home.social

#otx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #otx, aggregated by home.social.

fetched live
  1. ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

    Indicators extracted from public reporting. Source: thehackernews.com/2026/08/thre

    Pulse ID: 6a906c21774296d1a8d3121b
    Pulse Link: otx.alienvault.com/pulse/6a906
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 16:56:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #IoT #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  2. Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data

    Indicators extracted from public reporting. Source: hunt.io/blog/chinese-speaking-

    Pulse ID: 6a9041e9649a26bc2fca6394
    Pulse Link: otx.alienvault.com/pulse/6a904
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 13:55:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Chinese #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #Word #Wordpress #bot #CyberHunter_NL

  3. Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations

    Indicators extracted from public reporting. Source: cloudsek.com/blog/aurora-ranso

    Pulse ID: 6a9025cd9bb7a62fd915b277
    Pulse Link: otx.alienvault.com/pulse/6a902
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 11:55:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberAttack #CyberAttacks #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #bot #CyberHunter_NL

  4. Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

    Indicators extracted from public reporting. Source: krebsonsecurity.com/2026/08/tw

    Pulse ID: 6a9025d25142baef9c2634cd
    Pulse Link: otx.alienvault.com/pulse/6a902
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 11:56:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  5. JavaScript obfuscation: From party trick to phishing kit

    Indicators extracted from public reporting. Source: talosintelligence.com

    Pulse ID: 6a9025f6bf0b70cb1b0c5b68
    Pulse Link: otx.alienvault.com/pulse/6a902
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 11:56:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #Phishing #RCE #Talos #bot #CyberHunter_NL

  6. Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

    Pulse ID: 6a9019e1f9fa8373169cdae2
    Pulse Link: otx.alienvault.com/pulse/6a901
    Pulse Author: Tr1sa111
    Created: 2026-08-27 11:05:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111

  7. Dark Caracal Reloaded: New Malware, Same Hunting Grounds

    Pulse ID: 6a901a11aa953b033920222a
    Pulse Link: otx.alienvault.com/pulse/6a901
    Pulse Author: Tr1sa111
    Created: 2026-08-27 11:05:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #Tr1sa111

  8. RMM Phishing Campaign: Malware Analysis

    Pulse ID: 6a901a359b8d99b16f9c8bdb
    Pulse Link: otx.alienvault.com/pulse/6a901
    Pulse Author: Tr1sa111
    Created: 2026-08-27 11:06:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #bot #Tr1sa111

  9. Fortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers with Binary Ninja Workflows

    Pulse ID: 6a901a5eda2cfb54de588daa
    Pulse Link: otx.alienvault.com/pulse/6a901
    Pulse Author: Tr1sa111
    Created: 2026-08-27 11:07:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Vulnerability #bot #Tr1sa111

  10. Tortoiseshell: New Toolset and Operational Infrastructure Exposed | Group-IB Blog

    Join the Cybercrime Fighters Club, which aims to foster a community of like-minded individuals dedicated to combat cybercrime, and will be available to apply for a job in the UK and Ireland.

    Pulse ID: 6a9016ed3a7268e42cb27b62
    Pulse Link: otx.alienvault.com/pulse/6a901
    Pulse Author: Tr1sa111
    Created: 2026-08-27 10:52:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberCrime #CyberSecurity #GroupIB #InfoSec #Ireland #OTX #OpenThreatExchange #RAT #TortoiseShell #UK #bot #Tr1sa111

  11. Carry-On Compromise: TA4922 Packs PackClient

    Indicators extracted from public reporting. Source: threatintel.proofpoint.com

    Pulse ID: 6a90099f0716b88bbc8f10cb
    Pulse Link: otx.alienvault.com/pulse/6a900
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 09:55:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proofpoint #RCE #bot #CyberHunter_NL

  12. Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

    Indicators extracted from public reporting. Source: validin.com/blog/inhospitable_

    Pulse ID: 6a9009b60d50e343c4bfd8fa
    Pulse Link: otx.alienvault.com/pulse/6a900
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 09:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Russia #bot #CyberHunter_NL

  13. New Windows Backdoor Hides Inside ESET Agent and Wakes Up With a Secret Network Packet

    Indicators extracted from public reporting. Source: r136a1.dev/2026/08/24/sleepwal

    Pulse ID: 6a8fed83fd811fc5ce6249a5
    Pulse Link: otx.alienvault.com/pulse/6a8fe
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 07:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #ESET #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Windows #bot #CyberHunter_NL

  14. AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones

    Indicators extracted from public reporting. Source: socradar.io/blog/anonymouskit-

    Pulse ID: 6a8fdf75f3cb93a84f366ba9
    Pulse Link: otx.alienvault.com/pulse/6a8fd
    Pulse Author: CyberHunter_NL
    Created: 2026-08-27 06:55:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  15. Expands Toolset With New Backdoor, SSH Tunnel

    An Iranian-linked cyber-espionage group known as Tortoiseshell has enhanced its malware arsenal with newly identified tools, including a reverse SSH tunneling utility and a C++ backdoor. The SSH tunnel, disguised as wtsapi32.dll, leverages Windows OpenSSH client to establish connections with command-and-control infrastructure. The backdoor, showing similarities to TWOSTROKE malware, supports file execution, shell commands, in-memory DLL execution, and file manipulation capabilities. Infrastructure analysis revealed domains with subdomains referencing UAE, Saudi Arabia, UK, Belgium, Canada, Australia, and Japan, suggesting expanded targeting beyond the group's traditional focus on defense, aerospace, IT service providers, and military organizations in the Middle East and United States. Active since 2018, the group continues operations with persistent infrastructure despite domain suspensions.

    Pulse ID: 6a8f1fe0b63c473eb499fd00
    Pulse Link: otx.alienvault.com/pulse/6a8f1
    Pulse Author: AlienVault
    Created: 2026-08-26 17:18:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #BackDoor #Canada #CyberSecurity #Espionage #InfoSec #Iran #Japan #Malware #MiddleEast #Military #OTX #OpenThreatExchange #RAT #SSH #SaudiArabia #TortoiseShell #UAE #UK #UnitedStates #Windows #bot #cyberespionage #AlienVault

  16. Dark Caracal Reloaded: New Malware, Same Hunting Grounds

    During a targeted intrusion investigation in June 2026, investigators uncovered GoCaracal, a previously undocumented modular framework written in Go. This sophisticated toolkit exists in two operational profiles: a lightweight implant for establishing access and delivering payloads, and an extended build for sustained intelligence collection with capabilities including keylogging, browser credential theft, WebRTC remote desktop, and SOCKS5 proxying. Analysis of 249 samples traced the framework's evolution from January to July 2026, revealing active development and maturation. A notable innovation includes an Ethereum smart-contract fallback mechanism enabling operators to update C2 infrastructure without redeploying malware. The activity targeted a Venezuelan communications organization using Spanish-language financial lures, weaponized SVG files, and delivery methods consistent with established tradecraft. GoCaracal was deployed alongside an updated Bandook variant, suggesting the new framework currently ...

    Pulse ID: 6a8f1fe07f5ffb26e71db532
    Pulse Link: otx.alienvault.com/pulse/6a8f1
    Pulse Author: AlienVault
    Created: 2026-08-26 17:18:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bandook #Browser #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #SVG #bot #socks5 #AlienVault

  17. Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

    A suspected Chinese-speaking threat actor conducted targeted intrusions against Philippine nuclear research and defense organizations. On August 13, 2026, an open directory on a VPS exposed custom Python scripts exploiting CVE-2023-49105 in ownCloud and CVE-2024-28000 in WordPress LiteSpeed Cache. The operator exfiltrated approximately 9 GB from a nuclear agency, including reactor core databases, radiation safety documentation, employee PII, BitLocker keys, and strategic planning materials. A second victim, a marine engineering firm serving the Philippine Navy, had its complete WordPress installation compromised. Simplified Chinese language usage throughout scripts, logs, and folder structures indicates operator origin. The methodical targeting of nuclear and naval defense sectors aligns with South China Sea tensions and broader Chinese espionage activities against Philippine government infrastructure.

    Pulse ID: 6a8f1fe1d950c245b840741b
    Pulse Link: otx.alienvault.com/pulse/6a8f1
    Pulse Author: AlienVault
    Created: 2026-08-26 17:18:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #Cloud #CyberSecurity #Espionage #Government #InfoSec #OTX #OpenThreatExchange #Python #RAT #RDP #Word #Wordpress #bot #AlienVault

  18. FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

    Indicators extracted from public reporting. Source: lumen.com/blog/en-us/the-infra

    Pulse ID: 6a8f28b7aa1a03e978a5a813
    Pulse Link: otx.alienvault.com/pulse/6a8f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 17:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #CyberSecurity #FBI #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  19. Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

    Indicators extracted from public reporting. Source: group-ib.com/blog/tortoiseshel

    Pulse ID: 6a8f28baaa382d435ec88898
    Pulse Link: otx.alienvault.com/pulse/6a8f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 17:56:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Nim #OTX #OpenThreatExchange #RCE #SSH #TortoiseShell #bot #CyberHunter_NL

  20. When AI infrastructure becomes the target: Securing gateways and control points

    Indicators extracted from public reporting. Source: horizon3.ai/attack-research/vu

    Pulse ID: 6a8f28c202d31b018fbfad23
    Pulse Link: otx.alienvault.com/pulse/6a8f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 17:56:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  21. Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel

    Indicators extracted from public reporting. Source: group-ib.com/blog/tortoiseshel

    Pulse ID: 6a8f0c775aa15075b0a83d14
    Pulse Link: otx.alienvault.com/pulse/6a8f0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 15:55:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SSH #TortoiseShell #bot #CyberHunter_NL

  22. FBI disrupts proxy network enabling Chinese espionage operations

    Indicators extracted from public reporting. Source: bleepingcomputer.com/news/secu

    Pulse ID: 6a8efe7bb373d16e0ba14fca
    Pulse Link: otx.alienvault.com/pulse/6a8ef
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 14:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Espionage #FBI #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #RCE #bot #CyberHunter_NL

  23. NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

    Indicators extracted from public reporting. Source: island.io/blog/novacookies-at-

    Pulse ID: 6a8eff4afd3eccfc7437417a
    Pulse Link: otx.alienvault.com/pulse/6a8ef
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 14:59:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  24. ☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator

    Indicators extracted from public reporting. Source: reddit.com/r/netsec/comments/1

    Pulse ID: 6a8eff79a2d76f6b4bde0e88
    Pulse Link: otx.alienvault.com/pulse/6a8ef
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 15:00:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  25. Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels

    Indicators extracted from public reporting. Source: group-ib.com/blog/tortoiseshel

    Pulse ID: 6a8ef0aac1dcdcac076ba153
    Pulse Link: otx.alienvault.com/pulse/6a8ef
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 13:56:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #RCE #SSH #TortoiseShell #bot #CyberHunter_NL

  26. ClickFix Phishing Hidden in Malicious npm Packages

    OX Security identified a campaign distributing fake Cloudflare Captcha pages through 24 malicious npm packages. The threat actors exploit npm mirrors like unpkg, yarn, and npmmirror as free hosting infrastructure for phishing content. Each package contains an HTML page that displays a fraudulent Cloudflare verification interface. When accessed through mirror sites, these pages appear on trusted domains, increasing their credibility. The initial versions redirected victims to a typosquatted Microsoft domain, while later iterations used legitimate key-value storage services to dynamically retrieve redirection targets. Although downloading the packages is harmless, accessing the HTML files through mirror URLs can lead to ClickFix delivery or other phishing attacks. The campaign demonstrates infrastructure abuse where npm registries serve as persistent, validated storage for malicious payloads.

    Pulse ID: 6a8e42ad990953414676533f
    Pulse Link: otx.alienvault.com/pulse/6a8e4
    Pulse Author: AlienVault
    Created: 2026-08-26 01:34:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #Cloud #CyberSecurity #HTML #InfoSec #Microsoft #NPM #OTX #OpenThreatExchange #Phishing #RAT #Rust #bot #AlienVault

  27. Fortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers with Binary Ninja Workflows

    In May 2026, threat actors exploited CVE-2026-35616, an improper access control vulnerability in Fortinet EMS versions 7.4.5 through 7.4.6, to deploy EKZ Stealer within an energy sector organization. The malware was disguised as FortiEndpoint_Patch.exe and harvested browser credentials from Chromium-based browsers and Firefox before exfiltrating data via PowerShell to a command-and-control server. EKZ Stealer employs sophisticated compiler-based obfuscation techniques including indirect jumps, control-flow flattening, and XOR-based string encryption to evade analysis. The technical analysis demonstrates how Binary Ninja Workflows can be leveraged to defeat these obfuscation methods by matching repeatable Intermediate Language patterns and rewriting LLIL/MLIL expressions to restore readable control flow, significantly accelerating malware reverse engineering efforts.

    Pulse ID: 6a8e93fa515a9f75d15acbf5
    Pulse Link: otx.alienvault.com/pulse/6a8e9
    Pulse Author: AlienVault
    Created: 2026-08-26 07:21:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Encryption #Endpoint #FireFox #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #RAT #Vulnerability #bot #AlienVault

  28. RMM Phishing Campaign: Malware Analysis

    A sophisticated phishing operation initially appearing to target Canadians with fake Canada Revenue Agency T4 tax documents has evolved into a global campaign spanning 46 countries, with 45% of activity concentrated in the United States. Attackers impersonate trusted organizations including the Social Security Administration, Adobe, and various tax authorities to deliver legitimate Remote Management and Monitoring software that is then abused for unauthorized remote access. The campaign employs a reusable delivery kit featuring password-protected archives, browser fingerprinting, and Telegram-based victim filtering. Infrastructure rotates rapidly across 240 hosts, predominantly using Vercel deployments that provide legitimate TLS certificates and domain reputation. The operation leverages signed commercial RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian, making signature-based detection ineffective. Activity has remained steady from January 2026 onwards, targeting ...

    Pulse ID: 6a8edcdfbe73c1e4ce16cdf2
    Pulse Link: otx.alienvault.com/pulse/6a8ed
    Pulse Author: AlienVault
    Created: 2026-08-26 12:32:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #Canada #Canadian #ConnectWise #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #RCE #Rust #ScreenConnect #TLS #Telegram #UnitedStates #Word #bot #AlienVault

  29. Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware

    Indicators extracted from public reporting. Source: cyberproof.com/blog/ten-minute

    Pulse ID: 6a8ee252e4312a12b0ee12d4
    Pulse Link: otx.alienvault.com/pulse/6a8ee
    Pulse Author: CyberHunter_NL
    Created: 2026-08-26 12:55:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  30. Ten Minutes to Containment: How Agentic MXDR Scoped a Fake Claude Desktop Intrusion

    A masqueraded scheduled task alert triggered an aggressive threat hunt that uncovered a complete FakeAgent intrusion campaign within ten minutes using an automated threat hunting agent. The campaign leveraged malvertising on Bing to distribute trojanized Claude Desktop installers hosted on legitimate Anthropic infrastructure. The attack chain featured DLL sideloading via Java Chromium Embedded Framework, Microsoft Defender tampering, scheduled task persistence masquerading as Microsoft Edge updates, and blockchain-based command-and-control infrastructure using EtherHiding techniques. The hunting agent executed correlated queries across multiple kill chain phases simultaneously, providing confidence-scored findings that enabled rapid validation and remediation. The intrusion delivered SectopRAT malware with infostealing and remote desktop capabilities, requiring full endpoint reimaging and credential resets.

    Pulse ID: 6a8cb55752ef1f23f4813908
    Pulse Link: otx.alienvault.com/pulse/6a8cb
    Pulse Author: AlienVault
    Created: 2026-08-24 21:19:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ESET #Edge #Endpoint #EtherHiding #InfoSec #Java #Malvertising #Malware #Microsoft #MicrosoftDefender #MicrosoftEdge #OTX #OpenThreatExchange #RAT #SideLoading #Trojan #bot #AlienVault