home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. New.

    "The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."

    Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors rapid7.com/blog/post/tr-dprk-a @Rapid7Official #infosec #cybercrime #threatresearch #Linux

  2. New.

    "Huntress is observing the same anomalous pattern across unrelated endpoints in various organizations: rogue ScreenConnect clients repeatedly spawning wscript.exe to execute 1.vbs, 2.vbs, 3.vbs, and 4.vbs."

    Huntress: Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity huntress.com/blog/rogue-screen @huntress #infosec #threatresearch