#dcrat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dcrat, aggregated by home.social.
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846abfbc588c465571b8cb
Pulse Link: https://otx.alienvault.com/pulse/6a846abfbc588c465571b8cb
Pulse Author: cryptocti
Created: 2026-08-18 14:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846abfbc588c465571b8cb
Pulse Link: https://otx.alienvault.com/pulse/6a846abfbc588c465571b8cb
Pulse Author: cryptocti
Created: 2026-08-18 14:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846abfbc588c465571b8cb
Pulse Link: https://otx.alienvault.com/pulse/6a846abfbc588c465571b8cb
Pulse Author: cryptocti
Created: 2026-08-18 14:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846abfbc588c465571b8cb
Pulse Link: https://otx.alienvault.com/pulse/6a846abfbc588c465571b8cb
Pulse Author: cryptocti
Created: 2026-08-18 14:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846abfbc588c465571b8cb
Pulse Link: https://otx.alienvault.com/pulse/6a846abfbc588c465571b8cb
Pulse Author: cryptocti
Created: 2026-08-18 14:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846ac500763a217460eb4b
Pulse Link: https://otx.alienvault.com/pulse/6a846ac500763a217460eb4b
Pulse Author: cryptocti
Created: 2026-08-18 14:23:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846ac500763a217460eb4b
Pulse Link: https://otx.alienvault.com/pulse/6a846ac500763a217460eb4b
Pulse Author: cryptocti
Created: 2026-08-18 14:23:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846ac500763a217460eb4b
Pulse Link: https://otx.alienvault.com/pulse/6a846ac500763a217460eb4b
Pulse Author: cryptocti
Created: 2026-08-18 14:23:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846ac500763a217460eb4b
Pulse Link: https://otx.alienvault.com/pulse/6a846ac500763a217460eb4b
Pulse Author: cryptocti
Created: 2026-08-18 14:23:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846ac500763a217460eb4b
Pulse Link: https://otx.alienvault.com/pulse/6a846ac500763a217460eb4b
Pulse Author: cryptocti
Created: 2026-08-18 14:23:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
Trellix details a DCRat campaign that hides a malware archive in an SVG file using HTML smuggling and process hollowing.
#DCRat #DarkCrystalRAT #HTMLSmuggling #ProcessHollowing #Malware #Phishing
-
Trellix details a DCRat campaign that hides a malware archive in an SVG file using HTML smuggling and process hollowing.
#DCRat #DarkCrystalRAT #HTMLSmuggling #ProcessHollowing #Malware #Phishing
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
#DragonReturn #DCRat
https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/ -
Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
#DragonReturn #DCRat
https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/ -
Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
#DragonReturn #DCRat
https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/ -
Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
#DragonReturn #DCRat
https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/ -
Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
#DragonReturn #DCRat
https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/ -
Operation DragonReturn is a suspected China-nexus cyber espionage campaign targeting India's tax infrastructure using deceptive phishing emails and DcRAT.
#OperationDragonReturn #CyberSecurity #DcRAT #India #CyberEspionage #Phishing
-
Operation DragonReturn is a suspected China-nexus cyber espionage campaign targeting India's tax infrastructure using deceptive phishing emails and DcRAT.
#OperationDragonReturn #CyberSecurity #DcRAT #India #CyberEspionage #Phishing
-
Иллюзия разбоя: F6 проанализировала активность «Команды Legion» и её связь с кибергруппой NyashTeam
Специалисты департамента киберразведки (Threat Intelligence) компании F6 в ходе ежедневного мониторинга угроз обнаружили подозрительный исполняемый файл, который выглядел как программа-вымогатель. Однако анализ показал, что это блокировщик, маскирующийся под шифровальщика: вместо шифрования файлов он блокировал доступ к операционной системе. В сообщении было указано, что файлы и диски « зашифрованы … командой Legion », упоминания о которой ранее не встречались.
https://habr.com/ru/companies/F6/articles/992130/
#блокировщик #шифровальщик #nyashteam #webrat #dcrat #киберразведка #threat_intelligence #legion
-
Иллюзия разбоя: F6 проанализировала активность «Команды Legion» и её связь с кибергруппой NyashTeam
Специалисты департамента киберразведки (Threat Intelligence) компании F6 в ходе ежедневного мониторинга угроз обнаружили подозрительный исполняемый файл, который выглядел как программа-вымогатель. Однако анализ показал, что это блокировщик, маскирующийся под шифровальщика: вместо шифрования файлов он блокировал доступ к операционной системе. В сообщении было указано, что файлы и диски « зашифрованы … командой Legion », упоминания о которой ранее не встречались.
https://habr.com/ru/companies/F6/articles/992130/
#блокировщик #шифровальщик #nyashteam #webrat #dcrat #киберразведка #threat_intelligence #legion
-
Иллюзия разбоя: F6 проанализировала активность «Команды Legion» и её связь с кибергруппой NyashTeam
Специалисты департамента киберразведки (Threat Intelligence) компании F6 в ходе ежедневного мониторинга угроз обнаружили подозрительный исполняемый файл, который выглядел как программа-вымогатель. Однако анализ показал, что это блокировщик, маскирующийся под шифровальщика: вместо шифрования файлов он блокировал доступ к операционной системе. В сообщении было указано, что файлы и диски « зашифрованы … командой Legion », упоминания о которой ранее не встречались.
https://habr.com/ru/companies/F6/articles/992130/
#блокировщик #шифровальщик #nyashteam #webrat #dcrat #киберразведка #threat_intelligence #legion
-
Analyzing PHALT#BLYX: How Fake BSODs and Trusted Build Tools Are Used to Construct a Malware Infection
#DCRat
https://www.securonix.com/blog/analyzing-phaltblyx-how-fake-bsods-and-trusted-build-tools-are-used-to-construct-a-malware-infection/ -
Analyzing PHALT#BLYX: How Fake BSODs and Trusted Build Tools Are Used to Construct a Malware Infection
#DCRat
https://www.securonix.com/blog/analyzing-phaltblyx-how-fake-bsods-and-trusted-build-tools-are-used-to-construct-a-malware-infection/ -
Analyzing PHALT#BLYX: How Fake BSODs and Trusted Build Tools Are Used to Construct a Malware Infection
#DCRat
https://www.securonix.com/blog/analyzing-phaltblyx-how-fake-bsods-and-trusted-build-tools-are-used-to-construct-a-malware-infection/ -
Sophisticated ClickFix Campaign Targeting Hospitality Sector https://www.securityweek.com/sophisticated-clickfix-campaign-targeting-hospitality-sector/ #Malware&Threats #hospitality #ClickFix #DCrat #BSOD #RAT
-
Sophisticated ClickFix Campaign Targeting Hospitality Sector https://www.securityweek.com/sophisticated-clickfix-campaign-targeting-hospitality-sector/ #Malware&Threats #hospitality #ClickFix #DCrat #BSOD #RAT
-
Sophisticated ClickFix Campaign Targeting Hospitality Sector https://www.securityweek.com/sophisticated-clickfix-campaign-targeting-hospitality-sector/ #Malware&Threats #hospitality #ClickFix #DCrat #BSOD #RAT
-
Fake Voicemail Emails Install UpCrypter Malware on Windows – Source:hackread.com https://ciso2ciso.com/fake-voicemail-emails-install-upcrypter-malware-on-windows-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #FortiGuardLabs #cybersecurity #PhishingScam #BabylonRAT #UpCrypter #Fortinet #Hackread #PureHVNC #security #malware #Windows #DcRAT
-
Fake Voicemail Emails Install UpCrypter Malware on Windows – Source:hackread.com https://ciso2ciso.com/fake-voicemail-emails-install-upcrypter-malware-on-windows-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #FortiGuardLabs #cybersecurity #PhishingScam #BabylonRAT #UpCrypter #Fortinet #Hackread #PureHVNC #security #malware #Windows #DcRAT
-
Fake Voicemail Emails Installs UpCrypter Malware on Windows https://hackread.com/fake-voicemail-emails-install-upcrypter-malware-windows/ #FortiGuardLabs #Cybersecurity #PhishingScam #BabylonRAT #UpCrypter #Security #Fortinet #PureHVNC #Malware #Windows #DcRAT
-
Fake Voicemail Emails Installs UpCrypter Malware on Windows https://hackread.com/fake-voicemail-emails-install-upcrypter-malware-windows/ #FortiGuardLabs #Cybersecurity #PhishingScam #BabylonRAT #UpCrypter #Security #Fortinet #PureHVNC #Malware #Windows #DcRAT
-
Операция «Ликвидация»: изучаем и блокируем инфраструктуру группировки NyashTeam
Аналитики компании F6 вскрыли сеть доменов группировки, которая распространяет вредоносное ПО, а также предоставляет хостинг-услуги для киберпреступной инфраструктуры.
https://habr.com/ru/companies/F6/articles/928688/
#киберразведка #NyashTeam #maas #DCRat #webrat #threat_intelligence #противодействие_киберпреступности
-
Unmasking AsyncRAT: Navigating the labyrinth of forks
#AsyncRAT #DCRat #VenomRAT #BoratRAT #NonEuclidRAT #JasonRAT #XieBroRAT
https://www.welivesecurity.com/en/eset-research/unmasking-asyncrat-navigating-labyrinth-forks/ -
Unmasking AsyncRAT: Navigating the labyrinth of forks
#AsyncRAT #DCRat #VenomRAT #BoratRAT #NonEuclidRAT #JasonRAT #XieBroRAT
https://www.welivesecurity.com/en/eset-research/unmasking-asyncrat-navigating-labyrinth-forks/ -
#PorSiTeLoPerdiste Suplantan al gobierno colombiano para robar información: así opera el virus DCRAT que ataca a usuarios y empresas https://www.enter.co/colombia/suplantan-al-gobierno-colombiano-para-robar-informacion-asi-opera-el-virus-dcrat-que-ataca-a-usuarios-y-empresas/?utm_source=dlvr.it&utm_medium=mastodon #colombia #DCRAT #Fortinet
-
Suplantan al gobierno colombiano para robar información: así opera el virus DCRAT que ataca a usuarios y empresas https://www.enter.co/colombia/suplantan-al-gobierno-colombiano-para-robar-informacion-asi-opera-el-virus-dcrat-que-ataca-a-usuarios-y-empresas/?utm_source=dlvr.it&utm_medium=mastodon #colombia #DCRAT #Fortinet
-
We Smell a (DC)Rat: Revealing a Sophisticated Malware Delivery Chain
#DCRat
https://www.bleepingcomputer.com/news/security/we-smell-a-dcrat-revealing-a-sophisticated-malware-delivery-chain/ -
CERT-UA Warns of Escalating Cyberattacks Targeting Ukraine’s Defense Sector with DarkCrystal RAT https://thecyberexpress.com/cert-ua-warns-of-darkcrystal-rat/ #TheCyberExpressNews #Signalmessagingapp #TheCyberExpress #DarkCrystalRAT #FirewallDaily #DarkTortilla #DarkWebNews #CyberNews #UAC-0200 #CERT-UA #DCRAT
-
CERT-UA Warns of Escalating Cyberattacks Targeting Ukraine’s Defense Sector with DarkCrystal RAT https://thecyberexpress.com/cert-ua-warns-of-darkcrystal-rat/ #TheCyberExpressNews #Signalmessagingapp #TheCyberExpress #DarkCrystalRAT #FirewallDaily #DarkTortilla #DarkWebNews #CyberNews #UAC-0200 #CERT-UA #DCRAT