#spearphishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
🚨 The OpenAI/Mixpanel breach is not just a "vendor issue"—it's a systemic failure. We analyzed 3 years of security incidents at OpenAI and compared them to the fortified architectures of Google Gemini and Anthropic Claude.
#SecurityLand #ExpertDecode #AI #SecurityBreach #Cyberattack #OpenAI #ChatGPT #Claude #Gemini #SpearPhishing #Business #Enterprise #Mixpanel
Read More: https://www.security.land/openai-mixpanel-breach-security-analysis-2025/
-
Industrial companies in Europe targeted with GuLoader https://www.helpnetsecurity.com/2024/11/07/industrial-europe-spear-phishing-guloader/ #spearphishing #CadoSecurity #Don'tmiss #Hotstuff #malware #Europe #News
-
Spear-phishing is a more targeted form of #phishing, where attackers focus on specific individuals and craft personalised emails, based on gathered information.
For #CyberSecMonth, we hear from João Machado (#Cybersecurity Analyst at FCT -FCCN) how #SpearPhishing works, how widespread and damaging these attacks have become, how to prevent and counter them, and some real world examples: https://connect.geant.org/2024/10/15/spear-phishing-hack-the-mind-and-access-the-network
#CSM24 #CyberSecurityAwareness #SocialEngineering #ECSM #Security #cyberattacks
-
Trust, but always verify. And if something feels off, report it🛡️
By trusting his instincts and deciding to dig deeper, Dr. John Smart averted an attempt to infiltrate Guilder University’s #research, stopping a potential #security disaster in its tracks.
How would you have responded to an unsolicited offer for collaboration from someone you've never met? Would you have investigated further?
#CSM24 #CyberSecurity #Phishing #Spearphishing #pretexting #CyberSecurityAwareness #ECSM
-
Google’s threat team confirms Iran targeting Trump, Biden, and Harris campaigns - Enlarge / Roger Stone, former adviser to Donald Trump's presidential ca... - https://arstechnica.com/?p=2043545 #threatanalysisgroup #presidentbiden #spearphishing #kamalaharris #donaldtrump #rogerstone #googletag #security #phishing #biz #google #apt42 #gmail #iran