#threatresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
New.
Microsoft: ASCII smuggling crosses over from AI prompt injection to phishing evasion https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/ #Microsoft #threatresearch #phishing
-
New.
"Huntress is observing the same anomalous pattern across unrelated endpoints in various organizations: rogue ScreenConnect clients repeatedly spawning wscript.exe to execute 1.vbs, 2.vbs, 3.vbs, and 4.vbs."
Huntress: Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity https://www.huntress.com/blog/rogue-screenconnect-installations @huntress #infosec #threatresearch
-
New.
Group-IB: The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/ #phishing #infosec #cybercrime #threatresearch
-
Microsoft posted this late yesterday.
Microsoft: Counterfeit installers to system compromise: Tracking a deceptive software download campaign https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/ #Microsoft #infosec #threatresearch #malware #cybercrime
-
New.
Threat Fabric: Uncovering StreamRat: From Meta Ads to Full Device Takeover https://www.threatfabric.com/blogs/from-meta-ads-to-full-device-takeover-uncovering-streamrat #infosec #threatresearch #Meta #Android #malware
-
The next Censys ARC Flash is September 9 at 11 AM ET.
Join the Censys ARC team for a timely briefing on the research, threats, and Internet activity they're tracking, followed by a live Q&A where you can ask the researchers your questions directly.
Register to attend live:
https://info.censys.com/arc-webcast#CensysARC #ThreatResearch #ThreatIntelligence #InfoSec #CyberSecurity
-
New.
Any.Run: Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/ @anyrun_app #infosec #threatresearch
-
From yesterday.
"Oracle EBS exploitation began in August 2025, extortion emails went out in late September, victims were still being named in November, and ransom demands from that campaign ran into January 2026. In a single 24-hour period that January, Clop posted 43 victims to its leak site. As of mid-August 2026 the group has claimed roughly 1,300 victims in total, 46 of them in the preceding month alone."
Securonix: Clop Never Left: Inside the PTC Windchill Data Theft Campaign https://www.securonix.com/blog/clop-ptc-windchill-data-theft-campaign/ #infosec Cybercrime #threatresearch #ransomware #threatintel #threatintelligence
-
New.
"The recent CyberLeek operation, backed by a message of ‘No Disc, No Peace’ puts on the appearance that the threat actor advocates for gamers everywhere, despite self-serving motives."
Bitdefender: CyberLeek: Extortion Built for an Audience, Not a Victim https://www.bitdefender.com/en-us/blog/businessinsights/cyberleek-extortion-gta-vi-leaked-gameplay #infosec #ransomware #cybercrime #threatresearch
-
New.
Picus: How KryBit Ransomware Works and How to Test Your Defenses https://www.picussecurity.com/resource/blog/how-krybit-ransomware-works-and-how-to-test-your-defenses #infosec #ransomware #threatresearch
-
New.
Group-IB: Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/ #infosec #threatresearch #malware #cybercrime
-
New.
Check Point: Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/ #infosec #threatresearch #JavaScript
-
Wordfence Argus: Moving Beyond Human Research Capability
When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something...
https://www.wordfence.com/blog/2026/08/wordfence-argus-moving-beyond-human-research-capability/
-
Threat Research Bolsters SMB Cybersecurity with MDR
With ESET's Managed Detection Response (MDR), small and midsize businesses can tap into expert-driven threat monitoring and hunting capabilities, leveling up their cybersecurity game without needing an elite in-house team. This game-changing approach bridges the gap between threat research and real-world defense, empowering…
#ManagedDetectionResponse #Mdr #ThreatResearch #Cybersecurity #SmallAndMidsizeBusinesses
-
All of this was measured using Censys Internet intelligence to help defenders better understand an ecosystem that isn't well covered by traditional threat intelligence.
Read Alex Gartner's full research: https://censys.com/blog/roblox-minecraft-and-the-insidious-internet-for-children/
-
https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
#CyberSecurity #InfoSec #SupplyChainSecurity #SoftwareSupplyChain #NPM #OpenSourceSecurity #AppSec #DevSecOps #ThreatIntel #Malware #JavaScript #NodeJS #CICD #GitHubActions #CloudSecurity #TypeScript #ReactJS #WebDev #OpenSource #DevTools #SoftwareEngineering #DeveloperSecurity #SecureCoding #GitHub #SupplyChainAttack #Programming #TechNews #DevOps #ApplicationSecurity #ThreatResearch #SecurityEngineering #CyberAttack #Hackers #MalwareAlert #SecurityResearch #DevCommunity -
New research shows 3 flaws dubbed #ClaudyDay in Claude AI could be chained to steal user data using fake Google Ads, hidden prompts, and built-in features.
Read: https://hackread.com/claudy-day-flaws-data-theft-fake-claude-ai-ads/
#CyberSecurity #AI #ClaudeAI #InfoSec #DataSecurity #ThreatResearch #Malware #Privacy
-
REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.
Technical highlights:
• Migration to Ubuntu 24.04 (modern kernel + LTS support)
• Cast-based installer replacing legacy CLI deployment
• AI-assisted workflows via MCP server
• Integration support for Ghidra with AI pluginsTooling refresh includes:
YARA-X (Rust rewrite for performance improvements)
GoReSym (symbol recovery for Go binaries)
APKiD (Android packer detection)
Manalyze (PE/ELF/MachO static parsing)
This release signals an industry shift toward AI-augmented reverse engineering pipelines.
Is AI-assisted RE the new baseline for threat labs?Source: https://cyberpress.org/remnux-v8-released/
Engage below.
Follow @technadu for deep technical cybersecurity updates.#ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting
-
REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.
Technical highlights:
• Migration to Ubuntu 24.04 (modern kernel + LTS support)
• Cast-based installer replacing legacy CLI deployment
• AI-assisted workflows via MCP server
• Integration support for Ghidra with AI pluginsTooling refresh includes:
YARA-X (Rust rewrite for performance improvements)
GoReSym (symbol recovery for Go binaries)
APKiD (Android packer detection)
Manalyze (PE/ELF/MachO static parsing)
This release signals an industry shift toward AI-augmented reverse engineering pipelines.
Is AI-assisted RE the new baseline for threat labs?Source: https://cyberpress.org/remnux-v8-released/
Engage below.
Follow @technadu for deep technical cybersecurity updates.#ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting
-
REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.
Technical highlights:
• Migration to Ubuntu 24.04 (modern kernel + LTS support)
• Cast-based installer replacing legacy CLI deployment
• AI-assisted workflows via MCP server
• Integration support for Ghidra with AI pluginsTooling refresh includes:
YARA-X (Rust rewrite for performance improvements)
GoReSym (symbol recovery for Go binaries)
APKiD (Android packer detection)
Manalyze (PE/ELF/MachO static parsing)
This release signals an industry shift toward AI-augmented reverse engineering pipelines.
Is AI-assisted RE the new baseline for threat labs?Source: https://cyberpress.org/remnux-v8-released/
Engage below.
Follow @technadu for deep technical cybersecurity updates.#ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting
-
REMnux v8 represents a structural modernization of a long-standing malware analysis distribution.
Technical highlights:
• Migration to Ubuntu 24.04 (modern kernel + LTS support)
• Cast-based installer replacing legacy CLI deployment
• AI-assisted workflows via MCP server
• Integration support for Ghidra with AI pluginsTooling refresh includes:
YARA-X (Rust rewrite for performance improvements)
GoReSym (symbol recovery for Go binaries)
APKiD (Android packer detection)
Manalyze (PE/ELF/MachO static parsing)
This release signals an industry shift toward AI-augmented reverse engineering pipelines.
Is AI-assisted RE the new baseline for threat labs?Source: https://cyberpress.org/remnux-v8-released/
Engage below.
Follow @technadu for deep technical cybersecurity updates.#ThreatResearch #MalwareAnalysis #ReverseEngineering #YARAX #GoBinary #DFIR #Infosec #AIinSecurity #BlueTeam #StaticAnalysis #OpenSourceSecurity #SOC #ThreatHunting
-
We’ve been tracking a cluster of RDGA‑generated domains involved in distributing fake app‑store landing pages. These domains are consistently registered through Namecheap and protected by Cloudflare, which the operators use to obscure origin infrastructure and rapidly cycle through fresh front‑end domains.
The sites impersonate Google Play or iTunes, based on their device’s user‑agent, presenting users with pages that look and feel legitimate. Instead of real apps, the pages deliver Progressive Web Applications (PWAs) that persist on the device and enable ongoing notification abuse.
PWAs are a chrome application which plays cross platform, windows, linux, android, iOS and gets added as an icon on the desktop ofevery device.
Once installed, the PWA triggers a redirection chain through one or more intermediary domains before sending users to online casinos, adult content, or other low‑quality destinations. Because many of these casinos operate from regions where online gambling is restricted or illegal, the operators continually replace the final‑stage domains. This use of RDGA and PWAs allows them to evade regional blocking, reputation systems, and automated detection controls by rotating infrastructure at scale and keeping their persistence to the user devices.
fwiw, most large scale gambling operations like these are not simply illegal in the regions they target... they are scams and often connected to other major crimes, including human trafficking.
play-megawin[.]site
play-icefish[.]website
play-richcasino[.]site
play-casinostaat[.]site
mountainvertex[.]shop
play-fdjfrance[.]site
play-lucky7[.]site
funterra[.]shop
hotcoins[.]site
stonefestal[.]shop
spirevanguard[.]shop
play-crowngreen[.]website
forestoutpost[.]shop#threatintel #gambling #pwa #dns #fake #infoblox #threatresearch #malware #scam #fakeApp #googleplay #infobloxthreatintel #itunes
-
Operation Bizarre Bazaar documents systematic abuse of exposed LLM and MCP infrastructure with commercial monetization.
The campaign demonstrates how AI endpoints without authentication, rate limits, or proper exposure controls can enable compute theft, data access, and potential lateral movement.
AI infrastructure security is increasingly inseparable from traditional cloud and app security.
What controls are most effective in your environment?
Follow TechNadu for objective infosec research coverage.
#AIsecurity #LLM #MCP #CloudDefense #ThreatResearch #InfosecCommunity
-
⚠️ Smishing alert for Greek citizens. 💳 🚨
Scammers are pushing fake AADE (Independent Authority for Public Revenue) “unpaid taxes” SMS that lead to cloned payment pages designed to steal credit‑card info. If a text suddenly demands urgent payment, treat it like a pop‑up from nowhere—don’t click, don’t trust, don’t pay. Share to protect others.mycargr[.]com
aadcar[.]com
aadgee[.]com
aadgre[.]com#CyberThreatIntel #Infoblox #DNS #ThreatResearch #phishing #smishing #Cybercrime #AADE #Greece
-
New, from me: Who Operates the Badbox 2.0 Botnet?
The cybercriminals in control of Kimwolf -- a disruptive botnet that has infected more than 2 million devices -- recently shared a screenshot indicating they'd compromised the control panel for Badbox 2.0, a vast China-based botnet powered by malicious software that comes pre-installed on many Android TV streaming boxes. Both the FBI and Google say they are hunting for the people behind Badbox 2.0, and thanks to bragging by the Kimwolf botmasters we may now have a much clearer idea about that.
https://krebsonsecurity.com/2026/01/who-operates-the-badbox-2-0-botnet/
-
New, from me: The Kimwolf Botnet is Lurking in Corporate, Govt. Networks
A new Internet-of-Things botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Kimwolf’s ability to scan the local networks of compromised systems for other IoT devices to infect makes it a sobering threat to organizations, and new research reveals Kimwolf is surprisingly prevalent in government and corporate networks.
https://krebsonsecurity.com/2026/01/kimwolf-botnet-lurking-in-corporate-govt-networks/