home.social

#encryption — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #encryption, aggregated by home.social.

fetched live
  1. ICYMI: Brave cuts three GPU fingerprinting signals in version 1.93 by default: WebGL vendor and renderer strings collapse to one value for every user, hitting hash-based trackers. Brave says WebGPU extension randomization is planned next. ppc.land/brave-cuts-three-gpu- #BraveBrowser #Privacy #Encryption #WebGL #Fingerprinting

  2. ICYMI: Brave cuts three GPU fingerprinting signals in version 1.93 by default: WebGL vendor and renderer strings collapse to one value for every user, hitting hash-based trackers. Brave says WebGPU extension randomization is planned next. ppc.land/brave-cuts-three-gpu- #BraveBrowser #Privacy #Encryption #WebGL #Fingerprinting

  3. 🤡 Oh great, #Google is promising "private" #AI with #homomorphic #encryption, because we all know how trustworthy they are with our data! 😂 Let's just ignore the fact that most of us can't even pronounce "homomorphic," but sure, it'll definitely solve world #privacy issues. 🔐
    blog.google/security/how-googl #data #security #HackerNews #ngated

  4. 🤡 Oh great, #Google is promising "private" #AI with #homomorphic #encryption, because we all know how trustworthy they are with our data! 😂 Let's just ignore the fact that most of us can't even pronounce "homomorphic," but sure, it'll definitely solve world #privacy issues. 🔐
    blog.google/security/how-googl #data #security #HackerNews #ngated

  5. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  6. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  7. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  8. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  9. ⏰LAST CHANCE to fix #BillC22! It threatens 🇨🇦’ rights, #encryption, and privacy!

    Tell senators to reform it: openmedia.org/ReformC22-mtd

    The bill will require digital services to retain metadata for 6 months and enable secret orders forcing apps, messaging services, and others to build backdoors!

  10. ⏰LAST CHANCE to fix #BillC22! It threatens 🇨🇦’ rights, #encryption, and privacy!

    Tell senators to reform it: openmedia.org/ReformC22-mtd

    The bill will require digital services to retain metadata for 6 months and enable secret orders forcing apps, messaging services, and others to build backdoors!

  11. does anyone have a link for @micahflee's talk that involved a proof of concept steganographic encrypted OS that hides in the filesystem of another OS? I need it for a blog post I'm writing
    #encryption #steganography #qubes

  12. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  13. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  14. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  15. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  16. Secure Kubernetes Secrets at rest with AWS KMS: configure a CMK, set up the KMS plugin provider in kube-apiserver, and enable encryption config. API server encrypts Secrets via AWS KMS data key generation on writes. Kubernetes 1.13+. #kubernetes #kms #encryption

    valtersit.com/vault/encrypt-ku

  17. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  18. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  19. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  20. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  21. THIS WEEKEND! Lockdown Systems will be at HOPE 26! 🌐🐢

    Our collective member @redshiftzero will be giving a talk about post-quantum encryption and where we are in the post-quantum transition!

    The arrival of a cryptographically relevant quantum computer means that encrypted data collected now could be at risk of getting decrypted later. This is why we need to prepare now! 🔒️

    Harvest Now, Decrypt Later

    When: Sunday, August 16th at 10am
    Where: New York City (USA), New Yorker Hotel, Gramercy Park Suite

    schedule.hope.net/hope26/talk/

    #HOPE26 #LockdownSystems #Encryption #PostQuantumEncryption #QuantumComputer #NIST

  22. THIS WEEKEND! Lockdown Systems will be at HOPE 26! 🌐🐢

    Our collective member @redshiftzero will be giving a talk about post-quantum encryption and where we are in the post-quantum transition!

    The arrival of a cryptographically relevant quantum computer means that encrypted data collected now could be at risk of getting decrypted later. This is why we need to prepare now! 🔒️

    Harvest Now, Decrypt Later

    When: Sunday, August 16th at 10am
    Where: New York City (USA), New Yorker Hotel, Gramercy Park Suite

    schedule.hope.net/hope26/talk/

    #HOPE26 #LockdownSystems #Encryption #PostQuantumEncryption #QuantumComputer #NIST

  23. The Register: Signal adds an extra layer of security to make sure you’re actually chatting with the right person. “Signal has introduced a new layer of security to help make sure no one has secretly interfered with your encrypted chats. The chat app is favored by diplomats, activists, and journalists for its security. It uses end-to-end message encryption and ‘safety numbers’ – cryptographic […]

    https://rbfirehose.com/2026/08/12/the-register-signal-adds-an-extra-layer-of-security-to-make-sure-youre-actually-chatting-with-the-right-person/
  24. The Register: Signal adds an extra layer of security to make sure you’re actually chatting with the right person. “Signal has introduced a new layer of security to help make sure no one has secretly interfered with your encrypted chats. The chat app is favored by diplomats, activists, and journalists for its security. It uses end-to-end message encryption and ‘safety numbers’ – cryptographic […]

    https://rbfirehose.com/2026/08/12/the-register-signal-adds-an-extra-layer-of-security-to-make-sure-youre-actually-chatting-with-the-right-person/
  25. For people like me who are obsessed with details, the blog post is a long and fun read.

    Not that it is in any corporates' interest to allow their customers to encrypt communications entirely, but signal's work on encryption is worthy to be a product of its own.

    mastodon.world/@signalapp/1170

    #tech #encryption #E2EE #signal

  26. For people like me who are obsessed with details, the blog post is a long and fun read.

    Not that it is in any corporates' interest to allow their customers to encrypt communications entirely, but signal's work on encryption is worthy to be a product of its own.

    mastodon.world/@signalapp/1170

    #tech #encryption #E2EE #signal

  27. So I created a simple guide to use GNUPG. Take a look and feel free to provide any feedback (for improvements or any reviews)
    netizens-corner.neocities.org/

    Also; if think more of such simplistic guides should exist then please support me via:
    netizens-corner.neocities.org/

    #freesoftware #gnulinux #FSF #opensource #gnupg #gpg #libresoftware #encryption #privacy

  28. I think it's confusing to describe end-to-end encryption with phrases like "Not even WhatsApp can read your messages" or "The private key stays on your device — only you, not Signal, not anyone else, have access to this private key".

    That's because "WhatsApp" is referring to the company WhatsApp and its servers, but it appears to the reader as if it could refer to the app/client "WhatsApp" installed on their device—perhaps they aren't even aware there is such a distinction.

    But of course "WhatsApp" the app absolutely can and in fact does read your messages! That's how it can show them to you! So can Signal!

    This isn't just confusing if you're unfamiliar with E2EE, it also makes it more difficult to talk about how Signal having a free client vs. WhatsApp's proprietary client factors into the situation.

    So this phrasing is needlessly confusing. Maybe say something like "Not even the WhatsApp company servers can read your messages. They are only on your device.".

    #signal #whatsapp #encryption

  29. I think it's confusing to describe end-to-end encryption with phrases like "Not even WhatsApp can read your messages" or "The private key stays on your device — only you, not Signal, not anyone else, have access to this private key".

    That's because "WhatsApp" is referring to the company WhatsApp and its servers, but it appears to the reader as if it could refer to the app/client "WhatsApp" installed on their device—perhaps they aren't even aware there is such a distinction.

    But of course "WhatsApp" the app absolutely can and in fact does read your messages! That's how it can show them to you! So can Signal!

    This isn't just confusing if you're unfamiliar with E2EE, it also makes it more difficult to talk about how Signal having a free client vs. WhatsApp's proprietary client factors into the situation.

    So this phrasing is needlessly confusing. Maybe say something like "Not even the WhatsApp company servers can read your messages. They are only on your device.".

    #signal #whatsapp #encryption

  30. Signal führt mit »Automatic Key Verification« eine zusätzliche Absicherung für Ende-zu-Ende-verschlüsselte Chats ein.

    Über »Key Transparency« lässt sich erkennen, wenn der öffentliche Schlüssel eines Kontakts unerwartet ausgetauscht wurde. Cloudflare und Trail of Bits fungieren dabei als unabhängige Auditoren.

    Ein sinnvoller Schritt, der die bisherige manuelle Prüfung der Sicherheitsnummer ergänzt.

    signal.org/blog/automatic-key-

    #Signal #Messenger #Encryption #Datenschutz #ITSicherheit

  31. Signal führt mit »Automatic Key Verification« eine zusätzliche Absicherung für Ende-zu-Ende-verschlüsselte Chats ein.

    Über »Key Transparency« lässt sich erkennen, wenn der öffentliche Schlüssel eines Kontakts unerwartet ausgetauscht wurde. Cloudflare und Trail of Bits fungieren dabei als unabhängige Auditoren.

    Ein sinnvoller Schritt, der die bisherige manuelle Prüfung der Sicherheitsnummer ergänzt.

    signal.org/blog/automatic-key-

    #Signal #Messenger #Encryption #Datenschutz #ITSicherheit

  32. How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding

    WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...

    Pulse ID: 6a7b3ff969397d537e5d24fa
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:30:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault

  33. Bald ist wieder FrOSCon: warum ich seit zwanzig Jahren hinfahre und wen ich dort treffen möchte

    Am 15. und 16. August ist wieder FrOSCon in Sankt Augustin. Zwei Tage, sieben Vortragsschienen, freier Eintritt, und ich bin an beiden Tagen dort. Dazu meine Geschichte mit dieser Konferenz, acht Vorträge auf dem Zettel und das Jugendprogramm für die Kinder.

    kernel-error.de/2026/08/11/fro

  34. The 12 words that lock Catchlight are called a Privacy phrase, not a seed phrase, and that was deliberate.

    Seed phrase carries crypto baggage and puts the emphasis in the wrong place. It sounds like a recovery afterthought you jot down once and forget.

    Those words are the whole reason nobody else can read your writing.

    Same shape as a seed phrase, 12 words, a completely different job.

    catchlight.app/journal/passwor

    #Privacy #Encryption

  35. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  36. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  37. The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

    Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

    Pulse ID: 6a7a8be76fe0dfa36d01afa0
    Pulse Link: otx.alienvault.com/pulse/6a7a8
    Pulse Author: AlienVault
    Created: 2026-08-11 02:41:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault