home.social

#spearphishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.

  1. Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

    Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote…

    osintsights.com/iranian-hacker

    #IranianHackers #Noderabbit #CrossplatformMalware #Spearphishing #Linkedin

  2. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  3. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  4. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  5. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  6. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault