#trojan — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #trojan, aggregated by home.social.
-
Manic: il trojan Android che ruba i PIN bancari e li fa uscire di casa via Bluetooth anche offline
ThreatFabric ricostruisce Manic, ibrido tra banking malware e spyware che dà priorità all'Ucraina tra 169 app monitorate: intercetta PIN senza overlay di phishing e, quando il telefono è offline, esfiltra i dati attraverso una rete mesh Bluetooth/Wi-Fi Direct di dispositivi infetti vicini. -
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Pulse ID: 6a8592950ee0e8d05fc1bec9
Pulse Link: https://otx.alienvault.com/pulse/6a8592950ee0e8d05fc1bec9
Pulse Author: AlienVault
Created: 2026-08-19 11:25:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
Hackers Use Fake Claude Install Guide to Deploy MacSync Stealer and Trojanize Crypto Wallet Apps
Indicators extracted from public reporting. Source: https://www.huntress.com/blog/fake-claude-macsync
Pulse ID: 6a858bb7392a488e75dd639e
Pulse Link: https://otx.alienvault.com/pulse/6a858bb7392a488e75dd639e
Pulse Author: CyberHunter_NL
Created: 2026-08-19 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RCE #Trojan #bot #CyberHunter_NL
-
Projextor: Abusing Electron in Trojanized Productivity Applications
Pulse ID: 6a8533ca8d1f3a924aac5cc6
Pulse Link: https://otx.alienvault.com/pulse/6a8533ca8d1f3a924aac5cc6
Pulse Author: Tr1sa111
Created: 2026-08-19 04:40:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Trojan #bot #Tr1sa111
-
Projextor: Abusing Electron in Trojanized Productivity Applications
Projextor is a malware campaign that leverages Electron-based productivity applications to deliver malicious payloads. The threat disguises itself as legitimate document converters, meal planners, and PDF management tools with working user interfaces. Distribution occurs through impersonating websites that mimic genuine services, using high-ranking search results to lure victims. Applications like Kitchen Canvas, Food Formula, DocConvertWizard, and PDFGrip contain insecure Electron configurations that enable dynamic JavaScript execution and desktop capture capabilities. The infection chain begins with NSIS, Squirrel, or Inno Setup installers that download the main Electron application. Preload scripts abuse privileged Node.js APIs with intentionally disabled security features, allowing arbitrary code execution and screen monitoring. This enables threat actors to capture sensitive information, monitor user activity, and execute remote commands while maintaining the appearance of functional productivity soft...
Pulse ID: 6a8325c63ec6c1f8d93275f6
Pulse Link: https://otx.alienvault.com/pulse/6a8325c63ec6c1f8d93275f6
Pulse Author: AlienVault
Created: 2026-08-17 15:16:22Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #Java #JavaScript #Malware #Mimic #Nodejs #OTX #OpenThreatExchange #PDF #RAT #ScriptExecution #Squirrel #Trojan #bot #AlienVault
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7c433680aefab88821c968
Pulse Link: https://otx.alienvault.com/pulse/6a7c433680aefab88821c968
Pulse Author: CyberHunter_NL
Created: 2026-08-12 09:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7b9a56ed0787edeab00dfb
Pulse Link: https://otx.alienvault.com/pulse/6a7b9a56ed0787edeab00dfb
Pulse Author: CyberHunter_NL
Created: 2026-08-11 21:55:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
by Ondřej Trojan
https://tmblr.co/Z7VXvxjmleJ4iy00
#ondrej #documentary #ondřej #trojan #document #leica #abstraction #camera #monochrom #czech #bohemia #monochrome #street #black #shadow #people #leicam11 #artphoto #streets #light #urban #mono #bnw #dark #white #leicam #50 #mm #flickr #thingsdavidlikes
-
Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized...
Pulse ID: 6a74beb7cd2fbf6d191ba7c9
Pulse Link: https://otx.alienvault.com/pulse/6a74beb7cd2fbf6d191ba7c9
Pulse Author: AlienVault
Created: 2026-08-06 17:04:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Discord #Email #HTTP #InfoSec #InformationTheft #IoT #Malware #Minecraft #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #Steam #Telegram #Trojan #Troll #VPN #ZIP #bot #cryptocurrency #AlienVault
-
Supply Chain Compromise Affecting keyv and cacheable npm Packages
An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.
Pulse ID: 6a744e3869101e8bea80db85
Pulse Link: https://otx.alienvault.com/pulse/6a744e3869101e8bea80db85
Pulse Author: AlienVault
Created: 2026-08-06 09:04:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #DNS #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Trojan #Troll #Worm #bot #AlienVault
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.
Pulse ID: 6a73cac4902afff959b758aa
Pulse Link: https://otx.alienvault.com/pulse/6a73cac4902afff959b758aa
Pulse Author: AlienVault
Created: 2026-08-05 23:44:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault
-
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Indicators extracted from public reporting. Source: https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique
Pulse ID: 6a735d7ba06b98602c41c75a
Pulse Link: https://otx.alienvault.com/pulse/6a735d7ba06b98602c41c75a
Pulse Author: CyberHunter_NL
Created: 2026-08-05 15:57:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RCE #Trojan #bot #CyberHunter_NL
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...
Pulse ID: 6a722d8ce0ae0afdde284102
Pulse Link: https://otx.alienvault.com/pulse/6a722d8ce0ae0afdde284102
Pulse Author: AlienVault
Created: 2026-08-04 18:21:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain
Pulse ID: 6a72f492ee9dc3fc24d86c17
Pulse Link: https://otx.alienvault.com/pulse/6a72f492ee9dc3fc24d86c17
Pulse Author: AlienVault
Created: 2026-08-05 08:30:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Azure #Chinese #CyberSecurity #Endpoint #HTML #InfoSec #Java #JavaScript #Microsoft #OTX #OpenThreatExchange #RAT #RCE #SideLoading #Steam #SupplyChain #Trojan #VPN #Windows #bot #cryptocurrency #AlienVault
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Indicators extracted from public reporting. Source: https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant
Pulse ID: 6a72de9544036c10bb5df1e3
Pulse Link: https://otx.alienvault.com/pulse/6a72de9544036c10bb5df1e3
Pulse Author: CyberHunter_NL
Created: 2026-08-05 06:56:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SupplyChain #Trojan #Windows #bot #CyberHunter_NL
-
Huge issue: #Microsoft #Defender quarantines a #Synology #backup command for connection test falsely as a #trojan - which leads to serious issues. If you click "allow", it disabled the detection rule at all - device wide, for all time ...
-
ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework
A Russian-speaking, financially motivated threat actor designated UAT-11795 has been conducting a sophisticated malware campaign since June 2025, primarily targeting users in the United States. The operation utilizes ClickFix-style social engineering techniques with trojanized software installers for applications like MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT. The campaign deploys Starland RAT, a custom Python-based remote access tool that establishes persistence, performs reconnaissance, and collects cryptocurrency wallet information. The malware employs blockchain-based fallback C2 mechanisms via Polygon smart contracts. Additionally, the operation deploys the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT, demonstrating a modular architecture focused on credential theft, cryptocurrency harvesting, and long-term post-compromise access.
Pulse ID: 6a71a6ac7bd8297ea6d2093f
Pulse Link: https://otx.alienvault.com/pulse/6a71a6ac7bd8297ea6d2093f
Pulse Author: AlienVault
Created: 2026-08-04 08:45:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cisco #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #Remcos #RemcosRAT #Russia #SMS #SocialEngineering #Trojan #UnitedStates #Zoom #bot #cryptocurrency #AlienVault
-
MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets
MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.
Pulse ID: 6a708422cc9833fb7a2ec3f9
Pulse Link: https://otx.alienvault.com/pulse/6a708422cc9833fb7a2ec3f9
Pulse Author: cryptocti
Created: 2026-08-03 12:05:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti
-
A Deep Dive Into the Latest XCSSET Version
After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.
Pulse ID: 6a7059ccae49a160e5763d1d
Pulse Link: https://otx.alienvault.com/pulse/6a7059ccae49a160e5763d1d
Pulse Author: AlienVault
Created: 2026-08-03 09:05:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Chrome #Cloud #CyberSecurity #Encryption #GitHub #India #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Russia #SMS #SouthAsia #SupplyChain #Telegram #Trojan #bot #developers #AlienVault
-
Reverse Engineering the Six Stages of MacSync Stealer and RAT
MacSync is a sophisticated six-stage macOS attack chain initiated when victims search for Claude installation instructions, click malicious Google Ads, and reach weaponized claude.ai/share conversations posing as Apple Support guides. The victim pastes a curl command that deploys a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and wallet trojans. The operation steals browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials, but focuses heavily on cryptocurrency with approximately 60 wallet browser extensions, 21 desktop apps, and three trojanized hardware wallet companions designed to continuously phish recovery phrases. Infrastructure spans Cloudflare-fronted delivery domains (agenticsora[.]com, malwareaudit[.]com), an operator IP (103.216.221[.]95), dedicated RAT C2 (85.206.161[.]241:8443), and seed-phrase drop domains. The malware persists via LaunchAgents masquerading as legitimate updater se...
Pulse ID: 6a6a47bf77b7d1fa679717d8
Pulse Link: https://otx.alienvault.com/pulse/6a6a47bf77b7d1fa679717d8
Pulse Author: AlienVault
Created: 2026-07-29 18:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cloud #CyberSecurity #Google #GoogleAds #ICS #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Telegram #Trojan #Word #bot #cryptocurrency #AlienVault
-
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Pulse ID: 6a6ad68f50ddb7ab4a0f10ae
Pulse Link: https://otx.alienvault.com/pulse/6a6ad68f50ddb7ab4a0f10ae
Pulse Author: Tr1sa111
Created: 2026-07-30 04:43:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #bot #Tr1sa111
-
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.
Pulse ID: 6a696c951815449cad089687
Pulse Link: https://otx.alienvault.com/pulse/6a696c951815449cad089687
Pulse Author: AlienVault
Created: 2026-07-29 02:59:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Clipboard #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #NPM #Nodejs #OTX #OpenThreatExchange #Python #RAT #RemoteAccessTrojan #Trojan #bot #AlienVault
-
Analysis of BlueShell Variants Used by APT Groups
BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.
Pulse ID: 6a69c06b441d532a963887ee
Pulse Link: https://otx.alienvault.com/pulse/6a69c06b441d532a963887ee
Pulse Author: AlienVault
Created: 2026-07-29 08:57:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault