home.social

#rat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rat, aggregated by home.social.

fetched live
  1. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  2. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  3. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  4. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  5. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  6. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  7. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  8. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  9. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  10. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  11. There are many tales about the bad things that happen when you stiff your subcontractors. But this is the most famous one of all...

    #Germany #folktale #folklore #mage #rat
    wiki.sunkencastles.com/wiki/Th

  12. There are many tales about the bad things that happen when you stiff your subcontractors. But this is the most famous one of all...

    #Germany #folktale #folklore #mage #rat
    wiki.sunkencastles.com/wiki/Th

  13. There are many tales about the bad things that happen when you stiff your subcontractors. But this is the most famous one of all...

    #Germany #folktale #folklore #mage #rat
    wiki.sunkencastles.com/wiki/Th

  14. There are many tales about the bad things that happen when you stiff your subcontractors. But this is the most famous one of all...

    #Germany #folktale #folklore #mage #rat
    wiki.sunkencastles.com/wiki/Th

  15. There are many tales about the bad things that happen when you stiff your subcontractors. But this is the most famous one of all...

    #Germany #folktale #folklore #mage #rat
    wiki.sunkencastles.com/wiki/Th

  16. Angriff gegen Android kombiniert Malware mit Social Engineering

    Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat

  17. Angriff gegen Android kombiniert Malware mit Social Engineering

    Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat

  18. Angriff gegen Android kombiniert Malware mit Social Engineering

    Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat

  19. Angriff gegen Android kombiniert Malware mit Social Engineering

    Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat

  20. Angriff gegen Android kombiniert Malware mit Social Engineering

    Das (werden sollende) Opfer erhält einen Anruf, angeblich von seiner* Bank. Es gäbe ein Problem mit seiner Bezahlkarte. Das Opfer soll erst mal eine für den folgenden Vorgang angeblich notwendige App installieren. Der Name der App enthält sogar den Namen* des Opfers. Bei der App handelt es sich um ein RAT (remote access trojan), also eine Fernsteuerung. Der hier verwendete RAT ist unter dem Namen SpyNote seit 2016 bekannt. Einmal installiert nutzt der Angreifer es, um heimlich eine weitere Malware namens WindRelay dazu zu holen. Das ist eine App, die in NFC-Transaktionen eingreifen kann. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #android #banking #betrug #cybercrime #kreditkarte #smartphone #vorbeugen #nfc #rat

  21. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  22. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  23. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  24. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  25. DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/sig

    Pulse ID: 6a7f105c416203282deae39f
    Pulse Link: otx.alienvault.com/pulse/6a7f1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL

  26. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  27. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  28. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  29. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  30. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  31. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  32. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  33. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  34. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  35. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  36. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  37. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  38. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  39. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  40. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  41. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  42. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  43. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  44. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  45. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault

  46. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  47. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  48. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  49. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  50. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  51. Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/wea

    Pulse ID: 6a7ed8859b17643b3a21e6e1
    Pulse Link: otx.alienvault.com/pulse/6a7ed
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 08:57:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL

  52. Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/wea

    Pulse ID: 6a7ed8859b17643b3a21e6e1
    Pulse Link: otx.alienvault.com/pulse/6a7ed
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 08:57:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL

  53. Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/wea

    Pulse ID: 6a7ed8859b17643b3a21e6e1
    Pulse Link: otx.alienvault.com/pulse/6a7ed
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 08:57:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL

  54. Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/wea

    Pulse ID: 6a7ed8859b17643b3a21e6e1
    Pulse Link: otx.alienvault.com/pulse/6a7ed
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 08:57:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL

  55. Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits

    Indicators extracted from public reporting. Source: trellix.com/blogs/research/wea

    Pulse ID: 6a7ed8859b17643b3a21e6e1
    Pulse Link: otx.alienvault.com/pulse/6a7ed
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 08:57:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL

  56. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Pulse ID: 6a7eaefe3df629ea090e9bd0
    Pulse Link: otx.alienvault.com/pulse/6a7ea
    Pulse Author: Tr1sa111
    Created: 2026-08-14 06:00:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111

  57. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Pulse ID: 6a7eaefe3df629ea090e9bd0
    Pulse Link: otx.alienvault.com/pulse/6a7ea
    Pulse Author: Tr1sa111
    Created: 2026-08-14 06:00:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111

  58. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Pulse ID: 6a7eaefe3df629ea090e9bd0
    Pulse Link: otx.alienvault.com/pulse/6a7ea
    Pulse Author: Tr1sa111
    Created: 2026-08-14 06:00:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111

  59. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Pulse ID: 6a7eaefe3df629ea090e9bd0
    Pulse Link: otx.alienvault.com/pulse/6a7ea
    Pulse Author: Tr1sa111
    Created: 2026-08-14 06:00:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111

  60. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Pulse ID: 6a7eaefe3df629ea090e9bd0
    Pulse Link: otx.alienvault.com/pulse/6a7ea
    Pulse Author: Tr1sa111
    Created: 2026-08-14 06:00:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111