home.social

#remotecommandexecution — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.

  1. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti