home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

fetched live
  1. New.

    "Huntress recently observed a threat actor doing something unique post-compromise: instead of simply dropping a miner, they compiled one directly on the victim endpoint, tailoring the payload while generating unusually conspicuous EDR telemetry."

    "Compiling a cryptominer in this way on a victim's endpoint could have various advantages for a threat actor, including allowing them to customize based on the target environment (such as optimizing for the endpoint's CPU architecture). However, these processes also resulted in a significant spike in activity and was – ironically – quite noisy from an EDR telemetry perspective."

    Huntress: The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint huntress.com/blog/threat-actor @huntress #infosec #threatresearch

  2. The recent MikroTik RouterOS vulnerabilities have several conditions for exploitation.

    That may make mass exploitation more difficult, but targeted attacks are another story.

    @martijn_grooten and @silas break down what an attacker needs. censys.com/podcasts-videos/cen

    #CensysARC #MikroTik #ThreatIntelligence #ThreatResearch #InfoSec #Cybersecurity

  3. Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.

    Listen/Read: hackread.com/trellix-darksword

  4. The next Censys ARC Flash is September 9 at 11 AM ET.

    Join the Censys ARC team for a timely briefing on the research, threats, and Internet activity they're tracking, followed by a live Q&A where you can ask the researchers your questions directly.

    Register to attend live:
    info.censys.com/arc-webcast

    #CensysARC #ThreatResearch #ThreatIntelligence #InfoSec #CyberSecurity

  5. Wordfence Argus: Moving Beyond Human Research Capability

    When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something...

    wordfence.com/blog/2026/08/wor

    #wordpress #cybersecurity #ai #threatresearch

  6. All of this was measured using Censys Internet intelligence to help defenders better understand an ecosystem that isn't well covered by traditional threat intelligence.

    Read Alex Gartner's full research: censys.com/blog/roblox-minecra

    #InternetIntelligence #ThreatResearch #InfoSec #OSINT

  7. Mobile malware is becoming a billing engine.
    Kern Smith of Zimperium explains how Android fraud campaigns silently subscribe victims to premium SMS services, intercept OTPs, and monetize users through carrier billing systems.
    🔶 Carrier-specific targeting
    🔶 OTP interception
    🔶 Silent subscriptions
    🔶 Automated monetization

    Read the full discussion:
    technadu.com/when-your-phone-i

    #MobileSecurity #Android #SMSFraud #CyberSecurity #ThreatResearch #Malware

  8. Fake Claude Code installer campaigns are abusing trusted developer workflows instead of exploiting software vulnerabilities.
    Rhys Downing of Ontinue explains how attackers used fake documentation pages, modified install commands, PowerShell loaders, and browser compromise techniques to steal credentials and establish persistence.

    “Developers are becoming a preferred target because they sit at the intersection of trust and access.”

    Read more:
    technadu.com/copy-paste-compro

    #Cybersecurity #ThreatResearch #Developers #ApplicationSecurity #Ontinue #SecureCoding

  9. New research shows 3 flaws dubbed in Claude AI could be chained to steal user data using fake Google Ads, hidden prompts, and built-in features.

    Read: hackread.com/claudy-day-flaws-

  10. Citizen Lab identified indicators that Cellebrite forensic extraction tools were used on a Samsung device belonging to Kenyan activist Boniface Mwangi during police custody (July 2025).

    Amnesty International separately confirmed a successful Predator spyware infection on an Angolan journalist’s iPhone running iOS 16.2.

    Technical implications:
    • Commercial forensic tools can enable full device extraction
    • Predator supports modular deployment and anti-analysis techniques
    • Infection attempts leveraged WhatsApp delivery vectors
    • Restart disrupted active spyware persistence in one case
    Operational questions:
    – How should vendors enforce client compliance?
    – What detection artifacts can defenders monitor?
    – Are mobile EDR solutions sufficient against mercenary spyware?
    – What governance frameworks are realistically enforceable?

    Share your technical assessment below.

    Source: citizenlab.ca/research/cellebr

    Follow TechNadu for continued surveillance-tech and threat intelligence coverage.

    #IncidentResponse #MobileSecurity #ThreatResearch #SpywareAnalysis #Forensics #EDR #CyberGovernance #InfosecCommunity #ThreatIntel #DigitalRights

  11. REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.

    Technical highlights:
    • Migration to Ubuntu 24.04 (modern kernel + LTS support)
    • Cast-based installer replacing legacy CLI deployment
    • AI-assisted workflows via MCP server
    • Integration support for Ghidra with AI plugins

    Tooling refresh includes:
    YARA-X (Rust rewrite for performance improvements)
    GoReSym (symbol recovery for Go binaries)
    APKiD (Android packer detection)
    Manalyze (PE/ELF/MachO static parsing)
    This release signals an industry shift toward AI-augmented reverse engineering pipelines.
    Is AI-assisted RE the new baseline for threat labs?

    Source: cyberpress.org/remnux-v8-relea

    Engage below.
    Follow @technadu for deep technical cybersecurity updates.

    #ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting

  12. The TeamPCP campaign highlights how cloud-native misconfigurations can be industrialized into a full cybercrime platform.

    By abusing exposed Docker APIs, Kubernetes clusters, Redis, and vulnerable web apps, the group automates scanning, persistence, proxying, data theft, and monetization - often without novel exploits. This reinforces that operational scale, not exploit sophistication, is now the primary threat driver in cloud environments.

    Source: thehackernews.com/2026/02/team

    💬 Are cloud control planes receiving enough defensive visibility?

    🔔 Follow @technadu for ongoing cloud threat analysis

    #InfoSec #CloudSecurity #KubernetesSecurity #ThreatResearch #MalwareOps #CyberCrime #TechNadu

  13. We’ve been tracking a cluster of RDGA‑generated domains involved in distributing fake app‑store landing pages. These domains are consistently registered through Namecheap and protected by Cloudflare, which the operators use to obscure origin infrastructure and rapidly cycle through fresh front‑end domains.

    The sites impersonate Google Play or iTunes, based on their device’s user‑agent, presenting users with pages that look and feel legitimate. Instead of real apps, the pages deliver Progressive Web Applications (PWAs) that persist on the device and enable ongoing notification abuse.

    PWAs are a chrome application which plays cross platform, windows, linux, android, iOS and gets added as an icon on the desktop ofevery device.

    Once installed, the PWA triggers a redirection chain through one or more intermediary domains before sending users to online casinos, adult content, or other low‑quality destinations. Because many of these casinos operate from regions where online gambling is restricted or illegal, the operators continually replace the final‑stage domains. This use of RDGA and PWAs allows them to evade regional blocking, reputation systems, and automated detection controls by rotating infrastructure at scale and keeping their persistence to the user devices.

    fwiw, most large scale gambling operations like these are not simply illegal in the regions they target... they are scams and often connected to other major crimes, including human trafficking.

    play-megawin[.]site
    play-icefish[.]website
    play-richcasino[.]site
    play-casinostaat[.]site
    mountainvertex[.]shop
    play-fdjfrance[.]site
    play-lucky7[.]site
    funterra[.]shop
    hotcoins[.]site
    stonefestal[.]shop
    spirevanguard[.]shop
    play-crowngreen[.]website
    forestoutpost[.]shop

    #threatintel #gambling #pwa #dns #fake #infoblox #threatresearch #malware #scam #fakeApp #googleplay #infobloxthreatintel #itunes

  14. Operation Bizarre Bazaar documents systematic abuse of exposed LLM and MCP infrastructure with commercial monetization.

    The campaign demonstrates how AI endpoints without authentication, rate limits, or proper exposure controls can enable compute theft, data access, and potential lateral movement.

    AI infrastructure security is increasingly inseparable from traditional cloud and app security.

    What controls are most effective in your environment?

    Source: pillar.security/blog/operation

    Follow TechNadu for objective infosec research coverage.

    #AIsecurity #LLM #MCP #CloudDefense #ThreatResearch #InfosecCommunity

  15. ⚠️ Smishing alert for Greek citizens. 💳 🚨

    Scammers are pushing fake AADE (Independent Authority for Public Revenue) “unpaid taxes” SMS that lead to cloned payment pages designed to steal credit‑card info. If a text suddenly demands urgent payment, treat it like a pop‑up from nowhere—don’t click, don’t trust, don’t pay. Share to protect others.

    mycargr[.]com
    aadcar[.]com
    aadgee[.]com
    aadgre[.]com

    #CyberThreatIntel #Infoblox #DNS #ThreatResearch #phishing #smishing #Cybercrime #AADE #Greece

  16. New, from me: Who Operates the Badbox 2.0 Botnet?

    The cybercriminals in control of Kimwolf -- a disruptive botnet that has infected more than 2 million devices -- recently shared a screenshot indicating they'd compromised the control panel for Badbox 2.0, a vast China-based botnet powered by malicious software that comes pre-installed on many Android TV streaming boxes. Both the FBI and Google say they are hunting for the people behind Badbox 2.0, and thanks to bragging by the Kimwolf botmasters we may now have a much clearer idea about that.

    krebsonsecurity.com/2026/01/wh

    #infosec #botnet #IoT #Android #Google #threatresearch

  17. A large infostealer-linked credential dataset was found publicly exposed, containing millions of unique login records across consumer, financial, and government-associated services.

    The case reinforces ongoing challenges around endpoint compromise, credential reuse, and post-infection response - especially where malware persists silently.

    From an InfoSec standpoint, which control most often fails first in these scenarios?

    Source: expressvpn.com/blog/149m-infos

    Share insights and follow @technadu for objective security reporting.

    #InfoSec #CredentialTheft #ThreatResearch #EndpointSecurity #CyberRisk #TechNadu