home.social

#malware — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malware, aggregated by home.social.

  1. Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.

    linuxmint.hu/hir/2026/09/fizet

    #CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság

  2. Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.

    linuxmint.hu/hir/2026/09/fizet

    #CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság

  3. Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.

    linuxmint.hu/hir/2026/09/fizet

    #CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság

  4. Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.

    linuxmint.hu/hir/2026/09/fizet

    #CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság

  5. Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.

    linuxmint.hu/hir/2026/09/fizet

    #CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság

  6. Hackers Turned Ethereum Into a Secret Messaging System for Malware

    A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .

    Pulse ID: 6abbd180e44bac1271a42ec6
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL

  7. Hackers Turned Ethereum Into a Secret Messaging System for Malware

    A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .

    Pulse ID: 6abbd180e44bac1271a42ec6
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL

  8. Hackers Turned Ethereum Into a Secret Messaging System for Malware

    A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .

    Pulse ID: 6abbd180e44bac1271a42ec6
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL

  9. Hackers Turned Ethereum Into a Secret Messaging System for Malware

    A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .

    Pulse ID: 6abbd180e44bac1271a42ec6
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL

  10. Hackers Turned Ethereum Into a Secret Messaging System for Malware

    A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .

    Pulse ID: 6abbd180e44bac1271a42ec6
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL

  11. SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers

    Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .

    Pulse ID: 6abbd1840ec1548557e63430
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Chinese #Microsoft #Windows #OTX #CyberHunter_NL

  12. SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers

    Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .

    Pulse ID: 6abbd1840ec1548557e63430
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Chinese #Microsoft #Windows #OTX #CyberHunter_NL

  13. SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers

    Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .

    Pulse ID: 6abbd1840ec1548557e63430
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Chinese #Microsoft #Windows #OTX #CyberHunter_NL

  14. SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers

    Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .

    Pulse ID: 6abbd1840ec1548557e63430
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Chinese #Microsoft #Windows #OTX #CyberHunter_NL

  15. SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers

    Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .

    Pulse ID: 6abbd1840ec1548557e63430
    Pulse Link: otx.alienvault.com/pulse/6abbd
    Pulse Author: CyberHunter_NL
    Created: 2026-09-29 14:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #Chinese #Microsoft #Windows #OTX #CyberHunter_NL

  16. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  17. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  18. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  19. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  20. The attack isn't rocket science but from an attacker perspective quite neat.

    The MSI is quite small and contains, appart from the hostnames little "suspicious" code.

    The random readme prevents signature based detection.

    As the code is retrieved and directly executed in memory, file based detections can't detect it.
    Furthermore, attackers can modify it anytime and the next execution uses the updated code.

    And, last but not least there is less forensic evidence left on the infected system.

    As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴

    #Malware #SocialEngineering #Cybersecurity

  21. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  22. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  23. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  24. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity

  25. As I managed to get my hands on the malicious MSI file I can provide some more details.

    You can unpack the MSI file with 7zip.
    This reveals a PowerShell script.

    This script downloads a standalone Python interpreter, installs pip and some packages (pythonnet, pywin32, pywinpty, and websockets).

    It than creates a README.md with random ASCII content

    And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at /cl/flash/c?v=17 and executes the code

    Sadly, I failed to retrive the code from any of the above-mentioned hosts.

    So again, if someone has more success, let me know.

    #Malware #SocialEngineering #Cybersecurity