home.social

#rpc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rpc, aggregated by home.social.

fetched live
  1. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  2. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  3. An Evolution of the Botnet

    A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.

    Pulse ID: 6a7b3ea11dca2e714d4bff8d
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault

  4. The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

    Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

    Pulse ID: 6a7a8be76fe0dfa36d01afa0
    Pulse Link: otx.alienvault.com/pulse/6a7a8
    Pulse Author: AlienVault
    Created: 2026-08-11 02:41:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault

  5. Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Pulse ID: 6a698eb14601a4b3d4d30511
    Pulse Link: otx.alienvault.com/pulse/6a698
    Pulse Author: Tr1sa111
    Created: 2026-07-29 05:25:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RPC #bot #Tr1sa111

  6. Microsoft Teams Vishing Campaign Abuses Quick Assist to Deploy GoGRPC Backdoor

    Microsoft Teams vishing campaign targeting enterprises between January and June 2026. Attackers use email bombing, Teams impersonation and Quick Assist to deploy the GoGRPC backdoor, enabling ersistent access, reconnaissance and potential ransomware or extortion through compromised enterprise networks.

    Pulse ID: 6a693ba0eaf729fe7f4805da
    Pulse Link: otx.alienvault.com/pulse/6a693
    Pulse Author: cryptocti
    Created: 2026-07-28 23:30:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #Extortion #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RPC #RansomWare #bot #cryptocti

  7. #RicochetRefresh and #Arti build on #Fedora Atomic #OS.
    #rustlang environment is also functional in #rpm #ostree.
    (#immutability over sandboxing if not live?)
    #FreedomOfThePress #Journalism #ComputerScience #Linux @freedomofpress @torproject

    jk, Rotational #HDD and #Rust work together just fine.
    Anomalies and vulns in #QubesOS . . .
    #console #hacking #rpc #Wayland #fastly @rust

    Foreign Sources as attack vector
    dds6qkxpwdeubwucdiaord2xgbbeyd
    also → APT::KashGrow “true”;

    What other flaws might lie in confidential computing core trust mechanisms?
    theregister.com/security/2026/
    @QubesOS @whonix
    #attestation #TLS
    @rfceditor #GOS

    also, in case you didn't know,
    rpm-ostree kargs --append=
    is really great
    and rpm-ostress works over torsocks, atomic just doesn't like systemd so run 'tor' manually

    #Karg #Kernel

  8. Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

    Pulse ID: 6a678b1bffd8195d4d34ef68
    Pulse Link: otx.alienvault.com/pulse/6a678
    Pulse Author: AlienVault
    Created: 2026-07-27 16:45:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault

  9. 🪧 Proxy, Record, and Mock gRPC APIs with FauxRPC: Stop writing mock stubs by hand. How FauxRPC uses smart proxying, reflection, and CEL to automate your API testing.
    kmcd.dev/posts/fauxrpc-proxy/
    #Fauxrpc #Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3

  10. 🪧 Proxy, Record, and Mock gRPC APIs with FauxRPC: Stop writing mock stubs by hand. How FauxRPC uses smart proxying, reflection, and CEL to automate your API testing.
    kmcd.dev/posts/fauxrpc-proxy/
    #Fauxrpc #Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3

  11. 🪧 Introducing ProtoDocs: A protobuf-first documentation browser for APIs that deserve better than ugly generated docs.
    kmcd.dev/posts/introducing-pro
    #Protobuf #Grpc #Connectrpc #Documentation #Go #Rpc

  12. 🪧 Introducing ProtoDocs: A protobuf-first documentation browser for APIs that deserve better than ugly generated docs.
    kmcd.dev/posts/introducing-pro
    #Protobuf #Grpc #Connectrpc #Documentation #Go #Rpc

  13. Декларативное RPC вместо REST-ручек — победили сетевой бойлерплейт и вычистили код с помощью фреймворка Chord

    Во многих проектах взаимодействие фронта с бэком до сих пор строится по классике: ручки, fetch, headers, дублирование типов. При таком подходе внушительная часть кода уходит на обслуживание сети, а не на саму бизнес-логику. Мы решили эту проблему через Chord — фреймворк сетевого уровня на базе JSON-RPC. Используем его уже более 2 лет. Эта статья для фронтенд- и фулстек-разработчиков, работающих с TypeScript и мета-фреймворками вроде SvelteKit, Next или Nuxt. В ней покажу, как мы с помощью Chord вызываем серверные методы как обычные функции и получаем типы с бэка без дублирования.

    habr.com/ru/companies/dalee_gr

    #chord #rpc #rest #бэкенд #фулстекразработка #json #jsonrpc #svelte #sveltejs

  14. This 1990 paper reviewed the state of Remote Procedure Call systems by Xerox, Sun, Apollo, and more. Distributed computing was hot at the time.

    dl.acm.org/doi/abs/10.1145/382

    dl.acm.org/doi/pdf/10.1145/382

    #rpc #retrocomputing

  15. 🪧 ConnectRPC: Where is it now?: Reflecting on two years of ConnectRPC: How it evolved from a gRPC alternative to a complete API ecosystem.
    kmcd.dev/posts/connectrpc-wher
    #Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3 #Openapi

  16. 🪧 ConnectRPC: Where is it now?: Reflecting on two years of ConnectRPC: How it evolved from a gRPC alternative to a complete API ecosystem.
    kmcd.dev/posts/connectrpc-wher
    #Connectrpc #Grpc #Protobuf #Api #Rpc #Go #Golang #Http3 #Openapi

  17. Pratiques d’auto-édition en Chine
    Mercredi 13 mai – 19h30
    Bibliothèque associative de Malakoff

    « En dépit d’une censure écrasante et d’un contexte politique répressif, des pratiques de résistance par l’auto-édition subsistent aujourd’hui en Chine. Fanzines, brochures, livres d’art, etc. : nous présenterons certains de ces objets littéraires et politiques, venus de Pékin, Canton et Wuhan, ainsi que le contexte dans lequel ils ont été créés. »

    La soirée sera suivi d’un buffet participatif (tout le monde apporte quelque chose à partager).

    https://www.b-a-m.org/11070/autoedition-chine/

    Bibliothèque Associative de Malakoff
    14, impasse Carnot – interphone BAM.

    #Chine #RPC #censure #PresseAlternative #livres #zines #AutoEdition #DiYculture #anarchisme @bam

  18. Officially on the path to my RPC, South Africa's regulated aviation licence for professional drone pilots under SACAA. Air law, navigation, meteorology, practical flight ops, the full journey. 🌍

    Not just a licence. A foundation. More to come.

    #RemotePilot #RPC #SACAA #DroneLife #UAV #AviationSA #SouthAfrica #4IR #SkillsForTheFuture

  19. Des féministes chinoises réinventent la langue pour s’attaquer au patriarcat

    En Chine, des féministes remodèlent le mandarin écrit en modifiant d’anciens caractères et en inventant de nouveaux termes afin de contester le système patriarcal qui a longtemps dévalorisé les femmes.

    Le printemps dernier, une jeune femme qui se fait appeler « Puff » en ligne a créé un compte sur le réseau social XiaoHongShu afin de déverser sa colère contre le harcèlement sexuel en ligne et la discrimination contre les femmes enracinée dans la langue écrite.

    « Nous faisons passer une radiographie à la langue. Notre but est d’en révéler les biais de genre et de reprendre possession de notre langage et de notre regard culturel, avec un point de vue féminin. La langue façonne notre vision du monde et de nous-mêmes », soutient Puff.

    Sur son compte, elle invente de nouveaux mots. Elle remplace aussi des expressions qui stigmatisaient à l’origine les femmes et les remplace par d’autres qui stigmatisent les hommes afin que les Chinois prennent conscience de l’objectification et de la marginalisation que les femmes subissent en raison de la langue.

    https://ici.radio-canada.ca/nouvelle/2206758/feministes-chinoises-langage-patriarcat

    #Chine #RPC #femmes #feminisme #mandarin #sinogrammes #patriarcat

  20. Три года в одиночку: как я строил бэкенд-фреймворк поверх Next.js и что из этого вышло

    Почти три года я в одиночку строил бэкенд-фреймворк поверх Next.js App Router. По дороге мой ишью закрыл создатель C#, синтаксис подсказал Copilot, а три пакета-адаптера пришлось убить. Рассказываю, что вышло и какие грабли собрал.

    habr.com/ru/articles/1011948/

    #vovk #vovkts #nextjs_backend #rpc #typescript_framework #standard_schema

  21. Как работает RPC. Пишем свое RPC-приложение

    В данной статье мы подробно поговорим об устройстве RPC. Также для лучшего понимания применим знания на практике и напишем свое RPC-приложение под Windows. Изучить матчасть

    habr.com/ru/articles/1010204/

    #rpc #cybersecurity #network #безопасность #сетевая_безопасность #network_security #ipc #межпроцессное_взаимодействие

  22. От нуля к единице: MCP и много другого на пути к его пониманию

    Сегодня ядром данной статьи будет MCP — как мост между бекендом‑оберткой с LLM и внешними источниками , но при этом я также затрону смежные темы , чтобы картина была полной и не требовалось дополнительно гуглить. Я постараюсь не давать устоявшиеся термины в контексте MCP, а также в процессе буду пояснять некоторые «базовые» термины, которые все как бы понимают — но нередко нет, чтобы мы все улавливали один и тот же контекст статьи.

    habr.com/ru/articles/1005028/

    #mcp #mcpserver #ai #llm #agent #агенты #model_context_protocol #rpc #network

  23. Согласованность API по принципу единого источника истины

    Представим ситуацию: идет тяжёлый спринт, вы выполнили кучу задач, написали тонну нового функционала, готовитесь к релизу и вдруг обнаруживайте, что часть фич перестала работать! Идёте разбираться и обнаруживайте, что оказывается бэкендер Вася в последний момент решил переименовать поля в json-е, а вам об этом не сказал! Ситуация образная, но позволяет быстро обрисовать одну из болей во время разработки. В этой статье я бы хотел рассказать об одном из вариантов её решения в коде с помощью подхода Единого источника истины(Single source of truth).

    habr.com/ru/articles/1003398/

    #API #honojs #zod #RPC #SSOT #OpenAPI #typescript #monorepo #javascript