#malwareasaservice — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malwareasaservice, aggregated by home.social.
-
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Pulse ID: 6a8474eb4f130dfa41887e40
Pulse Link: https://otx.alienvault.com/pulse/6a8474eb4f130dfa41887e40
Pulse Author: AlienVault
Created: 2026-08-18 15:06:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault
-
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...
Pulse ID: 6a7b3ff969397d537e5d24fa
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ff969397d537e5d24fa
Pulse Author: AlienVault
Created: 2026-08-11 15:30:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault
-
Fake AI Tools Deliver Infostealer
In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...
Pulse ID: 6a722d8d66f65b167764ad69
Pulse Link: https://otx.alienvault.com/pulse/6a722d8d66f65b167764ad69
Pulse Author: AlienVault
Created: 2026-08-04 18:21:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Bank #BlockChain #CyberSecurity #EtherHiding #Europe #GitHub #InfoSec #InfoStealer #LUA #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SocialEngineering #SouthernEurope #bot #developers #AlienVault
-
Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.
Pulse ID: 6a6241aa476b940a0df81e20
Pulse Link: https://otx.alienvault.com/pulse/6a6241aa476b940a0df81e20
Pulse Author: AlienVault
Created: 2026-07-23 16:30:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberSecurity #Encryption #GSC #InfoSec #MaaS #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #Troll #Venom #Windows #bot #AlienVault
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
📬 Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort
#DarkCommerce #Malware #2FAumgehen #AccountÜbernahme #BrowserDatenklau #Cybercrime #Datendiebstahl #Infostealer #MalwareasaService #SessionHijacking #StormInfostealer https://sc.tarnkappe.info/d93668 -
📬 Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16
#ITSicherheit #Malware #2FA #AccessibilityService #Android16 #AndroidMalware #AndroidRAT #HiddenVNC #MalwareasaService #MobileSecurity #Oblivion #PermissionBypass https://sc.tarnkappe.info/345ceb -
📬 Telegram für Cyberkriminelle zunehmend unattraktiv
#DarkCommerce #Szene #AngelDrainer #BFRepo #Cybercrime #KasperskyDigitalFootprintIntelligence #MalwareasaService #Telegram #VladislavBelousov https://sc.tarnkappe.info/4a1824 -
Meduza Stealer Developers Arrested in Russia https://dailydarkweb.net/meduza-stealer-developers-arrested-in-russia/ #DarkWebNews&Services #MalwareasaService #MeduzaStealer #infostealer #Article273 #cybercrime #Rosgvardia #Astrakhan #Arrest #Russia #MVD
-
Meduza Stealer wasn’t just another malware—it was a game-changing tool that revived expired Chrome cookies and fueled a wave of cyber heists. Now, with its admins arrested in Russia, how will cybercrime adapt? Dive in to see the full story.
#meduzastealer
#malwareanalysis
#cybercrime
#infosec
#malwareasaservice -
Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?
#atroposia
#malwareasaservice
#cybercrime
#remotetrojan
#credentialtheft -
Malware-as-a-Service Campaign Exploits GitHub to Deliver Payloads – Source: www.infosecurity-magazine.com https://ciso2ciso.com/malware-as-a-service-campaign-exploits-github-to-deliver-payloads-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #MalwareasaService
-
📬 Operation Magnus: Info-Stealer RedLine und MetaStealer zerschlagen
#ITSicherheit #Rechtssachen #Eurojust #MalwareasaService #MetaStealer #OperationMagnus #RedLineStealer #Schadsoftware https://sc.tarnkappe.info/1f0e19 -
New ManticoraLoader Malware Attacking Citrix Users To Steal Data https://cybersecuritynews.com/manticoraloader-citrix-attack/ #MalwareasaService(MaaS) #CyberSecurityNews #ManticoraLoader #cybersecurity #CyberAttack #Malware
-
#CroudStrike is apparently now offering #BSOD as a service in a new bold #Enshittification #MalwareAsAService gambit.
-
DarkGate Malware Exploiting Excel Files And SMB File Shares https://gbhackers.com/darkgate-malware-excel-smb-exploitation/ #MalwareasaService(MaaS) #ExploitationTechniques #CyberAttack #DarkGate #Exploit #Malware
-
IT-Trends: Professionalisierung der Cyberkriminalität 2024 https://www.it-daily.net/it-sicherheit/cybercrime/professionalisierung-der-cyberkriminalitaet-in-2024 #CyberCrime #Malware #Ransomware #OpenSource #MaaS #RaaS #MalwareAsAService #RansomwareAsAService
-
Is malware as a service peak late stage capitalism or is it just me who thinks that?
"Rhadamanthys is a C++ information stealer that first emerged in August 2022, targeting email, FTP, and online banking service account credentials...
The stealer is sold to cybercriminals via a subscription model, so it is distributed to targets using a variety of channels, including malvertizing, laced torrent downloads, emails, YouTube videos, and more."
Generally a big fan of interoperability but not for this...
"Check Point analyzed Rhadamanthys version 0.5.0 and reports that it introduced a new plugin system that allows higher levels of customization for specific distribution needs.
Plugins could add a diverse range of capabilities to the malware while allowing cybercriminals to minimize their footprint by only loading those they need in each case.
The new plugin system indicates a shift towards a more modular and customizable framework as it allows threat actors to deploy plugins tailored to their targets, counteracting security measures identified during recon stages or exploiting specific vulnerabilities."
#malware #infosec #opsec #MalwareAsAService #cybersec #wtf #LateStageCapitalism #Capitalism #enshitifcation
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH
-
📬 Malware as a Service (MaaS) im Darknet: Hintergründe und Bedrohungen
#Hintergrundberichte #Malware #AlexanderZabrovsky #Backdoors #Botnets #Cyberkriminalität #Infostealer #kaspersky #Loader #MalwareasaService #RansomwareasaService https://tarnkappe.info/artikel/it-sicherheit/malware/malware-as-a-service-maas-im-darknet-hintergruende-und-bedrohungen-276234.html -
📬 macOS-Malware MacStealer klaut Mac-Usern ihre M… Passwörter
#ITSicherheit #Malware #Binance #chrome #Exodus #Firefox #iCloudSchlüsselbund #MaaS #macOS #MacStealer #MalwareasaService #MetaMask #Phantom #Tron #TrustWallet https://tarnkappe.info/artikel/it-sicherheit/macos-malware-macstealer-klaut-mac-usern-ihre-m-passwoerter-272237.html -
#RaccoonStealer admin will be extradited to the US, charged for computer crimeshttps://www.malwarebytes.com/blog/news/2022/11/racoon-stealer-admin-will-be-extradited-to-the-us-charged-for-computer-crimes
-
Shh!🤫 Don't talk about #Meta's core business. #malware
⚠️☣️ Check the address. 👀⚠️☣️
☣️#MalwareAsAService ☣️ is ☣️ #Meta ☣️
~50yo's know that ! 😆
⚠️☣️ #MarkTheVirus ☣️⚠️
-
📬 Prynt Stealer Malware stiehlt Hackern ihre Beute
#Hacking #Malware #Softwareentwicklung #AsyncRAT #Backdoor #DarkEye #MalwareasaService #StormKitty #TelegramToken #WorldWind https://tarnkappe.info/artikel/malware/prynt-stealer-malware-stiehlt-hackern-ihre-beute-255168.html -
@tao all the script kiddies these days just outsource their work to the cloud SMH