#ics — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ics, aggregated by home.social.
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
Rockwell Automation: 113 CVEs, avg CVSS 7.65. 94% unpatched. Trust Score: C. Critical infrastructure risk—patch now. #RockwellAutomation #ICS #cybersecurity
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
ABB: 97 CVEs, avg CVSS 7.59, 95% unpatched. Critical infrastructure risk. Trust Score: D. Patch your industrial control systems NOW. #ABB #ics #cybersecurity
-
📰 Polish Power Plant Breached via Private Cellular APN Network
A novel attack on a Polish power plant used a private cellular APN to pivot into the OT network. Attackers, linked to Russia's FSB, used default PLC credentials to shut down a steam turbine. #ICS #OT #CyberAttack #CriticalInfrastructure #Poland
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
📰 NIST Publishes Final Cybersecurity Framework Profile for Transit Sector
NIST has released the final version of its Transit Cybersecurity Framework Profile (NIST IR 8576). The guide helps U.S. transit agencies manage cybersecurity risks across their IT and operational technology (OT) systems. #NIST #Cybersecurity #OT #ICS
-
Dragos has a Vulnerability Analyst position open!
-
Dragos has a Vulnerability Analyst position open!
-
Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones
Indicators extracted from public reporting. Source: https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools
Pulse ID: 6a75c7e5ba5f5ced0fa6825a
Pulse Link: https://otx.alienvault.com/pulse/6a75c7e5ba5f5ced0fa6825a
Pulse Author: CyberHunter_NL
Created: 2026-08-07 11:56:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Espionage #HTTP #HTTPS #ICS #InfoSec #OTX #OpenThreatExchange #PDF #RCE #bot #CyberHunter_NL
-
Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones
Indicators extracted from public reporting. Source: https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools
Pulse ID: 6a75c7e5ba5f5ced0fa6825a
Pulse Link: https://otx.alienvault.com/pulse/6a75c7e5ba5f5ced0fa6825a
Pulse Author: CyberHunter_NL
Created: 2026-08-07 11:56:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Espionage #HTTP #HTTPS #ICS #InfoSec #OTX #OpenThreatExchange #PDF #RCE #bot #CyberHunter_NL
-
Fake Zoom Installer Delivers Overlord RAT on macOS
A sophisticated macOS campaign has been discovered using a fake Zoom installer to deploy Overlord RAT, an open-source remote access framework. The attack employs a .NET-based downloader disguised as ZoomMeetings, representing an uncommon approach for macOS threats. The multi-stage attack fingerprints the victim's system to deliver platform-specific payloads for macOS ARM64, macOS Intel, or Windows from attacker-controlled infrastructure. The second stage deploys Overlord RAT with extensive capabilities including keylogging, screen capture, audio and webcam access, filesystem manipulation, and remote desktop streaming. The malware communicates with command-and-control servers over encrypted WebSockets and maintains persistence through LaunchAgents. The campaign shares characteristics with previous North Korean operations, including similarities to FlexibleFerret malware and the Contagious Interview campaign.
Pulse ID: 6a758613edf8a990accc88ee
Pulse Link: https://otx.alienvault.com/pulse/6a758613edf8a990accc88ee
Pulse Author: AlienVault
Created: 2026-08-07 07:15:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #Korea #Mac #MacOS #Malware #NET #NorthKorea #OTX #OpenThreatExchange #RAT #RCE #Troll #Windows #Zoom #bot #AlienVault
-
Fake Zoom Installer Delivers Overlord RAT on macOS
A sophisticated macOS campaign has been discovered using a fake Zoom installer to deploy Overlord RAT, an open-source remote access framework. The attack employs a .NET-based downloader disguised as ZoomMeetings, representing an uncommon approach for macOS threats. The multi-stage attack fingerprints the victim's system to deliver platform-specific payloads for macOS ARM64, macOS Intel, or Windows from attacker-controlled infrastructure. The second stage deploys Overlord RAT with extensive capabilities including keylogging, screen capture, audio and webcam access, filesystem manipulation, and remote desktop streaming. The malware communicates with command-and-control servers over encrypted WebSockets and maintains persistence through LaunchAgents. The campaign shares characteristics with previous North Korean operations, including similarities to FlexibleFerret malware and the Contagious Interview campaign.
Pulse ID: 6a758613edf8a990accc88ee
Pulse Link: https://otx.alienvault.com/pulse/6a758613edf8a990accc88ee
Pulse Author: AlienVault
Created: 2026-08-07 07:15:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #Korea #Mac #MacOS #Malware #NET #NorthKorea #OTX #OpenThreatExchange #RAT #RCE #Troll #Windows #Zoom #bot #AlienVault
-
Analysis of a Modular Cyber Espionage Framework
Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a
Pulse ID: 6a75b204c9420179df545451
Pulse Link: https://otx.alienvault.com/pulse/6a75b204c9420179df545451
Pulse Author: AlienVault
Created: 2026-08-07 10:23:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault
-
Analysis of a Modular Cyber Espionage Framework
Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a
Pulse ID: 6a75b204c9420179df545451
Pulse Link: https://otx.alienvault.com/pulse/6a75b204c9420179df545451
Pulse Author: AlienVault
Created: 2026-08-07 10:23:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Payroll Pirates: Strange New Tides in Business Email Compromise
Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.
Pulse ID: 6a7546d2694489fe6ddddcd5
Pulse Link: https://otx.alienvault.com/pulse/6a7546d2694489fe6ddddcd5
Pulse Author: AlienVault
Created: 2026-08-07 02:45:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #AitM #Canada #CyberSecurity #Education #Email #Europe #Government #Healthcare #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #UnitedStates #bot #AlienVault
-
Payroll Pirates: Strange New Tides in Business Email Compromise
Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.
Pulse ID: 6a7546d2694489fe6ddddcd5
Pulse Link: https://otx.alienvault.com/pulse/6a7546d2694489fe6ddddcd5
Pulse Author: AlienVault
Created: 2026-08-07 02:45:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #AitM #Canada #CyberSecurity #Education #Email #Europe #Government #Healthcare #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #UnitedStates #bot #AlienVault
-
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
Microsoft Threat Intelligence identified a macOS ClickFix operation distributing infostealers including MacSync and Atomic Stealer through over 250 algorithmically generated domains. The campaign evolved from openly displaying malicious content to implementing server-side browser fingerprinting that only reveals lures to visitors whose environment matches genuine macOS browsers. The fingerprinting gate collects browser attributes, hardware details via WebGL, and environmental characteristics to filter out crawlers and sandboxes. Victims are shown fake download pages with Terminal commands that retrieve remote scripts, ultimately deploying AMOS infostealer to harvest credentials, browser data, cryptocurrency wallets, and authentication stores. This Traffic Distribution System approach significantly reduces visibility for security researchers and automated analysis tools while maintaining access to intended targets. The operation represents a notable shift in tradecraft, adding sophisticated cloaking to exis...
Pulse ID: 6a73869b069fb3586fddadf9
Pulse Link: https://otx.alienvault.com/pulse/6a73869b069fb3586fddadf9
Pulse Author: AlienVault
Created: 2026-08-05 18:53:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #ICS #InfoSec #InfoStealer #Mac #MacOS #Microsoft #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #AlienVault
-
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
Microsoft Threat Intelligence identified a macOS ClickFix operation distributing infostealers including MacSync and Atomic Stealer through over 250 algorithmically generated domains. The campaign evolved from openly displaying malicious content to implementing server-side browser fingerprinting that only reveals lures to visitors whose environment matches genuine macOS browsers. The fingerprinting gate collects browser attributes, hardware details via WebGL, and environmental characteristics to filter out crawlers and sandboxes. Victims are shown fake download pages with Terminal commands that retrieve remote scripts, ultimately deploying AMOS infostealer to harvest credentials, browser data, cryptocurrency wallets, and authentication stores. This Traffic Distribution System approach significantly reduces visibility for security researchers and automated analysis tools while maintaining access to intended targets. The operation represents a notable shift in tradecraft, adding sophisticated cloaking to exis...
Pulse ID: 6a73869b069fb3586fddadf9
Pulse Link: https://otx.alienvault.com/pulse/6a73869b069fb3586fddadf9
Pulse Author: AlienVault
Created: 2026-08-05 18:53:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #ICS #InfoSec #InfoStealer #Mac #MacOS #Microsoft #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #AlienVault
-
SecuritySnack - Account Farmers and Sellers
An investigation reveals a thriving underground economy of fraudulent account marketplaces that openly sell verified accounts across major platforms including email providers, social media, cloud services, and payment processors. These operations exploit lax fraud prevention by major tech companies, which often prioritize user growth metrics over security. The report identifies numerous Chinese, Vietnamese, and English-language websites selling accounts for services like Gmail, AWS, Stripe, TikTok, and Reddit at prices ranging from $1 to $300. These marketplaces offer fresh accounts, aged accounts with established trust signals, and hijacked high-karma accounts. The investigation highlights how internal corporate pressures to inflate user adoption numbers create security vulnerabilities, with some companies admitting up to 14% of their user base may be fraudulent.
Pulse ID: 6a7336a104e4148eaba5ac26
Pulse Link: https://otx.alienvault.com/pulse/6a7336a104e4148eaba5ac26
Pulse Author: AlienVault
Created: 2026-08-05 13:12:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Chinese #Cloud #CyberSecurity #Email #ICS #InfoSec #OTX #OpenThreatExchange #RAT #Rust #SocialMedia #Vietnam #bot #AlienVault
-
SecuritySnack - Account Farmers and Sellers
An investigation reveals a thriving underground economy of fraudulent account marketplaces that openly sell verified accounts across major platforms including email providers, social media, cloud services, and payment processors. These operations exploit lax fraud prevention by major tech companies, which often prioritize user growth metrics over security. The report identifies numerous Chinese, Vietnamese, and English-language websites selling accounts for services like Gmail, AWS, Stripe, TikTok, and Reddit at prices ranging from $1 to $300. These marketplaces offer fresh accounts, aged accounts with established trust signals, and hijacked high-karma accounts. The investigation highlights how internal corporate pressures to inflate user adoption numbers create security vulnerabilities, with some companies admitting up to 14% of their user base may be fraudulent.
Pulse ID: 6a7336a104e4148eaba5ac26
Pulse Link: https://otx.alienvault.com/pulse/6a7336a104e4148eaba5ac26
Pulse Author: AlienVault
Created: 2026-08-05 13:12:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Chinese #Cloud #CyberSecurity #Email #ICS #InfoSec #OTX #OpenThreatExchange #RAT #Rust #SocialMedia #Vietnam #bot #AlienVault
-
ENDLESSDOORS Is Phoning Home. Pick Up.
Zbtlink routers, manufactured by Shenzhen Zhibotong Electronics and sold globally under multiple brand names including Wiflyer, contain a pre-installed backdoor implant named ENDLESSDOORS. This implant, based on the open-source rctl tool, runs as disguised userland processes named 'kworker' and continuously attempts to contact command and control servers. The backdoor provides unauthenticated remote root access through plaintext communication on ports 7000 and 7001, allowing attackers to execute arbitrary commands or spawn interactive shells without any verification. Twenty different router models are confirmed affected, all phoning home to four primary endpoints including zbtctl.epplink.net and hardcoded IP addresses hosted on Alibaba Cloud. The vulnerability is assigned CVE-2026-66747. No fixed firmware exists as the backdoor appears intentionally embedded by the manufacturer across multiple firmware versions spanning several years.
Pulse ID: 6a734a554923448bd690f87e
Pulse Link: https://otx.alienvault.com/pulse/6a734a554923448bd690f87e
Pulse Author: AlienVault
Created: 2026-08-05 14:36:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #Endpoint #ICS #InfoSec #NET #OTX #OpenThreatExchange #RCE #Vulnerability #bot #AlienVault
-
ENDLESSDOORS Is Phoning Home. Pick Up.
Zbtlink routers, manufactured by Shenzhen Zhibotong Electronics and sold globally under multiple brand names including Wiflyer, contain a pre-installed backdoor implant named ENDLESSDOORS. This implant, based on the open-source rctl tool, runs as disguised userland processes named 'kworker' and continuously attempts to contact command and control servers. The backdoor provides unauthenticated remote root access through plaintext communication on ports 7000 and 7001, allowing attackers to execute arbitrary commands or spawn interactive shells without any verification. Twenty different router models are confirmed affected, all phoning home to four primary endpoints including zbtctl.epplink.net and hardcoded IP addresses hosted on Alibaba Cloud. The vulnerability is assigned CVE-2026-66747. No fixed firmware exists as the backdoor appears intentionally embedded by the manufacturer across multiple firmware versions spanning several years.
Pulse ID: 6a734a554923448bd690f87e
Pulse Link: https://otx.alienvault.com/pulse/6a734a554923448bd690f87e
Pulse Author: AlienVault
Created: 2026-08-05 14:36:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #Endpoint #ICS #InfoSec #NET #OTX #OpenThreatExchange #RCE #Vulnerability #bot #AlienVault
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-06
Water sector cyberattacks reportedly widen to at least 12 US states, deepening fears of Iranian-linked OT intrusions on critical infrastructure.
https://www.securityweek.com/water-sector-cyberattacks-reportedly-hit-at-least-12-states/
#Cybersecurity #ICS #CriticalInfrastructure #Iran -
CVE-2026-71254: CRITICAL out-of-bounds write in debevv nanoMODBUS (≤v1.23.0). Unauthenticated FC 0x14 requests can cause memory corruption, leading to DoS or RCE — especially on embedded targets. Patch/mitigate now. https://radar.offseq.com/threat/cve-2026-71254-cwe-787-in-debevv-nanomodbus-649361bc8788d305 #OffSeq #CVE #ICS #infosec
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...
Pulse ID: 6a722d8bdafe1dfae681f87b
Pulse Link: https://otx.alienvault.com/pulse/6a722d8bdafe1dfae681f87b
Pulse Author: AlienVault
Created: 2026-08-04 18:20:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...
Pulse ID: 6a722d8bdafe1dfae681f87b
Pulse Link: https://otx.alienvault.com/pulse/6a722d8bdafe1dfae681f87b
Pulse Author: AlienVault
Created: 2026-08-04 18:20:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...
Pulse ID: 6a722d8ce0ae0afdde284102
Pulse Link: https://otx.alienvault.com/pulse/6a722d8ce0ae0afdde284102
Pulse Author: AlienVault
Created: 2026-08-04 18:21:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...
Pulse ID: 6a722d8ce0ae0afdde284102
Pulse Link: https://otx.alienvault.com/pulse/6a722d8ce0ae0afdde284102
Pulse Author: AlienVault
Created: 2026-08-04 18:21:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.
Pulse ID: 6a72f3bde4df792f5fa8956d
Pulse Link: https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d
Pulse Author: AlienVault
Created: 2026-08-05 08:26:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.
Pulse ID: 6a72f3bde4df792f5fa8956d
Pulse Link: https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d
Pulse Author: AlienVault
Created: 2026-08-05 08:26:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-04
Suspected Iranian hackers expand coordinated OT attacks on US water utilities to 7+ states, forcing manual control switches.
https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/
#ICS #OTSecurity #CriticalInfrastructure #Cybersecurity -
HAHAHAHAHA<gasp>HAHAHAHAHA!!
Really now? Y'all think that's the answer? Creative, I'm sure.
-
HAHAHAHAHA<gasp>HAHAHAHAHA!!
Really now? Y'all think that's the answer? Creative, I'm sure.
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-03
CISA urges water utilities to lock down OT/PLCs after coordinated attacks hit multiple states, with signs pointing to Iranian threat actors.
https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/
#CISA #ICS #OT #Cybersecurity -
📰 CISA and FBI Warn of Attacks on US Water System PLCs
CISA & FBI issue urgent warning on cyberattacks targeting US water systems. Malicious actors are compromising internet-exposed Rockwell PLCs, causing operational disruptions and boil water notices. Operators urged to remove OT from internet. #ICS #OT...
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-02
US warns Iranian hackers are actively targeting Siemens, Schneider Electric & Rockwell ICS devices, raising critical infrastructure risk.
https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
#ICS #OT #Cybersecurity #InfoSec -
Following the cyberattacks on water & wastewater (WWS) in the U.S. over the last week, we looked at exposure of Rockwell, Siemens, and Schneider Electric devices, as those are vendors explicitly named in CISA’s updated advisory on this activity (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a).
Rockwell exposures have declined about 21% since we last looked at this in April, primarily driven by a drop in U.S. exposures.
While this is encouraging, I want to note this line from CISA’s most recent alert:
> Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.I’ll also note this from an FBI alert about the activity:
> At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.I’m going out on a limb to say this is not the same flavor of hacktivist activity we have seen around WWS in the recent past. This feels distinctly different and potentially more harmful.
More details on the exposures:
https://censys.com/blog/cisa-alert-water-tower-plc-targeting/
-
Following the cyberattacks on water & wastewater (WWS) in the U.S. over the last week, we looked at exposure of Rockwell, Siemens, and Schneider Electric devices, as those are vendors explicitly named in CISA’s updated advisory on this activity (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a).
Rockwell exposures have declined about 21% since we last looked at this in April, primarily driven by a drop in U.S. exposures.
While this is encouraging, I want to note this line from CISA’s most recent alert:
> Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.I’ll also note this from an FBI alert about the activity:
> At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.I’m going out on a limb to say this is not the same flavor of hacktivist activity we have seen around WWS in the recent past. This feels distinctly different and potentially more harmful.
More details on the exposures:
https://censys.com/blog/cisa-alert-water-tower-plc-targeting/
-
New from me: analysis of a June #Cl0p extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.
Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors. -
New from me: analysis of a June #Cl0p extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.
Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors. -
📰 CISA and FBI Warn of Attacks on US Water System PLCs
CISA & FBI issue urgent warning on cyberattacks targeting US water systems. Malicious actors are compromising internet-exposed Rockwell PLCs, causing operational disruptions and boil water notices. Operators urged to remove OT from internet. #ICS #OT...
-
OctLurk and SilkLurk: new Backdoors in Central Asia
Two newly identified backdoors, OctLurk and SilkLurk, have been targeting government organizations across Central Asia since January 2025. Victims span Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, affecting healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and educational institutions. Both backdoors employ heavily obfuscated loaders customized per victim, using machine-specific data for decryption. They deploy multiple plugins for command execution, file manipulation, credential harvesting, keylogging, network scanning, and remote access. The attackers also utilized LurkProxy for network traffic proxying and deployed additional tools including PlugX, Impacket, FSCAN, and Pandora FMS agents. Analysis indicates both backdoors are operated by the same Chinese-speaking threat actor, though attribution to a specific known group remains unconfirmed. The campaigns demonstrate sophisticated persistence mechanisms and ext...
Pulse ID: 6a6b4b97df5f9df74333adfa
Pulse Link: https://otx.alienvault.com/pulse/6a6b4b97df5f9df74333adfa
Pulse Author: AlienVault
Created: 2026-07-30 13:03:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #CentralAsia #Chinese #CredentialHarvesting #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Mac #OTX #Office #OpenThreatExchange #PlugX #Proxy #RAT #RCE #SMS #Syria #bot #AlienVault
-
OctLurk and SilkLurk: new Backdoors in Central Asia
Two newly identified backdoors, OctLurk and SilkLurk, have been targeting government organizations across Central Asia since January 2025. Victims span Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, affecting healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and educational institutions. Both backdoors employ heavily obfuscated loaders customized per victim, using machine-specific data for decryption. They deploy multiple plugins for command execution, file manipulation, credential harvesting, keylogging, network scanning, and remote access. The attackers also utilized LurkProxy for network traffic proxying and deployed additional tools including PlugX, Impacket, FSCAN, and Pandora FMS agents. Analysis indicates both backdoors are operated by the same Chinese-speaking threat actor, though attribution to a specific known group remains unconfirmed. The campaigns demonstrate sophisticated persistence mechanisms and ext...
Pulse ID: 6a6b4b97df5f9df74333adfa
Pulse Link: https://otx.alienvault.com/pulse/6a6b4b97df5f9df74333adfa
Pulse Author: AlienVault
Created: 2026-07-30 13:03:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #CentralAsia #Chinese #CredentialHarvesting #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Mac #OTX #Office #OpenThreatExchange #PlugX #Proxy #RAT #RCE #SMS #Syria #bot #AlienVault
-
Reverse Engineering the Six Stages of MacSync Stealer and RAT
MacSync is a sophisticated six-stage macOS attack chain initiated when victims search for Claude installation instructions, click malicious Google Ads, and reach weaponized claude.ai/share conversations posing as Apple Support guides. The victim pastes a curl command that deploys a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and wallet trojans. The operation steals browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials, but focuses heavily on cryptocurrency with approximately 60 wallet browser extensions, 21 desktop apps, and three trojanized hardware wallet companions designed to continuously phish recovery phrases. Infrastructure spans Cloudflare-fronted delivery domains (agenticsora[.]com, malwareaudit[.]com), an operator IP (103.216.221[.]95), dedicated RAT C2 (85.206.161[.]241:8443), and seed-phrase drop domains. The malware persists via LaunchAgents masquerading as legitimate updater se...
Pulse ID: 6a6a47bf77b7d1fa679717d8
Pulse Link: https://otx.alienvault.com/pulse/6a6a47bf77b7d1fa679717d8
Pulse Author: AlienVault
Created: 2026-07-29 18:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cloud #CyberSecurity #Google #GoogleAds #ICS #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Telegram #Trojan #Word #bot #cryptocurrency #AlienVault