home.social

#vnc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vnc, aggregated by home.social.

fetched live
  1. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  2. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  3. Analysis of a Phishing Email Attack Case

    The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

    Pulse ID: 6a70c6f0d15cdde2874f628e
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: AlienVault
    Created: 2026-08-03 16:50:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault

  4. Analysis of a Phishing Email Attack Case

    The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

    Pulse ID: 6a70c6f0d15cdde2874f628e
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: AlienVault
    Created: 2026-08-03 16:50:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault

  5. Weiss wer wie man vom #Android gerät eine #Proxmox vm via #VNC oder dieses #Spice erreicht?

    Spice ist etwas seltsam, weil man dazu überhaupt keine sinnvolle dokumentation darüber findet, wie man sich damit von einem anderen Gerät verbindet.

    #NoVNC ist seltsam, weil es scheinbar VNC ist aber es doch keinen weg gibt statdessen mit einem VNC client darauf zuzugreifen.

  6. Weiss wer wie man vom #Android gerät eine #Proxmox vm via #VNC oder dieses #Spice erreicht?

    Spice ist etwas seltsam, weil man dazu überhaupt keine sinnvolle dokumentation darüber findet, wie man sich damit von einem anderen Gerät verbindet.

    #NoVNC ist seltsam, weil es scheinbar VNC ist aber es doch keinen weg gibt statdessen mit einem VNC client darauf zuzugreifen.

  7. Still Circling: Toolkit Keeps Evolving

    Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.

    Pulse ID: 6a5b639c3194d1cc5f0e281b
    Pulse Link: otx.alienvault.com/pulse/6a5b6
    Pulse Author: AlienVault
    Created: 2026-07-18 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #Autoit #Bank #BlindEagle #Browser #Chrome #CyberSecurity #Encryption #GitHub #InfoSec #Java #JavaScript #LatinAmerica #OTX #OpenThreatExchange #RAT #VNC #Windows #bot #AlienVault

  8. Still Circling: Toolkit Keeps Evolving

    Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.

    Pulse ID: 6a5b639c3194d1cc5f0e281b
    Pulse Link: otx.alienvault.com/pulse/6a5b6
    Pulse Author: AlienVault
    Created: 2026-07-18 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #Autoit #Bank #BlindEagle #Browser #Chrome #CyberSecurity #Encryption #GitHub #InfoSec #Java #JavaScript #LatinAmerica #OTX #OpenThreatExchange #RAT #VNC #Windows #bot #AlienVault

  9. Got a bit bored and figured out VNC stuff on my iPod touch 2nd gen. Was a bit of a fickle to set up as the power and volume buttons don't work, so I had to make a malformed restore IPSW just to force it into DFU mode, then restore a modified 4.2.1 IPSW that had jailbreak baked in to give me Cydia. Once it was on I could finally get VNC running.

    Tried get root certificates working so Safari stops throwing a fit but I doubt it’s gonna work given how old this thing is.

    It is laggy and so on but I’m not surprised as springboard kept crashing at first, nor it is very intuitive using the VNC server but it works ig

    #iPodTouch #iOS #VNC #TigerVNC #RetroTech #Jailbreak #OldiOS #Apple #DFU

  10. Got a bit bored and figured out VNC stuff on my iPod touch 2nd gen. Was a bit of a fickle to set up as the power and volume buttons don't work, so I had to make a malformed restore IPSW just to force it into DFU mode, then restore a modified 4.2.1 IPSW that had jailbreak baked in to give me Cydia. Once it was on I could finally get VNC running.

    Tried get root certificates working so Safari stops throwing a fit but I doubt it’s gonna work given how old this thing is.

    It is laggy and so on but I’m not surprised as springboard kept crashing at first, nor it is very intuitive using the VNC server but it works ig

    #iPodTouch #iOS #VNC #TigerVNC #RetroTech #Jailbreak #OldiOS #Apple #DFU

  11. And now we're back to lightdm not accepting my password.

    I am tired. I just want to use the computer.

    15/N

    #LinuxMint #lightdm #VNC

  12. And now we're back to lightdm not accepting my password.

    I am tired. I just want to use the computer.

    15/N

    #LinuxMint #lightdm #VNC

  13. I may be resuming my rant today. So far, I'm just amused, not angry.

    The way I've set this up, I have to type two passwords to log in. One for VNC, and one for lightdm. Not ideal.

    VNC stopped working overnight. When I tried to open a session this morning, VNC took my VNC password, but lightdm would not accept my password. I rebooted the Linux box (VNC server), and it got better. I don't know why yet.

    (cont'd)

    13/N

    #LinuxMint #VNC

  14. I may be resuming my rant today. So far, I'm just amused, not angry.

    The way I've set this up, I have to type two passwords to log in. One for VNC, and one for lightdm. Not ideal.

    VNC stopped working overnight. When I tried to open a session this morning, VNC took my VNC password, but lightdm would not accept my password. I rebooted the Linux box (VNC server), and it got better. I don't know why yet.

    (cont'd)

    13/N

    #LinuxMint #VNC

  15. Anyway, the information on the Internet was uniformly wrong about how to integrate VNC into systemd. Wrong in many interesting ways. I delved into the systemd docs and finally got Xvnc plumbed into it, and then the problem was that VNC didn't have any X clients to run. So I looked up which display manager Mint uses. It's lightdm.

    (Question for the peanut gallery: does Ubuntu use lightdm? Canonical apparently wrote it, but Ubuntu might have migrated away.)

    8/N

    #LinuxMint #VNC #LightDM

  16. Anyway, the information on the Internet was uniformly wrong about how to integrate VNC into systemd. Wrong in many interesting ways. I delved into the systemd docs and finally got Xvnc plumbed into it, and then the problem was that VNC didn't have any X clients to run. So I looked up which display manager Mint uses. It's lightdm.

    (Question for the peanut gallery: does Ubuntu use lightdm? Canonical apparently wrote it, but Ubuntu might have migrated away.)

    8/N

    #LinuxMint #VNC #LightDM

  17. Where was I? Right. I started with RDP. I could not find reliable info on how to connect to an RDP server from MacOS, nor whether it's possible, so I didn't get far.

    So I switched to VNC. I used VNC 20 years ago. MacOS supports it. Let's see what's changed. I looked at RealVNC, tightVNC, and tigerVNC. RealVNC is apparently paid now. tightVNC is Windows first now(!) and only old versions support Linux. That leaves tigerVNC.

    5/N

    #RDP #VNC #RealVNC #tightVNC #tigerVNC

  18. Where was I? Right. I started with RDP. I could not find reliable info on how to connect to an RDP server from MacOS, nor whether it's possible, so I didn't get far.

    So I switched to VNC. I used VNC 20 years ago. MacOS supports it. Let's see what's changed. I looked at RealVNC, tightVNC, and tigerVNC. RealVNC is apparently paid now. tightVNC is Windows first now(!) and only old versions support Linux. That leaves tigerVNC.

    5/N

    #RDP #VNC #RealVNC #tightVNC #tigerVNC

  19. ... and installed Linux Mint. Because Cinnamon looks a lot cleaner than GNOME. It went okay. I got a desktop, logged in, used the familiar Debian tools to install some things, and started to get comfortable.

    Then I decided I wanted to use the desktop remotely from my Mac. (My 2005 $10 keyboard and mouse suck, and the monitor isn't conveniently placed.)

    RDP or VNC?

    ...

    3/N

    #LinuxMint #Cinnamon #VNC

  20. ... and installed Linux Mint. Because Cinnamon looks a lot cleaner than GNOME. It went okay. I got a desktop, logged in, used the familiar Debian tools to install some things, and started to get comfortable.

    Then I decided I wanted to use the desktop remotely from my Mac. (My 2005 $10 keyboard and mouse suck, and the monitor isn't conveniently placed.)

    RDP or VNC?

    ...

    3/N

    #LinuxMint #Cinnamon #VNC

  21. SOCAT and VNC
    Last night, we spent serious time testing different socat proxy block sizes and VPN MTU's with a modified variant of VNC over port 7443 (web/SSL). The magic spot was a "-b 1300" instead of our usual 768, the "nodelay" option and a VPN interface MTU of 1350. Tonight I get a message several remote technologists were very happy with these settings. Made my day.

  22. SOCAT and VNC
    Last night, we spent serious time testing different socat proxy block sizes and VPN MTU's with a modified variant of VNC over port 7443 (web/SSL). The magic spot was a "-b 1300" instead of our usual 768, the "nodelay" option and a VPN interface MTU of 1350. Tonight I get a message several remote technologists were very happy with these settings. Made my day. #socat #vnc #openvpn