home.social

#sms — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sms, aggregated by home.social.

fetched live
  1. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  2. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  3. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  4. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  5. CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

    An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.

    Pulse ID: 6a7b4a5db787f887767b8a2a
    Pulse Link: otx.alienvault.com/pulse/6a7b4
    Pulse Author: AlienVault
    Created: 2026-08-11 16:14:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault

  6. CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

    An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.

    Pulse ID: 6a7b4a5db787f887767b8a2a
    Pulse Link: otx.alienvault.com/pulse/6a7b4
    Pulse Author: AlienVault
    Created: 2026-08-11 16:14:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #RAT #SMS #bot #AlienVault

  7. @defred @Armavica @louisderrac : En gros c'est du genre #SMS mais on devrait pouvoir mettre dedans une #gif89a de #chaton mignon.

  8. @defred @Armavica @louisderrac : En gros c'est du genre #SMS mais on devrait pouvoir mettre dedans une #gif89a de #chaton mignon.

  9. RE: mastodon.social/@aboutsignal/1

    Many of my kids want to securely text other kids who have laptops but not a phone plan or a debit card or spare money securely. This will stop that.

    This will also make new users think that signal is a greedy company doing pay for privacy.

    #signal #money #privacy #kids #security #text #android #sms #thetruth #badidea #budgeting #floss #debitcard #nophone #frugal

  10. RE: mastodon.social/@aboutsignal/1

    Many of my kids want to securely text other kids who have laptops but not a phone plan or a debit card or spare money securely. This will stop that.

    This will also make new users think that signal is a greedy company doing pay for privacy.

    #signal #money #privacy #kids #security #text #android #sms #thetruth #badidea #budgeting #floss #debitcard #nophone #frugal

  11. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  12. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  13. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  14. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  15. @WeirdWriter

    Exactly.

    We’ve somehow confused communication with the corporations that mediate it.

    Email still works.

    SMS still works.

    The open web still works.

    The Fediverse works.

    But people now ask, “How will I contact you?” when what they really mean is, “Which closed platform are you still trapped inside?”

    That dependency is the problem.

    #Facebook #Meta #SocialMedia #OpenWeb #Fediverse #Mastodon #SMS #Email #DigitalIndependence #BigTech

  16. @WeirdWriter

    Exactly.

    We’ve somehow confused communication with the corporations that mediate it.

    Email still works.

    SMS still works.

    The open web still works.

    The Fediverse works.

    But people now ask, “How will I contact you?” when what they really mean is, “Which closed platform are you still trapped inside?”

    That dependency is the problem.

    #Facebook #Meta #SocialMedia #OpenWeb #Fediverse #Mastodon #SMS #Email #DigitalIndependence #BigTech

  17. 💰 hisabi-app/hisabi

    🤑 Open-source personal finance tracking web application with SMS parser

    Auto-detects bank transactions from SMS messages, visualizes spending, and provides AI-powered finance assistance from a self-hosted web application.

    ⭐ Stars: 455
    📅 Last Update: Aug 02, 2026

    github.com/hisabi-app/hisabi

    #selfhosted #homelab #selfhost #selfhosting #opensource #finance #sms

  18. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  19. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  20. Authentication Bypass Vulnerability in N-central Exploited In-The-Wild

    An authentication bypass vulnerability, CVE-2026-18577, affecting N-able N-central Remote Monitoring and Management platform has been actively exploited since August 1, 2026. This vulnerability emerged after an incomplete fix for a previous authentication bypass issue CVE-2026-18556. The flaw allows remote unauthenticated attackers to bypass authentication mechanisms and gain administrative control over vulnerable N-central servers. Attackers have exploited this vulnerability to leverage the platform's Take Control functionality for remote access to managed endpoints and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. Given that N-central is widely used by managed service providers and enterprise IT teams with extensive administrative privileges, successful compromise provides attackers an efficient pathway to compromise downstream managed systems. CISA added this vulnerability to its Known Exploited Vulnerability catalog on August 3, 2026.

    Pulse ID: 6a74564f0edb6c8f24fda004
    Pulse Link: otx.alienvault.com/pulse/6a745
    Pulse Author: AlienVault
    Created: 2026-08-06 09:39:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CISA #Cloud #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #SMS #Vulnerability #bot #AlienVault

  21. Authentication Bypass Vulnerability in N-central Exploited In-The-Wild

    An authentication bypass vulnerability, CVE-2026-18577, affecting N-able N-central Remote Monitoring and Management platform has been actively exploited since August 1, 2026. This vulnerability emerged after an incomplete fix for a previous authentication bypass issue CVE-2026-18556. The flaw allows remote unauthenticated attackers to bypass authentication mechanisms and gain administrative control over vulnerable N-central servers. Attackers have exploited this vulnerability to leverage the platform's Take Control functionality for remote access to managed endpoints and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. Given that N-central is widely used by managed service providers and enterprise IT teams with extensive administrative privileges, successful compromise provides attackers an efficient pathway to compromise downstream managed systems. CISA added this vulnerability to its Known Exploited Vulnerability catalog on August 3, 2026.

    Pulse ID: 6a74564f0edb6c8f24fda004
    Pulse Link: otx.alienvault.com/pulse/6a745
    Pulse Author: AlienVault
    Created: 2026-08-06 09:39:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CISA #Cloud #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #SMS #Vulnerability #bot #AlienVault

  22. Supply Chain Compromise Affecting keyv and cacheable npm Packages

    An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.

    Pulse ID: 6a744e3869101e8bea80db85
    Pulse Link: otx.alienvault.com/pulse/6a744
    Pulse Author: AlienVault
    Created: 2026-08-06 09:04:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Cloud #CyberSecurity #DNS #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Trojan #Troll #Worm #bot #AlienVault

  23. Supply Chain Compromise Affecting keyv and cacheable npm Packages

    An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.

    Pulse ID: 6a744e3869101e8bea80db85
    Pulse Link: otx.alienvault.com/pulse/6a744
    Pulse Author: AlienVault
    Created: 2026-08-06 09:04:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Cloud #CyberSecurity #DNS #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Trojan #Troll #Worm #bot #AlienVault

  24. Fake CAPTCHA, Real Business: Traffic Distribution for Hire

    A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

    Pulse ID: 6a734a570822e0edf4d1fdb5
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault

  25. Fake CAPTCHA, Real Business: Traffic Distribution for Hire

    A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

    Pulse ID: 6a734a570822e0edf4d1fdb5
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault

  26. npm Packages Hijacked in Supply Chain Attack

    Multiple npm packages in the keyv/cacheable ecosystem were compromised after attackers gained control of a GitHub maintainer account. Beginning at 9:00 UTC on August 4, 2026, the attacker introduced IDE persistence mechanisms and published malicious versions that propagated to over 400 distinct packages. The payload is a descendant of the 'Mini' Shai-Hulud malware family, sharing similarities with TeamPCP and antv campaigns. It targets sensitive data including cloud credentials, infrastructure secrets, developer credentials, AI configuration files, and cryptocurrency wallets. The malware uniquely retrieves command-and-control domains from an Ethereum smart contract rather than embedding them, allowing infrastructure updates without modifying the payload. Data is exfiltrated through GitHub repositories created under compromised identities. The campaign demonstrates sophisticated supply chain attack techniques targeting developer environments and CI/CD pipelines.

    Pulse ID: 6a722c48758de52f5ea94f17
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #bot #cryptocurrency #AlienVault

  27. npm Packages Hijacked in Supply Chain Attack

    Multiple npm packages in the keyv/cacheable ecosystem were compromised after attackers gained control of a GitHub maintainer account. Beginning at 9:00 UTC on August 4, 2026, the attacker introduced IDE persistence mechanisms and published malicious versions that propagated to over 400 distinct packages. The payload is a descendant of the 'Mini' Shai-Hulud malware family, sharing similarities with TeamPCP and antv campaigns. It targets sensitive data including cloud credentials, infrastructure secrets, developer credentials, AI configuration files, and cryptocurrency wallets. The malware uniquely retrieves command-and-control domains from an Ethereum smart contract rather than embedding them, allowing infrastructure updates without modifying the payload. Data is exfiltrated through GitHub repositories created under compromised identities. The campaign demonstrates sophisticated supply chain attack techniques targeting developer environments and CI/CD pipelines.

    Pulse ID: 6a722c48758de52f5ea94f17
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #bot #cryptocurrency #AlienVault

  28. Supply Chain Compromise Affecting keyv and cacheable npm Packages

    An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads. The attack began with the compromise of maintainer account Jaredwray, enabling the threat actor to inject malicious code across multiple package families. The malware harvests cloud and CI credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. It self-propagates by repackaging other npm packages with the same malicious hook and republishing them using stolen npm tokens. Stolen credentials are exfiltrated to threat actor-controlled GitHub repositories, with persistence mechanisms planted in developer directories.

    Pulse ID: 6a72f10a39d4c128ee7e2fa8
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:15:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Troll #bot #AlienVault

  29. Supply Chain Compromise Affecting keyv and cacheable npm Packages

    An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads. The attack began with the compromise of maintainer account Jaredwray, enabling the threat actor to inject malicious code across multiple package families. The malware harvests cloud and CI credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. It self-propagates by repackaging other npm packages with the same malicious hook and republishing them using stolen npm tokens. Stolen credentials are exfiltrated to threat actor-controlled GitHub repositories, with persistence mechanisms planted in developer directories.

    Pulse ID: 6a72f10a39d4c128ee7e2fa8
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:15:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Troll #bot #AlienVault

  30. Goomba Invaders (2026) by BriG78cx for Sega Master System. The mushrooms are done being stomped, so they're turning the tables. You blast endless ammo at 8 levels of invaders, with a bonus Koopa mother ship worth extra points.

    🎁 brig78cx.itch.io/goomba-invade

    #homebrew #sms #retro #game #goombainvaders

  31. Goomba Invaders (2026) by BriG78cx for Sega Master System. The mushrooms are done being stomped, so they're turning the tables. You blast endless ammo at 8 levels of invaders, with a bonus Koopa mother ship worth extra points.

    🎁 brig78cx.itch.io/goomba-invade

    #homebrew #sms #retro #game #goombainvaders

  32. ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework

    A Russian-speaking, financially motivated threat actor designated UAT-11795 has been conducting a sophisticated malware campaign since June 2025, primarily targeting users in the United States. The operation utilizes ClickFix-style social engineering techniques with trojanized software installers for applications like MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT. The campaign deploys Starland RAT, a custom Python-based remote access tool that establishes persistence, performs reconnaissance, and collects cryptocurrency wallet information. The malware employs blockchain-based fallback C2 mechanisms via Polygon smart contracts. Additionally, the operation deploys the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT, demonstrating a modular architecture focused on credential theft, cryptocurrency harvesting, and long-term post-compromise access.

    Pulse ID: 6a71a6ac7bd8297ea6d2093f
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 08:45:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cisco #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #Remcos #RemcosRAT #Russia #SMS #SocialEngineering #Trojan #UnitedStates #Zoom #bot #cryptocurrency #AlienVault

  33. ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework

    A Russian-speaking, financially motivated threat actor designated UAT-11795 has been conducting a sophisticated malware campaign since June 2025, primarily targeting users in the United States. The operation utilizes ClickFix-style social engineering techniques with trojanized software installers for applications like MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT. The campaign deploys Starland RAT, a custom Python-based remote access tool that establishes persistence, performs reconnaissance, and collects cryptocurrency wallet information. The malware employs blockchain-based fallback C2 mechanisms via Polygon smart contracts. Additionally, the operation deploys the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT, demonstrating a modular architecture focused on credential theft, cryptocurrency harvesting, and long-term post-compromise access.

    Pulse ID: 6a71a6ac7bd8297ea6d2093f
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 08:45:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cisco #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #Remcos #RemcosRAT #Russia #SMS #SocialEngineering #Trojan #UnitedStates #Zoom #bot #cryptocurrency #AlienVault

  34. Today I remembered that #SMS and #MMS still exist. If it weren't for a push notification, I would've never noticed that two of my clients are trying to reach me via text. Since #Telegram and #WhatsApp got blocked in our country, many people fled to other platforms — sometimes extremely weird ones.

    If before I only had to check two apps, now... **brace yourselves**:
    • VK

    • Telegram

    • WhatsApp

    • Max

    • Email

    • #Matrix

    • #Fediverse

    • SMS

    • #WeChat (yes, I actually have it!)

      Multiply all of this by the fact that besides my work accounts I also have personal ones. Everyone is scattered everywhere and it is extremely inconvenient. I'm trying to get all my friends and family onto the #ActivityPub + Matrix combo, but let's be honest, nobody outside our little bubble needs this Fediverse.

    #Decentralization #OpenSource #DigitalLife #Communication #Privacy #Messengers #PushNotification

  35. Analysis of a Phishing Email Attack Case

    The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

    Pulse ID: 6a70c6f0d15cdde2874f628e
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: AlienVault
    Created: 2026-08-03 16:50:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault

  36. Analysis of a Phishing Email Attack Case

    The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

    Pulse ID: 6a70c6f0d15cdde2874f628e
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: AlienVault
    Created: 2026-08-03 16:50:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault

  37. A Deep Dive Into the Latest XCSSET Version

    After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.

    Pulse ID: 6a7059ccae49a160e5763d1d
    Pulse Link: otx.alienvault.com/pulse/6a705
    Pulse Author: AlienVault
    Created: 2026-08-03 09:05:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Chrome #Cloud #CyberSecurity #Encryption #GitHub #India #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Russia #SMS #SouthAsia #SupplyChain #Telegram #Trojan #bot #developers #AlienVault

  38. A Deep Dive Into the Latest XCSSET Version

    After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.

    Pulse ID: 6a7059ccae49a160e5763d1d
    Pulse Link: otx.alienvault.com/pulse/6a705
    Pulse Author: AlienVault
    Created: 2026-08-03 09:05:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Chrome #Cloud #CyberSecurity #Encryption #GitHub #India #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Russia #SMS #SouthAsia #SupplyChain #Telegram #Trojan #bot #developers #AlienVault

  39. Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers

    A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.

    Pulse ID: 6a6b24fd9aca51b0320e47a6
    Pulse Link: otx.alienvault.com/pulse/6a6b2
    Pulse Author: AlienVault
    Created: 2026-07-30 10:18:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Cloud #CyberSecurity #Email #India #InfoSec #Malware #OTX #Office #OpenThreatExchange #Phishing #RAT #RCE #SMS #WhatsApp #Windows #ZIP #bot #AlienVault

  40. Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers

    A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.

    Pulse ID: 6a6b24fd9aca51b0320e47a6
    Pulse Link: otx.alienvault.com/pulse/6a6b2
    Pulse Author: AlienVault
    Created: 2026-07-30 10:18:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Cloud #CyberSecurity #Email #India #InfoSec #Malware #OTX #Office #OpenThreatExchange #Phishing #RAT #RCE #SMS #WhatsApp #Windows #ZIP #bot #AlienVault

  41. OctLurk and SilkLurk: new Backdoors in Central Asia

    Two newly identified backdoors, OctLurk and SilkLurk, have been targeting government organizations across Central Asia since January 2025. Victims span Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, affecting healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and educational institutions. Both backdoors employ heavily obfuscated loaders customized per victim, using machine-specific data for decryption. They deploy multiple plugins for command execution, file manipulation, credential harvesting, keylogging, network scanning, and remote access. The attackers also utilized LurkProxy for network traffic proxying and deployed additional tools including PlugX, Impacket, FSCAN, and Pandora FMS agents. Analysis indicates both backdoors are operated by the same Chinese-speaking threat actor, though attribution to a specific known group remains unconfirmed. The campaigns demonstrate sophisticated persistence mechanisms and ext...

    Pulse ID: 6a6b4b97df5f9df74333adfa
    Pulse Link: otx.alienvault.com/pulse/6a6b4
    Pulse Author: AlienVault
    Created: 2026-07-30 13:03:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #CentralAsia #Chinese #CredentialHarvesting #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Mac #OTX #Office #OpenThreatExchange #PlugX #Proxy #RAT #RCE #SMS #Syria #bot #AlienVault

  42. OctLurk and SilkLurk: new Backdoors in Central Asia

    Two newly identified backdoors, OctLurk and SilkLurk, have been targeting government organizations across Central Asia since January 2025. Victims span Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, affecting healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and educational institutions. Both backdoors employ heavily obfuscated loaders customized per victim, using machine-specific data for decryption. They deploy multiple plugins for command execution, file manipulation, credential harvesting, keylogging, network scanning, and remote access. The attackers also utilized LurkProxy for network traffic proxying and deployed additional tools including PlugX, Impacket, FSCAN, and Pandora FMS agents. Analysis indicates both backdoors are operated by the same Chinese-speaking threat actor, though attribution to a specific known group remains unconfirmed. The campaigns demonstrate sophisticated persistence mechanisms and ext...

    Pulse ID: 6a6b4b97df5f9df74333adfa
    Pulse Link: otx.alienvault.com/pulse/6a6b4
    Pulse Author: AlienVault
    Created: 2026-07-30 13:03:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #CentralAsia #Chinese #CredentialHarvesting #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Mac #OTX #Office #OpenThreatExchange #PlugX #Proxy #RAT #RCE #SMS #Syria #bot #AlienVault

  43. Stalactites (2026) by haroldo-ok for Sega Master System. Dodge falling drips and blast your way through 60-second waves in this SMS Power! competition entry. Freeze power-ups, mega bombs, and a rapid-fire twist keep the pressure on. How long can you last?

    🎁 haroldo-ok.itch.io/stalactites

    #homebrew #sms #retro #game #stalactites

  44. Stalactites (2026) by haroldo-ok for Sega Master System. Dodge falling drips and blast your way through 60-second waves in this SMS Power! competition entry. Freeze power-ups, mega bombs, and a rapid-fire twist keep the pressure on. How long can you last?

    🎁 haroldo-ok.itch.io/stalactites

    #homebrew #sms #retro #game #stalactites

  45. @ngorongoro

    @katzenmoshpit

    Ach Mist, das hab ich nicht so richtig mitbekommen.

    RCS habe ich auf meinem 6 Jahre alten Samsung mir Android 12 nicht gefunden...

    Ist es zu alt dafür?

    #Fedihelp #Fedihilfe #Fediwissen #MMS #SMS #android #Samsung

  46. Ach Mist, das hab ich nicht so richtig mitbekommen.

    RCS habe ich auf meinem 6 Jahre alten Samsung mir Android 12 nicht gefunden...

    Ist es zu alt dafür?

    #Fedihelp #Fedihilfe #Fediwissen #MMS #SMS #android #Samsung