home.social

#dcrat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dcrat, aggregated by home.social.

fetched live
  1. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846abfbc588c465571b8cb
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  2. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846abfbc588c465571b8cb
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  3. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846abfbc588c465571b8cb
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  4. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846abfbc588c465571b8cb
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  5. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846abfbc588c465571b8cb
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  6. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846ac500763a217460eb4b
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:23:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  7. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846ac500763a217460eb4b
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:23:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  8. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846ac500763a217460eb4b
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:23:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  9. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846ac500763a217460eb4b
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:23:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  10. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846ac500763a217460eb4b
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:23:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  11. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  12. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  13. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  14. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  15. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  16. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  17. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  18. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  19. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  20. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  21. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  22. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  23. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  24. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  25. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  26. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  27. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  28. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  29. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  30. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  31. Иллюзия разбоя: F6 проанализировала активность «Команды Legion» и её связь с кибергруппой NyashTeam

    Специалисты департамента киберразведки (Threat Intelligence) компании F6 в ходе ежедневного мониторинга угроз обнаружили подозрительный исполняемый файл, который выглядел как программа-вымогатель. Однако анализ показал, что это блокировщик, маскирующийся под шифровальщика: вместо шифрования файлов он блокировал доступ к операционной системе. В сообщении было указано, что файлы и диски « зашифрованы … командой Legion », упоминания о которой ранее не встречались.

    habr.com/ru/companies/F6/artic

    #блокировщик #шифровальщик #nyashteam #webrat #dcrat #киберразведка #threat_intelligence #legion

  32. Иллюзия разбоя: F6 проанализировала активность «Команды Legion» и её связь с кибергруппой NyashTeam

    Специалисты департамента киберразведки (Threat Intelligence) компании F6 в ходе ежедневного мониторинга угроз обнаружили подозрительный исполняемый файл, который выглядел как программа-вымогатель. Однако анализ показал, что это блокировщик, маскирующийся под шифровальщика: вместо шифрования файлов он блокировал доступ к операционной системе. В сообщении было указано, что файлы и диски « зашифрованы … командой Legion », упоминания о которой ранее не встречались.

    habr.com/ru/companies/F6/artic

    #блокировщик #шифровальщик #nyashteam #webrat #dcrat #киберразведка #threat_intelligence #legion

  33. Иллюзия разбоя: F6 проанализировала активность «Команды Legion» и её связь с кибергруппой NyashTeam

    Специалисты департамента киберразведки (Threat Intelligence) компании F6 в ходе ежедневного мониторинга угроз обнаружили подозрительный исполняемый файл, который выглядел как программа-вымогатель. Однако анализ показал, что это блокировщик, маскирующийся под шифровальщика: вместо шифрования файлов он блокировал доступ к операционной системе. В сообщении было указано, что файлы и диски « зашифрованы … командой Legion », упоминания о которой ранее не встречались.

    habr.com/ru/companies/F6/artic

    #блокировщик #шифровальщик #nyashteam #webrat #dcrat #киберразведка #threat_intelligence #legion

  34. Операция «Ликвидация»: изучаем и блокируем инфраструктуру группировки NyashTeam

    Аналитики компании F6 вскрыли сеть доменов группировки, которая распространяет вредоносное ПО, а также предоставляет хостинг-услуги для киберпреступной инфраструктуры.

    habr.com/ru/companies/F6/artic

    #киберразведка #NyashTeam #maas #DCRat #webrat #threat_intelligence #противодействие_киберпреступности