home.social

#remotecommandexecution — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.

fetched live
  1. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  2. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  3. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  4. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  5. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  6. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  7. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  8. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  9. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  10. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  11. Technical Analysis of a Novel IMEEX Framework

    The IMEEX framework is a newly discovered, custom-built malware targeting Windows systems. Delivered as a 64-bit DLL, it offers extensive control over compromised machines, featuring execution of additional modules, file manipulation, process management, registry modification, and remote command execution. It primarily targets Djibouti and Afghanistan, gathering system information and communicating with its command-and-control server over encrypted channels. The framework employs advanced techniques like masquerading as legitimate processes, mutex creation, and encrypted communications to maintain persistence and evade detection. Its modular approach, robust capabilities, and potential infrastructure overlap with ShadowPad suggest an evolution in threat actor tactics.

    Pulse ID: 670cf932eede40d2e1660012
    Pulse Link: otx.alienvault.com/pulse/670cf
    Pulse Author: AlienVault
    Created: 2024-10-14 10:57:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #CyberSecurity #ICS #InfoSec #Mac #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #ShadowPad #Windows #bot #AlienVault

  12. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐

  13. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐

  14. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐

  15. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐