home.social

#trojan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #trojan, aggregated by home.social.

fetched live
  1. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  2. From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

    A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

    Pulse ID: 6a8592950ee0e8d05fc1bec9
    Pulse Link: otx.alienvault.com/pulse/6a859
    Pulse Author: AlienVault
    Created: 2026-08-19 11:25:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #Nim #OTX #OpenThreatExchange #RAT #RPC #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  3. Hackers Use Fake Claude Install Guide to Deploy MacSync Stealer and Trojanize Crypto Wallet Apps

    Indicators extracted from public reporting. Source: huntress.com/blog/fake-claude-

    Pulse ID: 6a858bb7392a488e75dd639e
    Pulse Link: otx.alienvault.com/pulse/6a858
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RCE #Trojan #bot #CyberHunter_NL

  4. Projextor: Abusing Electron in Trojanized Productivity Applications

    Pulse ID: 6a8533ca8d1f3a924aac5cc6
    Pulse Link: otx.alienvault.com/pulse/6a853
    Pulse Author: Tr1sa111
    Created: 2026-08-19 04:40:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Trojan #bot #Tr1sa111

  5. Projextor: Abusing Electron in Trojanized Productivity Applications

    Projextor is a malware campaign that leverages Electron-based productivity applications to deliver malicious payloads. The threat disguises itself as legitimate document converters, meal planners, and PDF management tools with working user interfaces. Distribution occurs through impersonating websites that mimic genuine services, using high-ranking search results to lure victims. Applications like Kitchen Canvas, Food Formula, DocConvertWizard, and PDFGrip contain insecure Electron configurations that enable dynamic JavaScript execution and desktop capture capabilities. The infection chain begins with NSIS, Squirrel, or Inno Setup installers that download the main Electron application. Preload scripts abuse privileged Node.js APIs with intentionally disabled security features, allowing arbitrary code execution and screen monitoring. This enables threat actors to capture sensitive information, monitor user activity, and execute remote commands while maintaining the appearance of functional productivity soft...

    Pulse ID: 6a8325c63ec6c1f8d93275f6
    Pulse Link: otx.alienvault.com/pulse/6a832
    Pulse Author: AlienVault
    Created: 2026-08-17 15:16:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #Java #JavaScript #Malware #Mimic #Nodejs #OTX #OpenThreatExchange #PDF #RAT #ScriptExecution #Squirrel #Trojan #bot #AlienVault

  6. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  7. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  8. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  9. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  10. Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7c433680aefab88821c968
    Pulse Link: otx.alienvault.com/pulse/6a7c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 09:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  11. Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7b9a56ed0787edeab00dfb
    Pulse Link: otx.alienvault.com/pulse/6a7b9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 21:55:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  12. Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware

    Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized...

    Pulse ID: 6a74beb7cd2fbf6d191ba7c9
    Pulse Link: otx.alienvault.com/pulse/6a74b
    Pulse Author: AlienVault
    Created: 2026-08-06 17:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Discord #Email #HTTP #InfoSec #InformationTheft #IoT #Malware #Minecraft #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #Steam #Telegram #Trojan #Troll #VPN #ZIP #bot #cryptocurrency #AlienVault

  13. Supply Chain Compromise Affecting keyv and cacheable npm Packages

    An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.

    Pulse ID: 6a744e3869101e8bea80db85
    Pulse Link: otx.alienvault.com/pulse/6a744
    Pulse Author: AlienVault
    Created: 2026-08-06 09:04:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Cloud #CyberSecurity #DNS #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Trojan #Troll #Worm #bot #AlienVault

  14. Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

    On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.

    Pulse ID: 6a73cac4902afff959b758aa
    Pulse Link: otx.alienvault.com/pulse/6a73c
    Pulse Author: AlienVault
    Created: 2026-08-05 23:44:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault

  15. Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

    Indicators extracted from public reporting. Source: opensourcemalware.com/blog/nul

    Pulse ID: 6a735d7ba06b98602c41c75a
    Pulse Link: otx.alienvault.com/pulse/6a735
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 15:57:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DPRK #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RCE #Trojan #bot #CyberHunter_NL

  16. Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

    A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...

    Pulse ID: 6a722d8ce0ae0afdde284102
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:21:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  17. QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

    A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain

    Pulse ID: 6a72f492ee9dc3fc24d86c17
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:30:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #Chinese #CyberSecurity #Endpoint #HTML #InfoSec #Java #JavaScript #Microsoft #OTX #OpenThreatExchange #RAT #RCE #SideLoading #Steam #SupplyChain #Trojan #VPN #Windows #bot #cryptocurrency #AlienVault

  18. QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

    Indicators extracted from public reporting. Source: fortinet.com/blog/threat-resea

    Pulse ID: 6a72de9544036c10bb5df1e3
    Pulse Link: otx.alienvault.com/pulse/6a72d
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 06:56:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SupplyChain #Trojan #Windows #bot #CyberHunter_NL

  19. Huge issue: #Microsoft #Defender quarantines a #Synology #backup command for connection test falsely as a #trojan - which leads to serious issues. If you click "allow", it disabled the detection rule at all - device wide, for all time ...

    borncity.com/win/2026/08/04/i-

  20. ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework

    A Russian-speaking, financially motivated threat actor designated UAT-11795 has been conducting a sophisticated malware campaign since June 2025, primarily targeting users in the United States. The operation utilizes ClickFix-style social engineering techniques with trojanized software installers for applications like MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT. The campaign deploys Starland RAT, a custom Python-based remote access tool that establishes persistence, performs reconnaissance, and collects cryptocurrency wallet information. The malware employs blockchain-based fallback C2 mechanisms via Polygon smart contracts. Additionally, the operation deploys the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT, demonstrating a modular architecture focused on credential theft, cryptocurrency harvesting, and long-term post-compromise access.

    Pulse ID: 6a71a6ac7bd8297ea6d2093f
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 08:45:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cisco #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #Remcos #RemcosRAT #Russia #SMS #SocialEngineering #Trojan #UnitedStates #Zoom #bot #cryptocurrency #AlienVault

  21. MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets

    MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.

    Pulse ID: 6a708422cc9833fb7a2ec3f9
    Pulse Link: otx.alienvault.com/pulse/6a708
    Pulse Author: cryptocti
    Created: 2026-08-03 12:05:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti

  22. A Deep Dive Into the Latest XCSSET Version

    After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.

    Pulse ID: 6a7059ccae49a160e5763d1d
    Pulse Link: otx.alienvault.com/pulse/6a705
    Pulse Author: AlienVault
    Created: 2026-08-03 09:05:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Chrome #Cloud #CyberSecurity #Encryption #GitHub #India #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Russia #SMS #SouthAsia #SupplyChain #Telegram #Trojan #bot #developers #AlienVault

  23. Reverse Engineering the Six Stages of MacSync Stealer and RAT

    MacSync is a sophisticated six-stage macOS attack chain initiated when victims search for Claude installation instructions, click malicious Google Ads, and reach weaponized claude.ai/share conversations posing as Apple Support guides. The victim pastes a curl command that deploys a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and wallet trojans. The operation steals browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials, but focuses heavily on cryptocurrency with approximately 60 wallet browser extensions, 21 desktop apps, and three trojanized hardware wallet companions designed to continuously phish recovery phrases. Infrastructure spans Cloudflare-fronted delivery domains (agenticsora[.]com, malwareaudit[.]com), an operator IP (103.216.221[.]95), dedicated RAT C2 (85.206.161[.]241:8443), and seed-phrase drop domains. The malware persists via LaunchAgents masquerading as legitimate updater se...

    Pulse ID: 6a6a47bf77b7d1fa679717d8
    Pulse Link: otx.alienvault.com/pulse/6a6a4
    Pulse Author: AlienVault
    Created: 2026-07-29 18:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cloud #CyberSecurity #Google #GoogleAds #ICS #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Telegram #Trojan #Word #bot #cryptocurrency #AlienVault

  24. Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

    Pulse ID: 6a6ad68f50ddb7ab4a0f10ae
    Pulse Link: otx.alienvault.com/pulse/6a6ad
    Pulse Author: Tr1sa111
    Created: 2026-07-30 04:43:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #bot #Tr1sa111

  25. Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

    Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.

    Pulse ID: 6a696c951815449cad089687
    Pulse Link: otx.alienvault.com/pulse/6a696
    Pulse Author: AlienVault
    Created: 2026-07-29 02:59:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #Clipboard #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #NPM #Nodejs #OTX #OpenThreatExchange #Python #RAT #RemoteAccessTrojan #Trojan #bot #AlienVault

  26. Analysis of BlueShell Variants Used by APT Groups

    BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.

    Pulse ID: 6a69c06b441d532a963887ee
    Pulse Link: otx.alienvault.com/pulse/6a69c
    Pulse Author: AlienVault
    Created: 2026-07-29 08:57:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault