#rat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rat, aggregated by home.social.
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
Angriff gegen Android kombiniert Malware mit Social Engineering
Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:
#android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat
-
Angriff gegen Android kombiniert Malware mit Social Engineering
Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:
#android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat
-
Angriff gegen Android kombiniert Malware mit Social Engineering
Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:
#android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat
-
Angriff gegen Android kombiniert Malware mit Social Engineering
Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:
#android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat
-
Angriff gegen Android kombiniert Malware mit Social Engineering
Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:
#android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
Pulse ID: 6a7ec3107e8b34f88b5d610e
Pulse Link: https://otx.alienvault.com/pulse/6a7ec3107e8b34f88b5d610e
Pulse Author: AlienVault
Created: 2026-08-14 07:26:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...
Pulse ID: 6a7deb5e9423f6d0a5c5166d
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5e9423f6d0a5c5166d
Pulse Author: AlienVault
Created: 2026-08-13 16:05:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault
-
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
Pulse ID: 6a7ed8859b17643b3a21e6e1
Pulse Link: https://otx.alienvault.com/pulse/6a7ed8859b17643b3a21e6e1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 08:57:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL
-
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
Pulse ID: 6a7ed8859b17643b3a21e6e1
Pulse Link: https://otx.alienvault.com/pulse/6a7ed8859b17643b3a21e6e1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 08:57:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL
-
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
Pulse ID: 6a7ed8859b17643b3a21e6e1
Pulse Link: https://otx.alienvault.com/pulse/6a7ed8859b17643b3a21e6e1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 08:57:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL
-
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
Pulse ID: 6a7ed8859b17643b3a21e6e1
Pulse Link: https://otx.alienvault.com/pulse/6a7ed8859b17643b3a21e6e1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 08:57:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL
-
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
Pulse ID: 6a7ed8859b17643b3a21e6e1
Pulse Link: https://otx.alienvault.com/pulse/6a7ed8859b17643b3a21e6e1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 08:57:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Pulse ID: 6a7eaefe3df629ea090e9bd0
Pulse Link: https://otx.alienvault.com/pulse/6a7eaefe3df629ea090e9bd0
Pulse Author: Tr1sa111
Created: 2026-08-14 06:00:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Pulse ID: 6a7eaefe3df629ea090e9bd0
Pulse Link: https://otx.alienvault.com/pulse/6a7eaefe3df629ea090e9bd0
Pulse Author: Tr1sa111
Created: 2026-08-14 06:00:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Pulse ID: 6a7eaefe3df629ea090e9bd0
Pulse Link: https://otx.alienvault.com/pulse/6a7eaefe3df629ea090e9bd0
Pulse Author: Tr1sa111
Created: 2026-08-14 06:00:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Pulse ID: 6a7eaefe3df629ea090e9bd0
Pulse Link: https://otx.alienvault.com/pulse/6a7eaefe3df629ea090e9bd0
Pulse Author: Tr1sa111
Created: 2026-08-14 06:00:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Pulse ID: 6a7eaefe3df629ea090e9bd0
Pulse Link: https://otx.alienvault.com/pulse/6a7eaefe3df629ea090e9bd0
Pulse Author: Tr1sa111
Created: 2026-08-14 06:00:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111