#rpc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rpc, aggregated by home.social.
-
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Pulse ID: 6a8592950ee0e8d05fc1bec9
Pulse Link: https://otx.alienvault.com/pulse/6a8592950ee0e8d05fc1bec9
Pulse Author: AlienVault
Created: 2026-08-19 11:25:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Pulse ID: 6a698eb14601a4b3d4d30511
Pulse Link: https://otx.alienvault.com/pulse/6a698eb14601a4b3d4d30511
Pulse Author: Tr1sa111
Created: 2026-07-29 05:25:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RPC #bot #Tr1sa111
-
Microsoft Teams Vishing Campaign Abuses Quick Assist to Deploy GoGRPC Backdoor
Microsoft Teams vishing campaign targeting enterprises between January and June 2026. Attackers use email bombing, Teams impersonation and Quick Assist to deploy the GoGRPC backdoor, enabling ersistent access, reconnaissance and potential ransomware or extortion through compromised enterprise networks.
Pulse ID: 6a693ba0eaf729fe7f4805da
Pulse Link: https://otx.alienvault.com/pulse/6a693ba0eaf729fe7f4805da
Pulse Author: cryptocti
Created: 2026-07-28 23:30:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #Extortion #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RPC #RansomWare #bot #cryptocti
-
#RicochetRefresh and #Arti build on #Fedora Atomic #OS.
#rustlang environment is also functional in #rpm #ostree.
(#immutability over sandboxing if not live?)
#FreedomOfThePress #Journalism #ComputerScience #Linux @freedomofpress @torprojectjk, Rotational #HDD and #Rust work together just fine.
Anomalies and vulns in #QubesOS . . .
#console #hacking #rpc #Wayland #fastly @rustForeign Sources as attack vector
http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Install_Software#Foreign_Sources
also → APT::KashGrow “true”;What other flaws might lie in confidential computing core trust mechanisms?
https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056
@QubesOS @whonix
#attestation #TLS
@rfceditor #GOSalso, in case you didn't know,
rpm-ostree kargs --append=
is really great
and rpm-ostress works over torsocks, atomic just doesn't like systemd so run 'tor' manually -
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...
Pulse ID: 6a678b1bffd8195d4d34ef68
Pulse Link: https://otx.alienvault.com/pulse/6a678b1bffd8195d4d34ef68
Pulse Author: AlienVault
Created: 2026-07-27 16:45:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault
-
🪧 Proxy, Record, and Mock gRPC APIs with FauxRPC: Stop writing mock stubs by hand. How FauxRPC uses smart proxying, reflection, and CEL to automate your API testing.
https://kmcd.dev/posts/fauxrpc-proxy/
#Fauxrpc #Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3 -
🪧 Proxy, Record, and Mock gRPC APIs with FauxRPC: Stop writing mock stubs by hand. How FauxRPC uses smart proxying, reflection, and CEL to automate your API testing.
https://kmcd.dev/posts/fauxrpc-proxy/
#Fauxrpc #Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3 -
Billionaires are oligarchs.
Oligarchs are dangerous.
#Tell2 #RPC
https://revolutionparty.ca/eat-the-rich -
🪧 Introducing ProtoDocs: A protobuf-first documentation browser for APIs that deserve better than ugly generated docs.
https://kmcd.dev/posts/introducing-protodocs/
#Protobuf #Grpc #Connectrpc #Documentation #Go #Rpc -
🪧 Introducing ProtoDocs: A protobuf-first documentation browser for APIs that deserve better than ugly generated docs.
https://kmcd.dev/posts/introducing-protodocs/
#Protobuf #Grpc #Connectrpc #Documentation #Go #Rpc -
Декларативное RPC вместо REST-ручек — победили сетевой бойлерплейт и вычистили код с помощью фреймворка Chord
Во многих проектах взаимодействие фронта с бэком до сих пор строится по классике: ручки, fetch, headers, дублирование типов. При таком подходе внушительная часть кода уходит на обслуживание сети, а не на саму бизнес-логику. Мы решили эту проблему через Chord — фреймворк сетевого уровня на базе JSON-RPC. Используем его уже более 2 лет. Эта статья для фронтенд- и фулстек-разработчиков, работающих с TypeScript и мета-фреймворками вроде SvelteKit, Next или Nuxt. В ней покажу, как мы с помощью Chord вызываем серверные методы как обычные функции и получаем типы с бэка без дублирования.
https://habr.com/ru/companies/dalee_group/articles/1044744/
#chord #rpc #rest #бэкенд #фулстекразработка #json #jsonrpc #svelte #sveltejs
-
This 1990 paper reviewed the state of Remote Procedure Call systems by Xerox, Sun, Apollo, and more. Distributed computing was hot at the time.
https://dl.acm.org/doi/abs/10.1145/382244.382832
-
🪧 ConnectRPC: Where is it now?: Reflecting on two years of ConnectRPC: How it evolved from a gRPC alternative to a complete API ecosystem.
https://kmcd.dev/posts/connectrpc-where-is-it-now/
#Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3 #Openapi -
🪧 ConnectRPC: Where is it now?: Reflecting on two years of ConnectRPC: How it evolved from a gRPC alternative to a complete API ecosystem.
https://kmcd.dev/posts/connectrpc-where-is-it-now/
#Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3 #Openapi -
Pratiques d’auto-édition en Chine
Mercredi 13 mai – 19h30
Bibliothèque associative de Malakoff« En dépit d’une censure écrasante et d’un contexte politique répressif, des pratiques de résistance par l’auto-édition subsistent aujourd’hui en Chine. Fanzines, brochures, livres d’art, etc. : nous présenterons certains de ces objets littéraires et politiques, venus de Pékin, Canton et Wuhan, ainsi que le contexte dans lequel ils ont été créés. »
La soirée sera suivi d’un buffet participatif (tout le monde apporte quelque chose à partager).
https://www.b-a-m.org/11070/autoedition-chine/
Bibliothèque Associative de Malakoff
14, impasse Carnot – interphone BAM.#Chine #RPC #censure #PresseAlternative #livres #zines #AutoEdition #DiYculture #anarchisme @bam
-
Officially on the path to my RPC, South Africa's regulated aviation licence for professional drone pilots under SACAA. Air law, navigation, meteorology, practical flight ops, the full journey. 🌍
Not just a licence. A foundation. More to come.
#RemotePilot #RPC #SACAA #DroneLife #UAV #AviationSA #SouthAfrica #4IR #SkillsForTheFuture
-
Des féministes chinoises réinventent la langue pour s’attaquer au patriarcat
En Chine, des féministes remodèlent le mandarin écrit en modifiant d’anciens caractères et en inventant de nouveaux termes afin de contester le système patriarcal qui a longtemps dévalorisé les femmes.
Le printemps dernier, une jeune femme qui se fait appeler « Puff » en ligne a créé un compte sur le réseau social XiaoHongShu afin de déverser sa colère contre le harcèlement sexuel en ligne et la discrimination contre les femmes enracinée dans la langue écrite.
« Nous faisons passer une radiographie à la langue. Notre but est d’en révéler les biais de genre et de reprendre possession de notre langage et de notre regard culturel, avec un point de vue féminin. La langue façonne notre vision du monde et de nous-mêmes », soutient Puff.
Sur son compte, elle invente de nouveaux mots. Elle remplace aussi des expressions qui stigmatisaient à l’origine les femmes et les remplace par d’autres qui stigmatisent les hommes afin que les Chinois prennent conscience de l’objectification et de la marginalisation que les femmes subissent en raison de la langue.
https://ici.radio-canada.ca/nouvelle/2206758/feministes-chinoises-langage-patriarcat
#Chine #RPC #femmes #feminisme #mandarin #sinogrammes #patriarcat
-
Три года в одиночку: как я строил бэкенд-фреймворк поверх Next.js и что из этого вышло
Почти три года я в одиночку строил бэкенд-фреймворк поверх Next.js App Router. По дороге мой ишью закрыл создатель C#, синтаксис подсказал Copilot, а три пакета-адаптера пришлось убить. Рассказываю, что вышло и какие грабли собрал.
https://habr.com/ru/articles/1011948/
#vovk #vovkts #nextjs_backend #rpc #typescript_framework #standard_schema
-
Как работает RPC. Пишем свое RPC-приложение
В данной статье мы подробно поговорим об устройстве RPC. Также для лучшего понимания применим знания на практике и напишем свое RPC-приложение под Windows. Изучить матчасть
https://habr.com/ru/articles/1010204/
#rpc #cybersecurity #network #безопасность #сетевая_безопасность #network_security #ipc #межпроцессное_взаимодействие
-
От нуля к единице: MCP и много другого на пути к его пониманию
Сегодня ядром данной статьи будет MCP — как мост между бекендом‑оберткой с LLM и внешними источниками , но при этом я также затрону смежные темы , чтобы картина была полной и не требовалось дополнительно гуглить. Я постараюсь не давать устоявшиеся термины в контексте MCP, а также в процессе буду пояснять некоторые «базовые» термины, которые все как бы понимают — но нередко нет, чтобы мы все улавливали один и тот же контекст статьи.
https://habr.com/ru/articles/1005028/
#mcp #mcpserver #ai #llm #agent #агенты #model_context_protocol #rpc #network
-
Согласованность API по принципу единого источника истины
Представим ситуацию: идет тяжёлый спринт, вы выполнили кучу задач, написали тонну нового функционала, готовитесь к релизу и вдруг обнаруживайте, что часть фич перестала работать! Идёте разбираться и обнаруживайте, что оказывается бэкендер Вася в последний момент решил переименовать поля в json-е, а вам об этом не сказал! Ситуация образная, но позволяет быстро обрисовать одну из болей во время разработки. В этой статье я бы хотел рассказать об одном из вариантов её решения в коде с помощью подхода Единого источника истины(Single source of truth).
https://habr.com/ru/articles/1003398/
#API #honojs #zod #RPC #SSOT #OpenAPI #typescript #monorepo #javascript