home.social

#sliver — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sliver, aggregated by home.social.

fetched live
  1. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  2. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  3. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  4. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  5. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  6. The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

    An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

    Pulse ID: 6a72f3bde4df792f5fa8956d
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:26:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault

  7. The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

    An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

    Pulse ID: 6a72f3bde4df792f5fa8956d
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:26:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault

  8. The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

    An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

    Pulse ID: 6a72f3bde4df792f5fa8956d
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:26:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault

  9. The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

    An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

    Pulse ID: 6a72f3bde4df792f5fa8956d
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:26:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault

  10. The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

    An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

    Pulse ID: 6a72f3bde4df792f5fa8956d
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:26:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault

  11. A Light in the Dark
    atlas.whatip.xyz/post.php?slug
    <p>A thin sliver of Earth&amp;#8217;s edge is brightly illuminated against the vast darkness of space in
    #artemis #sliver #space #light

  12. A Light in the Dark
    atlas.whatip.xyz/post.php?slug
    <p>A thin sliver of Earth&amp;#8217;s edge is brightly illuminated against the vast darkness of space in
    #artemis #sliver #space #light

  13. «Ждите гостей»: новые инструменты и тактики PhantomCore в атаках на российские компании

    На примере новой атаки PhantomCore - одной из главных киберугроз для российских и белорусских компаний - показываем, как группировка развивает свои инструменты и тактики, внедряет новое ВПО и расширяет спектр используемых технологий, включая AI-решения. Одна из главных особенностей PhantomCore – её постоянная изменчивость: эта АРТ-группа быстро приспосабливается к новым условиям, оперативно меняет инструменты и изобретает нестандартные способы доставки ВПО до атакуемых организаций.

    habr.com/ru/companies/F6/artic

    #phantomcore #apt #kermit_rat #фишинговые_письма #киберразведка #threat_intelligence #mattermost #cyberstrike_ai #mashagent #sliver

  14. «Ждите гостей»: новые инструменты и тактики PhantomCore в атаках на российские компании

    На примере новой атаки PhantomCore - одной из главных киберугроз для российских и белорусских компаний - показываем, как группировка развивает свои инструменты и тактики, внедряет новое ВПО и расширяет спектр используемых технологий, включая AI-решения. Одна из главных особенностей PhantomCore – её постоянная изменчивость: эта АРТ-группа быстро приспосабливается к новым условиям, оперативно меняет инструменты и изобретает нестандартные способы доставки ВПО до атакуемых организаций.

    habr.com/ru/companies/F6/artic

    #phantomcore #apt #kermit_rat #фишинговые_письма #киберразведка #threat_intelligence #mattermost #cyberstrike_ai #mashagent #sliver

  15. «Ждите гостей»: новые инструменты и тактики PhantomCore в атаках на российские компании

    На примере новой атаки PhantomCore - одной из главных киберугроз для российских и белорусских компаний - показываем, как группировка развивает свои инструменты и тактики, внедряет новое ВПО и расширяет спектр используемых технологий, включая AI-решения. Одна из главных особенностей PhantomCore – её постоянная изменчивость: эта АРТ-группа быстро приспосабливается к новым условиям, оперативно меняет инструменты и изобретает нестандартные способы доставки ВПО до атакуемых организаций.

    habr.com/ru/companies/F6/artic

    #phantomcore #apt #kermit_rat #фишинговые_письма #киберразведка #threat_intelligence #mattermost #cyberstrike_ai #mashagent #sliver

  16. Movie TV Tech Geeks #MovieNews #BasicInstinct #Sliver #TheHousemaid Sydney Sweeney’s New Erotic Thriller Just Beat Sharon Stone’s ‘Basic Instinct’ Follow-Up at the Box Office dlvr.it/TQ3k3X

  17. **‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**

    "_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"

    Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). doi.org/10.1007/s10963-025-091.

    #OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons

  18. **‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**

    "_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"

    Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). doi.org/10.1007/s10963-025-091.

    #OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons

  19. **‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**

    "_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"

    Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). doi.org/10.1007/s10963-025-091.

    #OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons

  20. **‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**

    "_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"

    Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). doi.org/10.1007/s10963-025-091.

    #OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons

  21. Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
    #Sliver #Nirvana #Rock #Song #Lyrics #Analysis
    songreading.wordpress.com/2025

  22. Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
    #Sliver #Nirvana #Rock #Song #Lyrics #Analysis
    songreading.wordpress.com/2025

  23. Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
    #Sliver #Nirvana #Rock #Song #Lyrics #Analysis
    songreading.wordpress.com/2025

  24. Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
    #Sliver #Nirvana #Rock #Song #Lyrics #Analysis
    songreading.wordpress.com/2025

  25. Инструменты атакующих в 2023–2024 годах

    На конференции OFFZONE 2024, которая прошла в Москве в культурном центре ЗИЛ 22–23 августа, выступил наш сотрудник Семён Рогачёв, руководитель отдела реагирования на инциденты. Он рассказал, какие инструменты сегодня чаще всего используются в кибератаках на российскую Linux- и Windows-инфраструктуру, и объяснил, как эффективно отлавливать и отражать подобные атаки. Мы написали текст по мотивам этого доклада, обогатив его данными за конец 2024 года. Статья будет полезна для тех, кто занимается пентестами и реагированием на инциденты.

    habr.com/ru/companies/bastion/

    #GSocket #инструменты_хакеров #инструменты_для_атак_на_Linux #инструменты_для_атак_на_Windows #реагирование_на_инциденты #soc #расследование_инцидентов #Sliver #разведка_угроз #кибератаки_в_2024

  26. Инструменты атакующих в 2023–2024 годах

    На конференции OFFZONE 2024, которая прошла в Москве в культурном центре ЗИЛ 22–23 августа, выступил наш сотрудник Семён Рогачёв, руководитель отдела реагирования на инциденты. Он рассказал, какие инструменты сегодня чаще всего используются в кибератаках на российскую Linux- и Windows-инфраструктуру, и объяснил, как эффективно отлавливать и отражать подобные атаки. Мы написали текст по мотивам этого доклада, обогатив его данными за конец 2024 года. Статья будет полезна для тех, кто занимается пентестами и реагированием на инциденты.

    habr.com/ru/companies/bastion/

    #GSocket #инструменты_хакеров #инструменты_для_атак_на_Linux #инструменты_для_атак_на_Windows #реагирование_на_инциденты #soc #расследование_инцидентов #Sliver #разведка_угроз #кибератаки_в_2024

  27. Инструменты атакующих в 2023–2024 годах

    На конференции OFFZONE 2024, которая прошла в Москве в культурном центре ЗИЛ 22–23 августа, выступил наш сотрудник Семён Рогачёв, руководитель отдела реагирования на инциденты. Он рассказал, какие инструменты сегодня чаще всего используются в кибератаках на российскую Linux- и Windows-инфраструктуру, и объяснил, как эффективно отлавливать и отражать подобные атаки. Мы написали текст по мотивам этого доклада, обогатив его данными за конец 2024 года. Статья будет полезна для тех, кто занимается пентестами и реагированием на инциденты.

    habr.com/ru/companies/bastion/

    #GSocket #инструменты_хакеров #инструменты_для_атак_на_Linux #инструменты_для_атак_на_Windows #реагирование_на_инциденты #soc #расследование_инцидентов #Sliver #разведка_угроз #кибератаки_в_2024

  28. Play Ransomware Engagement

    Unit 42 has identified Jumpy Pisces, a North Korean state-sponsored threat group, as a key player in a recent ransomware incident. The group appears to be collaborating with the Play ransomware group, marking a shift in their tactics. This is the first observed instance of Jumpy Pisces using existing ransomware infrastructure, potentially acting as an initial access broker or an affiliate. The attack timeline spans from May to September 2024, involving initial access through a compromised user account, lateral movement, and persistence using tools like Sliver and DTrack. The incident culminated in the deployment of Play ransomware in early September. This collaboration signals deeper involvement of North Korean threat actors in the broader ransomware landscape, potentially leading to more widespread and damaging attacks globally.

    Pulse ID: 67225f8455c324e956f9ebc1
    Pulse Link: otx.alienvault.com/pulse/67225
    Pulse Author: AlienVault
    Created: 2024-10-30 16:32:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ICS #InfoSec #Korea #NorthKorea #OTX #OpenThreatExchange #PlayRansomware #RAT #RansomWare #Sliver #Unit42 #bot #AlienVault

  29. MimiStick — imitators of Sticky Werewolf

    F.A.C.C.T. Threat Intelligence discovered a malicious file targeting Russian defense industry enterprises. Initially thought to be the work of Sticky Werewolf, further analysis revealed a new threat actor named MimiStick. The attack used a PDF lure mimicking a letter from the Russian Ministry of Labor. The malware employed a multi-stage infection chain, ultimately deploying a Sliver implant. Later findings confirmed the campaign was indeed Sticky Werewolf, who had expanded their toolkit to include Sliver implant alongside their existing Quasar RAT. The group registered multiple domains, including one impersonating the Ministry of Labor, likely for future phishing campaigns.

    Pulse ID: 66f6e5caacbbdd830c3f1c8c
    Pulse Link: otx.alienvault.com/pulse/66f6e
    Pulse Author: AlienVault
    Created: 2024-09-27 17:05:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Malware #Mimic #OTX #OpenThreatExchange #PDF #Phishing #RAT #Russia #Sliver #StickyWerewolf #bot #AlienVault

  30. Auch von uns noch ein #Kommentar zu Donald #Trump: … nein.

    Aber natürlich zu Joe #Biden:

    Noch am Tag vor dem "Vorfall" (#Medien …) hat der alte Mann vor seinen jubelnden Anhängern gegen "#Donald" gehetzt, aber nachdem letzterem dann fast "erfolgreich" nach dem #Leben getrachtet wurde, dauerte es nur Minuten bis sich #Grandpa #Joe plötzlich doch medienwirksam "Sorgen" um die #Gesundheit seines #Duzrivalen machte. 🤔

    realclearpolitics.com/video/20

    #DonaldTrump #JoeBiden #GrandpaJoe #Nirvana #Sliver

  31. Auch von uns noch ein #Kommentar zu Donald #Trump: … nein.

    Aber natürlich zu Joe #Biden:

    Noch am Tag vor dem "Vorfall" (#Medien …) hat der alte Mann vor seinen jubelnden Anhängern gegen "#Donald" gehetzt, aber nachdem letzterem dann fast "erfolgreich" nach dem #Leben getrachtet wurde, dauerte es nur Minuten bis sich #Grandpa #Joe plötzlich doch medienwirksam "Sorgen" um die #Gesundheit seines #Duzrivalen machte. 🤔

    realclearpolitics.com/video/20

    #DonaldTrump #JoeBiden #GrandpaJoe #Nirvana #Sliver

  32. Auch von uns noch ein zu Donald : … nein.

    Aber natürlich zu Joe :

    Noch am Tag vor dem "Vorfall" (#Medien …) hat der alte Mann vor seinen jubelnden Anhängern gegen "#Donald" gehetzt, aber nachdem letzterem dann fast "erfolgreich" nach dem getrachtet wurde, dauerte es nur Minuten bis sich plötzlich doch medienwirksam "Sorgen" um die seines machte. 🤔

    realclearpolitics.com/video/20

  33. Nirvana - Sliver (Official Music Video) - YouTube

    youtube.com/watch?v=QECJ9pCyhn#Nirvana #Remastered #Sliver” おれがはじめて買ったNirvanaのシングル。当時はレコードプレーヤーも持ってた。その頃サラレーベルとか大量のダンスミュージックとかレコードしかリリースが無いうえに買わないと聴けない時代だったのでレコードプレーヤーはけっこう必要だった。その後引っ越しとかレコードに対する物欲がなくなりディスク・ユニオンにレコードほとんど売った。プレーヤーもオーディオユニオンに売った #YouTube

  34. @jeromesegura Here's another #Sliver C2 server on 94.156.65.98:8443. It's also on @abuse_ch ThreatFox
    threatfox.abuse.ch/ioc/1252442

    This second Sliver C2 has the same JA3/JA3S as the previous one.

  35. @jeromesegura Here's another #Sliver C2 server on 94.156.65.98:8443. It's also on @abuse_ch ThreatFox
    threatfox.abuse.ch/ioc/1252442

    This second Sliver C2 has the same JA3/JA3S as the previous one.

  36. @jeromesegura Here's another #Sliver C2 server on 94.156.65.98:8443. It's also on @abuse_ch ThreatFox
    threatfox.abuse.ch/ioc/1252442

    This second Sliver C2 has the same JA3/JA3S as the previous one.