#malwareasaservice — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malwareasaservice, aggregated by home.social.
-
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...
Pulse ID: 6a7b3ff969397d537e5d24fa
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ff969397d537e5d24fa
Pulse Author: AlienVault
Created: 2026-08-11 15:30:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault
-
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...
Pulse ID: 6a7b3ff969397d537e5d24fa
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ff969397d537e5d24fa
Pulse Author: AlienVault
Created: 2026-08-11 15:30:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault
-
Fake AI Tools Deliver Infostealer
In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...
Pulse ID: 6a722d8d66f65b167764ad69
Pulse Link: https://otx.alienvault.com/pulse/6a722d8d66f65b167764ad69
Pulse Author: AlienVault
Created: 2026-08-04 18:21:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Bank #BlockChain #CyberSecurity #EtherHiding #Europe #GitHub #InfoSec #InfoStealer #LUA #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SocialEngineering #SouthernEurope #bot #developers #AlienVault
-
Fake AI Tools Deliver Infostealer
In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...
Pulse ID: 6a722d8d66f65b167764ad69
Pulse Link: https://otx.alienvault.com/pulse/6a722d8d66f65b167764ad69
Pulse Author: AlienVault
Created: 2026-08-04 18:21:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Bank #BlockChain #CyberSecurity #EtherHiding #Europe #GitHub #InfoSec #InfoStealer #LUA #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SocialEngineering #SouthernEurope #bot #developers #AlienVault
-
Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.
Pulse ID: 6a6241aa476b940a0df81e20
Pulse Link: https://otx.alienvault.com/pulse/6a6241aa476b940a0df81e20
Pulse Author: AlienVault
Created: 2026-07-23 16:30:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberSecurity #Encryption #GSC #InfoSec #MaaS #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #Troll #Venom #Windows #bot #AlienVault
-
Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.
Pulse ID: 6a6241aa476b940a0df81e20
Pulse Link: https://otx.alienvault.com/pulse/6a6241aa476b940a0df81e20
Pulse Author: AlienVault
Created: 2026-07-23 16:30:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberSecurity #Encryption #GSC #InfoSec #MaaS #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #Troll #Venom #Windows #bot #AlienVault
-
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
-
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
-
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service.
Pulse ID: 6a584223f539e1c98cd537cb
Pulse Link: https://otx.alienvault.com/pulse/6a584223f539e1c98cd537cb
Pulse Author: AlienVault
Created: 2026-07-16 02:29:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #MaaS #Malware #MalwareAsAService #OTX #OpenThreatExchange #PowerShell #RAT #SocialEngineering #Vidar #bot #AlienVault
-
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service.
Pulse ID: 6a584223f539e1c98cd537cb
Pulse Link: https://otx.alienvault.com/pulse/6a584223f539e1c98cd537cb
Pulse Author: AlienVault
Created: 2026-07-16 02:29:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #MaaS #Malware #MalwareAsAService #OTX #OpenThreatExchange #PowerShell #RAT #SocialEngineering #Vidar #bot #AlienVault
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
Malware Campaigns Target Gamers, 86K Infected by CountLoader
A shocking 86,000 gamers have fallen victim to CountLoader, a sneaky malware campaign that's been targeting players since January 2026, and the masterminds behind it are making it easy for others to join the malicious party with their free, user-friendly malware service.
-
ESET Exposes BTMOB Android Malware Service
Meet BTMOB, a sneaky Android malware that's being sold as a subscription service - think $700/month or a one-time $5,000 fee for a lifetime license - making it easy for anyone to become a cyber threat actor. This malware-as-a-service platform even comes with a user-friendly APK builder, requiring zero coding skills.
#AndroidMalware #Malwareasaservice #RemoteAccessTrojan #Maas #Rat
-
Mirax RAT Exploits Meta Apps to Infiltrate Android Devices
Beware of fake ads on Meta apps - a sneaky new malware called Mirax RAT is using them to secretly take control of Android devices, with a focus on Spanish-speaking nations. This remote access Trojan is part of a growing Malware-as-a-Service economy that's putting unsuspecting users at risk.
#MiraxRat #Malwareasaservice #MetaApps #AndroidMalware #RemoteAccessTrojan
-
Mirax Trojan Hijacks Android Devices for Proxy Network
Meet Mirax, a sneaky new Android banking trojan that's not only stealing credentials, but also hijacking devices to create a powerful proxy network - putting European users at risk. This emerging malware is a triple threat, combining a malware-as-a-service model, remote access capabilities, and residential proxies to wreak havoc…
#AndroidBankingTrojan #EmergingThreats #Malwareasaservice #ResidentialProxies #Maas
-
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
Meduza Stealer Developers Arrested in Russia https://dailydarkweb.net/meduza-stealer-developers-arrested-in-russia/ #DarkWebNews&Services #MalwareasaService #MeduzaStealer #infostealer #Article273 #cybercrime #Rosgvardia #Astrakhan #Arrest #Russia #MVD
-
Meduza Stealer Developers Arrested in Russia https://dailydarkweb.net/meduza-stealer-developers-arrested-in-russia/ #DarkWebNews&Services #MalwareasaService #MeduzaStealer #infostealer #Article273 #cybercrime #Rosgvardia #Astrakhan #Arrest #Russia #MVD
-
Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.
#meduzastealer
#malwareanalysis
#cybercrime
#infosec
#malwareasaservice -
Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.
#meduzastealer
#malwareanalysis
#cybercrime
#infosec
#malwareasaservice -
Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?
#atroposia
#malwareasaservice
#cybercrime
#remotetrojan
#credentialtheft -
Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?
#atroposia
#malwareasaservice
#cybercrime
#remotetrojan
#credentialtheft -
Malware-as-a-Service Campaign Exploits GitHub to Deliver Payloads – Source: www.infosecurity-magazine.com https://ciso2ciso.com/malware-as-a-service-campaign-exploits-github-to-deliver-payloads-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #MalwareasaService
-
Malware-as-a-Service Campaign Exploits GitHub to Deliver Payloads – Source: www.infosecurity-magazine.com https://ciso2ciso.com/malware-as-a-service-campaign-exploits-github-to-deliver-payloads-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #MalwareasaService
-
📬 Operation Magnus: Info-Stealer RedLine und MetaStealer zerschlagen
#ITSicherheit #Rechtssachen #Eurojust #MalwareasaService #MetaStealer #OperationMagnus #RedLineStealer #Schadsoftware https://sc.tarnkappe.info/1f0e19 -
📬 Operation Magnus: Info-Stealer RedLine und MetaStealer zerschlagen
#ITSicherheit #Rechtssachen #Eurojust #MalwareasaService #MetaStealer #OperationMagnus #RedLineStealer #Schadsoftware https://sc.tarnkappe.info/1f0e19 -
New ManticoraLoader Malware Attacking Citrix Users To Steal Data https://cybersecuritynews.com/manticoraloader-citrix-attack/ #MalwareasaService(MaaS) #CyberSecurityNews #ManticoraLoader #cybersecurity #CyberAttack #Malware
-
New ManticoraLoader Malware Attacking Citrix Users To Steal Data https://cybersecuritynews.com/manticoraloader-citrix-attack/ #MalwareasaService(MaaS) #CyberSecurityNews #ManticoraLoader #cybersecurity #CyberAttack #Malware
-
#CroudStrike is apparently now offering #BSOD as a service in a new bold #Enshittification #MalwareAsAService gambit.
-
#CroudStrike is apparently now offering #BSOD as a service in a new bold #Enshittification #MalwareAsAService gambit.
-
DarkGate Malware Exploiting Excel Files And SMB File Shares https://gbhackers.com/darkgate-malware-excel-smb-exploitation/ #MalwareasaService(MaaS) #ExploitationTechniques #CyberAttack #DarkGate #Exploit #Malware
-
DarkGate Malware Exploiting Excel Files And SMB File Shares https://gbhackers.com/darkgate-malware-excel-smb-exploitation/ #MalwareasaService(MaaS) #ExploitationTechniques #CyberAttack #DarkGate #Exploit #Malware
-
Cybercrime: il fenomeno dei Malware as a Service. In streaming la sessione di secsolutionforum: Intervenuto a secsolutionforum in rappresentanza di Assintel Associazione Nazionale Imprese ICT, Riccardo Michetti ha esplorato il mondo del "Malware as a Service" (MaaS), con una approfondita analisi delle tattiche, delle tecniche e delle procedure associate a questo fenomeno. Ma, in...
#secsolutionforum #cybersecurity #cybercrime #MalwareasaService… http://dlvr.it/T97C9t #News -
Coper Elevating Android Malware-as-a-Service to the Next Level
Pulse ID: 65eafcd86c86f5be39126101
Pulse Link: https://otx.alienvault.com/pulse/65eafcd86c86f5be39126101
Pulse Author: cryptocti
Created: 2024-03-08 11:56:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #Android #MalwareAsAService #cryptocti
-
Coper / Octo - A Conductor for Mobile Mayhem… With Eight Limbs?
This report provides an analysis of Coper/Octo, an Android malware-as-a-service operation that has evolved from the Exobot malware family. The malware offers capabilities like keylogging, SMS interception, and remote access, allowing operators to target victims globally. Analysis of the command-and-control infrastructure reveals concentrations of victims in countries like Portugal, Spain, Turkey, and the United States.
Pulse ID: 65e8de7c233e6044e9fb5349
Pulse Link: https://otx.alienvault.com/pulse/65e8de7c233e6044e9fb5349
Pulse Author: AlienVault
Created: 2024-03-06 21:22:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #Android #Spain #RCE #RAT #MalwareAsAService #Turkey #SMS #UnitedStates #AlienVault
-
A Ukrainian Raccoon Infostealer operator is awaiting trial in the US – Source: securityaffairs.com https://ciso2ciso.com/a-ukrainian-raccoon-infostealer-operator-is-awaiting-trial-in-the-us-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #MalwareasaService #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime #hacking #Malware #Mobile
-
IT-Trends: Professionalisierung der Cyberkriminalität 2024 https://www.it-daily.net/it-sicherheit/cybercrime/professionalisierung-der-cyberkriminalitaet-in-2024 #CyberCrime #Malware #Ransomware #OpenSource #MaaS #RaaS #MalwareAsAService #RansomwareAsAService
-
Is malware as a service peak late stage capitalism or is it just me who thinks that?
"Rhadamanthys is a C++ information stealer that first emerged in August 2022, targeting email, FTP, and online banking service account credentials...
The stealer is sold to cybercriminals via a subscription model, so it is distributed to targets using a variety of channels, including malvertizing, laced torrent downloads, emails, YouTube videos, and more."
Generally a big fan of interoperability but not for this...
"Check Point analyzed Rhadamanthys version 0.5.0 and reports that it introduced a new plugin system that allows higher levels of customization for specific distribution needs.
Plugins could add a diverse range of capabilities to the malware while allowing cybercriminals to minimize their footprint by only loading those they need in each case.
The new plugin system indicates a shift towards a more modular and customizable framework as it allows threat actors to deploy plugins tailored to their targets, counteracting security measures identified during recon stages or exploiting specific vulnerabilities."
#malware #infosec #opsec #MalwareAsAService #cybersec #wtf #LateStageCapitalism #Capitalism #enshitifcation
-
Is malware as a service peak late stage capitalism or is it just me who thinks that?
"Rhadamanthys is a C++ information stealer that first emerged in August 2022, targeting email, FTP, and online banking service account credentials...
The stealer is sold to cybercriminals via a subscription model, so it is distributed to targets using a variety of channels, including malvertizing, laced torrent downloads, emails, YouTube videos, and more."
Generally a big fan of interoperability but not for this...
"Check Point analyzed Rhadamanthys version 0.5.0 and reports that it introduced a new plugin system that allows higher levels of customization for specific distribution needs.
Plugins could add a diverse range of capabilities to the malware while allowing cybercriminals to minimize their footprint by only loading those they need in each case.
The new plugin system indicates a shift towards a more modular and customizable framework as it allows threat actors to deploy plugins tailored to their targets, counteracting security measures identified during recon stages or exploiting specific vulnerabilities."
#malware #infosec #opsec #MalwareAsAService #cybersec #wtf #LateStageCapitalism #Capitalism #enshitifcation
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH
-
📬 Malware as a Service (MaaS) im Darknet: Hintergründe und Bedrohungen
#Hintergrundberichte #Malware #AlexanderZabrovsky #Backdoors #Botnets #Cyberkriminalität #Infostealer #kaspersky #Loader #MalwareasaService #RansomwareasaService https://tarnkappe.info/artikel/it-sicherheit/malware/malware-as-a-service-maas-im-darknet-hintergruende-und-bedrohungen-276234.html -
📬 Malware as a Service (MaaS) im Darknet: Hintergründe und Bedrohungen
#Hintergrundberichte #Malware #AlexanderZabrovsky #Backdoors #Botnets #Cyberkriminalität #Infostealer #kaspersky #Loader #MalwareasaService #RansomwareasaService https://tarnkappe.info/artikel/it-sicherheit/malware/malware-as-a-service-maas-im-darknet-hintergruende-und-bedrohungen-276234.html -
📬 macOS-Malware MacStealer klaut Mac-Usern ihre M… Passwörter
#ITSicherheit #Malware #Binance #chrome #Exodus #Firefox #iCloudSchlüsselbund #MaaS #macOS #MacStealer #MalwareasaService #MetaMask #Phantom #Tron #TrustWallet https://tarnkappe.info/artikel/it-sicherheit/macos-malware-macstealer-klaut-mac-usern-ihre-m-passwoerter-272237.html -
#RaccoonStealer admin will be extradited to the US, charged for computer crimeshttps://www.malwarebytes.com/blog/news/2022/11/racoon-stealer-admin-will-be-extradited-to-the-us-charged-for-computer-crimes
-
Shh!🤫 Don't talk about #Meta's core business. #malware
⚠️☣️ Check the address. 👀⚠️☣️
☣️#MalwareAsAService ☣️ is ☣️ #Meta ☣️
~50yo's know that ! 😆
⚠️☣️ #MarkTheVirus ☣️⚠️
-
📬 Prynt Stealer Malware stiehlt Hackern ihre Beute
#Hacking #Malware #Softwareentwicklung #AsyncRAT #Backdoor #DarkEye #MalwareasaService #StormKitty #TelegramToken #WorldWind https://tarnkappe.info/artikel/malware/prynt-stealer-malware-stiehlt-hackern-ihre-beute-255168.html -
@tao all the script kiddies these days just outsource their work to the cloud SMH