#malwareasaservice — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malwareasaservice, aggregated by home.social.
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.
Pulse ID: 6a9826f869eb70a6b15298ec
Pulse Link: https://otx.alienvault.com/pulse/6a9826f869eb70a6b15298ec
Pulse Author: AlienVault
Created: 2026-09-02 13:39:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault
-
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.
Pulse ID: 6a9826f869eb70a6b15298ec
Pulse Link: https://otx.alienvault.com/pulse/6a9826f869eb70a6b15298ec
Pulse Author: AlienVault
Created: 2026-09-02 13:39:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault
-
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.
Pulse ID: 6a9826f869eb70a6b15298ec
Pulse Link: https://otx.alienvault.com/pulse/6a9826f869eb70a6b15298ec
Pulse Author: AlienVault
Created: 2026-09-02 13:39:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault
-
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.
Pulse ID: 6a9826f869eb70a6b15298ec
Pulse Link: https://otx.alienvault.com/pulse/6a9826f869eb70a6b15298ec
Pulse Author: AlienVault
Created: 2026-09-02 13:39:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault
-
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.
Pulse ID: 6a9826f869eb70a6b15298ec
Pulse Link: https://otx.alienvault.com/pulse/6a9826f869eb70a6b15298ec
Pulse Author: AlienVault
Created: 2026-09-02 13:39:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault
-
هجوم RedWing على أجهزة Android
تفاصيل الهجوم في يوليو 2026، كشفت شركة الأمن السيبراني Zimperium عن برمجية خبيثة لنظام Android أطلقت عليها اسم RedWing. البرمجية لا تُباع كبرنامج عادي، وإنما تُقدم للمجرمين كنموذج Malware-as-a-Service (MaaS) عبرتطبيق Telegram، أي أن المهاجم يستطيع استئجار البنية والأدوات الجاهزة بدلًا من تطوير […] -
Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes
Indicators extracted from public reporting. Source: https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
Pulse ID: 6a87077b82a77bd532367445
Pulse Link: https://otx.alienvault.com/pulse/6a87077b82a77bd532367445
Pulse Author: CyberHunter_NL
Created: 2026-08-20 13:56:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL
-
Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes
Indicators extracted from public reporting. Source: https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
Pulse ID: 6a87077b82a77bd532367445
Pulse Link: https://otx.alienvault.com/pulse/6a87077b82a77bd532367445
Pulse Author: CyberHunter_NL
Created: 2026-08-20 13:56:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL
-
Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes
Indicators extracted from public reporting. Source: https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
Pulse ID: 6a87077b82a77bd532367445
Pulse Link: https://otx.alienvault.com/pulse/6a87077b82a77bd532367445
Pulse Author: CyberHunter_NL
Created: 2026-08-20 13:56:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL
-
Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes
Indicators extracted from public reporting. Source: https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
Pulse ID: 6a87077b82a77bd532367445
Pulse Link: https://otx.alienvault.com/pulse/6a87077b82a77bd532367445
Pulse Author: CyberHunter_NL
Created: 2026-08-20 13:56:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL
-
Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes
Indicators extracted from public reporting. Source: https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
Pulse ID: 6a87077b82a77bd532367445
Pulse Link: https://otx.alienvault.com/pulse/6a87077b82a77bd532367445
Pulse Author: CyberHunter_NL
Created: 2026-08-20 13:56:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL
-
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Pulse ID: 6a8592950ee0e8d05fc1bec9
Pulse Link: https://otx.alienvault.com/pulse/6a8592950ee0e8d05fc1bec9
Pulse Author: AlienVault
Created: 2026-08-19 11:25:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Pulse ID: 6a8592950ee0e8d05fc1bec9
Pulse Link: https://otx.alienvault.com/pulse/6a8592950ee0e8d05fc1bec9
Pulse Author: AlienVault
Created: 2026-08-19 11:25:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Pulse ID: 6a8592950ee0e8d05fc1bec9
Pulse Link: https://otx.alienvault.com/pulse/6a8592950ee0e8d05fc1bec9
Pulse Author: AlienVault
Created: 2026-08-19 11:25:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Pulse ID: 6a8592950ee0e8d05fc1bec9
Pulse Link: https://otx.alienvault.com/pulse/6a8592950ee0e8d05fc1bec9
Pulse Author: AlienVault
Created: 2026-08-19 11:25:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Pulse ID: 6a8592950ee0e8d05fc1bec9
Pulse Link: https://otx.alienvault.com/pulse/6a8592950ee0e8d05fc1bec9
Pulse Author: AlienVault
Created: 2026-08-19 11:25:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Pulse ID: 6a8474eb4f130dfa41887e40
Pulse Link: https://otx.alienvault.com/pulse/6a8474eb4f130dfa41887e40
Pulse Author: AlienVault
Created: 2026-08-18 15:06:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault
-
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Pulse ID: 6a8474eb4f130dfa41887e40
Pulse Link: https://otx.alienvault.com/pulse/6a8474eb4f130dfa41887e40
Pulse Author: AlienVault
Created: 2026-08-18 15:06:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault
-
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Pulse ID: 6a8474eb4f130dfa41887e40
Pulse Link: https://otx.alienvault.com/pulse/6a8474eb4f130dfa41887e40
Pulse Author: AlienVault
Created: 2026-08-18 15:06:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault
-
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Pulse ID: 6a8474eb4f130dfa41887e40
Pulse Link: https://otx.alienvault.com/pulse/6a8474eb4f130dfa41887e40
Pulse Author: AlienVault
Created: 2026-08-18 15:06:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault
-
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Pulse ID: 6a8474eb4f130dfa41887e40
Pulse Link: https://otx.alienvault.com/pulse/6a8474eb4f130dfa41887e40
Pulse Author: AlienVault
Created: 2026-08-18 15:06:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
Malware Campaigns Target Gamers, 86K Infected by CountLoader
A shocking 86,000 gamers have fallen victim to CountLoader, a sneaky malware campaign that's been targeting players since January 2026, and the masterminds behind it are making it easy for others to join the malicious party with their free, user-friendly malware service.
-
ESET Exposes BTMOB Android Malware Service
Meet BTMOB, a sneaky Android malware that's being sold as a subscription service - think $700/month or a one-time $5,000 fee for a lifetime license - making it easy for anyone to become a cyber threat actor. This malware-as-a-service platform even comes with a user-friendly APK builder, requiring zero coding skills.
#AndroidMalware #Malwareasaservice #RemoteAccessTrojan #Maas #Rat
-
Mirax RAT Exploits Meta Apps to Infiltrate Android Devices
Beware of fake ads on Meta apps - a sneaky new malware called Mirax RAT is using them to secretly take control of Android devices, with a focus on Spanish-speaking nations. This remote access Trojan is part of a growing Malware-as-a-Service economy that's putting unsuspecting users at risk.
#MiraxRat #Malwareasaservice #MetaApps #AndroidMalware #RemoteAccessTrojan
-
Mirax Trojan Hijacks Android Devices for Proxy Network
Meet Mirax, a sneaky new Android banking trojan that's not only stealing credentials, but also hijacking devices to create a powerful proxy network - putting European users at risk. This emerging malware is a triple threat, combining a malware-as-a-service model, remote access capabilities, and residential proxies to wreak havoc…
#AndroidBankingTrojan #EmergingThreats #Malwareasaservice #ResidentialProxies #Maas
-
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
Meduza Stealer Developers Arrested in Russia https://dailydarkweb.net/meduza-stealer-developers-arrested-in-russia/ #DarkWebNews&Services #MalwareasaService #MeduzaStealer #infostealer #Article273 #cybercrime #Rosgvardia #Astrakhan #Arrest #Russia #MVD
-
Meduza Stealer Developers Arrested in Russia https://dailydarkweb.net/meduza-stealer-developers-arrested-in-russia/ #DarkWebNews&Services #MalwareasaService #MeduzaStealer #infostealer #Article273 #cybercrime #Rosgvardia #Astrakhan #Arrest #Russia #MVD
-
Meduza Stealer Developers Arrested in Russia https://dailydarkweb.net/meduza-stealer-developers-arrested-in-russia/ #DarkWebNews&Services #MalwareasaService #MeduzaStealer #infostealer #Article273 #cybercrime #Rosgvardia #Astrakhan #Arrest #Russia #MVD
-
Meduza Stealer Developers Arrested in Russia https://dailydarkweb.net/meduza-stealer-developers-arrested-in-russia/ #DarkWebNews&Services #MalwareasaService #MeduzaStealer #infostealer #Article273 #cybercrime #Rosgvardia #Astrakhan #Arrest #Russia #MVD
-
Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.
#meduzastealer
#malwareanalysis
#cybercrime
#infosec
#malwareasaservice -
Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.
#meduzastealer
#malwareanalysis
#cybercrime
#infosec
#malwareasaservice -
Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.
#meduzastealer
#malwareanalysis
#cybercrime
#infosec
#malwareasaservice -
Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.
#meduzastealer
#malwareanalysis
#cybercrime
#infosec
#malwareasaservice -
Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?
#atroposia
#malwareasaservice
#cybercrime
#remotetrojan
#credentialtheft -
Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?
#atroposia
#malwareasaservice
#cybercrime
#remotetrojan
#credentialtheft