034e267449f1adb0e4
    Pulse Link: otx.alienvault.com/pulse/6ab54
    Pulse Author: CyberHunter_NL
    Created: 2026-09-24 15:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #Ukrainian #OTX #CyberHunter_NL

  22. Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    Indicators extracted from public reporting. Source: arcticwolf.com/resources/blog/

    Pulse ID: 6ab548034e267449f1adb0e4
    Pulse Link: otx.alienvault.com/pulse/6ab54
    Pulse Author: CyberHunter_NL
    Created: 2026-09-24 15:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #Ukrainian #OTX #CyberHunter_NL

  23. Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    Indicators extracted from public reporting. Source: arcticwolf.com/resources/blog/

    Pulse ID: 6ab548034e267449f1adb0e4
    Pulse Link: otx.alienvault.com/pulse/6ab54
    Pulse Author: CyberHunter_NL
    Created: 2026-09-24 15:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #Ukrainian #OTX #CyberHunter_NL

  24. Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    Indicators extracted from public reporting. Source: arcticwolf.com/resources/blog/

    Pulse ID: 6ab548034e267449f1adb0e4
    Pulse Link: otx.alienvault.com/pulse/6ab54
    Pulse Author: CyberHunter_NL
    Created: 2026-09-24 15:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #Ukrainian #OTX #CyberHunter_NL