#vbs — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vbs, aggregated by home.social.
-
Beware of Phishing Emails Disguised as Transaction Receipts
A sophisticated phishing campaign has been identified where attackers impersonate employees of a US company, sending emails that claim to contain transaction receipts. Recipients are urged to verify fund deposits by opening an attached PDF file. The malicious PDF displays a fake Adobe Flash Player update prompt, which when clicked, downloads a VBS script. This script executes with administrator privileges, displays a decoy payment receipt document, and silently installs ScreenConnect remote management software via an MSI package. The installation establishes persistent remote access to the compromised system, enabling attackers to execute commands, transfer files, and deploy additional payloads using legitimate administrative tools in a Living-off-the-Land attack technique.
Pulse ID: 6a8431e74688d3e47ef55014
Pulse Link: https://otx.alienvault.com/pulse/6a8431e74688d3e47ef55014
Pulse Author: AlienVault
Created: 2026-08-18 10:20:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ScreenConnect #VBS #bot #AlienVault
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
...#Skynex, geborene #Oerlikon Luftabwehrkanone (Munition dazu wurde vor Jahren von CH verweigert)
👇
https://bsky.app/profile/antongerashchenko.bsky.social/post/3msplpuf7hc2d
wo bleibt unser Wille zur Landesverteidigung?
#VBS verschleudert unsere Steuergelder an überteuerte Waffensysteme aus den #US - #F35 #patriot - welche wir ohne die Einwilligung der #USA im Ernstfall nicht einsetzen können
#CH #Vasallen #Politik #Bundesrat #Ständerat #Nationalrat #Landesverteidigung #armasuisse #Lobbyismus #Korruption
-
Hackers Distributing Malicious VBS/PowerShell RAT Chain Via Multiple DuckDNS Hosts
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/powershell-rat-chain-duckdns-hosts/
Pulse ID: 6a79924d4b01470c3d516097
Pulse Link: https://otx.alienvault.com/pulse/6a79924d4b01470c3d516097
Pulse Author: CyberHunter_NL
Created: 2026-08-10 08:56:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PowerShell #RAT #RCE #VBS #bot #CyberHunter_NL
-
...überleben der Kühe gesichert, dank VBS
(Landesverteidigung weiterhin prekär)
https://www.srf.ch/news/schweiz/besondere-lage-ausgerufen-armee-fliegt-wasser-auf-freiburger-alpen
-
#VBS legitimiert Lösegeldzahlung durch #Ruag - inside-it[.]ch
Das Militärdepartement schliesst seine Untersuchung zur Zahlung an die #Ransomware-Bande #Akira ab. Es gebe "keine Anhaltspunkte für eine Rechtsverletzung".
https://www.inside-it.ch/vbs-legitimiert-loesegeldzahlung-durch-ruag-20260804 #CyberCrime #Malware
-
Phishing Email Delivers ScreenConnect Malware
A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads.
Pulse ID: 6a722c0bba9d9f436322ae56
Pulse Link: https://otx.alienvault.com/pulse/6a722c0bba9d9f436322ae56
Pulse Author: AlienVault
Created: 2026-08-04 18:14:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #Email #InfoSec #LUA #Mac #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #ScreenConnect #UAE #VBS #Windows #ZIP #bot #AlienVault
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...
Pulse ID: 6a722d8bdafe1dfae681f87b
Pulse Link: https://otx.alienvault.com/pulse/6a722d8bdafe1dfae681f87b
Pulse Author: AlienVault
Created: 2026-08-04 18:20:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault
-
"...Konformität nach US-Recht geprüft" - ist die staatliche Ruag dem US-Gesetz unterstellt?
Wann werden die Lösegeldzahlungen nach CH-Recht geprüft?
#CH #Politik #VBS #Armee #armasuisse #Ruag #hacker #Lösegeld #Lösegeldzahlungen
-
...and, we still by things from these 'people'
https://thecradle.co/articles-id/38871
#israel #genocide #gaza
#CH #Politik #Bundesrat #Ständerat #Nationalrat #VBS #armasuisse #Kriegsverbrechen #Genozid -
...Firma "Swarmer", Kyiv, anrufen, die könnten weiter helfen 🤗
-
RUAG "...das Unternehmen hat alle Daten zurück erhalten."
alte Kopierweisheit: "Erst die Kopie machen und dann das Original wegschmeissen."
https://www.srf.ch/news/schweiz/cyberkriminalitaet-vbs-untersucht-ruag-loesegeldzahlung
-
also weil die saftnasen im #VBS ihren scheiss nicht im Griff haben, finanzieren wir nun mittels Steuergelder Kirminelle strukturen.
Und wenn da steht:
"von US-Rechtsexperten beraten lassen": Woher wissen wir, dass der Angriff selbst nicht von den Amis kam?
https://www.srf.ch/news/schweiz/nach-erpressung-in-den-usa-bundeskonzern-ruag-zahlt-loesegeld-an-hackergruppe
#ransomware #ruag #ruaginternational #hobby #imbecil #idiots #taxmoney #rightwing -
Ach, wieder so ein Sauladen der mit dem #VBS zu tun hat. #GSOA
https://social.pmj.rocks/@srfnewsrss/116701402524183882 -
Aviation weather for Brescia airport in Montichiari area (Italy) is “METAR LIPO 010920Z AUTO 11004KT 050V170 9999 FEW130/// 24/17 Q1014” : See what it means on https://www.bigorre.org/aero/meteo/lipo/en #bresciaairport #airport #montichiari #italy #lipo #vbs #metar #aviation #aviationweather #avgeek vl
-
What with Paul McCartney on SNL this weekend, I asked our son if he could name the 4 Beatles. He could only name one. Then I asked our twenty something waiter if he knew them and he could only name 2 of them.
I told my son that this summer he's going to VBS (Vacation Beatles School). Which Beatles doc should I make him watch with me?
-
...die spinnen!
#VBS noch mehr Geld, um #us Kriegsverbrechen zu finanzieren
#VBS #us #ch #politik #Landesverteidigung #Armee #beschaffungswesen #lobbyismus #korruption #F35 #Patriot
-
Aviation weather for Brescia airport in Montichiari area (Italy) is “LIPO 151150Z AUTO 03013KT 9999 FEW074/// BKN091/// 14/07 Q1008” : See what it means on https://www.bigorre.org/aero/meteo/lipo/en #bresciaairport #airport #montichiari #italy #lipo #vbs #metar #aviation #aviationweather #avgeek vl
-
Aviation weather for Brescia airport in Montichiari area (Italy) is “LIPO 041020Z AUTO 14003KT 100V180 5000 BR FEW008/// 13/10 Q1028” : See what it means on https://www.bigorre.org/aero/meteo/lipo/en #bresciaairport #airport #montichiari #italy #lipo #vbs #metar #aviation #aviationweather #avgeek vl
-
...das #VBS als Sicherheitsrisiko 🫣
- Valeriya Novodvorskaya bezeichnete Putin (schon vor 2013, als der Bube in Moskau 'studierte') als Monster
- 2014 wurde die Krim überfallen
- usw., usw. -
We opened a fake invoice and fell down a retro XWorm-shaped wormhole https://www.malwarebytes.com/blog/threats/2025/11/we-opened-a-fake-invoice-and-fell-down-a-retro-xworm-shaped-wormhole #ThreatIntel #powershell #Threats #bat #vbs
-
Aviation weather for Brescia airport in Montichiari area (Italy) is “LIPO 070920Z AUTO VRB02KT 9999 NCD 17/10 Q1022” : See what it means on https://www.bigorre.org/aero/meteo/lipo/en #montichiari #italy #bresciaairport #lipo #vbs #metar #aviation #aviationweather #avgeek #airport vl
-
Aviation weather for Brescia airport in Montichiari area (Italy) is “LIPO 070920Z AUTO VRB02KT 9999 NCD 17/10 Q1022” : See what it means on https://www.bigorre.org/aero/meteo/lipo/en #montichiari #italy #bresciaairport #lipo #vbs #metar #aviation #aviationweather #avgeek #airport vii3
-
…#Sturheit ist u n b e z a h l b a r
#CH #Politik #VBS #Beschaffungswesen #armasuisse #F35 #Luxusschrott #Lobbyismus #Korruption #Dummheit
-
@martinsteiger
Das weiss irgendwie die ganze Welt, das #VBS will trotzdem noch vielmehr #F35, die sind für die Fliegerli-Bubis einfach geiler.