home.social

#sideloading — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sideloading, aggregated by home.social.

fetched live
  1. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  2. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  3. Android Advanced Side loading is already available on my phone. It's not being enforced yet, but I'm already enrolling to just get rid of it while I don't need to install any app.
    At least it's simple, for now, and it's account bound from what I've read. Anyway, we'll see.

    #Android #Google #SideLoading #AndroidApps #Apps

  4. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846abfbc588c465571b8cb
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  5. DCRat Campaign Targeting Users via SVG-Based HTML Smuggling

    Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.

    Pulse ID: 6a846ac500763a217460eb4b
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: cryptocti
    Created: 2026-08-18 14:23:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti

  6. C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection

    Indicators extracted from public reporting. Source: zscaler.com/blogs/security-res

    Pulse ID: 6a8456747396ae3b2a46eb51
    Pulse Link: otx.alienvault.com/pulse/6a845
    Pulse Author: CyberHunter_NL
    Created: 2026-08-18 12:56:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ELF #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #SideLoading #Zscaler #bot #CyberHunter_NL

  7. It's ABSURD that installing software on the YOU OWN is considered akin to sneaking something in! is a grotesque weasel word coined by and in an attempt to gaslight you into believing that only they're legally allowed to access the phones that you paid for.

    The software we into our phones should be considered the only legitimate ones, not the trashware by these greedy AFTER they sold them to us!

  8. CoolClient backdoor goes deeper: Windows kernel rootkit added

    HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.

    Pulse ID: 6a7ef2da146fb06724520eb4
    Pulse Link: otx.alienvault.com/pulse/6a7ef
    Pulse Author: AlienVault
    Created: 2026-08-14 10:50:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault

  9. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  10. Agora que estamos a caminho do fim do #sideloading no #Android meu interesse por smartphones caiu vertiginosamente.

    A ideia de só usar apps que o Google permitir, sem falar nos ataques constantes à nossa privacidade, me intriga: pq vou me preocupar em investir num troço que tecnicamente não vou usar como eu quiser (não será meu de fato) e vai me vigiar o tempo inteiro?

    Meu próximo será um basicão e vou fazer o mínimo com ele, tipo ligar e atender e só.

    Como vocês se sentem?
    #enshitification

  11. QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

    A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain

    Pulse ID: 6a72f492ee9dc3fc24d86c17
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:30:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #Chinese #CyberSecurity #Endpoint #HTML #InfoSec #Java #JavaScript #Microsoft #OTX #OpenThreatExchange #RAT #RCE #SideLoading #Steam #SupplyChain #Trojan #VPN #Windows #bot #cryptocurrency #AlienVault

  12. Верификация Android разработчиков: что будет с устройствами в России

    Привет, Хабр! Это SafeMobile. Прошлым летом Google объявил, что на Android телефоны можно будет устанавливать приложения только от проверенных разработчиков. С тех пор нас регулярно спрашивают, что будет с устройствами, которыми управляет MDM – могут ли они остаться без управления, будут ли проблемы с распространением инхаусного софта и т.д. В этой статье мы расскажем, что узнали – если на устройствах нет сервисов Google, можно не беспокоиться, но и на сертифицированных Google устройствах в РФ, похоже, всё хорошо. Детали под катом. Верифицироваться

    habr.com/ru/companies/safemobi

    #android_developer_verification #верификация_разработчиков #android #google_play #mdm #emm #play_protect #sideloading #корпоративная_мобильность #установка_приложений

  13. JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake

    In mid-April 2026, an exposed directory on an Alibaba Cloud server revealed a comprehensive China-nexus operation targeting government, healthcare, and education sectors across Southeast Asia and Latin America. The investigation uncovered simultaneous intrusions against Vietnamese hospitals, the Malaysian Ministry of Foreign Affairs, Hong Kong educational institutions, and targets in Honduras and Venezuela. At the center is TriBack Loader, a custom malware family using DLL sideloading with signed binaries and Win32 callback APIs to deliver AdaptixC2 and Beagle backdoors. The exposed server contained post-exploitation toolkits, bash history, and victim paths, revealing ongoing operations. Infrastructure analysis showed consistent use of NameSilo registrations, Alibaba hosting, and Cloudflare fronting. Phishing campaigns included fake portals impersonating Venezuelan tax systems and Claude-Pro software. The operation demonstrates shared tooling common across Chinese APT groups, with TTPs overlapping multiple...

    Pulse ID: 6a620199948bf751adbd698b
    Pulse Link: otx.alienvault.com/pulse/6a620
    Pulse Author: AlienVault
    Created: 2026-07-23 11:57:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #China #Chinese #Cloud #CyberSecurity #Education #Government #Healthcare #HongKong #Hospital #Hospitals #InfoSec #LatinAmerica #Malware #OTX #OpenThreatExchange #Phishing #RAT #SideLoading #Vietnam #bot #AlienVault

  14. DarkGram: как мы делаем power‑user Telegram‑клиент для iOS — и почему его нет в App Store

    Мы сделали клиент Telegram для iOS, у которого не будет ни страницы в App Store, ни кнопки Get. И дело не в деньгах. Рассказываем, что мы построили и почему пошли своим путём.

    habr.com/ru/articles/1060956/

    #sideloading #telegram #форк #Форк_telegram

  15. Поставил свою Flutter-игру на iPhone друга без Mac и подписки Apple Developer

    Занимаюсь разработкой своей игры на Flutter. Дошёл до этапа, когда её пора было показать другу-тестировщику, а у него iPhone. Первая мысль — покупать Mac Mini или подписку Apple Developer за $99 в год. Обе цены платить не хотелось, пока проект не подтвердил, что вообще будет. На Samsung всё это делается за 15 минут: dev mode, USB, установка. На iPhone пришлось искать схему, которую нигде не находил собранной в одном месте — четыре инструмента, час на реализацию и заметно дольше на то, чтобы вообще понять, что она существует. Внутри: рабочий пайплайн Tenorshare iCareFone → GitHub Actions → Sideloadly → доверие на устройстве. Полный yml для сборки unsigned .ipa на хостовом macOS-раннере (со всеми нюансами Flutter-версии, precache, packaging и --dart-define для API). Разбор тонких моментов, которые не вылезают в туториалах: bundle ID под бесплатным Apple ID, Firebase-конфиги, миграция macos-latest на macOS 26 в июне 2026. Отдельно — честная экономика iOS-релиза из России в июле 2026: как теперь оплачивать Apple Developer, когда с 1 апреля отключили мобильную оплату; во сколько по факту обходится 99 долларов через Gift Card, посредников и иностранные карты; и сравнение с Google Play ($25 единоразово), RuStore и AppGallery.

    habr.com/ru/articles/1058788/

    #Flutter #iOS #iPhone #GitHub_Actions #Sideloadly #unsigned_ipa #Apple_Developer #sideloading #индиразработка #cicd

  16. 2/2/ ✋ Our member @fsfe successfully intervened in the case to hold #Apple accountable, where they argued that people must have access and be able to distribute and run their software in environments controlled by Apple.

    This includes unfettered software installation (sometimes called #sideloading and effective and free-of-charge interoperability.

    🎉 This Court decision is a big win for software freedom in Europe. More about EDRi's assessment of the DMA ⤵️ edri.org/our-work/the-dma-is-a

  17. Building a new #android app for the first time in a long time.

    I'm trying out the unifiedpush.org stuff. It seems like it shouldn't work as well as it does.

    I'm basically targeting self-hosting an apk, or putting it on f-droid. But sadly it feels like #fdroid is doomed due to Google putting up hurdles to prevent smooth use of alternative stores. (e.g. trying to break #sideloading, requiring a dance to allow installing, scare screens, etc.)

    I'd target #linux, but no phones?!?

    #buildinpublic

  18. duh.

    “Meta and Google get data from the app your boss uses to track you theverge.com/policy/935299/bos

    if the app is from the Google app store, Google uses it to track you.

    if the app has a Google or Facebook login, Meta & Google use it to track you.

    if the app is on an #android #TMobile phone purchased in USA or Canada, Meta, Google and Amazon use it to track you.

    that’s why Google wants to kill #sideloading. they want to monopolize #stalkerware