#malware — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malware, aggregated by home.social.
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: suite[.]trezcr-live[.]com
🔍 Analysis at: https://phishdestroy.io/domain/suite.trezcr-live.com/#scam #CryptoHacking #CyberFraud #malware #CryptoThreats #BlockchainSafety #Web3Awareness
-
#Apple :apple_inc: verschickt Warnungen: #Mercenary-#Spyware in 110 Ländern | Mac & i https://www.heise.de/news/Apple-verschickt-Warnungen-Mercenary-Spyware-in-110-Laendern-11414273.html #MercenarySpyware #Malware #Datenschutz #privacy
-
#Apple :apple_inc: verschickt Warnungen: #Mercenary-#Spyware in 110 Ländern | Mac & i https://www.heise.de/news/Apple-verschickt-Warnungen-Mercenary-Spyware-in-110-Laendern-11414273.html #MercenarySpyware #Malware #Datenschutz #privacy
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: jetsobet[.]com
🔍 Analysis at: https://phishdestroy.io/domain/jetsobet.com/#ProtectCrypto #CyberFraud #scam #BlockchainSafety #Web3Hacking #malware
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: signin[.]bh-stc[.]com
🔍 Analysis at: https://phishdestroy.io/domain/signin.bh-stc.com/#CryptoProtection #DigitalFraud #malware #WalletHackers #NFT #fake #CryptoThreats
-
Live now experimenting with ReVa and knowledge graphs for malware analysis and identification! We will be using some local models and Pi agent with Hindsight!
Let's see if we can automatically transfer analysis!
-
Live now experimenting with ReVa and knowledge graphs for malware analysis and identification! We will be using some local models and Pi agent with Hindsight!
Let's see if we can automatically transfer analysis!
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: 938262-gemini[.]com
🔍 Analysis at: https://phishdestroy.io/domain/938262-gemini.com/#CryptoDrainers #malware #ScamDetection #WalletSecurity #BlockchainSafety #CryptoHacking #CyberFraud
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: maxouru[.]com
🔍 Analysis at: https://phishdestroy.io/domain/maxouru.com/#FraudDetection #BlockchainFraud #CryptoAwareness #SecureYourWallet #malware #CryptoProtection
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: claim-om[.]netlify[.]app
🔍 Analysis at: https://phishdestroy.io/domain/claim-om.netlify.app/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: claim-fl[.]netlify[.]app
🔍 Analysis at: https://phishdestroy.io/domain/claim-fl.netlify.app/#malware #PhishingWarning #NFT #WalletSecurity #SecureYourWallet #CryptoDrainers #FraudDetection
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: claim-sl[.]netlify[.]app
🔍 Analysis at: https://phishdestroy.io/domain/claim-sl.netlify.app/#Web3Security #fake #Web3Hacking #CyberFraud #CryptoHacking #CryptoProtection #malware
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: claim-ib[.]netlify[.]app
🔍 Analysis at: https://phishdestroy.io/domain/claim-ib.netlify.app/#BlockchainSafety #CryptoAwareness #CryptoDrainers #WalletDrainers #malware #cybersec #CryptoSafety
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: claim-nq[.]netlify[.]app
🔍 Analysis at: https://phishdestroy.io/domain/claim-nq.netlify.app/#CyberFraud #WalletSecurity #scam #ProtectCrypto #CryptoProtection #malware
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: updates-phantom[.]com
🔍 Analysis at: https://phishdestroy.io/domain/updates-phantom.com/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: ftmtokenclaim[.]xyz
🔍 Analysis at: https://phishdestroy.io/domain/ftmtokenclaim.xyz/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: rapidsol[.]fun
🔍 Analysis at: https://phishdestroy.io/domain/rapidsol.fun/#malware #PhishingWarning #CryptoThreats #ScamDetection #CryptoAwareness
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: solcrypto[.]bond
🔍 Analysis at: https://phishdestroy.io/domain/solcrypto.bond/#malware #scamalert #CryptoHacking #cybersec #Web3Hacking #ScamPrevention
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: orcaclaim[.]live
🔍 Analysis at: https://phishdestroy.io/domain/orcaclaim.live/#CryptoAwareness #malware #Web3Hacking #PhishingScam #Web3Awareness
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: rainbett[.]eu[.]com
🔍 Analysis at: https://phishdestroy.io/domain/rainbett.eu.com/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: maxsstru[.]com
🔍 Analysis at: https://phishdestroy.io/domain/maxsstru.com/#AntiPhishing #WalletDrainers #CryptoDrainers #malware #WalletHackers #CryptoAwareness #scam
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: 65[.]jj38142[.]vip
🔍 Analysis at: https://phishdestroy.io/domain/65.jj38142.vip/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: d9vgttnp3sis73eqb2lg[.]qopc-defender[.]sbs
🔍 Analysis at: https://phishdestroy.io/domain/d9vgttnp3sis73eqb2lg.qopc-defender.sbs/#NFT #malware #CryptoThreats #BlockchainSafety #DigitalFraud #CryptoDrainers
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: d9vgsrfp3sis73eq8ckg[.]qopc-defender[.]sbs
🔍 Analysis at: https://phishdestroy.io/domain/d9vgsrfp3sis73eq8ckg.qopc-defender.sbs/#CryptoAwareness #malware #cybersec #scam #FraudDetection #CryptoHacking
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: laokkks1[.]blogspot[.]com
🔍 Analysis at: https://phishdestroy.io/domain/laokkks1.blogspot.com/#scamalert #AntiPhishing #WalletSecurity #malware #cybersec #PhishingWarning #fake
-
📰 Umbral Stealer malware targets credentials and crypto wallets
The 'Umbral Stealer' malware is targeting Windows users via phishing and trojanized games. It steals browser data, crypto wallets, and Discord/Telegram tokens, while attempting to disable Microsoft Defender. #Malware #InfoStealer #CyberSecurity
-
📰 Phantom Stealer malware uses PNG steganography to evade detection
Phantom Stealer malware is using steganography to hide its payload in PNG files, evading detection. The .NET stealer targets browser data, crypto wallets, and more. Be wary of links on Discord & Telegram. #Malware #InfoStealer #CyberSecurity
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: gladagnn[.]blogspot[.]com
🔍 Analysis at: https://phishdestroy.io/domain/gladagnn.blogspot.com/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: betyeni[.]pro
🔍 Analysis at: https://phishdestroy.io/domain/betyeni.pro/#Web3Awareness #FraudDetection #CryptoProtection #scamalert #malware #PhishingScam
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: ithelpdeskwebformnotice[.]weebly[.]com
🔍 Analysis at: https://phishdestroy.io/domain/ithelpdeskwebformnotice.weebly.com/ -
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals
Indicators extracted from public reporting. Source: https://www.recordedfuture.com/research/malware-crypting-services-threat-actors
Pulse ID: 6a7f024a33246de9a1d05cad
Pulse Link: https://otx.alienvault.com/pulse/6a7f024a33246de9a1d05cad
Pulse Author: CyberHunter_NL
Created: 2026-08-14 11:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #bot #CyberHunter_NL
-
CoolClient backdoor goes deeper: Windows kernel rootkit added
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.
Pulse ID: 6a7ef2da146fb06724520eb4
Pulse Link: https://otx.alienvault.com/pulse/6a7ef2da146fb06724520eb4
Pulse Author: AlienVault
Created: 2026-08-14 10:50:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel
Indicators extracted from public reporting. Source: https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
Pulse ID: 6a7ef483bde8f195b14ed712
Pulse Link: https://otx.alienvault.com/pulse/6a7ef483bde8f195b14ed712
Pulse Author: CyberHunter_NL
Created: 2026-08-14 10:57:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Telecom #bot #CyberHunter_NL
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
Pulse ID: 6a7eca0c254771760ee44515
Pulse Link: https://otx.alienvault.com/pulse/6a7eca0c254771760ee44515
Pulse Author: CyberHunter_NL
Created: 2026-08-14 07:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Three actors. Zero sites compromised. Thousands of victims inherited.
In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.
Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.
⛔️ Sample IOCs:
Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]comFull indicators on GitHub. https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
Indicators extracted from public reporting. Source: https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
Pulse ID: 6a7df72c743c82d5d51acf07
Pulse Link: https://otx.alienvault.com/pulse/6a7df72c743c82d5d51acf07
Pulse Author: CyberHunter_NL
Created: 2026-08-13 16:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Note: Recorded Future collects everything and the kitchen sink, and the only way to opt out of this madness is to send them an email request.
Recorded Future: Malware Crypting Services and the Threat Actors Who Sell Them https://www.recordedfuture.com/research?page=1 #infosec #malware
-
New.
Fortinet: Multi-Functional Linux Botnet “Evooo1Bot” https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot @fortinet #infosec #threatresearch #botnet #malware
-
#Sandworm hackers target IT pros with trojanized #WireGuard #VPN client
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
Windows users face six times more malware than Mac owners, Surfshark reveals — but 'Macs are safer' is only half true | TechRadar https://www.techradar.com/vpn/vpn-services/windows-users-face-six-times-more-malware-than-mac-owners-surfshark-reveals-but-macs-are-safer-is-only-half-true #cybersecurity #Windows #Mac #malware #socialengineering
-
Desinfec’t-AMA live auf Discord: Wir beantworten eure Fragen
Am 13. August beantworten Peter Siering und Dennis Schirrmacher eure Fragen zu Desinfec’t 2026 live auf dem neuen heise- & c’t-Discord-Server.
-
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7da2b72179e3a4cb0c1d31
Pulse Link: https://otx.alienvault.com/pulse/6a7da2b72179e3a4cb0c1d31
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Novo malware WindRelay rouba dados de cartões no Android via NFC em chamadas de 13 minutos. Investigadores da Group-IB descobriram uma nova ameaça a circular nos dispositivos Android, que permite aos atacantes roubar dados de cartões de pagamento e efetuar transações fraudulentas em tempo real. 🚨
-
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
Pulse ID: 6a7d49b1ea1377ce35778d90
Pulse Link: https://otx.alienvault.com/pulse/6a7d49b1ea1377ce35778d90
Pulse Author: Tr1sa111
Created: 2026-08-13 04:36:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #Tr1sa111