home.social

#spearphishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.

fetched live
  1. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  2. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  3. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  4. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  5. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  6. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  7. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  8. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  9. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  10. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  11. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  12. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  13. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  14. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  15. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  16. Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

    Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote…

    osintsights.com/iranian-hacker

    #IranianHackers #Noderabbit #CrossplatformMalware #Spearphishing #Linkedin

  17. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  18. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  19. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  20. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  21. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  22. 📢 Des hackers soutenus par des États ciblent des hauts fonctionnaires de l'UE via WhatsApp

    Le CERT-EU (EU Computer Emergency Response Team) a formellement identifié des campagnes de spearphishing étatique ciblant des hauts fonctionnaires de l'Union européenne via des applications de messagerie, notamment WhatsApp et Signal.

    📖 cyberveille : cyberveille.ch/posts/2026-08-2
    🌐 source : politico.eu/article/hackers-ta
    🟢 vérification factuelle haute
    #CERTEU #spearphishing #Cyberveille

  23. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  24. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  25. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  26. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  27. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  28. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  29. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  30. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  31. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  32. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  33. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  34. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  35. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  36. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  37. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  38. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  39. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  40. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  41. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  42. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  43. Meta Disrupts NSO Group's WhatsApp Phishing Campaign

    Meta detected and blocked a sneaky WhatsApp phishing campaign linked to NSO Group, where attackers tried to trick people into clicking malicious links that led to external websites. The company also filed a contempt order against NSO for allegedly violating a court injunction by targeting WhatsApp users.

    osintsights.com/meta-disrupts-

    #WhatsappPhishing #NsoGroup #SpearPhishing #Meta #1clickPhishing

  44. SideCopy Targets Afghan Finance Ministry with Xeno RAT Malware

    Seqrite Labs researchers uncovered a sneaky malware attack, dubbed Operation XENOFISCAL, where the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance and government officials with a cleverly crafted phishing lure written in Pashto. The attack used Xeno RAT Malware, delivered through a ZIP archive with a malicious…

    osintsights.com/sidecopy-targe

    #XenoRatMalware #Sidecopy #Afghanistan #FinanceSector #SpearPhishing