#spearphishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Beware of the LegionLoader malware being distributed via the ClickFix method
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.
Pulse ID: 6aa3fef84a7f54f4ae325151
Pulse Link: https://otx.alienvault.com/pulse/6aa3fef84a7f54f4ae325151
Pulse Author: AlienVault
Created: 2026-09-11 13:15:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault
-
Google’s threat team confirms Iran targeting Trump, Biden, and Harris campaigns - Enlarge / Roger Stone, former adviser to Donald Trump's presidential ca... - https://arstechnica.com/?p=2043545 #threatanalysisgroup #presidentbiden #spearphishing #kamalaharris #donaldtrump #rogerstone #googletag #security #phishing #biz #google #apt42 #gmail #iran