Search/socks5
Vendor

socks5

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
socks5
Connections
38 relationships
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Fortinet FortiGuard Labs said. Evidence indicates that the botnet has been active in the wild since July 2026, exploiting known vulnerabilities in publicly-accessible devices to deliver the malware. Some of the security flaws weaponized by the botnet are below - CVE-2007-3010 - Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability CVE-2016-6277 - NETGEAR Multiple Routers Remote Code Execution Vulnerability CVE-2018-14558 - Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability CVE-2019-14931 - Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability CVE-2020-10987 - Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability CVE-2021-46422 - Telesquare SDT-CW3B1 Command Injection vulnerability CVE-2022-37055 - D-Link Routers Buffer Overflow Vulnerability CVE-2024-29269 - Telesquare TLR-2005KSH Command Injection Vulnerability CVE-2025-10123 - D-Link DIR-823X Command Injection Vulnerability CVE-2025-55583 - D-Link DIR-868L B1 router Command Injection Vulnerability Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture. The script subsequently clears Bash history to erase traces of the attack. Upon execution, the binary checks for the presence of analysis tools, sandboxes, and virtual environments, before establishing encrypted communications with a command-and-control (C2) server on port 443. The port choice is intentional as it allows the malware to blend in with expected HTTPS traffic at the network perimeter. Once the host is registered with the C2 server, it waits for further commands to take action. It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws. The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (CVE-2021-36260), Atlassian Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), Zyxel (CVE-2022-30525), TP-Link (CVE-2023-1389), PHP (CVE-2024-4577), D-Link (CVE-2024-10914), Kubernetes (CVE-2025-1974). The proxy component, on the other hand, transforms an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy that the threat actor can leverage as a network relay to conduct follow-on operations and evade detection. "This capability significantly increases the value of an infected host to attackers," Fortinet said. "The victim's IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine." "In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services."
thehackernews.comAug 17, 2026extracted
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. The malware's capabilities extend beyond turning devices into proxy nodes and include credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks. Since at least July, Evooo1Bot has been targeting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across various regions by exploiting known vulnerabilities. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” Fortinet researchers found. Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, Fortinet notes that some of the embedded exploits are not correctly implemented, leading to failed exploitation. When leveraging an exploit successfully, a script downloads one of the 12 available malware builds that match the host’s CPU architecture, then clears Bash history to wipe traces of the attack. Evooo1Bot uses encrypted command-and-control (C2) communications over port 443 and performs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it launches on the infected device. Persistence is established through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes. An interactive shell gives operators direct control over compromised systems, while file-transfer commands support uploads and downloads. The malware also features a credential sniffer module that monitors ‘/proc/net/tcp’ and attempts to capture HTTP Basic Authentication and Cookie headers. The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or potentially access networks through compromised systems. Fortinet says proxying sessions run independently, and multiple can be opened simultaneously, allowing monetization through residential proxy services if the botnet grows large enough. The SSH scanner module uses 150 username and password combinations for enterprise-oriented accounts, and performs post-login checks to avoid honeypots. Finally, the DDoS module that was inherited by Mirai supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customizable requests. To defend against botnet malware, keep your IoT devices’ firmware updated, replace default admin credentials, turn off remote access panels, and replace devices when the vendor no longer provides support for them. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 15, 2026extracted
Hundreds of fake Chrome VPN extensions route traffic through a proxy
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider. Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver. Researchers at application security company Socket found that the campaign relied on 40 publisher accounts and used a shared analytics account. While on the Chrome Web Store, the extensions were downloaded nearly 75,000 times, mainly by Russian users looking for tools to bypass blocked services in the country. “With all browser traffic forced through it [the relay], the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP,” Socket explains. The researchers identified three threat behaviors associated with the campaign: 520 extensions configured Chrome to route all browser traffic through the operator’s SOCKS5 proxies on port 1082. 104 extensions resolved their proxy hostnames through Cloudflare or Google DNS-over-HTTPS to protect the operator’s domain from scrutiny. Extensions that advertised non-existent premium servers in Japan, Singapore, Canada, Australia, and Turkey for subscription fraud Socket could not analyze the code in all of the extensions because 212 of them had already been removed when the researchers collected them. Based on the strings found, the campaign appears to be an attempt to funnel customers to a subscription-based VPN service in Russia. The researchers noted that the mechanism used by the extensions appears no different from that of a legitimate service, but they identified several indicators of intentional deception: impersonating well-known brands advertising nonexistent premium server locations nonfunctional payment or connection mechanisms misleading disclosures to store reviewers adding remote configuration after the extension was approved the use of techniques to hide proxy destinations from analysis Socket says that while Google removed more than 200 of the extensions related to the identified campaign, over 500 of them are still available in Chrome's Web Store. Socket has published the IDs of all extensions linked to the campaign and recommends that users check their browsers for any of them and remove them if found. They should also confirm that Chrome’s proxy configuration is back to normal. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 12, 2026extracted
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
Microsoft warns of a Windows-based cryptocurrency clipper that establishes a lightweight backdoor blending data exfiltration and remote code execution (RCE) capabilities. Dubbed CryptoBandits, the malware has been used in attacks since February 2026, deploying a portable Tor client on the infected systems and routing traffic through a local SOCKS5 proxy. “The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C&C server. It carries out high-frequency clipboard theft, screenshot exfiltration, and wallet-address substitution,” Microsoft explains. CryptoBandits is distributed through malicious shortcut (.lnk) payloads. On the infected systems, it deploys two components: a worm for propagation and a clipper/stealer to steal cryptocurrency wallet information. For propagation, the malware scans connected USB devices and creates additional malicious shortcuts of legitimate files. It can also deliver file-based payloads that it excludes from Defender scanning. The clipper is a script that interacts with the system via WScript and ActiveXObject, and checks whether Task Manager is running as an anti-analysis defense. Persistence is achieved through scheduled tasks. CryptoBandits launches a renamed Tor binary to establish command-and-control (C&C) communication and register the victim device, and then enters a continuous loop, polling the C&C for instructions every 500 milliseconds. The malware can extract seed phrases and private keys associated with cryptocurrency wallets, and can replace cryptocurrency addresses in the clipboard with attacker-provided ones to hijack them. According to Microsoft, the malware employs multi-layered obfuscation, decrypting all components at runtime. Both the Python script that handles installation and its JavaScript payloads are also obfuscated. The central component of the threat is the bundled Tor client, which routes communication over localhost:9050 and resolves destination domains to reduce DNS visibility and hide its C&C location. “This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking. Organizations should focus on hardening script execution paths, monitoring local SOCKS proxy abuse, and using behavioral hunting to connect script activity with network, clipboard, and process signals,” Microsoft notes. Related: Rokarolla Banking Trojan Targets 200 Applications Related: Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack Related: OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month Related: Infostealers Turn Millions of Devices Into Credential Theft Machines
securityweek.comJun 19, 2026extracted
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022. "Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files, and functioning as a SOCKS5 proxy," Lumen Technologies Black Lotus Labs said in a report shared with The Hacker News. It's assessed that the malware has been employed by at least one, and possibly more, threat activity clusters affiliated with China, with correlations identified between command-and-control (C2) nodes and IP addresses geolocated to Chengdu, the capital city of the Chinese province of Sichuan. One such threat actor is Calypso (aka Bronze Medley and Red Lamassu), which is known to be active since at least September 2016, targeting state institutions in Brazil, India, Kazakhstan, Russia, Thailand, and Turkey. It was first publicly documented by Positive Technologies in October 2019. Some of the key tools in its arsenal include PlugX and backdoors like WhiteBird and BYEBY, the latter of which is part of a broader cluster tracked by ESET under the moniker Mikroceen. The use of Mikroceen has been attributed to a closer known as SixLittleMonkeys, which, in turn, shares tactical overlaps with another China-linked group referred to as Webworm. This puts Showboat along with other shared frameworks like PlugX, ShadowPad, and NosyDoor that have been used by multiple China-nexus groups. This "resource pooling" reinforces the presence of a digital quartermaster that state-sponsored threat actors from China have relied on to supply them with necessary tooling. The starting point of the investigation was an ELF binary that was uploaded to VirusTotal in May 2025, with the malware scanning platform classifying it as a sophisticated Linux backdoor with rootkit-like capabilities. Kaspersky is tracking the artifact as EvaRAT. Black Lotus Labs security researcher Danny Adamitis told The Hacker News that the exact initial access vector used to deliver the malware is currently unknown. However, in the past, Calypso has been observed leveraging an ASPX web shell after exploiting a flaw or breaking into a default account used for remote access. The adversary was also among the earliest China-aligned groups to weaponize CVE-2021-26855, a security vulnerability in Microsoft Exchange Server that serves as the first step in an exploit chain called ProxyLogon. The malware is designed to contact a C2 server, gather system information, and transmit the information back to the server in a PNG field as an encrypted and Base64-encoded string. It's also equipped to upload and download files to and from the host machine, conceal its presence from the process list, and manage C2 servers. To hide itself on the host machine, Showboat retrieves a code snippet hosted on Pastebin. The paste was created on January 11, 2022. Furthermore, the malware can scan for other devices and connect to them via the SOCKS5 proxy. This suggests that the primary purpose of Showboat is to establish a foothold on compromised systems. "This would allow the attackers to interact with machines that are not exposed publicly to the internet and only accessible via the LAN," Black Lotus Labs said. Further infrastructure analysis has uncovered two victims: an Afghanistan-based internet service provider (ISP) and another unknown entity located in Azerbaijan. A secondary C2 cluster using similar X.509 certificates as the original C2 server has uncovered two possible compromises in the U.S. and one in Ukraine. "While some threat actors are increasingly using stealthy, native system tools to evade detection, others still deploy persistent malware implants," Adamitis said. "The presence of such threats should be taken as an early warning sign, indicating the potential for broader and more serious security issues within affected networks." Also put to use by Calypso in the campaign targeting the telecommunications provider in Afghanistan is a fully featured Windows implant codenamed JFMBackdoor that's delivered via DLL side-loading. The attack chain involves a batch script that's used to launch a legitimate executable that then loads the rogue DLL. JFMBackdoor supports a wide range of capabilities, including remote shell access, file operations, network proxying, screenshot capture, and self-removal. "The targeting of Afghanistan and its telecommunications sector aligns with what we assess to almost certainly be Red Lamassu's wider operational goals and objectives," PricewaterhouseCoopers (PwC) said in a coordinated report.
thehackernews.comMay 21, 2026extracted
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. "TrickMo relies on a runtime-loaded APK (dex.module), used also by the previous variant, but updated with new features adding new network-oriented functionality, including reconnaissance, SSH tunnelling, and SOCKS5 proxying capabilities that allow infected devices to function as programmable network pivots and traffic-exit nodes," the Dutch mobile security company said in a report shared with The Hacker News. TrickMo is the name assigned to a device takeover (DTO) malware that's been active in the wild since late 2019. It was first flagged by CERT-Bund and IBM X-Force, describing its ability to abuse Android's accessibility services to hijack one-time passwords (OTPs). It's also equipped with a wide range of features to phish for credentials, log keystrokes, record screen, facilitate live screen streaming, intercept SMS messages, essentially granting the operator complete remote control of the device. The latest versions, labeled TrickMo C, are distributed via phasing websites and dropper apps, the latter of which serve as a conduit for a dynamically loaded APK ("dex.module") that's retrieved at runtime from attacker-controlled infrastructure. A notable shift in the architecture entails the use of the TON decentralized blockchain for stealthy C2 communications. "TrickMo carries an embedded native TON proxy that the host APK starts on a loopback port at process start," ThreatFabric said. "The bot's HTTP client is wired through that proxy, so every outbound command-and-control request is addressed to an .adnl hostname and resolved through the TON overlay." Dropper apps containing the malware masquerade as adult-friendly versions of TikTok through Facebook, whereas the actual malware impersonates Google Play Services - com.app16330.core20461 or com.app15318.core1173 (Dropper) uncle.collop416.wifekin78 or nibong.lida531.butler836 (TrickMo) While previous iterations of "dex.module" implemented the accessibility-driven remote control functionality through a socket.io-based channel, the new version utilizes a network-operative subsystem that turns the malware into a tool for managed foothold than a traditional banking trojan. The subsystem supports commands like curl, dnslookup, ping, telnet, and traceroute, giving the attacker a "remote shell-equivalent for network reconnaissance from the victim's network position, including any internal corporate or home network the device is currently associated with," per ThreatFabric. Another important feature is a SOCKS5 proxy that turns the compromised device into a network exit node that routes malicious traffic, while defeating IP-based fraud-detection signatures on banking, e-commerce and cryptocurrency exchange services. Furthermore, TrickMo includes two dormant features that bundle the Pine hooking framework and declare extensive NFC-related permissions. But neither of them are actually implemented. This likely indicates the core developers are looking to expand on the trojan's capabilities in the future. "Instead of relying on conventional DNS and public internet infrastructure, the malware communicates through .adnl endpoints routed via an embedded local TON proxy, reducing the effectiveness of traditional takedown and network-blocking efforts while making the traffic blend with legitimate TON activity," ThreatFabric said. "This latest variant also expands the operational role of infected devices through SSH tunnelling and authenticated SOCKS5 proxying, effectively turning compromised phones into programmable network pivots and traffic-exit nodes whose connections originate from the victim’s own network environment."
thehackernews.comMay 12, 2026extracted
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy malware called SystemBC. According to new research published by Check Point, the command-and-control (C2 or C&C) server linked to SystemBC has led to the discovery of a botnet of more than 1,570 victims. "SystemBC establishes SOCKS5 network tunnels within the victim’s environment and connects to its C&C server using a custom RC4‑encrypted protocol," Check Point said. "It can also download and execute additional malware, with payloads either written to disk or injected directly into memory." Since its emergence in July 2025, The Gentlemen has quickly established itself as one of the most prolific ransomware groups, claiming more than 320 victims on its data leak site. Operating under a classic double-extortion model, the group is versatile as it's sophisticated, exhibiting capabilities to target Windows, Linux, NAS, and BSD systems with a Go-based locker as well as employing legitimate drivers and custom malicious tools to subvert defenses. Exactly how the threat actors obtain initial access is unclear, although evidence suggests that internet-facing services or compromised credentials are being abused to establish an initial foothold, followed by engaging in discovery, lateral movement, payload staging (i.e., Cobalt Strike, SystemBC, and the encryptor), defense evasion, and ransomware deployment. A notable aspect of the attacks is the abuse of Group Policy Objects (GPOs) to facilitate domain-wide compromise. "By tailoring their tactics against specific security vendors, The Gentlemen have demonstrated an acute awareness of their targets' environments and a willingness to engage in in-depth reconnaissance and tool modification throughout the course of their operation," security vendor Trend Micro noted in an analysis of the group's tradecraft in September 2025. The latest findings from Check Point show that an affiliate of The Gentlemen RaaS deployed SystemBC on a compromised host, with the C2 server linked to the proxy malware commandeering hundreds of victims across the globe, including the U.S., the U.K., Germany, Australia, and Romania. While SystemBC has been used in ransomware operations as far back as 2020, the exact nature of the connection between the malware and The Gentlemen e-crime scheme remains unclear, such as whether it's part of the attack playbook or if it's something deployed by a specific affiliate for data exfiltration and remote access. "During lateral movement, the ransomware makes an attempt to blind Windows Defender on each reachable remote host by pushing a PowerShell script that disables real-time monitoring, adds broad exclusions for the drive, staging share, and its own process, shuts down the firewall, re-enables SMB1, and loosens LSA anonymous access controls, all before deploying and executing the ransomware binary on that host," Check Point said. The ESXi variant incorporates fewer functionalities than the Windows variant, but is equipped to shut down virtual machines to enhance the effectiveness of the attack, adds persistence via crontab, and inhibits recovery before the ransomware binary is deployed. "Most ransomware groups make noise when they launch and then disappear. The Gentlemen are different," Eli Smadja, group manager at Check Point Research, said in a statement shared with The Hacker News. "They've cracked the affiliate recruitment problem by offering a better deal than anyone else in the criminal ecosystem. When we got inside one of their operator's servers, we found over 1,570 compromised corporate networks that hadn't even made the news yet. The real scale of this operation is significantly larger than what's publicly known, and it's still growing." The findings come as Rapid7 highlighted the inner workings of another relatively new ransomware family called Kyber that surfaced in September 2025, targeting Windows and VMware ESXi infrastructures using encryptors developed in Rust and C++, respectively. "The ESXi variant is specifically built for VMware environments, with capabilities for datastore encryption, optional virtual machine termination, and defacement of management interfaces," the cybersecurity company said. "The Windows variant, written in Rust, includes a self-described 'experimental' feature for targeting Hyper-V." "Kyber ransomware isn't a masterpiece of complex code, but it is highly effective at causing destruction. It reflects a shift toward specialization over sophistication." According to data compiled by ZeroFox, at least 2,059 separate ransomware and digital extortion (R&DE) incidents have been observed in Q1 2026, with March accounting for no less than 747 incidents. The most active groups during the time period were Qilin (338), Akira (197), The Gentlemen (192), INC Ransom, and Cl0p. "Notably, North America-based victims accounted for approximately 20 percent of The Gentlemen's attacks in Q3 2025, 2% in Q4 2025, and 13% in Q1 2026," ZeroFox said. "This largely goes against typical regional targeting trends by other R&DE collectives, at least 50 percent of whose victims are North America-based." The Shifting Velocity of Ransomware Attacks Cybersecurity company Halcyon, in its 2025 Ransomware Evolution Report, revealed that the threat continues to mature into something more disciplined and a business-driven criminal enterprise, even as ransomware attacks targeting the automotive industry more than doubled in 2025, taking up 44% of all cyber incidents across the sector. Other significant trends include attempts to impair security Endpoint Detection and Response (EDR) tools, use of the Bring Your Own Vulnerable Driver (BYOVD) attack technique to escalate privileges and disable security solutions, blurring of nation-state and criminal ransomware campaigns, and increased targeting of small and mid-sized organizations and operational technology (OT) environments. "Ransomware continued to grow as a durable, industrialized ecosystem built on specialization, shared infrastructure, and rapid regeneration rather than any single brand," it said. "Law enforcement pressure and infrastructure seizures disrupted major operations, driving fragmentation, rebranding, and intensified competition across a more fluid landscape." Ransomware operations are increasingly fast-moving, with dwell times collapsing from days to hours. About 69% of observed attack attempts have been found to be deliberately staged during nights and weekends to outpace defender response. For instance, attacks involving Akira ransomware have demonstrated an unusual swiftness, rapidly escalating from initial foothold to full encryption within an hour in some cases without detection, highlighting a well-oiled attack engine designed to maximize impact. "Akira's combination of rapid compromise capabilities, disciplined operational tempo, and investment in reliable decryption infrastructure sets it apart from many ransomware operators," Halcyon said. "Defenders should treat Akira not as an opportunistic threat, but as a capable, persistent adversary that will exploit every available weakness to reach its objective."
thehackernews.comApr 21, 2026extracted
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. "Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real time," Italian online fraud prevention firm Cleafy said. "Beyond traditional RAT behavior, Mirax enhances its operational value by turning infected devices into residential proxy nodes. Leveraging SOCKS5 protocol support and Yamux multiplexing, it establishes persistent proxy channels that allow attackers to route their traffic through the victim's real IP address." Details of Mirax first emerged last month when Outpost24's KrakenLabs revealed that a threat actor going by the name "Mirax Bot" has been advertising a private malware-as-a-service (MaaS) offering on underground forums for $2,500 for a three-month subscription. Also available for $1,750 per month is a lightweight variant that removes certain features like the proxy and the ability to bypass Google Play Protect using a crypter. Like other Android malware, Mirax supports the ability to capture keystrokes, steal photos, gather lock screen details, run commands, navigate the user interface, and monitor user activity on the compromised device. It can also dynamically fetch HTML overlay pages from a command-and-control (C2) server to be rendered over legitimate applications for credential theft. The incorporation of a SOCKS proxy, on the other hand, is a relatively lesser-known feature that sets it apart from conventional RAT behavior. The proxy botnet offers several advantages in that it allows threat actors to get around geolocation-based restrictions, evade fraud detection systems, and conduct account takeovers or transaction fraud under the guise of increased anonymity and legitimacy. "Unlike typical MaaS offerings, Mirax is distributed through a highly controlled and exclusive model, limited to a small number of affiliates," researchers Alberto Giust, Alessandro Strino, and Federico Valentini said. "Access appears to be prioritized for Russian-speaking actors with established reputations in underground communities, indicating a deliberate effort to maintain operational security and campaign effectiveness." Attack chains distributing the malware use Meta ads to promote dropper app web pages, tricking unsuspecting users into downloading them. As many as six ads have been observed actively advertising a streaming service with free access to live sports and movies. Of these, five ads are directed against users in Spain. One of the ads, which started running on April 6, 2026, has a reach of 190,987 accounts. The dropper app URLs implement a number of checks to ensure that they are accessed from mobile devices and to prevent automated scans from revealing their true color. The names of the malicious apps are listed below - StreamTV (org.lgvvfj.pluscqpuj or org.dawme.secure5ny) - Dropper app Reproductor de video (org.yjeiwd.plusdc71 or org.azgaw.managergst1d) - Mirax A notable aspect of the campaign is the use of GitHub to host the malicious dropper APK files. In addition, the builder panel offers the ability to choose between two crypters – Virbox and Golden Crypt (aka Golden Encryption) – for enhanced APK protection. Once installed, the dropper instructs users to allow installation from unknown sources to deploy the malware. The process of extracting the final payload is a "sophisticated, multi-stage operation" that's designed to sidestep security analysis and automated sandboxing tools. The malware, after getting installed on the device, masquerades as a video playback utility and prompts the victim to enable accessibility services, thereby allowing it to run in the background, display a fake error message stating the installation was unsuccessful, and serve bogus overlays to conceal malicious activities. It also establishes multiple bidirectional C2 channels for tasking and data exfiltration - WebSocket on port 8443, to manage remote access and execute remote commands. WebSocket on port 8444, to manage remote streaming and data exfiltration. WebSocket on port 8445 (or a custom port), to set up the residential proxy using SOCKS5. "This convergence of RAT and proxy capabilities reflects a broader shift in the threat landscape," Cleafy said. "While residential proxy abuse has historically been associated with compromised IoT devices and low-cost Android hardware such as smart TVs, Mirax marks a new phase by embedding this functionality within a full-featured banking trojan." "This approach not only increases the monetization potential of each infection but also expands the operational scope of attackers, who can now leverage compromised devices for both direct financial fraud and as infrastructure for wider cybercriminal activities." The disclosure comes as Breakglass Intelligence detailed an Arabic-language Android RAT called ASO RAT that's distributed via apps disguised as PDF readers and Syrian government applications. "The platform provides full device compromise capabilities – SMS interception, camera access, GPS tracking, call logging, file exfiltration, and DDoS launching from victim devices," the company said. "A multi-user panel with role-based access control suggests this operates as a RAT-as-a-Service or supports a multi-operator team." It's currently not known what the exact end goals of the campaign are, but Syria-themed lures for the apps (e.g., SyriaDefenseMap and GovLens) suggest that it may be targeting individuals with an interest in Syrian military or governance matters as part of what's suspected to be a surveillance operation. Update Following the publication of the story, a Google spokesperson shared the following statement with The Hacker News - "Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."
thehackernews.comApr 14, 2026extracted
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access
Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that's exploiting a recently disclosed critical security flaw in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability in question is CVE-2026-20131 (CVSS score: 10.0), a case of insecure deserialization of user-supplied Java byte stream, which could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary Java code as root on an affected device. According to data gleaned from the tech giant's MadPot global sensor network, the security flaw is said to have been exploited as a zero-day since January 26, 2026, more than a month before it was publicly disclosed by Cisco. "This wasn't just another vulnerability exploit; Interlock had a zero-day in their hands, giving them a week's head start to compromise organizations before defenders even knew to look. Upon making this discovery, we shared our findings with Cisco to help support their investigation and protect customers," CJ Moses, chief information security officer (CISO) of Amazon Integrated Security, said in a report shared with The Hacker News. The discovery, Amazon said, was made possible, thanks to an operational security blunder on the part of the threat actor that exposed their cybercrime group's operational toolkit via a misconfigured infrastructure server, offering insights into its multi-stage attack chain, bespoke remote access trojans, reconnaissance scripts, and evasion techniques. The attack chain involves sending crafted HTTP requests to a specific path in the affected software with an aim to execute arbitrary Java code, after which the compromised system issues an HTTP PUT request to an external server to confirm successful exploitation. Once this step is complete, the commands are sent to fetch an ELF binary from a remote server, which hosts other tools linked to Interlock. The list of identified tools is as follows - A PowerShell reconnaissance script used for systematic Windows environment enumeration, gathering details about operating system and hardware, running services, installed software, storage configuration, Hyper-V virtual machine inventory, user file listings across Desktop, Documents, and Downloads directories, browser artifacts from Chrome, Edge, Firefox, Internet Explorer, and 360 browser, active network connections, and RDP authentication events from Windows event logs. Custom remote access trojans written in JavaScript and Java for command-and-control, interactive shell access, arbitrary command execution, bidirectional file transfer, and SOCKS5 proxy capability. It also supports self-update and self-delete mechanisms to replace or remove the artifact without having to reinfect the machine and challenge forensic investigation. A Bash script for configuring Linux servers as HTTP reverse proxies to obscure the attacker's true origins. The script delivers fail2ban, an open-source Linux intrusion prevention tool, and compiles and spawns an HAProxy instance that listens on port 80 and forwards all inbound HTTP traffic to a hard-coded target IP address. Furthermore, the infrastructure laundering script runs a log erasure routine as a cron job every five minutes to aggressively delete and purge the contents of *.log files and suppress shell history by unsetting the HISTFILE variable. A memory-resident web shell for inspecting incoming requests for specially crafted parameters containing encrypted command payloads, which are then decrypted and executed. A lightweight network beacon for phoning attacker-controlled infrastructure likely to validate successful code execution or confirm network port reachability following initial exploitation. ConnectWise ScreenConnect for persistent remote access and for serving as an alternative pathway should other footholds be detected and removed. Volatility Framework, an open-source memory forensics framework to parse memory dumps and access to sensitive data such as credentials. Certify, an open-source offensive security tool to exploit misconfigurations in Active Directory Certificate Services (AD CS) and identify vulnerable certificate templates and enrollment permissions that allow requesting authentication-capable certificates. The links to Interlock stem from "convergent" technical and operational indicators, including the embedded ransom note and TOR negotiation portal. Evidence shows that the threat actor is likely operational during the UTC+3 time zone. In light of active exploitation of the flaw, users are advised to apply patches as soon as possible, conduct security assessments to identify potential compromise, review ScreenConnect deployments for unauthorized installations, and implement defense-in-depth strategies. "The real story here isn't just about one vulnerability or one ransomware group—it's about the fundamental challenge zero-day exploits pose to every security model," Moses said. "When attackers exploit vulnerabilities before patches exist, even the most diligent patching programs can't protect you in that critical window." "This is precisely why defense-in-depth is essential—layered security controls provide protection when any single control fails or hasn't yet been deployed. Rapid patching remains foundational in vulnerability management, but defense in depth helps organizations not to be defenseless during the window between exploit and patch." The disclosure comes as Google revealed that ransomware actors are changing their tactics in response to declining payment rates, targeting vulnerabilities in common VPNs and firewalls for initial access and leaning less on external tooling and more on built-in Windows capabilities. Multiple threat clusters, both ransomware operators themselves and initial access brokers, have also been found to employ malvertising and/or search engine optimization (SEO) tactics to distribute malware payloads for initial access. Other commonly observed techniques include the use of compromised credentials, backdoors, or legitimate remote desktop software to establish a foothold, as well as relying on built-in and already installed tools for reconnaissance, privilege escalation, and lateral movement. "While we anticipate ransomware to remain one of the most dominant threats globally, the reduction in profits may cause some threat actors to seek other monetization methods," Google said. "This could manifest as increased data theft extortion operations, the use of more aggressive extortion tactics, or opportunistically using access to victim environments for secondary monetization mechanisms such as using compromised infrastructure to send phishing messages." Update Cisco has updated its advisory for CVE-2026-20131 to confirm reports of active exploitation. "Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability," it added.
thehackernews.comMar 18, 2026extracted
Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls
Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls Amazon threat intelligence has identified an active Interlock ransomware campaign exploiting CVE-2026-20131, a critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device, which was disclosed by Cisco on March 4, 2026. After Cisco’s disclosure, Amazon threat intelligence began research into this vulnerability using Amazon MadPot’s global sensor network—a system of honeypot servers that attract and monitor cybercriminal activity. While looking for any current or past exploits of this vulnerability, our research found that Interlock was exploiting this vulnerability 36 days before its public disclosure, beginning January 26, 2026. This wasn’t just another vulnerability exploit, Interlock had a zero-day in their hands, giving them a week’s head start to compromise organizations before defenders even knew to look. Upon making this discovery, we shared our findings with Cisco to help support their investigation and protect customers. A misconfigured infrastructure server—essentially, a poorly secured staging area used by the attackers—exposed Interlock’s complete operational toolkit. This rare mistake provided Amazon’s security teams with visibility into the ransomware group’s multi-stage attack chain, custom remote access trojans (backdoor programs that give attackers control of compromised systems), reconnaissance scripts (automated tools for mapping victim networks), and evasion techniques. AWS infrastructure and customer workloads on AWS were not observed to be involved in this campaign. This advisory shares comprehensive technical analysis and indicators of compromise to help organizations identify potential compromise and defend against Interlock’s operations. Organizations running Cisco Secure Firewall Management Center should immediately apply Cisco’s security patches and review the indicators provided below. Discovery and investigation timeline Amazon threat intelligence identified threat activity potentially related to CVE-2026-20131 beginning January 26, 2026, predating the public disclosure. Observed activity involved HTTP requests to a specific path in the affected software. Request bodies contained Java code execution attempts and two embedded URLs: one used to deliver configuration data supporting the exploit, and another designed to confirm successful exploitation by causing a vulnerable target to perform an HTTP PUT request and upload a generated file. Multiple variations of these URLs were observed across different exploit attempts. To advance the investigation and obtain additional threat intelligence, we performed the expected HTTP PUT request with the anticipated file content—essentially, we pretended to be a successfully compromised system. This successfully prompted Interlock to proceed to the next stage, issuing commands to fetch and execute a malicious ELF binary (a Linux executable file) from a remote server. When analysts retrieved the binary, they discovered the same host (attacker-controlled server) is used for distributing Interlock’s entire operational toolkit. The exposed infrastructure organized artifacts into separate paths corresponding to individual targets, with the same paths used for both downloading tools to compromised hosts and uploading operational artifacts back to the staging server. Attribution to Interlock ransomware The ELF binary and associated artifacts are attributable to the Interlock ransomware family based on convergent technical and operational indicators. The embedded ransom note and TOR negotiation portal are consistent with Interlock’s established branding and infrastructure. The ransom note’s invocation of multiple data protection regulations reflects Interlock’s documented practice of citing regulatory exposure to pressure victims, essentially threatening organizations not just with data encryption, but with regulatory fines and compliance violations. The campaign-specific organization identifier embedded in the note aligns with Interlock’s per-victim tracking model. Interlock has historically targeted specific sectors where operational disruption creates maximum pressure for payment. Education represents the largest share of their activity, followed by engineering, architecture, and construction firms, manufacturing and industrial organizations, healthcare providers, and government and public sector entities. Temporal analysis performed on timestamps from observed threat activities, artifacts stored on the misconfigured infrastructure server, and metadata embedded within recovered threat artifacts indicates the actor most likely operates in UTC+3 with 75–80% confidence. Systematic analysis across all UTC offsets showed UTC+3 produced the best fit: first activity around 08:30, peak activity between 12:00 and 18:00, and a probable sleep window of 00:30–08:30. Technical analysis: Interlock’s operational toolkit Post-compromise reconnaissance script Once Interlock gains initial access, they use a variety of priority tools to complete their attack. Amazon threat intelligence teams recovered a PowerShell script designed for systematic Windows environment enumeration (automated information gathering about the victim’s network). The script collects operating system and hardware details, running services, installed software, storage configuration, Hyper-V virtual machine inventory, user file listings across Desktop, Documents, and Downloads directories, browser artifacts from Chrome, Edge, Firefox, Internet Explorer, and 360 browser (including history, bookmarks, stored credentials, and extensions), active network connections correlated with responsible processes, ARP tables, iSCSI session data, and RDP authentication events from Windows event logs. The script stages results to a centralized network share (\JK-DC2\Temp) using each system’s fully qualified hostname to create dedicated directories—essentially creating a folder for each compromised computer. Following collection, it compresses data into ZIP archives named after each hostname and removes original raw data. This structured per-host output format indicates the script operates across multiple machines within a network—a hallmark of ransomware intrusion chains that prepare for organization-wide encryption. Custom remote access trojans Remote access trojans (RATs) are malicious programs that give attackers persistent control over compromised systems, functioning like unauthorized remote desktop software. JavaScript implant: Amazon threat intelligence recovered an obfuscated JavaScript remote access trojan that suppresses debugging output by overriding browser console methods (hiding its activity from basic detection tools). On execution, it profiles the infected host using PowerShell and Windows Management Instrumentation (WMI), collecting system identity, domain membership, username, OS version, and privilege context before transmitting this data during an encrypted initialization handshake. Command-and-control communication occurs over persistent WebSocket connections with RC4-encrypted messages using per-message 16-byte random keys embedded in packet headers—essentially, each message uses a different encryption key, making interception more difficult. The implant cycles through multiple operator-controlled hostnames and IP addresses in randomized order with exponential backoff between reconnection attempts. The implant provides interactive shell access, arbitrary command execution, bidirectional file transfer, and SOCKS5 proxy capability for tunneling TCP traffic (routing malicious traffic through other systems to hide its origin). Self-update and self-delete capabilities allow operators to replace or remove the implant without reinfection, supporting operational cleanup to hinder forensic investigation. Java implant: A functionally equivalent client implemented in Java provides identical command-and-control capabilities. Built on GlassFish ecosystem libraries, it uses Grizzly for non-blocking I/O transport and Tyrus for WebSocket protocol communication. In simpler terms, Interlock built the same backdoor in two different programming languages, ensuring they maintain access even if defenders detect one version. Infrastructure laundering script Sophisticated threat actors don’t attack from their own infrastructure, they build disposable relay networks to hide their tracks. Amazon threat intelligence teams identified a Bash script that configures Linux servers as HTTP reverse proxies (intermediary servers that forward traffic to hide the attacker’s true location). The script performs system updates, installs fail2ban with SSH brute-force protection, and compiles HAProxy 3.1.2 from source. The HAProxy instance listens on port 80 and forwards all inbound HTTP traffic to a hardcoded target IP, with systemd ensuring persistence across reboots. A notable component is a log erasure routine running as a cron job every five minutes. The routine truncates all *.log files under /var/log and suppresses shell history by unsetting the HISTFILE variable. This aggressive evidence destruction, wiping logs every five minutes, combined with the purpose-built HTTP forwarding proxy, indicates the script establishes disposable traffic-laundering relay nodes. These nodes obscure exploit traffic origin, relay command-and-control communications, or proxy data exfiltration, making it nearly impossible to trace attacks back to their source. Memory-resident webshell Amazon threat intelligence teams observed a Java class file delivered as an alternative to the ELF binary drop. When loaded by the Java Virtual Machine (JVM), its static initializer registers a ServletRequestListener with the server’s StandardContext, essentially installing a persistent memory-resident backdoor that intercepts HTTP requests without writing files to disk. This “fileless” approach evades traditional antivirus scanning that looks for malicious files. The listener inspects incoming requests for specially crafted parameters containing encrypted command payloads. Payloads are decrypted using AES-128 with a key derived from the MD5 hash of the hardcoded seed “geckoformboundary99fec155ea301140cbe26faf55ed2f40″ (using the first 16 characters: 09b1a8422e8faed0). Decrypted payloads are treated as compiled Java bytecode, dynamically loaded into the JVM, and executed—a technique designed to evade file-based detection by running malicious code entirely in memory. Connectivity verification tool Amazon threat intelligence teams recovered Java class files implementing a basic TCP server listening on port 45588 (encoded as Unicode character 넔 to obscure the port number from static analysis). The server accepts connections, logs connecting IP addresses, sends a greeting message, and immediately closes connections. This operational profile is consistent with a lightweight network beacon—essentially a “phone home” tool used to verify successful code execution or confirm network port reachability following initial exploitation. Legitimate tool abuse Interlock deployed ConnectWise ScreenConnect, a legitimate commercial remote desktop tool, alongside custom implants. When ransomware operators deploy legitimate remote access tools alongside their custom malware, they’re buying insurance—if defenders find and remove one backdoor, they still have another way in. This indicates multiple redundant remote access mechanisms—a pattern consistent with ransomware operators seeking to maintain access even if individual footholds are removed. The tool’s legitimate network footprint helps blend with authorized remote administration traffic, making detection more challenging. Amazon threat intelligence teams also recovered Volatility, an open-source memory forensics framework typically used by incident responders (the same tool defenders use to investigate attacks). While no artifacts indicated automated use, its presence alongside custom implants and reconnaissance scripts is consistent with advanced threat operations. Both ransomware groups and nation-state actors have been observed deploying Volatility during intrusions. The tool’s focus on parsing memory dumps provides access to sensitive data such as credentials stored in RAM, which can enable lateral movement (spreading through the network) and deeper environment compromise in support of ransom operations or espionage objectives. Interlock also used Certify, an open source offensive security tool designed to exploit misconfigurations in Active Directory Certificate Services (AD CS). For ransomware operators, Certify provides a pathway to identify vulnerable certificate templates and enrollment permissions that allow requesting authentication-capable certificates. These certificates can be used to impersonate users, escalate privileges, or maintain persistent access. These capabilities directly support both initial compromise and long-term persistence objectives in ransomware operations. Indicators of compromise (IoCs) The following indicators support defensive measures by organizations that may be affected. Due to Interlock’s use of content variation techniques, most file hashes are not included as reliable indicators. The threat actor modified most artifacts like scripts and binaries downloaded to different targets. This resulted in different file hashes for functionally identical tools. The customization allowed each attack to evade signature-based detection that looks for exact file matches. Defensive recommendations Organizations should take the following actions to protect against Interlock ransomware operations. Immediate actions: Apply Cisco’s security patches for Cisco Secure Firewall Management Center Review logs for the indicators of compromise listed above Conduct security assessments to identify potential compromise Review ScreenConnect deployments for unauthorized installations Detection opportunities: Monitor for PowerShell scripts staging data to network shares with hostname-based directory structures Detect Java ServletRequestListener registrations in web application contexts (unusual modifications to Java web applications) Identify HAProxy installations with aggressive log deletion cron jobs (proxy servers that erase their own logs every five minutes) Watch for TCP connections to unusual high-numbered ports (e.g., 45588) Long-term measures: Implement defense-in-depth strategies with multiple layers of security controls Maintain continuous threat monitoring and hunting capabilities Ensure comprehensive logging with secure, centralized log storage (stored separately from systems that could be compromised) Regularly test incident response procedures for ransomware scenarios Educate security teams on Interlock’s tactics, techniques, and procedures The real story here isn’t just about one vulnerability or one ransomware group—it’s about the fundamental challenge zero-day exploits pose to every security model. When attackers exploit vulnerabilities before patches exist, even the most diligent patching programs can’t protect you in that critical window. This is precisely why defense in depth is essential—layered security controls provide protection when any single control fails or hasn’t yet been deployed. Rapid patching remains foundational in vulnerability management, but defense in depth helps organizations not to be defenseless during the window between exploit and patch. Amazon Threat Intelligence teams continue to monitor Interlock ransomware operations and will provide updates as additional information becomes available. The intelligence gathered from this campaign is being integrated into AWS security services to protect customers proactively. If you have feedback about this post, submit comments in the Comments section below. If you have questions about this post, contact AWS Support.
aws.amazon.comMar 18, 2026extracted
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks
Cybersecurity researchers have disclosed details of a suspected artificial intelligence (AI)-generated malware codenamed Slopoly put to use by a financially motivated threat actor named Hive0163. "Although still relatively unspectacular, AI-generated malware such as Slopoly shows how easily threat actors can weaponize AI to develop new malware frameworks in a fraction of the time it used to take," IBM X-Force researcher Golo Mühr said in a report shared with The Hacker News. Hive0163's operations are driven by extortion through large-scale data exfiltration and ransomware. The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware. In one ransomware attack observed by the company in early 2026, the threat actor was observed deploying Slopoly during the post-exploitation phase so as to maintain persistent access to the compromised server for more than a week. Slopoly's discovery can be traced back to a PowerShell script that's likely deployed into the "C:\ProgramData\Microsoft\Windows\Runtime\" folder by means of a builder. Persistence is achieved by setting up a scheduled task called "Runtime Broker." There are signs that the malware was developed with the help of an as-yet-undetermined large language model (LLM). This includes the presence of extensive comments, logging, error handling, and accurately named variables. The comments also describe the script as a "Polymorphic C2 Persistence Client," indicating that it's part of a command-and-control (C2) framework. "However, the script does not possess any advanced techniques and can hardly be considered polymorphic, since it's unable to modify its own code during execution," Mühr noted. "The builder may, however, generate new clients with different randomized configuration values and function names, which is standard practice among malware builders." The PowerShell script functions as a full-fledged backdoor that can beacon a heartbeat message containing system information to a C2 server every 30 seconds, poll for a new command every 50 seconds, execute it via "cmd.exe," and relay the results back to the server. The exact nature of the commands run on the compromised network is currently unknown. The attack in itself is said to have leveraged the ClickFix social engineering tactic to trick the victim into running a PowerShell command, which then downloads NodeSnake, a known malware attributed to Hive0163. A first-stage component, NodeSnake, is designed to run shell commands, establish persistence, and retrieve and launch a wider malware framework referred to as Interlock RAT. Hive0163 has a track record of employing ClickFix and malvertising for initial access. Another method the threat actor uses to establish a foothold is by relying on initial access brokers such as TA569 (aka SocGholish) and TAG-124 (aka KongTuke and LandUpdate808). The framework has multiple implementations in PowerShell, PHP, C/C++, Java, and JavaScript to support both Windows and Linux. Like NodeSnake, it also communicates with a remote server to fetch commands that allow it to launch a SOCKS5 proxy tunnel, spawn a reverse shell on the infected machine, and deliver more payloads, such as Interlock ransomware and Slopoly. The emergence of Slopoly adds to a growing list of AI-assisted malware, which also includes VoidLink and PromptSpy, highlighting how bad actors are using the technology to accelerate malware development and scale their operations. "The introduction of AI-generated malware does not pose a new or sophisticated threat from a technical standpoint," IBM X-Force said. "It disproportionately enables threat actors by reducing the time an operator needs to develop and execute an attack."
thehackernews.comMar 12, 2026extracted
ThreatsDay Bulletin: OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & More
Another Thursday, another pile of weird security stuff that somehow happened in just seven days. Some of it is clever. Some of it is lazy. A few bits fall into that uncomfortable category of “yeah… this is probably going to show up in real incidents sooner than we’d like.” The pattern this week feels familiar in a slightly annoying way. Old tricks are getting polished. New research shows how flimsy certain assumptions really are. A couple of things that make you stop mid-scroll and think, “wait… people are actually pulling this off?” There’s also the usual mix of strange corners of the ecosystem doing strange things — infrastructure behaving a little too professionally for comfort, tools showing up where they absolutely shouldn’t, and a few cases where the weakest link is still just… people clicking stuff they probably shouldn’t. Anyway. If you’ve got five minutes and a mild curiosity about what attackers, researchers, and the broader internet gremlins were up to lately, this week’s ThreatsDay Bulletin on The Hacker News has the quick hits. Scroll on. OAuth consent abuseCloud security firm Wiz has warned of the dangers posed by malicious OAuth applications, highlighting how "consent fatigue" could open the door for attackers to gain access to a victim's sensitive data by giving their malicious apps a legitimate-looking name. By accepting the permissions requested by a rogue OAuth application, the user is "adding" the attacker's app into their company's tenant. "Once 'Accept' is clicked, the sign-in process is complete," Wiz said. "But instead of going to a normal landing page, the access token is sent to the attacker's Redirect URL. With that token, the attacker now has access to the user's files or emails without ever needing to know their password." The Google-owned company also said it detected a large-scale campaign active in early 2025 that involved 19 distinct OAuth applications impersonating well-known brands such as Adobe, DocuSign, and OneDrive, and targeted multiple organizations. Details of the activity were documented by Proofpoint in August 2025. Messaging account takeoverRussian-linked hackers are trying to break into the Signal and WhatsApp accounts of government officials, journalists, and military personnel globally with an aim to get unauthorized access – not by breaking encryption, but by simply tricking people into handing over the security verification codes or PINs. "The most frequently observed method used by the Russian hackers is to masquerade as a Signal Support chatbot in order to induce their targets to divulge their codes," the Netherlands Defence Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) said. "The hackers can then use these codes to take over the user's account. Another method used by the Russian actors takes advantage of the 'linked devices' function within Signal and WhatsApp." It's worth noting that a similar warning was issued by Germany last month. "These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users' accounts," Signal said. Google warned last year that Signal's widespread use among Ukrainian soldiers, politicians, and journalists had made it a frequent target for Russian espionage operations. Cloud breach via software flawsGoogle has revealed that threat actors are increasingly exploiting vulnerabilities in third-party software to breach cloud environments. "The window between vulnerability disclosure and mass exploitation collapsed by an order of magnitude, from weeks to days," the tech giant's cloud division said. "While software-based exploits increased, initial access by threat actors using misconfiguration, which accounted for 29.4% of incidents in the first half of 2025, dropped to 21% in H2 2025. Similarly, exposed sensitive UI or APIs continued a downward trend, falling from 11.8% in H1 to 4.9% in H2. This decline suggests that automated guardrails are making identity and configuration errors harder to exploit and that threat actors are being driven toward more sophisticated and costly vectors that specifically target software vulnerabilities to gain a foothold." In most attacks investigated by Google, the actor's objective was silent exfiltration of high volumes of data without immediate extortion and long-term persistence. Microcontroller debug bypassNew research from Quarkslab has found that it's possible to bypass the 16-byte password protection required for debug access on several variants of the RH850 microcontroller family using voltage fault injection in under one minute. "Voltage glitching technique is performed by underpowering or overpowering the chip for a controlled amount of time to alter its behavior," the security company said. "The crowbar attack is a specific type of voltage glitch where the power supply is shorted to the ground instead of injecting a specific voltage, using a MOSFET, for example." Solar Spider suspects arrestedTwo Nigerian nationals have been arrested by authorities in the Indian state of Uttar Pradesh for their alleged involvement in an e-crime operation known as Solar Spider. The suspects are believed to have been planning to siphon large amounts of money by leveraging security flaws in Indian cooperative banking systems. According to a report from The420.in, the individuals have been identified as Okechukwu Imeka and Chinedu Okafor. The duo is suspected to be part of an international fraud syndicate involved in targeting financial institutions. Solar Spider has a history of targeting banking systems across India and the Middle East, often through spear-phishing campaigns. In a report published in July 2025, Tata Communications revealed that threat actors leverage their initial access to steal credentials, tamper with NEFT/RTGS transactions, and focus on Structured Financial Messaging System (SFMS) and Host-to-Host (H2H) infrastructures. The group is also known for deploying a sophisticated attack framework dubbed JSOutProx since at least 2019. PlugX malware campaignCheck Point has disclosed targeted campaigns against entities in Qatar using conflict-related content as lures to deliver malware families like PlugX and Cobalt Strike. The attack chain uses Windows shortcut (LNK) files contained within ZIP archives, which, when opened, cause it to download a next-stage payload from a compromised server. The payload then displays the decoy document while using DLL side-loading to deploy PlugX. The activity, detected on March 1, 2026, has been attributed to Mustang Panda (aka Camaro Dragon). A second attack has been observed using a password-protected archive to execute a previously undocumented Rust loader that's responsible for deploying Cobalt Strike using DLL side-loading. "This loader exploits DLL hijacking of nvdaHelperRemote.dll, a component of the open-source screen reader NVDA. Abuse of this component has previously been observed in only a limited number of Chinese-nexus campaigns, including China-aligned activity associated with a campaign delivering Voldemort backdoor, as well as a wave of attacks targeting the Philippines and Myanmar back in 2025," Check Point said. While this attack is assessed as China-aligned, it has not been attributed to a specific threat actor. "The attackers leveraged the ongoing war in the Middle East to make their lures more credible and engaging, demonstrating the ability to rapidly adapt to major developments and breaking news," the company said. Teen DDoS kit sellersPolish police have referred seven suspected minor cybercriminals to family court over an alleged scheme to sell distributed denial-of-service (DDoS) kits online. The suspects, aged between 12 and 16 at the time of the alleged offenses, face charges related to selling DDoS tools as part of a profit-driven scheme designed to target popular websites, including auction and sales portals, IT domains, hosting services, and accommodation booking sites. "Using the tools they administer, popular websites such as auction and sales portals, IT domains, hosting services, and accommodation booking services were attacked," Poland's Central Bureau for Combating Cybercrime (CBZC) said. Phishing-resistant Windows loginMicrosoft is rolling out passkey support for Microsoft Entra on Windows devices, adding phishing-resistant passwordless authentication via Windows Hello. "We're introducing Microsoft Entra passkeys on Windows to enable phishing-resistant sign-in to Entra-protected resources. This update allows users to create device-bound passkeys stored in the Windows Hello container and authenticate using Windows Hello methods (face, fingerprint, or PIN)," Microsoft said. "It also expands passwordless authentication to Windows devices that aren't Entra-joined or registered, helping organizations strengthen security and reduce reliance on passwords." Sysmon built into WindowsMicrosoft has natively integrated System Monitor (Sysmon) functionality directly into Windows 11 and Windows Server 2025 as an optional built-in feature as of Windows 11's March feature update (KB5079473). It's disabled by default. The company announced the integration in November 2025. "You no longer need to package it dynamically; you can simply enable it programmatically via PowerShell," Nick Carroll, cyber incident response manager at Nightwing, said. "Coupled with Microsoft's simultaneous announcement that Windows Intune will enable 'hotpatching' by default in May 2026, this drastically lowers the barrier to entry for deep endpoint visibility and represents a massive operational win for network defenders." Canada phishing campaignAn active phishing campaign is targeting Canadian residents (and possibly present in other countries) using fraudulent domains impersonating trusted institutions, including the Government of British Columbia and Hydro-Québec, with the goal of collecting personal information and credit card details, Flare said. The hosting infrastructure behind this campaign is linked to RouterHosting LLC (aka Cloudzy), a provider that was publicly accused in 2023 of supplying services to at least 17 state-sponsored hacking groups from countries including Iran, China, Russia, and North Korea. Private link safety in chatsMeta has detailed the workings of Advanced Browsing Protection (ABP) in Messenger, which protects the privacy of the links clicked on within chats while still warning people about malicious links. "In its standard setting, Safe Browsing uses on-device models to analyze malicious links shared in chats," the company said. "But we've extended this further with an advanced setting called Advanced Browsing Protection (ABP) that leverages a continually updated watchlist of millions more potentially malicious websites." ABP leverages an approach called private information retrieval (PIR) to implement a privacy-preserving "URL-matching" scheme between the client's query and the server hosting the database, along with Oblivious HTTP, AMD SEV-SNP, and Path ORAM for added privacy guarantees. BlackSanta EDR killerA sophisticated attack campaign targeting HR departments and job recruiters has combined social engineering with advanced evasion techniques to stealthily compromise systems by avoiding analysis environments and leveraging a specialized module designed to kill antivirus and endpoint detection software. The attack begins with a resume-themed ISO file delivered likely through spam or phishing emails, which then drops next-stage payloads, including a DLL that's launched via DLL side-loading to gather basic system information, initiate communication with a remote server, run sandbox checks, employ geographic filtering to avoid running in restricted regions, and drop additional payloads, such as BlackSanta EDR that employs legitimate but vulnerable kernel drivers to impair system defenses, a known tactic referred to as Bring Your Own Vulnerable Driver (BYOVD). "Rather than functioning as a simple auxiliary payload, BlackSanta acts as a dedicated defense-neutralization module that programmatically identifies and interferes with protection and monitoring processes prior to the deployment of follow-on stages," Aryaka said. "By targeting endpoint security engines alongside telemetry and logging agents, it directly reduces alert generation, limits behavioral logging, and weakens investigative visibility on compromised hosts." It's currently not known what the follow-on payloads are or how widespread the campaign is. Phishing campaigns don't just target HR teams, but also impersonate them in attacks. "Impersonating HR provides many benefits to threat actors. Tasks from HR are typically mandatory, so HR emails carry authority," Cofense said. "Legitimate HR tasks can also have strict deadlines, which a threat actor can use to impose urgency. Finally, regular HR tasks are expected by employees." ZIP evasion techniqueA new technique dubbed Zombie ZIP allows attackers to conceal payloads in specially crafted compressed files that can bypass security tools. "Malformed ZIP headers can cause antivirus and endpoint detection and response software (EDR) to produce false negatives," the CERT Coordination Center (CERT/CC) said. "Despite the presence of malformed headers, some extraction software is still able to decompress the ZIP archive, allowing potentially malicious payloads to run upon file decompression." The vulnerability, tracked as CVE-2026-0866, has been codenamed Zombie Zip by researcher Christopher Aziz, who discovered it. The technique was demonstrated by Bombadil Systems security researcher Chris Aziz. AI agent breaches platformResearchers at autonomous offensive security startup CodeWall said their AI agent hacked McKinsey's internal AI platform Lili and gained full read and write access to the chatbot platform in just two hours. This enabled access to the entire production database, including 46.5 million chat messages about strategy, mergers and acquisitions, and client engagements, all in plaintext, along with 728,000 files containing confidential client data, 57,800 user accounts, and 95 system prompts controlling the AI's behavior. The development is an indicator that agentic AI tools are becoming more effective for conducting cyber attacks. The agent said it found over 200 endpoints that were totally exposed, out of which 22 were unprotected. One of these endpoints, which wrote user search queries to the database, suffered from an SQL injection that could have made it possible to access sensitive data and rewrite the system prompts silently. McKinsey has since addressed the problem. There is no evidence that the issue was exploited in the wild. Teams social engineering malwareHackers have contacted employees at financial and healthcare organizations over Microsoft Teams to trick them into granting remote access through Quick Assist and deploy a new piece of malware called A0Backdoor. The modus operandi, which aligns with the playbook of Storm-1811 (aka STAC5777 or Blitz Brigantine), employs social engineering to gain the employee's trust by first flooding their inbox with spam and then contacting them over Teams, pretending to be the company's IT staff and offering assistance with the problem. To obtain access to the target machine, the threat actor instructs the user to start a Quick Assist remote session, which is used to deploy a malicious toolset that includes digitally signed MSI packages, some of which were hosted on Microsoft cloud storage tied to personal accounts. The installers serve as a conduit for launching a DLL that, in turn, decrypts and runs shellcode responsible for running anti-analysis checks and dropping A0Backdoor, which establishes contact to a remote server using DNS tunnelling to receive commands. The activity has been active since at least August 2025 through late February 2026. Industrialized disinformation networkThe Russian influence operation known as Doppelgänger has been described as industrialized and prioritizing infrastructure resilience, scalability, and operational continuity over short-term visibility. "Rather than functioning as a loose collection of spoofed websites or transient propaganda outlets, the network exhibits the hallmarks of a coordinated, professionally managed influence apparatus," DomainTools said. "At its core, the ecosystem relies on systematic media brand impersonation executed at scale." Campaigns mounted as part of the operation exhibit deliberate geographic micro-targeting across European Union member states and the U.S. Pentagon AI disputeAnthropic has filed a lawsuit to block the Pentagon from placing it on a national security blocklist, stating the supply chain risk designation was unlawful and violated its free speech and due process rights. The development comes after the Pentagon formally branded the artificial intelligence (AI) company a supply chain risk after it refused to remove guardrails against using its technology for autonomous weapons or domestic surveillance. In its own statement, Anthropic said "we had been having productive conversations with the Department of War over the last several days, both about ways we could serve the Department that adhere to our two narrow exceptions, and ways for us to ensure a smooth transition if that is not possible." However, the Pentagon said there is no active negotiation happening with Anthropic. It also reiterated that the department "does not do and will not do domestic mass surveillance." The development follows OpenAI's own deal with the U.S. Department of Defense, with CEO Sam Altman stating the defense contract would include protections against the same red lines that Anthropic had insisted on. The company has since amended its contract to ensure "the AI system shall not be intentionally used for domestic surveillance of U.S. persons and nationals." Anthropic's CEO Dario Amodei has called OpenAI's messaging "safety theater" and "straight up lies." GitHub SEO malwareA new information stealer campaign distributing BoryptGrab is leveraging a network of more than 100 public GitHub repositories that claim to offer software tools for free, using search engine optimization (SEO) keywords to lure victims. The multi-stage infection chain begins when a ZIP file is downloaded from a fake GitHub download page. BoryptGrab can harvest browser data, cryptocurrency wallet information, and system information. It's also capable of capturing screenshots, collecting common files, and extracting Telegram information, Discord tokens, and passwords. Also delivered as part of the attack is a backdoor called TunnesshClient that establishes a reverse SSH tunnel to communicate with the attacker and acts as a SOCKS5 proxy. The earliest ZIP file dates back to late 2025. Certain iterations of the campaign have been found to deliver Vidar Stealer or a Golang downloader dubbed HeaconLoad, which then downloads and runs additional payloads. RAT campaign against IndiaThe Pakistan-aligned threat actor known as Transparent Tribe has been attributed to a fresh set of attacks targeting Indian government entities to infect systems with a RAT that enables remote command execution, process monitoring and termination, remote program execution, file upload/download, file enumeration, screenshot capture, and live screen monitoring capabilities. "The campaign primarily relies on social engineering techniques, distributing a malicious ZIP archive disguised as examination-related documents to persuade recipients to interact with the files," CYFIRMA said. "Upon extraction, the archive delivers deceptive shortcut files along with a macro-enabled PowerPoint add-in, which collectively initiate the infection chain. The threat actors employ multiple layers of obfuscation and redundant execution mechanisms to enhance the probability of successful compromise while reducing the likelihood of user suspicion." Signed phishing malwareMicrosoft is warning of multiple phishing campaigns using workplace meeting lures, PDF attachments, and abuse of legitimate binaries to deliver signed malware. The activity, observed in February 2026, has not been attributed to a specific threat actor or group. "Phishing emails directed users to download malicious executables masquerading as legitimate software," the company said. "The files were digitally signed using an Extended Validation (EV) certificate issued to TrustConnect Software PTY LTD. Once executed, the applications installed remote monitoring and management (RMM) tools that enabled the attacker to establish persistent access on compromised systems." Some of the deployed RMM tools include ScreenConnect, Tactical RMM, and MeshAgent. The use of the TrustConnect branding was disclosed by Proofpoint last week. Furthermore, the deployment of multiple RMM frameworks within a single intrusion indicates a deliberate strategy to ensure continuous access and ensure operational resilience even if one access mechanism is detected or removed. "These campaigns demonstrate how familiar branding and trusted digital signatures can be abused to bypass user suspicion and gain an initial foothold in enterprise environments," Microsoft added. TikTok allowed in CanadaFollowing a national security review of TikTok, Canada's Minister of Industry, Mélanie Joly, said the company can keep its business operational. "TikTok will implement enhanced protection for Canadians’ personal information, including new security gateways and privacy-enhancing technologies to control access to Canadian user data in order to reduce the risk of unauthorized or prohibited access," the government said. "TikTok will implement enhanced protections for minors." The development marks a complete 180 from a 2024 decision, when it was ordered to shut down its operations, citing unspecified "national security risks." However, that order was paused in early 2025. Vulnerabilities rise 12%Flashpoint said it catalogued 44,509 vulnerability disclosures in 2025, a 12% increase year-over-year (YoY). Of those, 466 were confirmed as exploited in the wild. Nearly 33%, or 14,593 vulnerabilities, had publicly available exploit code. Ransomware attacks also increased 53% YoY in 2025, with 8,835 total attacks recorded. The top RaaS groups by attack volume in 2025 were Qilin at 1,213 attacks, Akira at 1,044, Cl0p at 529, Safepay at 452, and Play at 395. Manufacturing was the most targeted industry with 1,564 attacks, followed by technology at 987 and healthcare at 905. The U.S. accounted for approximately 53% of named victim organizations. Botnet exploiting 174 flawsThe RondoDox DDoS botnet has been found to implement 174 different exploits between May 25, 2025, and February 16, 2026, peaking at 15,000 exploitation attempts in a single day between December 2025 and January 2026. It's believed that the threat actors are using compromised residential IP addresses as hosting infrastructure. "The operators of RondoDox have been using a shotgun approach, where they send multiple exploits to the same endpoint, hoping for one to work," Bitsight said. Of the 174 different vulnerabilities, 15 have a public proof-of-concept (PoC), but no CVE, and 11 do not have PoC code at all. RondoDox is notable for its fast addition of recently disclosed vulnerabilities, in some cases incorporating the PoC even before the CVE was published (e.g., CVE-2025-62593). Memory-only keylogger attackPhishing emails bearing purchase order lures are being used to distribute an executable within RAR archives. Once launched, the binary extracts and runs VIP Keylogger in memory without touching the disk. "This keylogger captures either browser cookies, logins, credit card details, autofills, visited URLs, downloads, or top sites from the appropriate files in each of the application's designated folders," K7 Labs said. It's also capable of targeting a wide range of web browsers, stealing the email accounts from Outlook, Foxmail, Thunderbird, and Postbox, and collecting Discord tokens. Cloudflare-shielded phishingA new Microsoft 365 credential harvesting campaign has been observed abusing Cloudflare's services to delay detection and risk profiling. The gatekeeping is designed to ensure the visitor is a real target and not a security scanner or bot. "The campaign implemented multiple anti-detection techniques, including the use of CloudFlare human verification, hardcoded IP block lists, user agent checks, and multiple sites and redirects," DomainTools said. Some of the stuff in this week’s list feels a little too practical. Not big flashy hacks — just simple tricks used in the right place at the right time. The kind of things that make defenders sigh because… yeah, that’ll probably work. There’s also a bit of the usual theme: tools and features doing exactly what they were designed to do… just not for the people who built them. Add some creative thinking, and suddenly normal workflows start looking like attack paths. Anyway — quick reads, strange ideas, and a few reminders that security problems rarely disappear… they just change shape. Scroll on.
thehackernews.comMar 12, 2026extracted
Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets
Cybersecurity researchers have discovered half-a-dozen new Android malware families that come with capabilities to steal data from compromised devices and conduct financial fraud. The Android malware range from traditional banking trojans like PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and Oblivion RAT to full-fledged remote administration tools such as SURXRAT. PixRevolution, according to Zimperium, targets Brazil's Pix instant payment platform, hijacking victims' money transfers in real-time to route them to the threat actors instead of the intended payee. "This new strain of malware operates stealthily within the device until the moment the victim initiates a Pix transfer," security researcher Aazim Yaswant said. "What distinguishes this threat from conventional banking trojans is its fundamental design: a human or AI agent operator is actively engaged on the remote end, observing the victim's phone screen instantaneously, poised to act at the precise moment of transaction." The Android malware propagates via fake Google Play Store app listing pages for apps like Expedia, Sicredi, and Correios to trick users into installing the malicious dropper APK files. Once installed, the apps urge users to enable accessibility services to realize their goals. It also connects to an external server over TCP on port 9000 to send periodic heartbeat messages containing device information and activate real-time screen capture using Android's MediaProjection API. The main functionality of PixRevolution, though, is the monitoring of the victim's screen and serving a fake overlay as soon as a victim enters the desired amount and the Pix key of the recipient to initiate the payment. At that point, the trojan shows a fake WebView overlay that says "Aguarde..." (meaning "wait" in Portuguese/Spanish), while, in the background, it edits the Pix key with that of the attacker's to complete the funds transfer. In the final stage, the overlay is removed, and the victim is displayed a "transfer complete" confirmation screen in the Pix app. "From the victim's perspective, nothing unusual happened," Yaswant said. "The app briefly showed a loading indicator, something that occurs routinely during legitimate banking operations. The transfer was confirmed successfully. The amount they intended to send was deducted from their account." "It is only later, sometimes much later, that the victim discovers the money went to the wrong account. And because Pix transfers are instant and final, recovery is extraordinarily difficult." Brazilian users have also become the target of another Android‑based malware campaign called BeatBanker, which spreads primarily through phishing attacks via a website disguised as the Google Play Store. BeatBanker gets its name from the use of an unusual persistence mechanism that involves playing an almost inaudible audio file, a 5-second recording featuring Chinese words, on a loop to prevent it from being terminated. Besides incorporating runtime checks for emulated or analysis environments, the malware monitors battery temperature and percentage, and verifies whether the user is using the device to start or stop the Monero miner as required. It uses Google's Firebase Cloud Messaging (FCM) for command‑and‑control (C2). "To achieve their goals, the malicious APKs carry multiple components, including a cryptocurrency miner and a banking trojan capable of completely hijacking the device and spoofing screens, among other things," Kaspersky said. "When the user tries to make a USDT transaction, BeatBanker creates overlay pages for Binance and Trust Wallet, covertly replacing the destination address with the threat actor's transfer address." The banking module also monitors web browsers like Chrome, Edge, Firefox, Brave, Opera, DuckDuckGo, Dolphin Browser, and sBrowser to URLs accessed by the victim. In addition, it supports the ability to receive a long list of commands from the server to collect personal information and gain complete control of the device. Recent iterations of the campaign have been found to drop BTMOB RAT instead of the banking module. It provides operators with comprehensive remote control, persistent access, and surveillance over compromised devices. BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families, all of which have been linked to a Syrian threat actor who goes by the online alias EVLF. "We also saw the distribution and sale of leaked BTMOB source code on some dark web forums," the Russian security vendor said. "This may suggest that the creator of BeatBanker acquired BTMOB from its original author or the source of the leak and is utilizing it as the final payload." TaxiSpy RAT, similar to PixRevolution, abuses Android's accessibility service and MediaProjection APIs to collect SMS messages, contacts, call logs, clipboard contents, installed apps list, notifications, lock screen PINs, and keystrokes, as well as target Russian banking, cryptocurrency, and government apps by serving overlays to conduct credential theft. The malware combines traditional banking trojan functionality with full RAT capabilities, enabling threat actors to gather sensitive data and execute commands sent via Firebase push messages. Several TaxiSpy samples have been discovered by both CYFIRMA and Zimperium, indicating active efforts on the part of attackers to evade signature-based detection and blacklist defenses. "The malware leverages advanced evasion techniques, such as native library encryption, rolling XOR string obfuscation, and real-time VNC-like remote control via WebSocket," CYFIRMA said. "Its design allows comprehensive device surveillance, including SMS, call logs, contacts, notifications, and banking app monitoring, highlighting its financially motivated and region-specific focus." Another Android banking trojan of note is Mirax, which has been advertised by a threat actor named Mirax Bot as a private malware-as-a-service (MaaS) offering for a monthly price of $2,500 for a full version or $1,750 for a light variant. Mirax claims to offer banking overlays, information gathering (e.g., keystrokes, SMS, lock patterns), and a SOCKS5 proxy to route malicious traffic through compromised devices. Mirax is not the only Android MaaS offering detected in recent months. A new Android remote access trojan called Oblivion is being sold for around $300 per month (or $1,900 per year and $2,200 for lifetime access) and claims to bypass detection and security features on devices from major manufacturers. Once installed, the malware employs an automated permission-granting mechanism that requires no interaction from the victim. This approach, per the seller, works across MIUI / HyperOS (Xiaomi), One UI (Samsung), ColorOS (OPPO), MagicOS (Honor), and OxygenOS (OnePlus). "What sets it apart isn't any single feature. It's the combination: automated permission bypass, hidden remote control, deep persistence, and a point-and-click builder that puts all of it within reach of would-be hackers with even the most minimal level of technical skill," Certos said. "Google has made progressive restrictions on accessibility service abuse a priority across successive Android versions. A tool that credibly bypasses those protections on the latest release – and does so across devices from Samsung, Xiaomi, OPPO, and others – represents a genuine challenge to platform-level defenses." Also commercially distributed through a Telegram-based MaaS ecosystem is an Android malware family called SURXRAT, which is assessed to be an improved version of Arsink. The malware abuses accessibility permissions for persistent control and communicates with a Firebase-based C2 infrastructure to commandeer infected devices. The malware is marketed on a Telegram channel managed by an Indonesian threat actor. What's notable about some of the new samples is the presence of a large language model (LLM) component, indicating that the threat actors behind the malware are experimenting with artificial intelligence (AI) capabilities, along with traditional surveillance. That said, the download of the LLM module is triggered only when specific gaming applications are active on the victim's device, or when it receives alternative target package names dynamically from the server - Free Fire MAX x JUJUTSU KAISEN (com.dts.freefiremax) Free Fire x JUJUTSU KAISEN (com.dts.freefireth) Select SURXRAT samples also incorporate a ransomware-style screen locker module that makes it possible for a remote operator to hijack control of a victim's device and deny access by displaying a full-screen lock message until a payment is made. "This evolution highlights how existing Android RAT frameworks continue to be repurposed and expanded by threat actors, accelerating malware development cycles and enabling rapid introduction of new surveillance and control functionalities," Cyble said. "The observed experimentation with large AI model integration further indicates that threat actors are actively exploring emerging technologies to enhance operational effectiveness and evade detection."
thehackernews.comMar 12, 2026extracted
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials
Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts. The package, named "@openclaw-ai/openclawai," was uploaded to the registry by a user named "openclaw-ai" on March 3, 2026. It has been downloaded 178 times to date. The library is still available for download as of writing. JFrog, which discovered the package, said it's designed to steal system credentials, browser data, crypto wallets, SSH keys, Apple Keychain databases, and iMessage history, as well as install a persistent RAT with remote access capabilities, SOCKS5 proxy, and live browser session cloning. It's tracking the activity under the name GhostClaw. "The attack is notable for its broad data collection, its use of social engineering to harvest the victim's system password, and the sophistication of its persistence and C2 [command-and-control] infrastructure," security researcher Meitar Palas said. "Internally, the malware identifies itself as GhostLoader." The malicious logic is triggered by means of a postinstall hook, which re-installs the package globally using the command: "npm i -g @openclaw-ai/openclawai." Once the installation is complete, the OpenClaw binary points to "scripts/setup.js" by means of the "bin" property in the "package.json" file. It's worth noting that the "bin" field is used to define executable files that should be added to the user's PATH during package installation. This, in turn, turns the package into a globally accessible command-line tool. The file "setup.js" serves as the first-stage dropper that, upon running, displays a convincing fake command-line interface with animated progress bars to give the impression that OpenClaw is being installed on the host. After the purported installation step is complete, the script shows a bogus iCloud Keychain authorization prompt, asking users to enter their system password. Simultaneously, the script retrieves an encrypted second-stage JavaScript payload from the C2 server ("trackpipe[.]dev"), which is then decoded, written to a temporary file, and spawned as a detached child process to continue running in the background. The temp file is deleted after 60 seconds to cover up traces of the activity. "If the Safari directory is inaccessible (no Full Disk Access), the script displays an AppleScript dialog urging the user to grant FDA to Terminal, complete with step-by-step instructions and a button that opens System Preferences directly," JFrog explained. "This enables the second-stage payload to steal Apple Notes, iMessage, Safari history, and Mail data." The JavaScript second-stage, featuring about 11,700 lines, is a full-fledged information stealer and RAT framework that's capable of persistence, data collection, browser decryption, C2 communication, a SOCKS5 proxy, and live browser cloning. It's also equipped to steal a wide range of data - macOS Keychain, including both the local login.keychain-db and all iCloud Keychain databases Credentials, cookies, credit cards, and autofill data from all Chromium-based browsers, such as Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera, Yandex, and Comet Data from desktop wallet applications and browser extensions Cryptocurrency wallet seed phrases SSH keys Developer and cloud credentials for AWS, Microsoft Azure, Google Cloud, Kubernetes, Docker, and GitHub Artificial intelligence (AI) agent configurations, and Data protected by the FDA, including Apple Notes, iMessage history, Safari browsing history, Mail account configurations, and Apple account information In the final stage, the collected data is compressed into a tar.gz archive and exfiltrated through multiple channels, including directly to the C2 server, Telegram Bot API, and GoFile.io. What's more, the malware enters a persistent daemon mode that allows it to monitor clipboard content every three seconds and transmit any data that matches one of the nine pre-defined patterns corresponding to private keys, WIF key, SOL private key, RSA private key, BTC address, Ethereum address, AWS key, OpenAI key, and Strike key. Other features include keeping tabs on running processes, scanning incoming iMessage chats in real-time, and executing commands sent from the C2 server to run arbitrary shell command, open a URL on the victim's default browser, download additional payloads, upload files, start/stop a SOCKS5 proxy, list available browsers, clone a browser profile and launch it in headless mode, stop the browser clone, self-destruct, and update itself. The browser cloning function is particularly dangerous as it launches a headless Chromium instance with the existing browser profile that contains cookies, login, and history data. This gives the attacker a fully authenticated browser session without the need for accessing credentials. "The @openclaw-ai/openclawai package combines social engineering, encrypted payload delivery, broad data collection, and a persistent RAT into a single npm package," JFrog said. "The polished fake CLI installer and Keychain prompt are convincing enough to extract system passwords from cautious developers, and once captured, those credentials unlock macOS Keychain decryption and browser credential extraction that would otherwise be blocked by OS-level protections." Update The package has been removed from the npm registry as of March 10, 2026.
thehackernews.comMar 9, 2026extracted
Over 100 GitHub Repositories Distributing BoryptGrab Stealer
A new information stealer has been distributed through a network of more than 100 GitHub repositories, Trend Micro reports. Dubbed BoryptGrab, the malware can harvest browser and cryptocurrency wallet data, along with system information and user files. Additionally, certain iterations of the stealer can drop a backdoor dubbed TunnesshClient, which uses an SSH tunnel for command-and-control (C&C) communication. Trend Micro’s investigation into BoryptGrab revealed the existence of multiple ZIP archives masquerading as free software tools that have been distributed since late 2025 through the GitHub repositories. All identified binaries contained similar Russian-language comments and URL-fetching logic, although the malware’s execution logic was not the same for all ZIP archives. In some cases, DLL sideloading was used for execution, leveraging an executable within the archive, while in others, VBS Script was used to fetch the launcher’s executable. A .NET executable, a Golang downloader named HeaconLoad, and other execution paths were also observed. BoryptGrab is a C/C++ information stealer that includes VM and anti-analysis checks and attempts to execute with elevated privileges. It can harvest information from close to a dozen browsers, uses Chrome App Bound Encryption techniques from two GitHub repositories, and downloads a Chromium helper to collect information from the targeted browsers. It can also collect data from desktop cryptocurrency wallet applications and browser extensions, harvest system information, take screenshots, and collect files with specific extensions. Additionally, Trend Micro discovered that the stealer can obtain Telegram files, browser passwords, and, in newer iterations, Discord tokens. All the harvested information is archived and sent to the attacker’s C&C server. Some of the identified variants also deploy the TunnesshClient backdoor, which in other cases is dropped using different downloaders. TunnesshClient can execute commands provided by the attacker via a reverse SSH tunnel. Based on these, the malware acts as a SOCKS5 proxy, executes shell commands, lists files, searches for files, uploads and downloads files, or sends entire folders to the attacker’s server. “The BoryptGrab campaign illustrates an evolving threat ecosystem targeting users through deceptive software downloads and fake GitHub repositories,” Trend Micro notes, adding that the operation shows an increasing level of engineering sophistication. Related: ‘Arkanix Stealer’ Malware Disappears Shortly After Debut Related: ‘SolyxImmortal’ Information Stealer Emerges Related: Lumma Stealer Activity Drops After Doxxing Related: Hundreds Targeted in New Atomic macOS Stealer Campaign
securityweek.comMar 7, 2026extracted
Fake Zoom and Google Meet scams install Teramind: A technical deep dive
UPDATE (February 27, 2026): We have added more clarity around the abuse of legitimate commercial products, and of Teramind’s stealth mode. Important note: Teramind, the software vendor referenced in this article, has stated they are not affiliated with the threat actors described, did not deploy the software referenced, and condemn any unauthorized misuse of commercial monitoring technologies. Teramind is a legitimate commercial product with lawful enterprise use cases. February 24, 2026, we published an article about how a fake Zoom meeting “update” silently installs monitoring software, documenting a campaign that used a convincing fake Zoom waiting room to push a legitimate Teramind installer abused for unauthorized surveillance onto Windows machines. Following publication of our findings, the malicious domain was reported to its domain name registrar, Namecheap, which confirmed it suspended the service. Despite the takedown, our continued monitoring shows the campaign is not only still active but growing: we have now identified a parallel operation impersonating Google Meet, running from a different domain and infrastructure. In this article, we’ll provide the deeper technical analysis behind both variants, cataloguing the use of Teramind instance IDs by scammers that we have directly observed or collected from sandbox repositories, document our hands-on detonation of the installer in a controlled environment, and answer a question that emerged during our research: How can a single, identical Windows installer package serve several different attacker accounts? The campaign expands to Google Meet While the original Zoom-themed site at uswebzoomus[.]com was taken down by Namecheap following community reporting, a second site at googlemeetinterview[.]click is actively deploying the same payload using an identical playbook adapted for Google Meet. The Google Meet variant presents a fake Microsoft Store page branded as “Google Meet for Meetings” published by “Google Meet Video Communications, Inc,” which is a fabricated entity. A “Starting download…” button is displayed while the MSI file is silently delivered via the path /Windows/download.php. The referring page is /Windows/microsoft-store.php, confirming the fake Microsoft Store screen is served by the attacker’s infrastructure, not by Microsoft. Our Fiddler traffic capture of the Google Meet variant shows the response header: Content-Disposition: attachment; filename="teramind_agent_x64_s-i(__06a23f815bc471c82aed60b60910b8ec1162844d).msi". Unlike the Zoom variant, where the filename was disguised as a Zoom component, this variant does not even attempt to hide the scammer’s abuse of Teramind in the filename. We verified both files are byte-for-byte identical (MD5: AD0A22E393E9289DEAC0D8D95D8118B5), confirming a single binary is being served across both campaigns with only the filename changed. Infrastructure differences between variants Despite using the same payload, the two variants are hosted on different infrastructure. The Zoom variant at uswebzoomus[.]com ran on Apache/2.4.58 (Ubuntu) and was registered through Namecheap on 2026-02-16. The Google Meet variant at googlemeetinterview[.]click runs on a LiteSpeed server. Both serve the download via PHP scripts and use the same fake Microsoft Store redirect pattern, but the switch in web server and domain registrar suggests the operator anticipated takedowns and pre-positioned fallback infrastructure. One binary, many identities. How the installer reads its own filename During our investigation, we identified 14 distinct MSI filenames sharing the same SHA-256 hash. Of these, two were directly captured from malicious infrastructure through our malware domain analysis: the Zoom variant from uswebzoomus[.]com and the Google Meet variant from googlemeetinterview[.]click. The remaining filenames were sourced from sandbox repositories. It is important to note that some of these sandbox-sourced filenames may represent legitimate corporate Teramind deployments rather than malicious activity. Teramind is a commercial product with lawful enterprise use cases, and files submitted to sandbox services do not necessarily indicate abuse. Nevertheless, they all share the same binary and demonstrate the same filename-based configuration mechanism. Every file shares the same SHA-256 hash: 644ef9f5eea1d6a2bc39a62627ee3c7114a14e7050bafab8a76b9aa8069425fa. This raised an immediate question: if the Teramind instance ID changes with every filename, but the binary is byte-for-byte identical, where is the ID actually stored? The answer lies in a .NET custom action embedded inside the MSI. Our behavioral analysis reveals the following sequence: Calling custom action Teramind.Setup.Actions!Teramind.Setup.Actions.CustomActions.ReadPropertiesFromMsiName PROPERTY CHANGE: Modifying TMINSTANCE property. Its current value is 'onsite'. Its new value: '__941afee582cc71135202939296679e229dd7cced'. PROPERTY CHANGE: Adding TMROUTER property. Its value is 'rt.teramind.co'. The MSI ships with a default TMINSTANCE value of onsite. This is the standard Teramind on-premise default. At install time, the ReadPropertiesFromMsiName custom action parses the installer’s own filename, extracts the 40-character hex string from the s-i(__) portion, and overwrites the default with the attacker-specific instance ID. The log also shows the message Failed to get router from msi name. The installer attempted to extract a C2 server address from the filename but could not. In this case, it falls back to the default value rt.teramind.co, which is preconfigured inside the MSI. However, TMROUTER is an exposed MSI property, so it could potentially be overridden at install time or changed in a different build. The filename in this campaign carries only the instance ID; the C2 destination is determined by the MSI’s default configuration. Live detonation: what the installer actually does on a real system To go beyond sandbox-based behavioral analysis, we detonated the MSI installer in an isolated Windows 10 virtual machine with verbose MSI logging enabled, ApateDNS for DNS interception, and Fiddler for network monitoring. This hands-on analysis revealed several critical behaviors not visible in automated sandbox reports. Installation chain and the CheckHosts gate The MSI installer progresses through four .NET custom actions in sequence, all executed via the WiX Toolset’s zzzzInvokeManagedCustomActionOutOfProc mechanism: ReadPropertiesFromMsiName: Parses the MSI’s own filename to extract the Teramind instance ID and overwrites the default onsite value CheckAgent: Determines whether a Teramind agent is already installed on the machine ValidateParams: Validates the extracted configuration parameters CheckHosts: Performs a pre-flight connectivity check against the C2 server rt.teramind.co The CheckHosts action is a hard gate: if the installer cannot reach the Teramind server, installation aborts with error code 1603. Our initial detonation attempt in a network-isolated VM failed at exactly this point: TM: TMINSTANCE = __941afee582cc71135202939296679e229dd7cced TM: TMROUTER = rt.teramind.co CustomAction CheckHosts returned actual error code 1603 This behavior is significant for two reasons. First, it reveals the C2 server address: rt.teramind.co. Second, it means that victims on corporate networks with restrictive DNS or outbound filtering may be inadvertently protected. The installer will silently fail if it cannot phone home during installation. However, the MSI does support a TMSKIPSRVCHECK property that can bypass this check, and its default value is no. To complete our analysis, we added rt.teramind.co to the Windows hosts file pointing to localhost, allowing the DNS resolution to succeed and the CheckHosts action to pass. The installation then completed successfully. Stealth mode confirmed The successful installation log confirms what the original article suspected: Teramind’s stealth mode (called Hidden Agent, a deployment option that runs silently in the background) is enabled by default in this build. Hidden or stealth deployment modes are standard features in legitimate enterprise endpoint monitoring products, typically used for insider threat detection or compliance monitoring with appropriate employee notice and consent. In this campaign, however, threat actors can abuse this feature to deploy the agent without victim knowledge. The MSI property dump shows: Property(S): TMSTEALTH = 1 This confirms the agent installs with no taskbar icon, no system tray entry, and no visible entry in the Windows Programs list. The victim has no visual indication that monitoring software is running. Two services, not one The install log reveals the campaign deploys two persistent services, not just the one documented in our original article: Both service names are chosen to blend in: tsvchst mimics the legitimate Windows svchost.exe naming pattern, while pmon with the display name “Performance Monitor” mimics the built-in Windows Performance Monitor. Both run as LocalSystem, the highest privilege level on a Windows machine. Both services are configured with aggressive failure recovery: restart on first failure, restart on second failure, and restart on subsequent failures, with delays of 160 seconds (tsvchst) and 130 seconds (pmon). This means even if a user or security tool terminates the service, it automatically restarts within minutes. Live C2 callback observed Immediately after installation, ApateDNS captured the agent phoning home. DNS queries for rt.teramind.co appeared within seconds of the service starting, confirming the agent begins its callback cycle immediately. The queries repeated at approximately 11-second intervals, showing a persistent polling pattern. In a real-world scenario where the victim has internet connectivity, these would resolve to Teramind’s infrastructure and the agent would begin transmitting captured data. Full MSI configuration surface The verbose installation log exposes every configurable parameter the MSI supports through its SecureCustomProperties list. This reveals the installer’s full configuration surface: TMSTEALTH — Stealth mode (set to 1 in this build) TMINSTANCE — Account identifier (extracted from filename) TMROUTER — C2 server address (hardcoded to rt.teramind.co) TMENCRYPTION — C2 communication encryption toggle TMSOCKSHOST / TMSOCKSPORT / TMSOCKSUSER / TMSOCKSPASSWORD — Built-in SOCKS5 proxy support for tunneling C2 traffic through proxies TMHTTPPROXY — HTTP proxy support TMSKIPSRVCHECK — Skip the C2 connectivity pre-flight check TMNODRV / TMNOFSDRV — Disable kernel filter drivers TMNOIPCCLIPBOARD — Clipboard monitoring toggle TMNOREMOTETS — Remote terminal services monitoring toggle TMHASHUSERNAMES — Anonymize/hash captured usernames TMDISABLESCREEN — Disable screenshot capture TMADDENTRYTOARP — Add/remove entry from Add/Remove Programs (off in stealth) TMCRASHUPLOADURL — Crash telemetry upload endpoin TMREVEALEDPASSWORDLESS — Toggle for passwordless reveal functionality The SOCKS5 proxy support is particularly noteworthy from a threat perspective. While proxy configuration is a standard enterprise feature—allowing organizations to route agent traffic through corporate infrastructure—in this context it means the agent could be configured to route captured data through an attacker-controlled proxy, making network-level detection significantly harder by disguising C2 traffic as legitimate proxy traffic. Observed Teramind instance IDs The following table lists every MSI filename and corresponding Teramind instance ID we have collected. Of these, two were directly observed in the wild through our own malware domain analysis: the Zoom variant (941afee…7cced, captured from uswebzoomus[.]com) and the Google Meet variant (06a23f8…2844d, captured from googlemeetinterview[.]click). The remaining filenames were sourced from sandbox repositories. As noted above, some of these may represent legitimate enterprise deployments rather than malicious use. All files share the same SHA-256 hash. Two filenames share the same instance ID c0cea71…0a6d7, indicating the same attacker account was used across multiple filename variations. The variety of filename prefixes is notable: zoom_agent, ZoomApp_agent, GoogleMeet_agent, AdobeReader_agent, teramind_agent, and file_agent. This suggests the campaign extends beyond video conferencing impersonation. However, the AdobeReader-branded variant was found only in sandbox repositories and may represent testing or planned expansion rather than an active deployment. The filenames with generic prefixes like teramind_agent and file_agent similarly appear to be sandbox submissions that retained the default naming rather than a brand-specific social engineering lure. Indicators of Compromise File hashes SHA-256: 644ef9f5eea1d6a2bc39a62627ee3c7114a14e7050bafab8a76b9aa8069425fa MD5: AD0A22E393E9289DEAC0D8D95D8118B5 Domains uswebzoomus[.]com (Zoom variant: taken down by Namecheap) googlemeetinterview[.]click (Google Meet variant: active as of 2026-02-26) Detection and defense recommendations Alert on the ProgramData GUID directory {4CEC2908-5CE4-48F0-A717-8FC833D8017A} . This GUID is fixed across all observed variants. Query for both services: sc query tsvchst andsc query pmon . Either running on a non-corporate machine confirms active surveillance. Watch for kernel driver loads: tm_filter.sys andtmfsdrv2.sys loading on personal machines should trigger high-severity alerts. Block MSI execution from browser download directories. Both variants rely on the user running an MSI from their Downloads folder. Application control policies that prevent MSI execution from user-writable paths would stop this attack chain. Educate employees: Never update applications by clicking links in messages. Use the application’s built-in update mechanism or navigate to the vendor’s official website manually. Deploy browser policies that warn on or block automatic file downloads from unrecognized domains. Removal To uninstall the agent, run the following command as Administrator: msiexec /x {4600BEDB-F484-411C-9861-1B4DD6070A23} /qb. This removes the services, kernel drivers, and most installed files. However, our testing confirmed the uninstaller fails to fully delete the ProgramData directory due to runtime-generated files. After uninstalling, manually remove any remnants with rmdir /s /q "C:\ProgramData\{4CEC2908-5CE4-48F0-A717-8FC833D8017A}" and reboot to fully unload the kernel drivers from memory. Conclusion This campaign demonstrates a growing trend: the abuse of legitimate commercial software for malicious purposes. The attackers did not write custom malware. Instead, they took an off-the-shelf monitoring product—one designed for lawful enterprise use—and abused its built-in stealth mode and filename-based configuration system, wrapping it in social engineering designed to exploit trust in brands like Zoom and Google Meet. This type of abuse can affect any legitimate software vendor and underscores the importance of user education about social engineering tactics. The expansion to Google Meet, plus additional sandbox-sourced variants including an AdobeReader-branded filename, suggests this is an evolving operation that may expand to impersonate other applications. Our hands-on detonation revealed details invisible to automated sandboxes: the CheckHosts C2 pre-flight gate, the rt.teramind.co router address, the second pmon service masquerading as Performance Monitor, the confirmed TMSTEALTH = 1 flag, and the full SOCKS5 proxy capability for C2 evasion. The fact that a single binary serves unlimited attacker accounts through nothing more than a filename rename makes this campaign easily scalable. Acknowledgments We would like to thank security researcher @JAMESWT_WT for promptly reporting the original malicious domain to Namecheap, leading to the takedown of uswebzoomus[.]com. Teramind has confirmed that the company was not involved in this campaign and had no knowledge of or affiliation with the threat actors. Like many legitimate commercial software products, Teramind can be abused by malicious actors—a risk that exists across the enterprise software ecosystem. Because Teramind is a legitimate commercial product, it is not inherently flagged by security software, meaning we have no visibility into whether this campaign has resulted in real-world infections. What we can confirm is that the infrastructure we documented—including purpose-built phishing domains impersonating Zoom and Google Meet, fake Microsoft Store pages, and a Teramind agent configured in stealth mode—is consistent with a campaign designed to deploy monitoring software onto targets’ machines without their knowledge or consent.
malwarebytes.comFeb 26, 2026extracted
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. The activity, first observed on January 26, 2026, has resulted in the deployment of new malware families that share overlapping samples previously identified as used by the threat actor, according to a report published by Group-IB. These include downloaders like GhostFetch and HTTP_VIP, along with a Rust backdoor called CHAR and an advanced implant codenamed GhostBackDoor that's dropped by GhostFetch. "These attacks follow similar patterns and align with the killchains previously observed in MuddyWater attacks; starting with a phishing email with a Microsoft Office document attached to it that contains malicious macro code that decodes the embedded payload and drops it on the system and executes it, providing the adversary with remote control of the system," the company said. One such attack chain employing a malicious Microsoft Excel document prompts users to enable macros in order to activate the infection and ultimately drop CHAR. Another variant of the same attack has been found to lead to the deployment of the GhostFetch downloader, which then downloads GhostBackDoor. A third version of the attack leverages themes such as flight tickets and reports, in contrast to using lures mimicking an energy and marine services company in the Middle East, to distribute the HTTP_VIP downloader that subsequently deploys the AnyDesk remote desktop software. A brief description of the four tools is as follows - GhostFetch, a first-stage downloader that profiles the system, validates mouse movements and checks screen resolution, checks for the presence of debuggers, virtual machine artifacts, and antivirus software, and fetches and executes secondary payloads directly in memory. GhostBackDoor, a second-stage backdoor delivered by GhostFetch that supports an interactive shell, file read/write, and re-run GhostFetch. HTTP_VIP, a native downloader that conducts system reconnaissance, connects to an external server ("codefusiontech[.]org") to authenticate and deploy AnyDesk from the C2 server. A new variant of the malware also adds the ability to retrieve victim information and retrieve instructions to start an interactive shell, download/upload files, capture clipboard contents, and update the sleep/beaconing interval. CHAR, a Rust backdoor that's controlled by a Telegram bot (whose first name is "Olalampo" and username is "stager_51_bot") to change directory and execute a cmd.exe or PowerShell command. The PowerShell command is designed to execute a SOCKS5 reverse proxy or another backdoor named Kalim, upload data stolen from web browsers, and run unknown executables referred to as "sh.exe" and "gshdoc_release_X64_GUI.exe." Group-IB's analysis of CHAR's source code has revealed signs of artificial intelligence (AI)-assisted development owing to the presence of emojis in debug strings, a finding that's consistent with Google's revelations last year that the threat actor is experimenting with generative AI tools to facilitate the development of custom malware to support file transfer and remote execution. Another notable aspect is that CHAR shares a similar structure and development environment as the Rust-based malware BlackBeard (aka Archer RAT and RUSTRIC), which was flagged by CloudSEK and Seqrite Labs as put to use by the threat actor to target various entities in the Middle East. MuddyWater has also been observed exploiting recently disclosed vulnerabilities on public-facing servers as a way to obtain initial access to target networks. "The MuddyWater APT group remains an active threat within the META [Middle East, Turkey, and Africa] region, with this operation primarily targeting organizations in the MENA region," Group-IB concluded. "The group's continued adoption of AI technology, combined with continued development of custom malware and tooling and diversified command-and-control (C2) infrastructures, underscores their dedication and intent to expand their operations."
thehackernews.comFeb 23, 2026extracted
ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws & 20+ Stories
The cyber threat space doesn’t pause, and this week makes that clear. New risks, new tactics, and new security gaps are showing up across platforms, tools, and industries — often all at the same time. Some developments are headline-level. Others sit in the background but carry long-term impact. Together, they shape how defenders need to think about exposure, response, and preparedness right now. This edition of ThreatsDay Bulletin brings those signals into one place. Scan through the roundup for quick, clear updates on what’s unfolding across the cybersecurity and hacking landscape. Privacy model hardeningGoogle announced the first beta version of Android 17, with two privacy and security enhancements: the deprecation of Cleartext Traffic Attribute and support for HPKE Hybrid Cryptography to enable secure communication using a combination of public key and symmetric encryption (AEAD). "If your app targets (Android 17) or higher and relies on usesCleartextTraffic='true' without a corresponding Network Security Configuration, it will default to disallowing cleartext traffic," Google said. "You are encouraged to migrate to Network Security Configuration files for granular control." RaaS expands cross-platform reachA new analysis of the LockBit 5.0 ransomware has revealed that the Windows version packs in various defense evasion and anti-analysis techniques, including packing, DLL unhooking, process hollowing, patching Event Tracing for Windows (ETW) functions, and log clearing. "What's notable among the multiple systems support is its proclaimed capability to 'work on all versions of Proxmox,'" Acronis said. "Proxmox is an open-source virtualization platform and is being adopted by enterprises as an alternative to commercial hypervisors, which makes it another prime target of ransomware attacks." The latest version also introduces dedicated builds tailored for enterprise environments, highlighting the continued evolution of ransomware-as-a-service (RaaS) operations. Mac users lured via nested obfuscationCybersecurity researchers have detailed a new evolution of the ClickFix social engineering tactic targeting macOS users. "Dubbed Matryoshka due to its nested obfuscation layers, this variant uses a fake installation/fix flow to trick victims into executing a malicious Terminal command," Intego said. "While the ClickFix tactic is not new, this campaign introduces stronger evasion techniques — including an in-memory, compressed wrapper and API-gated network communications — designed to hinder static analysis and automated sandboxes." The campaign primarily targets users attempting to visit software review sites, leveraging typosquatting in the URL name to redirect them to fake sites and activate the infection chain. Loader pipeline drives rapid domain takeoverAnother new ClickFix campaign detected in February 2026 has been observed delivering a malware-as-a-service (MaaS) loader known as Matanbuchus 3.0. Huntress, which dissected the attack chain, said the ultimate objective of the intrusion was to deploy ransomware or exfiltrate data based on the fact that the threat actor rapidly progressed from initial access to lateral movement to domain controllers via PsExec, rogue account creation, and Microsoft Defender exclusion staging. The attack also led to the deployment of a custom implant dubbed AstarionRAT that supports 24 commands to facilitate credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution. According to data from the cybersecurity company, ClickFix fueled 53% of all malware loader activity in 2025. Typosquat chain targets macOS credentialsIn yet another ClickFix campaign, threat actors are relying on the "reliable trick" to host malicious instructions on fake websites disguised as Homebrew ("homabrews[.]org") to trick users into pasting them on the Terminal app under the pretext of installing the macOS package manager. In the attack chain documented by Hunt.io, the commands in the typosquatted Homebrew domain are used to deliver a credential-harvesting loader and a second-stage macOS infostealer dubbed Cuckoo Stealer. "The injected installer looped on password prompts using 'dscl . -authonly,' ensuring the attacker obtained working credentials before deploying the second stage," Hunt.io said. "Cuckoo Stealer is a full-featured macOS infostealer and RAT: It establishes LaunchAgent persistence, removes quarantine attributes, and maintains encrypted HTTPS command-and-control communications. It collects browser credentials, session tokens, macOS Keychain data, Apple Notes, messaging sessions, VPN and FTP configurations, and over 20 cryptocurrency wallet applications." The use of "dscl . -authonly" has been previously observed in attacks deploying Atomic Stealer. Phobos affiliate detained in EuropeAuthorities from Poland's Central Bureau for Combating Cybercrime (CBZC) have detained a 47-year-old man over suspected ties to the Phobos ransomware group. He faces a potential prison sentence of up to five years. The CBZC said the "47-year-old used encrypted messaging to contact the Phobos criminal group, known for conducting ransomware attacks," adding the suspect's devices contained logins, passwords, credit card numbers, and server IP addresses that could have been used to launch "various attacks, including ransomware." The arrest is part of Europol's Operation Aether, which targets the 8Base ransomware group, believed to be linked to Phobos. It has been almost exactly a year since international law enforcement dismantled the 8Base crew. More than 1,000 organizations around the world have been targeted in Phobos ransomware attacks, and the cybercriminals are believed to have obtained over $16 million in ransom payments. Industrial ransomware surge acceleratesThere has been a sharp rise in the number of ransomware groups targeting industrial organizations as cybercriminals continue to exploit vulnerabilities in operational technology (OT) and industrial control systems (ICS), Dragos warned. A total of 119 ransomware groups targeting industrial organizations were tracked during 2025, a 49% increase from the 80 tracked in 2024. 2025 saw 3,300 industrial organizations around the world hit by ransomware, compared with 1693 in 2024. The most targeted sector was manufacturing, followed by transportation. In addition, a hacking group tracked as Pyroxene has been observed conducting "supply chain-leveraged attacks targeting defense, critical infrastructure, and industrial sectors, with operations expanding from the Middle East into North America and Western Europe." It often leverages initial access provided by PARISITE, to enable movement from IT into OT networks. Pyroxene overlaps with activity attributed to Imperial Kitten (aka APT35), a threat actor affiliated with the cyber arm of the Islamic Revolutionary Guard Corps (IRGC). Copilot bypassed DLP safeguardsMicrosoft confirmed a bug (CW1226324) that let Microsoft 365 Copilot summarize confidential emails from Sent Items and Drafts folders since January 21, 2026, without users' permission, bypassing data loss prevention (DLP) policies put in place to safeguard sensitive data. A fix was deployed by the company on February 3, 2026. However, the company did not disclose how many users or organizations were affected. "Users' email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat," Microsoft said. "The Microsoft 365 Copilot 'work tab' Chat is summarizing email messages even though these email messages have a sensitivity label applied, and a DLP policy is configured. A code issue is allowing items in the sent items and draft folders to be picked up by Copilot even though confidential labels are set in place." (Update: As of February 19, 2026, Microsoft said the root cause of this issue has been addressed for most customers, and that it's now "completing a longer-term, comprehensive sync to apply this fix retroactively to previously affected messages within the Sent and Draft folders to fully remediate the impact.") Jira trials weaponized for spamThreat actors are abusing the trust and reputation associated with Atlassian Jira Cloud and its connected email system to run automated spam campaigns and bypass traditional email security. To accomplish this, the operators created Atlassian Cloud trial accounts using randomized naming conventions, allowing them to generate disposable Jira Cloud instances at scale. "Emails were tailored to target specific language groups, targeting English, French, German, Italian, Portuguese, and Russian speakers — including highly skilled Russian professionals living abroad," Trend Micro said. "These campaigns not only distributed generic spam, but also specifically targeted sectors such as government and corporate entities." The attacks, active from late December 2025 through late January 2026, primarily targeted organizations using Atlassian Jira. The goal was to get recipients to open the emails and click on malicious links, which would initiate a redirect chain powered by the Keitaro Traffic Distribution System (TDS) and then finally lead them to pages peddling investment scams and online casino landing sites, suggesting that financial gain was likely the main objective. GitLab SSRF now federally mandated patchThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on February 18, 2026, added CVE-2021-22175 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by March 11, 2026. "GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled," CISA said. In March 2025, GreyNoise revealed that a cluster of about 400 IP addresses was actively exploiting multiple SSRF vulnerabilities, including CVE-2021-22175, to target susceptible instances in the U.S., Germany, Singapore, India, Lithuania, and Japan. Telegram bots fuel Fortune 500 phishingAn elusive, financially motivated threat actor dubbed GS7 has been targeting Fortune 500 companies in a new phishing campaign that leverages trusted company branding with lookalike websites aimed at harvesting credentials via Telegram bots. The campaign, codenamed Operation DoppelBrand, targets top financial institutions, including Wells Fargo, USAA, Navy Federal Credit Union, Fidelity Investments, and Citibank, as well as technology, healthcare, and telecommunications firms worldwide. Victims are lured through phishing emails and redirected to counterfeit pages where credentials are harvested and transmitted to Telegram bots controlled by the attacker. According to SOCRadar, the group itself, however, has a history stretching back to 2022. The threat actor is said to have registered more than 150 malicious domains in recent months using registrars such as NameCheap and OwnRegistrar, and routing traffic through Cloudflare to evade detection. GS7's end goals include not only harvesting credentials, but also downloading remote management and monitoring (RMM) tools like LogMeIn Resolve on victim systems to enable remote access or the deployment of malware. This has raised the possibility that the group may even act as an initial access broker (IAB), selling the access to ransomware groups or other affiliates. Remcos shifts to live C2 surveillancePhishing emails disguised as invoices, job offers, or government notices are being used to distribute a new variant of Remcos RAT to facilitate comprehensive surveillance and control over infected systems. "The latest Remcos variant has been observed exhibiting a significant change in behaviour compared to previous versions," Point Wild said. "Instead of stealing and storing data locally on the infected system, this variant establishes direct online command-and-control (C2) communication, enabling real-time access and control. In particular, it leverages the webcam to capture live video streams, allowing attackers to monitor targets remotely. This shift from local data exfiltration to live, online surveillance represents an evolution in Remcos’ capabilities, increasing the risk of immediate espionage and persistent monitoring." China-made vehicles restricted on basesPoland's Ministry of Defence has banned Chinese cars, and other motor vehicles equipped with technology to record position, images, or sound, from entering protected military facilities due to national security concerns and to "limit the risk of access to sensitive data." The ban also extends to connecting work phones to infotainment systems in motor vehicles produced in China. The ban isn't permanent: the Defence Ministry has called for the development of a vetting process to allow carmakers to undergo a security assessment that, if passed, can allow their vehicles to enter protected facilities. "Modern vehicles equipped with advanced communication systems and sensors can collect and transmit data, so their presence in protected zones requires appropriate safety regulations," the Polish Army said. The measures introduced are preventive and comply with the practices of NATO countries and other allies to ensure the highest standards of defense infrastructure protection. They are part of a wider process of adapting security procedures to the changing technological environment and current requirements for the protection of critical infrastructure." DKIM replay fuels invoice scamsBad actors are abusing legitimate invoices and dispute notifications from trusted vendors, such as PayPal, Apple, DocuSign, and Dropbox Sign (formerly HelloSign), to bypass email security controls. "These platforms often allow users to enter a 'seller name' or add a custom note when creating an invoice or notification," Casey-owned INKY said. "Attackers abuse this functionality by inserting scam instructions and a phone number into those user-controlled fields. They then send the resulting invoice or dispute notice to an email address they control, ensuring the malicious content is embedded in a legitimate, vendor-generated message." Because these emails originate from a legitimate company, they bypass checks like Domain-based Message Authentication, Reporting and Conformance (DMARC). As soon as the legitimate email is received, the attacker proceeds to forward it to the intended targets, allowing the "authentic looking" message to land in the victims' inboxes. The attack is known as a DKIM replay attack. RMM abuse surges 277%A new report from Huntress has revealed that the abuse of Remote Monitoring and Management (RMM) software surged 277% year-over-year, accounting for 24% of all observed incidents. Threat actors have begun to increasingly favor these tools because they are ubiquitous in enterprise environments, and the trusted nature of the RMM software allows malicious activity to blend in with legitimate usage, making detection harder for defenders. They also offer increased stealth, persistence, and operational efficiency. "As cybercriminals built entire playbooks around these legitimate, trusted tools to drop malware, steal credentials, and execute commands, the use of traditional hacking tools plummeted by 53%, while remote access trojans and malicious scripts dropped by 20% and 11.7%, respectively," the company said. Texas targets China-linked tech firmsTexas Attorney General Ken Paxton has sued TP-Link for "deceptively marketing its networking devices and allowing the Chinese Communist Party ('CCP') to access American consumers' devices in their homes." Paxton's lawsuit alleges that TP Link's products have been used by Chinese hacking groups to launch cyber attacks against the U.S. and that the company is subject to Chinese data laws, which it said require firms operating in the country to support its intelligence services by "divulging Americans' data." TP-Link told The Record that these allegations are "without merit" and that neither the Chinese government nor the Chinese Communist Party (CCP) exercises control over the company, its products, or user data. It also added that all U.S. user data is stored on domestic Amazon Web Services (AWS) servers. In a second lawsuit, Paxton also accused Anzu Robotics of misleading Texas consumers about the "origin, data practices, and security risks of its drones." Paxton's office described the company's products as "21st century Trojan horse linked to the CCP." MetaMask backdoor expands DPRK campaignThe North Korea-linked campaign known as Contagious Interview is designed to target IT professionals working in cryptocurrency, Web3, and artificial intelligence sectors to steal sensitive data and financial information using malware such as BeaverTail and InvisibleFerret. However, recent iterations of the campaign have expanded their data theft capabilities by tampering with the MetaMask wallet extension (if it's installed) through a lightweight JavaScript backdoor that shares the same functionality as InvisibleFerret, according to security researcher Seongsu Park. "Through the backdoor, attackers instruct the infected system to download and install a fake version of the popular MetaMask cryptocurrency wallet extension, complete with a dynamically generated configuration file that makes it appear legitimate," Park said. "Once installed, the compromised MetaMask extension silently captures the victim's wallet unlock password and transmits it to the attackers’ command-and-control server, giving them complete access to cryptocurrency funds." Booking.com kits hit hotels, guestsBridewell has warned of a resurgence in malicious activity targeting the hotel and retail sector. "The primary motivation driving this incident is financial fraud, targeting two victims: hotel businesses and hotel customers, in sequential order," security researcher Joshua Penny said. "The threat actor(s) utilize impersonation of the Booking.com platform through two distinct phishing kits dedicated to harvesting credentials and banking information from each victim, respectively." It's worth noting that the activity shares overlap with a prior activity wave disclosed by Sekoia in November 2025, although the use of a dedicated phishing kit is a new approach by either the same or new operators. EPMM exploits enable persistent accessThe recently disclosed security flaws in Ivanti Endpoint Manager Mobile (EPMM) have been exploited by bad actors to establish a reverse shell, deliver JSP web shells, conduct reconnaissance, and download malware, including Nezha, cryptocurrency miners, and backdoors for remote access. The two critical vulnerabilities, CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to remotely execute arbitrary code on target servers, granting them full control over mobile device management (MDM) infrastructure without requiring user interaction or credentials. According to Palo Alto Networks Unit 42, the campaign has affected state and local government, healthcare, manufacturing, professional and legal services, and high technology sectors in the U.S., Germany, Australia, and Canada. "Threat actors are accelerating operations, moving from initial reconnaissance to deploying dormant backdoors designed to maintain long-term access even after organizations apply patches," the cybersecurity company said. In a related development, Germany's Federal Office for Information Security (BSI) has reported evidence of exploitation since the summer of 2025 and has urged organizations to audit their systems for indicators of compromise (IoCs) as far back as July 2025. AI passwords lack true randomnessNew research by Irregular has found that passwords generated directly by a large language model (LLM) may appear strong but are fundamentally insecure, as "LLMs are designed to predict tokens – the opposite of securely and uniformly sampling random characters." The artificial intelligence (AI) security company said it detected LLM-generated passwords in the real world as part of code development tasks instead of leaning on traditional secure password generation methods. "People and coding agents should not rely on LLMs to generate passwords," the company said. "LLMs are optimized to produce predictable, plausible outputs, which is incompatible with secure password generation. AI coding agents should be directed to use secure password generation methods instead of relying on LLM-output passwords. Developers using AI coding assistants should review generated code for hardcoded credentials and ensure agents use cryptographically secure methods or established password managers." PDF engine flaws enable account takeoverCybersecurity researchers have discovered more than a dozen vulnerabilities (CVE-2025-70401, CVE-2025-70402, and CVE-2025-66500) in popular PDF platforms from Foxit and Apryse, potentially allowing attackers to exploit them for account takeover, session hijacking, data exfiltration, and arbitrary JavaScript execution. "Rather than isolated bugs, the issues cluster around recurring architectural failures in how PDF platforms handle untrusted input across layers," Novee Security researchers Lidor Ben Shitrit, Elad Meged, and Avishai Fradlis said. "Several vulnerabilities were exploitable with a single request and affected trusted domains commonly embedded inside enterprise applications." The issues have been addressed by both Apryse and Foxit through product updates. Training labs expose cloud backdoorsA "widespread" security issue has been discovered where security vendors inadvertently expose deliberately vulnerable training applications, such as OWASP Juice Shop, DVWA, bWAPP, and Hackazon, to the public internet. This can open organizations to severe security risks when they are executed from a privileged cloud account. "Primarily deployed for internal testing, product demonstrations, and security training, these applications were frequently left accessible in their default or misconfigured states," Pentera Labs said. "These critical flaws not only allowed attackers full control over the compromised compute engine but also provided pathways for lateral movement into sensitive internal systems. Violations of the principle of least privilege and inadequate sandboxing measures further facilitated privilege escalation, endangering critical infrastructure and sensitive organizational data." Further analysis has determined that threat actors are exploiting this blind spot to plant web shells, cryptocurrency miners, and persistence mechanisms on compromised systems. Evasion loader refines C2 stealthThe malware loader known as Oyster (aka Broomstick or CleanUpLoader) has continued to evolve into early 2026, fine-tuning its C2 infrastructure and obfuscation methods, per findings from Sekoia. The malware is distributed mainly through fake websites that distribute installers for legitimate software like Microsoft Teams, with the core payload often deployed as a DLL for persistent execution. "The initial stage leverages excessive legitimate API call hammering and simple anti-debugging traps to thwart static analysis," the company said. "The core payload is delivered in a highly obfuscated manner. The final stage implements a robust C2 communication protocol that features a dual-layer server infrastructure and highly-customized data encoding." Stealer taunts researchers in codeNoodlophile is the name given to an information-stealing malware that has been distributed via fake AI tools promoted on Facebook. Assessed to be the work of a threat actor based in Vietnam, it was first documented by Morphisec in May 2025. Since then, there have been other reports detailing various campaigns, such as UNC6229 and PXA Stealer, orchestrated by Vietnamese cybercriminals. Morphisec's latest analysis of Noodlophile has revealed that the threat actor "padded the malware with millions of repeats of a colorful Vietnamese phrase translating to 'f*** you, Morphisec,'" suggesting that the operators were not thrilled about getting exposed. "Not just to vent frustration over disrupted campaigns, but also to bloat the file and crash AI-based analysis tools that are based on the Python disassemble library – dis.dis(obj)," security researcher Michael Gorelik said. Crypto library RCE risk patchedThe OpenSSL project has patched a stack buffer overflow flaw that can lead to remote code execution attacks under certain conditions. The vulnerability, tracked as CVE-2025-15467, resides in how the library processes Cryptographic Message Syntax data. Threat actors can use CMS packets with maliciously crafted AEAD parameters to crash OpenSSL and run malicious code. CVE-2025-15467 is one of 12 issues that were disclosed by AISLE late last month. Another high-severity vulnerability is CVE-2025-11187, which could trigger a stack-based buffer overflow due to a missing validation. Machine accounts expand delegation riskNew research from Silverfort has cleared a "common assumption" that Kerberos delegation -- which allows a service to request resources or perform actions on behalf of a user -- applies not just to human users, but also to machine accounts as well. In other words, a computer account can be delegated on behalf of highly privileged machine identities such as domain controllers. "That means a service trusted for delegation can act not just on behalf of other users, but also on behalf of machine accounts, the most critical non-human identities (NHIs) in any domain," Silverfort researcher Dor Segal said. "The risk is obvious. If an adversary can leverage delegation, it can act on behalf of sensitive machine accounts, which in many environments hold privileges equivalent to Domain Administrator." To counter the risk, it's advised to run "Set-ADAccountControl -Identity “HOST01$” -AccountNotDelegated $true" for each sensitive machine account. Security news rarely breaks in isolation. One incident leads to another, new research builds on older findings, and attacker playbooks keep adjusting along the way. The result is a constant stream of signals that are easy to miss without a structured view. This roundup pulls those signals together into a single, readable snapshot. Go through the full list to get quick clarity on the developments shaping defender priorities and risk conversations right now.
thehackernews.comFeb 19, 2026extracted
Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging
Microsoft has disclosed details of a new version of the ClickFix social engineering tactic in which the attackers trick unsuspecting users into running commands that carry out a Domain Name System (DNS) lookup to retrieve the next-stage payload. Specifically, the attack relies on using the "nslookup" (short for nameserver lookup) command to execute a custom DNS lookup triggered via the Windows Run dialog. ClickFix is an increasingly popular technique that's traditionally delivered via phishing, malvertising, or drive-by download schemes, often redirecting targets to bogus landing pages that host fake CAPTCHA verification or instructions to address a non-existent problem on their computers by running a command either through the Windows Run dialog or the macOS Terminal app. The attack method has become widespread over the past two years since it hinges on the victims infecting their own machines with malware, thereby allowing the threat actors to bypass security controls. The effectiveness of ClickFix has been such that it has spawned several variants, such as FileFix, JackFix, ConsentFix, CrashFix, and GlitchFix. "In the latest DNS-based staging using ClickFix, the initial command runs through cmd.exe and performs a DNS lookup against a hard-coded external DNS server, rather than the system's default resolver," the Microsoft Threat Intelligence team said in a series of posts on X. "The output is filtered to extract the Name: DNS response, which is executed as the second-stage payload." Microsoft said this new variation of ClickFix uses DNS as a "lightweight staging or signaling channel," enabling the threat actor to reach infrastructure under their control, as well as erect a new validation layer before executing the second-stage payload. "Using DNS in this way reduces dependency on traditional web requests and can help blend malicious activity into normal network traffic," the Windows maker added. The downloaded payload subsequently initiates an attack chain that leads to the download of a ZIP archive from an external server ("azwsappdev[.]com"), from which a malicious Python script is extracted and run to conduct reconnaissance, run discovery commands, and drop a Visual Basic Script (VBScript) responsible for launching ModeloRAT, a Python-based remote access trojan previously distributed through CrashFix. To establish persistence, a Windows shortcut (LNK) file pointing to the VBScript is created in the Windows Startup folder so that the malware is automatically launched every time the operating system is started. The disclosure comes as Bitdefender warned of a surge in Lumma Stealer activity, driven by ClickFix-style fake CAPTCHA campaigns that deploy an AutoIt-version of CastleLoader, a malware loader associated with a threat actor codenamed GrayBravo (formerly TAG-150). CastleLoader incorporates checks to determine the presence of virtualization software and specific security programs before decrypting and launching the stealer malware in memory. Outside of ClickFix, websites advertising cracked software and pirated movies serve as bait for CastleLoader-based attack chains, deceiving users into downloading rogue installers or executables masquerading as MP4 media files. Other CastleLoader campaigns have also leveraged websites promising cracked software downloads as a starting point to distribute a fake NSIS installer that also runs obfuscated VBA scripts prior to running the AutoIt script that loads Lumma Stealer. The VBA loader is designed to run scheduled tasks responsible for ensuring persistence. "Despite significant law enforcement disruption efforts in 2025, Lumma Stealer operations continued, demonstrating resilience by rapidly migrating to new hosting providers and adapting alternative loaders and delivery techniques," the Romanian cybersecurity company said. "At the core of many of these campaigns is CastleLoader, which plays a central role in helping LummaStealer spread through delivery chains." Interestingly, one of the domains on CastleLoader's infrastructure ("testdomain123123[.]shop") was flagged as a Lumma Stealer command-and-control (C2), indicating that the operators of the two malware families are either working together or sharing service providers. The majority of Lumma Stealer infections have been recorded in India, followed by France, the U.S., Spain, Germany, Brazil, Mexico, Romania, Italy, and Canada. "The effectiveness of ClickFix lies in its abuse of procedural trust rather than technical vulnerabilities," Bitdefender said. "The instructions resemble troubleshooting steps or verification workarounds that users may have encountered previously. As a result, victims often fail to recognize that they are manually executing arbitrary code on their own system." CastleLoader is not the only loader that's being used to distribute Lumma Stealer. Campaigns observed as early as March 2025 have leveraged another loader dubbed RenEngine Loader, with the malware propagated under the guise of game cheats and pirated software like CorelDRAW graphics editor. In these attacks, the loader makes way for a secondary loader named Hijack Loader, which then deploys Lumma Stealer. According to data from Kaspersky, RenEngine Loader attacks have primarily affected users in Russia, Brazil, Turkey, Spain, Germany, Mexico, Algeria, Egypt, Italy, and France since March 2025. The developments coincide with the emergence of various campaigns using social engineering lures, including ClickFix, to deliver a variety of stealers and malware loaders - A macOS campaign that has used phishing and malvertising ploys to deliver Odyssey Stealer, a rebrand of Poseidon Stealer, which itself is a fork of Atomic macOS Stealer (AMOS). The stealer exfiltrates credentials and data from 203 browser wallet extensions and 18 desktop wallet applications to facilitate cryptocurrency theft. "Beyond credential theft, Odyssey operates as a full remote access trojan," Censys said. "A persistent LaunchDaemon polls the C2 every 60 seconds for commands, supporting arbitrary shell execution, reinfection, and a SOCKS5 proxy for tunneling traffic through victim machines." A ClickFix attack chain targeting Windows systems that uses fake CAPTCHA verification pages on legitimate-but-compromised websites to trick users into executing PowerShell commands that deploy the StealC information stealer. An email phishing campaign that uses a malicious SVG file contained within a password‑protected ZIP archive to instruct the victim to run a PowerShell command using ClickFix, ultimately resulting in the deployment of an open-source .NET infostealer called Stealerium. A campaign that exploits the public sharing feature of generative artificial intelligence (AI) services like Anthropic Claude to stage malicious ClickFix instructions on how to perform a variety of tasks on macOS (e.g., "online DNS resolver"), and distribute these links via sponsored results on search engines like Google to deploy Atomic Stealer and MacSync Stealer. A campaign that directs users searching for "macOS cli disk space analyzer" to a fake Medium article impersonating Apple's Support Team to deceive them into running ClickFix instructions that deliver next-stage stealer payloads from an external server "raxelpak[.]com." "The C2 domain raxelpak[.]com has URL history going back to 2021, when it appeared to host a safety workwear e-commerce site," MacPaw's Moonlock Lab said. "Whether the domain was hijacked or simply expired and re-registered by the [threat actor] is unclear, but it fits the broader pattern of leveraging aged domains with existing reputation to avoid detection." A variation of the same campaign that stages ClickFix instructions for supposedly installing Homebrew on links associated with Claude and Evernote and distributes them through sponsored results to install stealer malware. "The ad shows a real, recognized domain (claude.ai), not a spoof or typo-squatted site," AdGuard said. "Clicking the ad leads to a real Claude page, not a phishing copy. The consequence is clear: Google Ads + a well-known trusted platform + technical users with high downstream impact = a potent malware distribution vector." A macOS email phishing campaign that prompts recipients to download and run an AppleScript file to address supposed compatibility issues, resulting in the deployment of another AppleScript designed to steal credentials and retrieve additional JavaScript payloads. "The malware does not grant permissions to itself; instead, it forges TCC authorizations for trusted Apple-signed binaries (Terminal, osascript, Script Editor, and bash) and then executes malicious actions through these binaries to inherit their permissions," Darktrace said. A ClearFake campaign that employs fake CAPTCHA lures on compromised WordPress sites to trigger the execution of an HTML Application (HTA) file and deploy Lumma Stealer. The campaign is also known to use malicious JavaScript injections to take advantage of a technique known as EtherHiding to execute a contract hosted on the BNB Smart Chain and fetch an unknown payload hosted on GitHub. EtherHiding offers attackers several advantages. It allows malicious traffic to blend with legitimate Web3 activity. Because blockchain is immutable and decentralized, it also offers increased resilience in the face of takedown efforts. The use of ClickFix techniques to target macOS underlines a broader trend where threat actors are increasingly seeking out machines that run Apple's operating system to infect them with infostealers and sophisticated tools, per a recent analysis published by Flare. No less than 103 Chrome crypto extensions are targeted by macOS stealers, with attackers obtaining valid Apple developer signatures to bypass Gatekeeper protections. "Nearly every macOS stealer prioritizes cryptocurrency theft above all else," the company said. "This laser focus reflects economic reality. Cryptocurrency users disproportionately use Macs. They often hold significant value in software wallets. Unlike bank accounts, crypto transactions are irreversible. Once seed phrases are compromised, funds disappear permanently with no recourse." "The 'Macs don't get viruses' assumption is not just outdated but actively dangerous. Organizations with Mac users need detection capabilities for macOS-specific TTPs: unsigned applications requesting passwords, unusual Terminal activity, connections to blockchain nodes for non-financial purposes, and data exfiltration patterns targeting Keychain and browser storage."
thehackernews.comFeb 15, 2026extracted
40 open-source tools redefining how security teams secure the stack
40 open-source tools redefining how security teams secure the stack Open source security software has become a key way for teams to get flexibility, transparency, and capability without licensing costs. The free tools in this roundup address problems security teams deal with, from managing large environments to catching misconfigurations and understanding how new technologies change threat exposure. Aegis Authenticator: Free, open-source 2FA app for Android Aegis Authenticator is an open-source 2FA app for Android that helps you manage login codes for your online accounts. Arkime: Open-source network analysis and packet capture system Arkime is an open-source system for large-scale network analysis and packet capture. It works with your existing security tools to store and index network traffic in standard PCAP format, making it easy to search and access. Artemis: Open-source modular vulnerability scanner Artemis is an open-source modular vulnerability scanner that checks different aspects of a website’s security and translates the results into easy-to-understand messages that can be shared with the organizations being scanned. Autoswagger: Open-source tool to expose hidden API authorization flaws Autoswagger is a free, open-source tool that scans OpenAPI-documented APIs for broken authorization vulnerabilities. These flaws are still common, even at large enterprises with mature security teams, and are especially dangerous because they can be exploited with little technical skill. Buttercup: Open-source AI-driven system detects and patches vulnerabilities Buttercup is a free, automated, AI-powered platform that finds and fixes vulnerabilities in open-source software. Developed by Trail of Bits, it recently earned second place in DARPA’s AI Cyber Challenge (AIxCC). Calico: Open-source solution for Kubernetes networking, security, and observability Calico is an open-source unified platform that brings together networking, security, and observability for Kubernetes, whether you’re running in the cloud, on-premises, or at the edge. The solution uses the lowest amount of processing resources, which is especially important in edge environments where compute resources are limited. Chekov: Open-source static code analysis tool Checkov is an open-source tool designed to help teams secure their cloud infrastructure and code. At its core, it’s a static code analysis tool for infrastructure as code (IaC), but it also goes a step further by providing software composition analysis (SCA) for container images and open source packages. cnspec: Open-source, cloud-native security and policy project cnspec is an open source tool that helps when you are trying to keep a sprawling setup of clouds, containers, APIs and endpoints under control. It checks security and compliance across all of it, which makes it easier to see what needs attention. DefectDojo: Open-source DevSecOps platform DefectDojo is an open-source tool for DevSecOps, application security posture management (ASPM), and vulnerability management. It helps teams manage security testing, track and remove duplicate findings, handle remediation, and generate reports. Dependency-Track: Open-source component analysis platform Software is a patchwork of third-party components, and keeping tabs on what’s running under the hood has become a challenge. The open-source platform Dependency-Track tackles that problem head-on. Rather than treating software composition as a one-time scan, it continuously monitors every version of every application, giving organizations a live view of risk across their entire portfolio. EntraGoat: Vulnerable Microsoft Entra ID infrastructure to simulate identity security misconfigurations EntraGoat is a purpose-built tool that sets up a vulnerable Microsoft Entra ID environment to mimic real-world identity security issues. It’s designed to help security professionals practice spotting and exploiting common misconfigurations. Falco: Open-source cloud-native runtime security tool for Linux Falco is an open-source runtime security tool for Linux systems, built for cloud-native environments. It monitors the system in real time to spot unusual activity and possible security threats. Firezone: Open-source platform to securely manage remote access Firezone is an open-source platform that helps organizations of any size manage secure remote access. Unlike most VPNs, it uses a least-privileged model, giving users only the access they need. Garak: Open-source LLM vulnerability scanner LLMs can make mistakes, leak data, or be tricked into doing things they were not meant to do. Garak is a free, open-source tool designed to test these weaknesses. It checks for problems like hallucinations, prompt injections, jailbreaks, and toxic outputs. By running different tests, it helps developers understand where a model might fail and how to make it safer. GitPhish: Open-source GitHub device code flow security assessment tool GitPhish is an open-source security research tool built to replicate GitHub’s device code authentication flow. It features three core operating modes: an authentication server, automated landing page deployment, and an administrative management interface. Heisenberg: Open-source software supply chain health check tool Heisenberg is an open-source tool that checks the health of a software supply chain. It analyzes dependencies using data from deps.dev, Software Bills of Materials (SBOMs), and external advisories to measure package health, detect risks, and generate reports for individual dependencies or entire projects. InterceptSuite: Open-source network traffic interception tool InterceptSuite is an open-source, cross-platform network traffic interception tool designed for TLS/SSL inspection, analysis, and manipulation at the network level. Kanister: Open-source data protection workflow management tool Kanister is an open-source tool that lets domain experts define how to manage application data using blueprints that are easy to share and update. It handles the complex parts of running these tasks on Kubernetes and gives a consistent way to manage different applications at scale. Kanvas: Open-source incident response case management tool Kanvas is an open-source incident response case management tool with a simple desktop interface, built in Python. It gives investigators a place to work with SOD (Spreadsheet of Doom) or similar files, so they can handle key tasks without jumping between different programs. Kopia: Open-source encrypted backup tool for Windows, macOS, Linux Kopia is an open-source backup and restore tool that lets you create encrypted snapshots of your files and store them in cloud storage, on a remote server, on network-attached storage, or on your own computer. It doesn’t create a full image of your machine. Instead, you pick the files and folders you want to back up or restore. LudusHound: Open-source tool brings BloodHound data to life LudusHound is an open-source tool that takes BloodHound data and uses it to set up a working Ludus Range for safe testing. It creates a copy of an Active Directory environment using previously gathered BloodHound data. Maltrail: Open-source malicious traffic detection system Maltrail is an open-source network traffic detection system designed to spot malicious or suspicious activity. It works by checking traffic against publicly available blacklists, as well as static lists compiled from antivirus reports and user-defined sources. These “trails” can include domain names, URLs, IP addresses, or even HTTP User-Agent values. On top of that, Maltrail can use optional heuristic methods to identify new or unknown threats, such as emerging malware. Metis: Open-source, AI-driven tool for deep security code review Metis is an open source tool that uses AI to help engineers run deep security reviews on code. Arm’s product security team built Metis to spot subtle flaws that are often buried in large or aging codebases where traditional tools struggle. Nagios: Open-source monitoring solution Nagios is an open-source monitoring solution, now included as part of the robust Nagios Core Services Platform (CSP). It delivers end-to-end visibility across the entire IT infrastructure, covering everything from websites and DNS to servers, routers, switches, workstations, and critical services. It helps organizations proactively detect issues, minimize downtime, and ensure the reliability of their systems. Nodepass: Open-source TCP/UDP tunneling solution When you think of network tunneling, “lightweight” and “enterprise-grade” rarely appear in the same sentence. NodePass, an open-source project, wants to change that. It’s a compact but powerful TCP/UDP tunneling solution built for DevOps teams and system administrators who need to manage complex network environments without wading through configuration files or rigid infrastructure setups. Nosey Parker: Open-source tool finds sensitive information in textual data and Git history Nosey Parker is an open-source command-line tool that helps find secrets and sensitive information hidden in text files. It works like a specialized version of grep, focused on spotting things like passwords, API keys, and other confidential data. Obot MCP Gateway: Open-source platform to securely manage the adoption of MCP servers Obot MCP Gateway is a free, open-source gateway that enables IT organizations to securely manage and scale adoption of Model Context Protocol (MCP) servers. OpenFGA: The open-source engine redefining access control OpenFGA is an open-source, high-performance, and flexible authorization engine inspired by Google’s Zanzibar system for relationship-based access control. It helps developers model and enforce fine-grained access control in their applications. Portmaster: Open-source application firewall Portmaster is a free and open source application firewall built to monitor and control network activity on Windows and Linux. The project is developed in the EU and is designed to give users stronger privacy without asking them to manage every rule by hand. pqcscan: Open-source post-quantum cryptography scanner pqcscan is an open-source tool that lets users scan SSH and TLS servers to see which Post-Quantum Cryptography (PQC) algorithms they claim to support. It saves the results in JSON files. You can turn one or more of these files into an HTML report that opens in a web browser. ProxyBridge: Open-source proxy routing for Windows applications ProxyBridge is a lightweight, open-source tool that lets Windows users route network traffic from specific applications through SOCKS5 or HTTP proxies. It can redirect both TCP and UDP traffic and gives users the option to route, block, or allow connections on a per-application basis. Proximity: Open-source MCP security scanner Proximity is a new open-source tool that scans Model Context Protocol (MCP) servers. It identifies the prompts, tools, and resources that a server makes available, and it can evaluate how those elements might introduce security risks. The tool also work with NOVA, a rule engine that checks for issues such as prompt injection or jailbreak attempts. Rayhunter: EFF releases open-source tool to detect cellular spying The Electronic Frontier Foundation (EFF) has released Rayhunter, a new open-source tool designed to detect cell site simulators (CSS). These devices, also known as IMSI catchers or Stingrays, mimic cell towers to trick phones into connecting so they can collect data. Rayhunter gives researchers, journalists, and privacy advocates a way to identify suspicious cellular activity. Reconmap: Open-source vulnerability assessment, pentesting management platform Reconmap is an open source tool for vulnerability assessments and penetration testing. It helps security teams plan, carry out, and report on security tests from start to finish. RIFT: New open-source tool from Microsoft helps analyze Rust malware Microsoft’s Threat Intelligence Center has released a new tool called RIFT to help malware analysts identify malicious code hidden in Rust binaries. While Rust is becoming more popular for its speed and memory safety, those same qualities make malware written in Rust harder to analyze. RIFT is designed to cut through that complexity and make the job easier. Secretless Broker: Open-source tool connects apps securely without passwords or keys Secretless Broker is an open-source connection broker that eliminates the need for client applications to manage secrets when accessing target services like databases, web services, SSH endpoints, or other TCP-based systems. sqlmap: Open-source SQL injection and database takeover tool Finding and exploiting SQL injection vulnerabilities is one of the oldest and most common steps in web application testing. sqlmap streamlines this process. It is an open-source penetration testing tool that automates the detection and exploitation of SQL injection flaws and can take over database servers when configured to do so. Strix: Open-source AI agents for penetration testing Security teams know that application flaws tend to show up at the worst time. Strix presents itself as an open source way to catch them earlier by using autonomous agents that behave like human attackers. These agents run code, explore an application, uncover weaknesses, and prove those findings with working proof of concepts. Vulnhuntr: Open-source tool to identify remotely exploitable vulnerabilities Vulnhuntr is an open-source tool that finds remotely exploitable vulnerabilities. It uses LLMs and static code analysis to trace how data moves through an application, from user input to server output. This helps it spot complex, multi-step vulnerabilities that traditional tools often miss. VulnRisk: Open-source vulnerability risk assessment platform VulnRisk is an open-source platform for vulnerability risk assessment. It goes beyond basic CVSS scoring by adding context-aware analysis that reduces noise and highlights what matters. The tool is free to use and designed for local development and testing. Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comDec 11, 2025extracted
Week in review: Windows kernel flaw patched, suspected Fortinet FortiWeb zero-day exploited
Week in review: Windows kernel flaw patched, suspected Fortinet FortiWeb zero-day exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Adopting a counterintelligence mindset in luxury logistics In this Help Net Security interview, Andrea Succi, Group CISO at Ferrari Group, discusses how cybersecurity is integrated into every aspect of the logistics industry. He explains why protecting data can be as critical as securing physical assets and how a layered defense approach helps safeguard both. Succi adds that awareness, collaboration, and resilience keep client trust and operations consistent. Wi-Fi signals may hold the key to touchless access control Imagine walking into a secure building where the door unlocks the moment your hand hovers near it. No keycards, no PINs, no fingerprints. Instead, the system identifies you by the way your palm distorts the surrounding Wi-Fi signal. That is the idea behind a new study from researchers at the Aeronautics Institute of Technology (ITA) in Brazil. To get funding, CISOs are mastering the language of money In this Help Net Security interview, Chris Wheeler, CISO at Resilience, talks about how CISOs are managing changing cybersecurity budgets. While overall spending is up, many say the increases don’t match their most pressing needs. Wheeler explains how organizations are reallocating funds, measuring ROI, and linking cybersecurity plans to business goals. When every day is threat assessment day In this Help Net Security interview, Paul J. Mocarski, VP & CISO at Sammons Financial Group, discusses how insurance carriers are adapting their cybersecurity strategies. He explains how ongoing threat assessments, AI-driven automation, and third-party risk management help maintain readiness. Healthcare security is broken because its systems can’t talk to each other In this Help Net Security interview, Cameron Kracke, CISO at Prime Therapeutics, discusses how the healthcare ecosystem can achieve cohesive security visibility. With hospitals, clinics, telehealth, and cloud partners all in the mix, maintaining visibility remains a complex task. Kracke shares how interoperability, collaboration, and strategic investment can strengthen resilience across the healthcare security landscape. Why your security strategy is failing before it even starts In this Help Net Security interview, Adnan Ahmed, CISO at Ornua, discusses how organizations can build a cybersecurity strategy that aligns with business goals. He explains why many companies stumble by focusing on technology before understanding risk and shares how embedding cybersecurity across the business helps build resilience. Attackers exploited another Gladinet Triofox vulnerability (CVE-2025-12480) Attackers have exploited yet another vulnerability (CVE-2025-12480) in the Gladinet Triofox secure file sharing and remote access platform, Mandiant revealed on Monday. CISA: Patch Samsung flaw exploited to deliver spyware (CVE-2025-21042) CISA has added CVE-2025-21042, a vulnerability affecting Samsung mobile devices, to its Known Exploited Vulnerabilities (KEV) catalog, and has ordered US federal civilian agencies to address it by the start of December. Patch Tuesday: Microsoft fixes actively exploited Windows kernel vulnerability (CVE-2025-62215) Microsoft has delivered a rather light load of patches for November 2025 Patch Tuesday: some 60+ vulnerabilities have received a fix, among them an actively exploited Windows Kernel flaw (CVE-2025-62215). UK’s new Cyber Security and Resilience Bill targets weak links in critical services The UK government has introduced the Cyber Security and Resilience Bill, a major piece of legislation designed to boost the country’s protection against cyber threats. The new law aims to strengthen the digital defenses of essential public services and update the ageing Network and Information Systems (NIS) Regulations 2018, the UK’s only cross-sector cyber security law. Rhadamanthys infostealer operation disrupted by law enforcement The rumors were true: Operation Endgame, a joint effort between law enforcement and judicial authorities of several European countries, Australia, Canada, the UK and the US, has disrupted the infrastructure supporting the operation of the Rhadamanthys infostealer. “Patched” but still exposed: US federal agencies must remediate Cisco flaws (again) CISA has ordered US federal agencies to fully address two actively exploited vulnerabilities (CVE-2025-20333, CVE-2025-20362) in Cisco Adaptive Security Appliances (ASA) and Firepower firewalls. Fake spam filter alerts are hitting inboxes A new phishing campaign is attempting to trick users into believing they’ve missed important emails, security researchers are warning. The bogus email alerts look like they are coming from the recipient’s email domain, and falsely claim that due to a “Secure Message system” upgrade, important messages have been blocked. A suspected Fortinet FortiWeb zero-day is actively exploited, researchers warn A suspected (but currently unidentified) zero-day vulnerability in Fortinet FortiWeb is being exploited by unauthenticated attackers to create new admin accounts on vulnerable, internet-facing devices. Chinese cyber spies used Claude AI to automate 90% of their attack campaign, Anthropic claims “Analysis of operational tempo, request volumes, and activity patterns confirms the AI executed approximately 80 to 90 percent of all tactical work independently, with humans serving in strategic supervisory roles,” Anthropic said. Shadow AI risk: Navigating the growing threat of ungoverned AI adoption AI is transforming how businesses operate, but it’s also creating new, often hidden risks. As employees and business units eagerly embrace and experiment with AI solutions, many organizations are losing control over where and how AI is being used. A new threat is emerging: shadow AI. This unsanctioned use of AI tools without oversight from IT or security teams has quickly become a top concern for CISOs. How to adopt AI security tools without losing control In this Help Net Security video, Josh Harguess, CTO of Fire Mountain Labs, explains how to evaluate, deploy, and govern AI-driven security tools. He talks about the growing role of AI in security operations and the new kinds of risks it brings. sqlmap: Open-source SQL injection and database takeover tool Finding and exploiting SQL injection vulnerabilities is one of the oldest and most common steps in web application testing. sqlmap streamlines this process. It is an open-source penetration testing tool that automates the detection and exploitation of SQL injection flaws and can take over database servers when configured to do so. CISOs are cracking under pressure Cybersecurity leaders are hitting their limit. A new report from Nagomi Security shows that most CISOs are stretched thin, dealing with nonstop incidents, too many tools, and growing pressure from their boards. The pressures are so intense that many say they are burned out and thinking about walking away. How far can police push privacy before it breaks Police use drones, body cameras, and license plate readers as part of their daily work. Supporters say these tools make communities safer. Critics see something different, a system that collects too much data and opens the door to abuse. When surveillance expands without public oversight, civil liberties start to slip away, especially for people who already face bias and discrimination. ProxyBridge: Open-source proxy routing for Windows applications ProxyBridge is a lightweight, open-source tool that lets Windows users route network traffic from specific applications through SOCKS5 or HTTP proxies. It can redirect both TCP and UDP traffic and gives users the option to route, block, or allow connections on a per-application basis. Autonomous AI could challenge how we define criminal behavior Whether we ever build AI that thinks like a person is still uncertain. What seems more realistic is a future with more independent machines. These systems already work across many industries and digital environments. Alongside human-to-human and human-to-machine contact, communication between machines is growing fast. Criminology should start to look at what this shift means for crime and social control. Google adds Emerging Threats Center to speed detection and response When a new vulnerability hits the news, security teams often scramble to find out if they are at risk. The process of answering that question can take days or weeks, involving manual research, rule-writing, and testing. Google Security Operations wants to close that window with its new Emerging Threats Center, designed to help teams understand their exposure and detection coverage in near real time. Sprout: Open-source bootloader built for speed and security Sprout is an open-source bootloader that delivers sub-second boot times and uses a clean, data-driven configuration format that works across operating systems. Wanna bet? Scammers are playing the odds better than you are Placing a bet has never been this easy, and that’s the problem. The convenience of online gambling is the same thing scammers are cashing in on. Whether it’s a fake app, a “can’t-miss” tipster, or a rigged casino, the game is stacked against you. Los Alamos researchers warn AI may upend national security For decades, the United States has built its defense posture around predictable timelines for technological progress. That assumption no longer holds, according to researchers at Los Alamos National Laboratory. Their paper argues that AI is advancing so quickly that the current defense system cannot adapt in time. Protecting mobile privacy in real time with predictive adversarial defense Mobile sensors are everywhere, quietly recording how users move, tilt, or hold their phones. The same data that powers step counters and activity trackers can also expose personal details such as gender, age, or even identity. A new study introduces a method designed to stop that information from being inferred in the first place, without interrupting the phone’s normal functions. AI is rewriting how software is built and secured AI has become part of everyday software development, shaping how code is written and how fast products reach users. A new report from Cycode, The 2026 State of Product Security for the AI Era, explores how deeply AI now runs through development pipelines and how security teams are trying to manage the risks that come with it. Hidden risks in the financial sector’s supply chain When a cyber attack hits a major bank or trading platform, attention usually turns to the institution. But new research suggests the real danger may lie elsewhere. BitSight researchers found that many of the technology providers serving the financial sector have weaker cybersecurity performance than the institutions they support. GNU Coreutils 9.9 brings fixes and updates across essential tools GNU Coreutils is the backbone of many enterprise Linux environments. It provides the basic file, shell, and text utilities that every GNU-based system depends on. The latest release, version 9.9, refines these tools with fixes and performance improvements. What the latest data reveals about hard drive reliability What really counts as a hard drive failure? That’s the question at the center of Backblaze’s Q3 2025 Drive Stats report, which tracks the performance of 328,348 hard drives across its global data centers. The latest findings build on more than a decade of data that has made Backblaze one of the most transparent sources on drive reliability for IT teams, researchers, and data professionals. AI is forcing boards to rethink how they govern security Boards are spending more time on cybersecurity but still struggle to show how investments improve business performance. The focus has shifted from whether to fund protection to how to measure its return and ensure it supports growth. The browser is eating your security stack Employees log into SaaS platforms, upload files, use AI tools, and manage customer data from a single tab. While the browser has become the enterprise’s main workspace, it remains largely outside the reach of security controls. According to the 2025 Browser Security Report by LayerX, that blind spot has turned into a major risk surface for data loss, identity theft, and AI misuse. Automation can’t fix broken security basics Most enterprises continue to fall short on basic practices such as patching, access control, and vendor oversight, according to Swimlane’s Cracks in the Foundation: Why Basic Security Still Fails report. Leadership often focuses on broad resilience goals while the day-to-day work that supports them remains inconsistent and underfunded. What happens when employees take control of AI Executives may debate AI strategy, but many of the advances are happening at the employee level. A recent Moveworks study shows that AI adoption is being led from the ground up, with employees, not senior leaders, driving the change. Download: Strengthening Identity Security whitepaper Identity threats are escalating. Attackers increasingly exploit compromised credentials, often undetected by organizations, and use social engineering to gain access. Most companies lack visibility into service account activity and don’t have the tools to detect identity-led threats. Cybersecurity jobs available right now: November 11, 2025 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: November 14, 2025 Here’s a look at the most interesting products from the past week, featuring releases from Action1, Avast, Cyware, Firewalla, and Nokod Security.
helpnetsecurity.comNov 16, 2025extracted
ProxyBridge: Open-source proxy routing for Windows applications
ProxyBridge: Open-source proxy routing for Windows applications ProxyBridge is a lightweight, open-source tool that lets Windows users route network traffic from specific applications through SOCKS5 or HTTP proxies. It can redirect both TCP and UDP traffic and gives users the option to route, block, or allow connections on a per-application basis. The tool operates at the kernel level using WinDivert, which means it works even with applications that are not proxy-aware. Users do not need to change any app settings or modify configurations for it to function. ProxyBridge offers a graphical interface and a command-line tool, making it suitable for casual users and power users alike. It supports a range of proxy protocols and can handle TCP and UDP traffic across various services, including HTTP, HTTPS, RDP, SSH, databases, and games. One of its main strengths is control. Users can decide which processes connect directly, which use a proxy, and which are blocked entirely. Rules can target specific processes, IP addresses, ports, and protocols, with wildcard matching for flexibility. The tool can also block applications from accessing the internet or local networks, and it includes an exclusion feature to prevent proxy loops. ProxyBridge is available for free on GitHub. Must read: 35 open-source security tools to power your red team, SOC, and cloud security GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comNov 12, 2025extracted
Gootloader malware is back with new tricks after 7-month break
The Gootloader malware loader operation has returned after a 7-month absence and is once again performing SEO poisoning to promote fake websites that distribute the malware. Gootloader is a JavaScript-based malware loader spread through compromised or attacker-controlled websites, used to trick users into downloading malicious documents. The websites are promoted in search engines either via ads or through search engine optimization (SEO) poisoning, which ranks a website higher in the results for a particular keyword, like legal documents and agreements. In the past, these websites would display fake message boards that pretended to discuss users' query, with some posts recommending (malicious) document templates that could be downloaded. The SEO campaigns later switched to using websites that pretend to offer free templates for various legal documents. When a visitor clicked the "Get Document" button, the site checked if they were a legitimate user and, if so, downloaded an archive containing a malicious document with a .js extension. For example, the archive could include a file named mutual_non_disclosure_agreement.js. Gootloader would execute when launching the document and downloaded additional malware payloads onto the device, including Cobalt Strike, backdoors, and bots that provided initial access to corporate networks. Other threat actors then used this access to deploy ransomware or conduct other attacks. Gootloader returns A cybersecurity researcher operating under the pseudonym "Gootloader" has been tracking and actively disrupting the malware operation for years by filing abuse reports with ISPs and hosting platforms to take down attacker-controlled infrastructure. The researcher told BleepingComputer that his activities led to the Gootloader operation suddenly ceasing on March 31st, 2025. The researcher and Anna Pham of Huntress Labs now report that Gootloader has returned in a new campaign that once again impersonates legal documents. "In this latest campaign, we've observed thousands of unique keywords spread over 100 websites," reads a new blog post by the Gootloader researcher. "The ultimate goal remains the same: convince victims to download a malicious ZIP archive containing a JScript (.JS) file that establishes initial access for follow-on activity — usually leading to ransomware deployment." However, the researchers say this new variant uses a few techniques to evade automated analysis tools and security researchers. Huntress found that the JavaScript added to malicious websites hides the real filenames by using a special web font that replaces letters with look-alike symbols. In the HTML source, you see nonsense text, but when the page is rendered, the font's swapped glyph shapes display normal words, making it harder for security software and researchers to find keywords like "invoice" or "contract" in the source code. "Rather than using OpenType substitution features or character mapping tables, the loader swaps what each glyph actually displays. The font's metadata appears completely legitimate—the character "O" maps to a glyph named "O", the character "a" maps to a glyph named "a", and so forth," explains Huntress. "However, the actual vector paths that define these glyphs have been swapped. When the browser requests the shape for glyph "O", the font provides the vector coordinates that draw the letter "F" instead. Similarly, "a" draws "l", "9" draws "o", and special Unicode characters like "±" draw "i". The gibberish string Oa9Z±h• in the source code renders as "Florida" on screen." Researchers from the DFIR Report also discovered that Gootloader is using malformed Zip archives to distribute Gootloader scripts from attacker-controlled websites. These archives are crafted so that when the downloaded ZIP file is extracted with Windows Explorer, the malicious JavaScript file, Review_Hearings_Manual_2025.js, is extracted. However, that same archive, when extracted within VirusTotal, Python's zip utilities, or 7-Zip, will unpack a harmless text file named Review_Hearings_Manual_202.txt. As you can see in the image below of 010 Editor, the archive contains both files but is malformed, causing it to be extracted differently depending on the tool used. It's unclear whether this is the same concatenation trick described in 2024 or if they are using a new technique to get Windows to extract the JS file. Finally, the campaign is dropping the Supper SOCKS5 backdoor on devices, which is used to gain remote access to the network. The Supper backdoor is malware that provides remote access to infected devices and is known to be used by a ransomware affiliate tracked as Vanilla Tempest. This threat actor has a long history of conducting ransomware attacks and is believed to have been an affiliate of Inc, BlackCat, Quantum Locker, Zeppelin, and Rhysida. In the attacks observed by Huntress, the threat actor moved fast once a device was infected, performing reconnaissance within 20 minutes and ultimately compromising the Domain Controller within 17 hours. With Gootloader now back in operation, consumers and corporate users need to be careful about searching for and downloading legal agreements and templates from the web. Unless the website is known for offering these types of templates, it should be treated with suspicion and avoided. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 5, 2025extracted
⚡ Weekly Recap: F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More
It’s easy to think your defenses are solid — until you realize attackers have been inside them the whole time. The latest incidents show that long-term, silent breaches are becoming the norm. The best defense now isn’t just patching fast, but watching smarter and staying alert for what you don’t expect. Here’s a quick look at this week’s top threats, new tactics, and security stories shaping the landscape. ⚡ Threat of the Week F5 Exposed to Nation-State Breach — F5 disclosed that unidentified threat actors broke into its systems and stole files containing some of BIG-IP's source code and information related to undisclosed vulnerabilities in the product. The company said it learned of the incident on August 9, 2025, although it's believed that the attackers were in its network for at least 12 months. The attackers are said to have used a malware family called BRICKSTORM, which is attributed to a China-nexus espionage group dubbed UNC5221. GreyNoise said it observed elevated scanning activity targeting BIG-IP in three waves on September 23, October 14, and October 15, 2025, but emphasized the anomalies may not necessarily relate to the hack. Censys said it identified over 680,000 F5 BIG-IP load balancers and application gateways visible on the public internet, with the majority of hosts located in the U.S., followed by Germany, France, Japan, and China. Not all identified systems are necessarily vulnerable, but each represents a publicly accessible interface that should be inventoried, access-restricted, and patched proactively as a precautionary measure. "Edge infrastructure and security vendors remain prime targets for long-term, often state-linked threat actors," John Fokker, vice president of threat intelligence strategy at Trellix, said. "Over the years, we have seen nation-state interest in exploiting vulnerabilities in edge devices, recognizing their strategic position in global networks. Incidents like these remind us that strengthening collective resilience requires not only hardened technology but also open collaboration and intelligence sharing across the security community." Zero Trust + AI: Thrive in the AI Era and Empower Your Workforce It’s no surprise, hackers are using AI in creative ways to compromise users and breach organizations. Zscaler Zero Trust + AI helps defeat ransomware and AI-power attacks today by enabling you to detect and block advanced threats, and discover and classify sensitive data everywhere. Learn more about Zscaler Zero Trust + AI ➝ 🔔 Top News N. Korea Uses EtherHiding to Hide Malware Inside Blockchain Smart Contracts — North Korean threat actors have been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a state-sponsored hacking group has embraced the method. The activity has been attributed to a cluster tracked as UNC5342 (aka Famous Chollima). The attack wave is part of a long-running campaign codenamed Contagious Interview, wherein the attackers approach potential targets on LinkedIn by posing as recruiters or hiring managers, and trick them into running malicious code under the pretext of a job assessment after shifting the conversation to Telegram or Discord. In the latest attack waves observed since February 2025, the threat actors use a JavaScript downloader that interacts with a malicious BSC smart contract to download JADESNOW, which subsequently queries the transaction history associated with an Ethereum address to fetch the JavaScript version of InvisibleFerret. LinkPro Linux Rootkit Spotted in the Wild — An investigation into the compromise of an Amazon Web Services (AWS)-hosted infrastructure led to the discovery of a new GNU/Linux rootkit dubbed LinkPro. The backdoor features functionalities relying on the installation of two extended Berkeley Packet Filter (eBPF) modules to conceal itself and to be remotely activated upon receiving a magic packet - a TCP SYN packet with a specific window size (54321) that signals the rootkit to await further instructions within a one-hour window, allowing it to evade traditional security defenses. The commands supported by LinkPro include executing /bin/bash in a pseudo-terminal, running a shell command, enumerating files and directories, performing file operations, downloading files, and setting up a SOCKS5 proxy tunnel. It's currently not known who is behind the attack, but it's suspected that the threat actors are financially motivated. Zero Disco Campaign Targets Cisco Devices with Rootkits — A new campaign has exploited a recently disclosed security flaw impacting Cisco IOS Software and IOS XE Software to deploy Linux rootkits on older, unprotected systems. The activity, codenamed Operation Zero Disco by Trend Micro, involves the weaponization of CVE-2025-20352 (CVSS score: 7.7), a stack overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow an authenticated, remote attacker to execute arbitrary code by sending crafted SNMP packets to a susceptible device. The operation primarily impacted Cisco 9400, 9300, and legacy 3750G series devices, Trend Micro said. The intrusions have not been attributed to any known threat actor or group. Pixnapping Attack Leads to Data Theft on Android Devices — Android devices from Google and Samsung have been found vulnerable to a side-channel attack that could be exploited to covertly steal two-factor authentication (2FA) codes, Google Maps timelines, and other sensitive data without the users' knowledge pixel-by-pixel. The attack has been codenamed Pixnapping. Google is tracking the issue under the CVE identifier CVE-2025-48561 (CVSS score: 5.5). Patches for the vulnerability were issued by the tech giant as part of its September 2025 Android Security Bulletin, with additional fixes forthcoming in December. Chinese Threat Actors Exploited ArcGIS Server as Backdoor — Threat actors with ties to China have been attributed to a novel campaign that compromised an ArcGIS system and turned it into a backdoor for more than a year. The activity is the handiwork of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal Panda and RedJuliett. "The group cleverly modified a geo-mapping application's Java server object extension (SOE) into a functioning web shell," ReliaQuest said. "By gating access with a hardcoded key for exclusive control and embedding it in system backups, they achieved deep, long-term persistence that could survive a full system recovery." The attack chain involved the threat actors targeting a public-facing ArcGIS server that was linked to a private, internal ArcGIS server by compromising a portal administrator account to deploy a malicious SOE, thereby allowing them to blend in with normal traffic and maintain access for extended periods. The attackers then instructed the public-facing server to create a hidden directory to serve as the group's "private workspace." They also blocked access to other attackers and admins with a hard-coded key. The findings demonstrate Flax Typhoon's consistent modus operandi of quietly turning an organization's own tools against itself rather than using sophisticated malware or exploits. ️🔥 Trending CVEs Hackers move fast. They often exploit new vulnerabilities within hours, turning a single missed patch into a major breach. One unpatched CVE can be all it takes for a full compromise. Below are this week’s most critical vulnerabilities gaining attention across the industry. Review them, prioritize your fixes, and close the gap before attackers take advantage. This week’s list includes — CVE-2025-24990, CVE-2025-59230 (Microsoft Windows), CVE-2025-47827 (IGEL OS before 11), CVE-2023-42770, CVE-2023-40151 (Red Lion Sixnet RTUs), CVE-2025-2611 (ICTBroadcast), CVE-2025-55315 (Microsoft ASP.NET Core), CVE-2025-11577 (Clevo UEFI firmware), CVE-2025-37729 (Elastic Cloud Enterprise), CVE-2025-9713, CVE-2025-11622 (Ivanti Endpoint Manager), CVE-2025-48983, CVE-2025-48984 (Veeam), CVE-2025-11756 (Google Chrome), CVE-2025-49201 (Fortinet FortiPAM and FortiSwitch Manager), CVE-2025-58325 (Fortinet FortiOS CLI), CVE-2025-49553 (Adobe Connect collaboration suite), CVE-2025-9217 (Slider Revolution plugin), CVE-2025-10230 (Samba), CVE-2025-54539 (Apache ActiveMQ), CVE-2025-41703, CVE-2025-41704, CVE-2025-41706, CVE-2025-41707 (Phoenix Contact QUINT4), and CVE-2025-11492, CVE-2025-11493 (ConnectWise Automate). 📰 Around the Cyber World Microsoft Unveils New Security Improvements — Microsoft revealed that "parts of the kernel in Windows 11 have been rewritten in Rust, which helps mitigate against memory corruption vulnerabilities like buffer overflows and helps reduce attack surfaces." The company also noted that it's taking steps to secure AI-powered agentic experiences on the operating system by ensuring that they operate with limited permissions and only obtain access to resources users' explicitly provide permission to. In addition, Microsoft said agents that integrate with Windows must be cryptographically signed by a trusted source so that they can be revoked if found to be malicious. Each AI agent will also run under its own dedicated agent account that's distinct from the user account on the device. "This facilitates agent-specific policy application that can be different from the rules applied to other accounts like those for human users," it said. SEO Campaign Uses Fake Ivanti Installers to Steal Credentials — A new attack campaign has leveraged SEO poisoning to lure users into downloading a malicious version of the Ivanti Pulse Secure VPN client. The activity targets users searching for legitimate software on search engines like Bing, redirecting them to attacker-controlled lookalike websites (ivanti-pulsesecure[.]com or ivanti-secure-access[.]org). The goal of this attack is to steal VPN credentials from the victim's machine, enabling further compromise. "The malicious installer, a signed MSI file, contains a credential-stealing DLL designed to locate, parse, and exfiltrate VPN connection details," Zscaler said. "The malware specifically targets the connectionstore.dat file to steal saved VPN server URIs, which it combines with hardcoded credentials for exfiltration. Data is sent to a command-and-control (C2) server hosted on Microsoft Azure infrastructure." Qilin's Ties with BPH Providers Exposed — Cybersecurity researchers from Resecurity examined Qilin ransomware group's "close affiliation" with underground bulletproof hosting (BPH) operators, finding that the e-crime actor has not only relied on Cat Technologies Co. Limited. (which, in turn, is hosted on an IP address tied to Aeza Group) for hosting its data leak site, but also advertised services like BEARHOST Servers (aka Underground) on its WikiLeaksV2 site, where the group publishes content about their activities. BEARHOST has been operational since 2016, offering its services for anywhere from $95 to $500. While BEARHOST abruptly announced the stoppage of its service on December 28, 2024, it is assessed that the threat actors have taken the BPH service into private mode, catering only to trusted and vetted underground actors. On May 8, 2025, it resurfaced as Voodoo Servers, only for the operators to terminate the service again towards the end of the month, citing political reasons. "The actors decided to disappear through an 'exit scam' scenario, keeping the underground audience completely clueless," Resecurity said. "Notably, the legal entities behind the service continue their operations." Notably, Cat Technologies Co. Limited. also shares links to shadowy entities like Red Bytes LLC, Hostway, Starcrecium Limited, and Chang Way Technologies Co. Limited, the last of which has been associated with extensive malware activity, hosting command-and-control (C2) servers of Amadey, StealC, and Cobalt Strike used by cybercriminals. Another entity of note is Next Limited, which shares the same Hong Kong address as Chang Way Technologies Co. Limited and has been attributed to malicious activity in connection with Proton66. U.S. Judge Bars NSO Group from Targeting WhatsApp — A U.S. judge barred NSO Group from targeting WhatsApp users and cut the punitive damages verdict awarded to Meta by a jury in May 2025 to $4 million, because the court did not have enough evidence to determine that NSO Group's behavior was "particularly egregious." The permanent injunction handed out by U.S. District Judge Phyllis Hamilton means that the Israeli vendor cannot use WhatsApp as a way to infect targets' devices. As a refresher, Meta sued the NSO Group in 2019 over the use of Pegasus spyware by exploiting a then-zero-day flaw in the messaging app to spy on 1,400 people from 20 countries, including journalists and human rights activists. It was fined close to $168 million earlier this May. The proposed injunction requires NSO Group to delete and destroy computer code related to Meta's platforms, and she concluded that the provision is "necessary to prevent future violations, especially given the undetectable nature of defendants' technology." Google's Privacy Sandbox Initiative is Officially Dead — In 2019, Google launched an initiative called Privacy Sandbox to come up with privacy-enhancing alternatives to replace third-party cookies on the web. However, with the company abandoning its plans to deprecate third-party tracking cookies, the project appears to be winding down. To that end, the tech giant said it's retiring the following Privacy Sandbox technologies citing low levels of adoption: Attribution Reporting API (Chrome and Android), IP Protection, On-Device Personalization, Private Aggregation (including Shared Storage), Protected Audience (Chrome and Android), Protected App Signals, Related Website Sets (including requestStorageAccessFor and Related Website Partition), SelectURL, SDK Runtime and Topics (Chrome and Android). In a statement shared with Adweek, the company said it will continue to work to improve privacy across Chrome, Android, and the web, but not under the Privacy Sandbox branding. Russia Blocks Foreign SIM Cards — Russia said it's taking steps to temporarily block mobile internet for foreign SIM cards, citing national security reasons. The new rule imposes a mandatory 24-hour mobile internet blackout for anyone entering Russia with a foreign SIM card. Flaw in CORS headers in Web Browsers Disclosed — The CERT Coordination Center (CERT/CC) disclosed details of a vulnerability in cross-origin resource sharing (CORS) headers in Chromium, Google Chrome, Microsoft Edge, Safari, and Firefox that enables the CORS policy to be manipulated. This can be combined with DNS rebinding techniques to issue arbitrary requests to services listening on arbitrary ports, regardless of the CORS policy in place by the target. "An attacker can use a malicious site to execute a JavaScript payload that periodically sends CORS headers in order to ask the server if the cross-origin request is safe and allowed," CERT/CC explained. "Naturally, the attacker-controlled hostname will respond with permissive CORS headers that will circumvent the CORS policy. The attacker then performs a DNS rebinding attack so that the hostname is assigned the IP address of the target service. After the DNS responds with the changed IP address, the new target inherits the relaxed CORS policy, allowing an attacker to potentially exfiltrate data from the target." Mozilla is tracking the vulnerability as CVE-2025-8036. Phishing Campaigns Use Microsoft's Logo for Tech Support Scams — Threat actors are exploiting Microsoft's Name and branding in phishing emails to lure users into fraudulent tech support scams. The messages contain links that, when clicked, take the victims to a fake CAPTCHA challenge, after which they are redirected to a phishing landing page to unleash the next stage of the attack. "After passing the captcha verification, the victim is suddenly visually overloaded with several pop-ups that appear to be Microsoft security alerts," Cofense said. "Their browser is manipulated to appear locked, and they lose the ability to locate or control their mouse, which adds to the feeling that the system is compromised. This involuntary loss of control creates a faux ransomware experience, leading the user to believe their computer is locked and to take immediate action to remedy the infection." From there, users are instructed to call a number to reach Windows Support, at which they are connected to a bogus technician to take the attack forward. "The threat actor could exploit further by asking the user to provide account credentials or persuade the user to install remote desktop tools, allowing full access to their system," the company said. Taxpayers, Drivers Targeted in Refund and Road Toll Smishing Scams — A smishing campaign has leveraged at least 850 newly-registered domain names in September and early October to target people living in the U.S., the U.K., and elsewhere with phishing links that use tax refunds, road toll charges, or failed package deliveries as a lure. The websites, designed to be loaded only when launched from a mobile device, claim to provide information about their tax refund status or obtain a subsidy of up to £300 to help offset winter fuel costs (note: this is a real U.K. government initiative), only to prompt them to provide personal details such as name, home address, telephone number and email address, as well as payment card information. The entered data is exfiltrated to the attackers over the WebSocket protocol. Some of the scam websites have also been found to target Canadian, German, and Spanish residents and visitors, per Netcraft. Meta's New Collage Feature May Use Photos in Phone's Camera Roll — Meta is officially rolling out a new opt-in feature to Facebook users in the U.S. and Canada to suggest the best photos and videos from users' camera roll and create collages and edits. "With your permission and the help of AI, our new feature enables Facebook to automatically surface hidden gems – those memorable moments that get lost among screenshots, receipts, and random snaps – and edit them to save or share," the company said. The feature was first tested back in late June 2025. The social media company emphasized that the suggestions are private and that it does not use media obtained from users' devices via the camera roll to train its models, unless users opt to edit the media with their AI tools or publish those suggestions to Facebook. Users who wish to opt out of the feature can do so by navigating Settings and Privacy > Settings > Preferences > Camera Roll Sharing Suggestions. Fake Homebrew, TradingView, LogMeIn Sites Serve Stealer Malware Targeting Macs — Threat actors are employing social engineering tactics to trick users into visiting fake websites impersonating trusted platforms like as Homebrew, TradingView, and LogMeIn, where they are instructed to copy and run a malicious command on the Terminal app as part of ClickFix-style attacks, resulting in the deployment of stealer malware such as Atomic Stealer and Odyssey Stealer. "More than 85 phishing domains were identified, connected through shared SSL certificates, payload servers, and reused infrastructure," Hunt.io said. "The findings suggest a coordinated and ongoing campaign in which operators continuously adapt their infrastructure and tactics to maintain persistence and evade detection within the macOS ecosystem." It's suspected that users are driven to these websites via sponsored ads on search engines like Bing and Google. Dutch Data Protection Watchdog Fines Experian $3.2 Million for Privacy Violations — The Dutch Data Protection Authority (DPA) imposed a fine of €2.7 million ($3.2 million) on Experian Netherlands for collecting data in contravention of the E.U. General Data Protection Regulation (GDPR). The DPA said the consumer credit reporting company gathered information on people from both public and non-public sources and failed to make it clear why the collection of certain data was necessary. In addition to the penalty, Experian is expected to delete the database of personal data by the end of the year. The company has also ceased its operations in the country. "Until January 1, 2025, Experian provided credit assessments about individuals to its clients," the DPA said. "To do this, the company collected data such as negative payment behavior, outstanding debts, or bankruptcies. The AP found that Experian violated the law by unlawfully using personal data." Threat Actors Send Fake Password Manager Breach Alerts — Bad actors are sending phishing alerts claiming that their password manager accounts for 1Password and Lastpass have been compromised in order to trick users into providing their passwords and hijack their accounts. In response to the attack, LastPass said it has not been hacked and that it's an attempt on the part of the attackers to generate a false sense of urgency. In some cases spotted by Bleeping Computer, the activity has also been found to urge recipients to install a more secure version of the password manager, resulting in the deployment of a legitimate remote access software called Syncro. The software vendor has since moved to shut down the malicious accounts to prevent further installs. SocGholish MaaS Detailed — LevelBlue has published an analysis of a threat activity cluster known as SocGholish (aka FakeUpdates), which is known to be active since 2017, leveraging fake web browser update prompts on compromised websites as a lure to distribute malware. Victims are typically routed through Traffic Distribution Systems (TDS) like Keitaro and Parrot TDS to filter users based on specific factors such as geography, browser type, or system configuration, ensuring that only the intended targets are exposed to the payload. It's offered under a malware-as-a-service (MaaS) by a financially motivated cybercrime group called TA569. SocGholish stands out for its ability to turn legitimate websites into large-scale distribution platforms for malware. Acting as an initial access broker (IAB), its operations profit from follow-on compromises by other actors. "Once executed, its payloads range from loaders and stealers to ransomware, allowing for extensive follow-up exploitation," LevelBlue said. "This combination of broad reach, simple delivery mechanisms, and flexible use by multiple groups makes SocGholish a persistent and dangerous threat across industries and regions." One of its primary users is Evil Corp, with the malware also used to deliver RansomHub in early 2025. 🎥 Cybersecurity Webinars The Practical Framework to Govern AI Agents Without Slowing Innovation → AI is changing everything fast — but for most security teams, it still feels like a fight just to keep up. The goal isn’t to slow innovation with more controls; it’s to make those controls work for the business. By building security into AI from the start, you can turn what used to be a bottleneck into a real accelerator for growth and trust. The Future of AI in GRC: Turning Risk Into a Compliance Advantage - AI is changing how companies manage risk and compliance — fast. It brings big opportunities but also new challenges. This webinar shows you how to use AI safely and effectively in GRC, avoid common mistakes, and turn complex rules into a real business advantage. Workflow Clarity: How to Blend AI and Human Effort for Real Results - Too many teams are rushing to “add AI” without a plan — and ending up with messy, unreliable workflows. Join us to learn a clearer approach: how to use AI thoughtfully, simplify automation, and build systems that scale securely. 🔧 Cybersecurity Tools Beelzebub - It turns honeypot deployment into a powerful, low-code experience. It uses AI to simulate real systems, helping security teams detect attacks, track emerging threats, and share insights through a global threat intelligence network. NetworkHound - It maps your Active Directory network from the inside out. It discovers every device — domain-joined or shadow-IT — validates SMB and web services, and builds a full BloodHound-compatible graph so you can see and secure your environment clearly. Disclaimer: These tools are for educational and research use only. They haven’t been fully security-tested and could pose risks if used incorrectly. Review the code before trying them, test only in safe environments, and follow all ethical, legal, and organizational rules. 🔒 Tip of the Week Most Cloud Breaches Aren’t Hacks — They’re Misconfigurations. Here’s How to Fix Them — Cloud storage buckets like AWS S3, Azure Blob, and Google Cloud Storage make data sharing easy — but one wrong setting can expose everything. Most data leaks happen not because of hacking, but because someone left a public bucket, skipped encryption, or used a test bucket that never got locked down. Cloud platforms give you flexibility, not guaranteed safety, so you need to check and control access yourself. Misconfigurations usually happen when permissions are too broad, encryption is disabled, or visibility is lost across multiple clouds. Doing manual checks doesn’t scale — especially if you manage data in AWS, Azure, and GCP. The fix is using tools that automatically find, report, and even fix unsafe settings before they cause damage. ScoutSuite is a strong starting point for cross-cloud visibility. It scans AWS, Azure, and GCP for open buckets, weak IAM roles, and missing encryption, then creates an easy-to-read HTML report. Prowler goes deeper into AWS, checking S3 settings against CIS and AWS benchmarks to catch bad ACLs or unencrypted buckets. For ongoing control, Cloud Custodian lets you write simple policies that automatically enforce rules — for example, forcing all new buckets to use encryption. And CloudQuery can turn your cloud setup into a searchable database, so you can monitor changes, track compliance, and visualize risks in one place. The best approach is to combine them: run ScoutSuite or Prowler weekly to find issues, and let Cloud Custodian handle automatic fixes. Even a few hours spent setting these up can stop the kind of data leaks that make headlines. Always assume every bucket is public until proven otherwise — and secure it like it is. Conclusion The truth is, no tool or patch will ever make us fully secure. What matters most is awareness — knowing what’s normal, what’s changing, and how attackers think. Every alert, log, or minor anomaly is a clue. Keep connecting those dots before someone else does.
thehackernews.comOct 20, 2025extracted
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
An investigation into the compromise of an Amazon Web Services (AWS)-hosted infrastructure has led to the discovery of a new GNU/Linux rootkit dubbed LinkPro, according to findings from Synacktiv. "This backdoor features functionalities relying on the installation of two eBPF [extended Berkeley Packet Filter] modules, on the one hand to conceal itself, and on the other hand to be remotely activated upon receiving a 'magic packet,'" security researcher Théo Letailleur said. The infection, per the French cybersecurity company, involved the attackers exploiting an exposed Jenkins server vulnerable to CVE-2024-23897 (CVSS score: 9.8) as the starting point, following which a malicious Docker Hub image named "kvlnt/vv" (now removed) was deployed on several Kubernetes clusters. The Docker image consists of a Kali Linux base along with a folder called "app" containing three files - start.sh, a shell script to start the SSH service and execute the remaining two files link, an open-source program called vnt that acts as a VPN server and provides proxy capabilities by connecting to vnt.wherewego[.]top:29872, allowing the attacker to connect to the compromised server from anywhere and use it as a proxy to reach other servers app, a Rust-based downloader referred to as vGet that receives an encrypted VShell payload from an S3 bucket, which then proceeds to communicate with its own command-and-control (C2) server (56.155.98[.]37) over a WebSocket connection Also delivered to the Kubernetes nodes were two other malware strains, a dropper embedding another vShell backdoor, and LinkPro, a rootkit written in Golang. The stealthy malware can operate in either passive (aka reverse) or active (aka forward) mode, depending on its configuration, allowing it to listen for commands from the C2 server only upon receiving a specific TCP packet or directly initiate contact with the server. While the forward mode supports five different communication protocols, including HTTP, WebSocket, UDP, TCP, and DNS, the reverse mode only uses the HTTP protocol. The overall sequence of events unfolds as follows - Install the "Hide" eBPF module, which contains eBPF programs of the Tracepoint and Kretprobe types to hide its processes and network activity If the "Hide" module installation fails, or if it has been disabled, install the shared library "libld.so" in /etc/ld.so.preload If reverse mode is used, install the "Knock" eBPF module, which contains two eBPF programs of the eXpress Data Path (XDP) and Traffic Control (TC) types to ensure that the C2 communication channel is fired only upon the receipt of the magic packet Achieve persistence by setting up a systemd service Execute C2 commands On interruption (SIGHUP, SIGINT, and SIGTERM signals), uninstall the eBPF modules and delete the modified /etc/libld.so and restore it back to its original version To achieve this, LinkPro modifies the "/etc/ld.so.preload" configuration file to specify the path of the libld.so shared library embedded within it with the main objective of concealing various artifacts that could reveal the backdoor's presence. "Thanks to the presence of the /etc/libld.so path in /etc/ld.so.preload, the libld.so shared library installed by LinkPro is loaded by all programs that require /lib/ld-linux.so14," Letailleur explained. "This includes all programs that use shared libraries, such as glibc." "Once libld.so is loaded at the execution of a program, for example /usr/bin/ls, it hooks (before glibc) several libc functions to modify results that could reveal the presence of LinkPro." The magic packet, per Synacktiv, is a TCP packet with a window size value of 54321. Once this packet is detected, the Knock module saves the source IP address of the packet and an associated expiration date of one hour as its value. The program then keeps an eye out for additional TCP packets whose source IP address matches that of the already saved IP. In other words, the core functionality of LinkPro is to wait for a magic packet to be sent, after which the threat actor has a one-hour window to send commands to a port of their choice. The Knock module is also designed to modify the incoming TCP packet's header to replace the original destination port with LinkPro's listening port (2333), and alter the outgoing packet to replace the source port (2233) with the original port. "The purpose of this maneuver is to allow the operator to activate command reception for LinkPro by going through any port authorized by the front-end firewall," Synacktiv said. "This also makes the correlation between the front-end firewall logs and the network activity of the compromised host more complex." The commands supported by LinkPro include executing /bin/bash in a pseudo-terminal, running a shell command, enumerating files and directories, performing file operations, downloading files, and setting up a SOCKS5 proxy tunnel. It's currently not known who is behind the attack, but it's suspected that the threat actors are financially motivated. "For its concealment at the kernel level, the rootkit uses eBPF programs of the tracepoint and kretprobe types to intercept the getdents (file hiding) and sys_bpf (hiding its own BPF programs) system calls. Notably, this technique requires a specific kernel configuration (CONFIG_BPF_KPROBE_OVERRIDE)," the company said. "If the latter is not present, LinkPro falls back on an alternative method by loading a malicious library via the /etc/ld.so.preload file to ensure the concealment of its activities in user space."
thehackernews.comOct 16, 2025extracted
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown
Cybersecurity researchers have flagged a malicious package on the Python Package Index (PyPI) repository that claims to offer the ability to create a SOCKS5 proxy service, while also providing a stealthy backdoor-like functionality to drop additional payloads on Windows systems. The deceptive package, named soopsocks, attracted a total of 2,653 downloads before it was taken down. It was first uploaded by a user named "soodalpie" on September 26, 2025, the same date the account was created. "While providing this capability, it exhibits behavior as a backdoor proxy server targeting Windows platforms, using automated installation processes via VBScript or an executable version," JFrog said in an analysis. The executable ("_AUTORUN.EXE") is a compiled Go file that, besides including a SOCKS5 implementation as advertised, is also designed to run PowerShell scripts, set firewall rules, and relaunch itself with elevated permissions. It also carries out basic system and network reconnaissance, including Internet Explorer security settings and Windows installation date, and exfiltrates the information to a hard-coded Discord webhook. "_AUTORUN.VBS," the Visual Basic Script launched by the Python package in versions 0.2.5 and 0.2.6, is also capable of running a PowerShell script, which then downloads a ZIP file containing the legitimate Python binary from an external domain ("install.soop[.]space:6969") and generates a batch script that's configured to install the package using the "pip install" command and run it. The PowerShell script then invokes the batch script, causing the Python package to be executed, which, in turn, elevates itself to run with administrative privileges (if not already), configure firewall rules to allow UDP and TCP communication via port 1080, install as a service, maintain communication with a Discord webhook, and set up persistence on the host using a scheduled task to make sure it automatically starts upon a system reboot. "soopsocks is a well-designed SOCKS5 proxy with full bootstrap Windows support," JFrog said. "However, given the way it performs and actions it takes during runtime, it shows signs of malicious activity, such as firewall rules, elevated permissions, various PowerShell commands, and the transfer from simple, configurable Python scripts to a Go executable with hardcoded parameters, version with reconnaissance capabilities to a predetermined Discord webhook." The disclosure comes as npm package maintainers have raised concerns related to a lack of native 2FA workflows for CI/CD, self-hosted workflow support for trusted publishing, and token management following sweeping changes introduced by GitHub in response to a growing wave of software supply chain attacks, Socket said. Earlier this week, GitHub said it will shortly revoke all legacy tokens for npm publishers and that all granular access tokens for npm will have a default expiration of seven days (down from 30 days) and a maximum expiration of 90 days, which used to be unlimited previously. "Long-lived tokens are a primary vector for supply chain attacks. When tokens are compromised, shorter lifetimes limit the window of exposure and reduce potential damage," it said. "This change brings npm in line with security best practices already adopted across the industry." It also comes as the software supply chain security firm released a free tool called Socket Firewall that blocks malicious packages at install time across npm, Python, and Rust ecosystems, giving developers the ability to safeguard their environments against potential threats. "Socket Firewall isn't limited to protecting you from problematic top-level dependencies. It will also prevent the package manager from fetching any transitive dependency that is known to be malicious," the company added.
thehackernews.comOct 2, 2025extracted
Top 5 Tecniche per Monitorare il Dark Web e Raccogliere e Automatizzare Intelligence (OSINT)
Il Dark Web è spesso raccontato come un luogo misterioso, popolato da criminali informatici e marketplace di merce illegale. In realtà, per chi si occupa di cybersecurity e threat intelligence, rappresenta un’enorme fonte di dati utili: forum dove vengono vendute credenziali rubate, dump di database aziendali, annunci di Ransomware-as-a-Service e molto altro. Monitorare questi spazi in modo sistematico e sicuro permette ai team di threat intelligence e ai SOC di guadagnare tempo prezioso: scoprire prima che i propri dati vengano pubblicati, anticipare nuove TTP degli attaccanti e arricchire la detection con indicatori in tempo reale. In questo articolo vediamo 5 tecniche pratiche per monitorare il Dark Web, con esempi concreti di strumenti, piccoli script e pipeline di automazione. L’obiettivo non è “navigare per curiosità”, ma capire come un SOC o un team di incident response possa integrare queste informazioni nei propri processi di detection e difesa. 1. Crawler .onion personalizzati Il punto di partenza per esplorare il Dark Web è la creazione di un piccolo crawler in grado di visitare hidden services e scaricare i contenuti di interesse. Dal punto di vista tecnico, basta configurare Tor come proxy locale e usare una libreria come Stem per Python o semplici richieste HTTP instradate via SOCKS5. Questo permette di predisporre script che si connettono a indirizzi .onion, scaricano le pagine e le salvano localmente per successive analisi. Un esempio pratico in Python può essere realizzato con poche righe di codice usando requests e una sessione proxata su 127.0.0[.]1:9050. Naturalmente, l’ambiente deve essere isolato tramite VM dedicata (QUI la nostra guida per navigare in sicurezza nel dark web). Questo approccio consente di raccogliere contenuti senza interazione diretta, riducendo il rischio, dall’altro permette di costruire un archivio locale su cui applicare ricerche e analisi successive. Setup tecnico: Installare Tor e usare la libreria Stem per Python. Creare uno script che si connette via socks5://127.0.0.1:9050 e scarica contenuti. Esempio di snippet in Python: import requests session = requests.session() session.proxies = {'http': 'socks5h://127.0.0.1:9050', 'https': 'socks5h://127.0.0.1:9050'} url = "http://exampleonionaddress[.]onion" response = session.get(url) print(response.text[:500]) 2. Monitoraggio marketplace e forum Se i crawler servono a raccogliere dati, i forum e i marketplace sono i luoghi dove quei dati vengono messi in circolazione. Qui si trovano credenziali, database, accessi RDP o VPN in vendita, ma anche discussioni che anticipano trend futuri. Per documentare e analizzare in modo strutturato queste fonti esistono strumenti come OnionScan, capace di mappare hidden services e correlare metadata, e Hunchly, utile a conservare prove in maniera forense. Un’altra opzione è Spiderfoot, che permette di automatizzare OSINT e integrare moduli dedicati al Dark Web. Il metodo efficace è definire una lista di parole chiave: domini email aziendali, nomi di brand, prodotti interni. Lo scraper raccoglie i testi, un parser li analizza e li archivia in un database. A quel punto, ogni volta che un termine di interesse appare in un thread, è possibile investigare immediatamente. La difficoltà sta nel distinguere i “fake leak” da annunci reali: molti attori pubblicano campioni incompleti come anche falsi. Serve quindi un processo di validazione, che può includere analisi di hash, confronti con credenziali interne o sandboxing di file sospetti. Strumenti utili: OnionScan: scanner open source per analizzare hidden services. Hunchly: utile per documentare e preservare prove (catena di custodia). Spiderfoot: per automatizzare OSINT, anche su domini .onion. Come impostare un monitoraggio: Definire una lista di keyword (es. nome azienda, dominio email, nomi di prodotto). Usare cronjob o scheduler per eseguire scraping periodico. Salvare contenuti in un database locale per successiva analisi. 3. Feed Dark Web + integrazione CTI Oltre alle attività di raccolta autonoma, esistono feed pubblici e piattaforme di condivisione che forniscono indicatori già arricchiti. MISP e OpenCTI sono due strumenti open source ormai standard in molti SOC, che consentono di centralizzare IoC (indicatori di compromissione), correlare eventi e storicizzare campagne. Integrare i dati del Dark Web in queste piattaforme consente di arricchire le indagini. Lo scenario tipico prevede una pipeline dove: Il crawler scarica pagine .onion. Un parser estrapola email, domini, indirizzi IP, fingerprint PGP. Gli indicatori vengono importati in MISP o OpenCTI. Il SIEM aziendale li usa come lista di correlazione nei log di autenticazione, proxy e firewall. Snippet shell per grep di domini nei dump raccolti: grep -i “example[.]com” darkweb_dumps/*.txt | cut -d: -f1 | sort | uniq 4. Analisi di PGP keys e reti di trust Un aspetto spesso sottovalutato è l’uso delle chiavi PGP nel Dark Web. Molti attori firmano i propri messaggi con la stessa chiave per creare una sorta di reputazione. Collezionare e analizzare queste chiavi consente di correlare identità apparentemente distinte su più forum. Con GPG (GNU Privacy Guard) è possibile importare fingerprint e creare un database locale. A questo punto, è possibile osservare le chiavi utilizzati dai threat actor: se una chiave compare associata a un vendor in due marketplace diversi, vuol dire che si tratta dello stesso attore. Questa informazione è preziosa per analisi di attribution, ma anche per verificare la credibilità di un annuncio di leak. Le reti di fiducia costruite intorno a PGP permettono anche di individuare pattern di collaborazione tra gruppi criminali: incrociando le firme si scoprono spesso alleanze, rivalità o transizioni di identità tra nickname. Come fare: Salvare i fingerprint PGP pubblicati nei forum. Confrontare se la stessa chiave appare su più marketplace. Usare gpg –recv-keys per collezionare chiavi da keyserver pubblici. Caso pratico: Se un venditore usa lo stesso fingerprint PGP in due forum diversi, è probabile che le sue attività siano collegate: informazione preziosa in un’indagine di attribution. 5. Automazione e alerting continuo Il limite principale del monitoraggio manuale è la scalabilità. Un analista può esplorare un forum, ma non centinaia di hidden services contemporaneamente. La soluzione è l’automazione. Un esempio pratico: se una lista di username trapelati viene importata in Splunk, è possibile scrivere una query che correla questi account con tentativi di login falliti o accessi da geografie insolite. Lo stesso vale per indirizzi IP o hash di file malevoli. Anche il monitoraggio del traffico Tor in uscita può fornire insight: non sempre è segno di attività malevola, ma può indicare un comportamento anomalo su endpoint aziendali. Strumenti come Zeek o Suricata consentono di generare alert quando un host interno inizia a comunicare con nodi noti della rete Tor. Integrazione con SIEM: Importare indicatori in Elastic/Splunk. Creare alert per correlare username leaked con login sospetti. Query esempio Splunk: index=auth (user IN [list_user_leaked]) | stats count by user, src_ip Monitoraggio di traffico verso Tor: Bloccare o almeno loggare outbound traffic su porte 9050/9150. Con Suricata/Zeek, rilevare pattern tipici di handshake Tor. Pipeline consigliata (schema): Dark Web crawler → Parser → MISP/OpenCTI → SIEM (alert) → Incident Response Una pipeline efficace prevede un crawler periodico, un parser che normalizza i dati in JSON o CSV, un’integrazione con MISP/OpenCTI e infine l’invio degli IoC al SIEM. A quel punto si possono creare regole di alerting. Conclusione Il Dark Web non è per forza un luogo da cui stare alla larga; in ambito cybersecurity può essere una miniera di dati che possono fare la differenza in un programma di cyber threat intelligence. La chiave è trasformare dati grezzi in intelligence: osservare, raccogliere, arricchire e correlare. In questo modo un potenziale leak diventa un alert concreto in un SIEM, una chiave PGP diventa un collegamento tra due attori, un annuncio di vendita diventa l’inizio di un investigation playbook. L’elemento fondamentale resta la sicurezza: lavorare sempre in ambienti isolati, non interagire direttamente con i criminali e rispettare il quadro legale. Fatto in questo modo, il monitoraggio del Dark Web non è un esercizio accademico, ma uno strumento operativo per difendere in maniera proattiva le infrastrutture aziendali.
blog.8bitsecurity.comOct 2, 2025extracted
SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servers
A proxy network known as REM Proxy is powered by malware known as SystemBC, offering about 80% of the botnet to its users, according to new findings from the Black Lotus Labs team at Lumen Technologies. "REM Proxy is a sizeable network, which also markets a pool of 20,000 Mikrotik routers and a variety of open proxies it finds freely available online," the company said in a report shared with The Hacker News. "This service has been a favorite for several actors such as those behind TransferLoader, which has ties to the Morpheus ransomware group." SystemBC is a C-based malware that turns infected computers into SOCKS5 proxies, allowing infected hosts to communicate with a command-and-control (C2) server and download additional payloads. First documented by Proofpoint in 2019, it's capable of targeting both Windows and Linux systems. In a report earlier this January, ANY.RUN revealed that the Linux variant of SystemBC proxy implant is potentially designed for internal corporate services, and that it's mainly used to target corporate networks, cloud servers, and IoT devices. As is typically the case with any proxy solution, users of the network reach out to SystemBC C2s on high-numbered ports, which then route the user through to one of the victims before reaching their destination. According to Lumen, the SystemBC botnet comprises over 80 C2 servers and a daily average of 1,500 victims, of which nearly 80% are compromised virtual private server (VPS) systems from several large commercial providers. Interestingly, 300 of those victims are part of another botnet called GoBruteforcer (aka GoBrut). Of these, close to 40% of the compromises have "extremely long average" infection lifespans, lasting over 31 days. To make matters worse, the vast majority of the victimized servers have been found to be susceptible to several known security flaws. Each victim has 20 unpatched CVEs and at least one critical CVE on average, with one of the identified VPS servers in the U.S. city of Atlanta vulnerable to more than 160 unpatched CVEs. "The victims are made into proxies that enable high volumes of malicious traffic for use by a host of criminal threat groups," the company noted. "By manipulating VPS systems instead of devices in residential IP space, as is typical in malware-based proxy networks, SystemBC can offer proxies with massive amounts of volume for longer periods of time." Besides REM Proxy, some of the other customers of the SystemBC include at least two different Russia-based proxy services, one Vietnamese proxy service called VN5Socks (aka Shopsocks5), and a Russian web scraping service. Crucial to the functioning of the malware is the IP address 104.250.164[.]214, which not only hosts the artifacts but also appears to be the source of attacks to recruit potential victims. Once new victims are ensnared, a shell script is dropped on the machine to subsequently deliver the malware. The botnet operates with little regard for stealth, with the primary goal being to expand in volume to enlist as many devices as possible into the botnet. One of the largest use cases of the illicit network is by the threat actors behind SystemBC themselves, who use it to brute-force WordPress site credentials. The end goal is likely to sell the harvested credentials to other criminal actors in underground forums, who then weaponize them to inject malicious code into the sites in question for follow-on campaigns. "SystemBC has exhibited sustained activity and operational resilience across multiple years, establishing itself as a persistent vector within the cyber threat landscape," Lumen said. "Originally used by threat actors to enable ransomware campaigns, the platform has evolved to offer the assembly and sale of bespoke botnets." "Their model offers considerable advantages: it enables the execution of widespread reconnaissance, spam dissemination, and related activities, allowing an attacker to reserve more selective proxy resources for targeted attacks informed by prior intelligence gathering."
thehackernews.comSep 19, 2025extracted
InterceptSuite: Open-source network traffic interception tool
InterceptSuite: Open-source network traffic interception tool InterceptSuite is an open-source, cross-platform network traffic interception tool designed for TLS/SSL inspection, analysis, and manipulation at the network level. “InterceptSuite is designed primarily for non-HTTP protocols, although it does support HTTP/1 and HTTP/2. It offers support for databases, SMTP, and custom protocols, and can manage unknown protocols and their TLS connections. Developed in C, it ensures efficient memory management and performance, utilising native SOCKS5 proxy support on Linux, Mac, and Windows, with OpenSSL for TLS,” Sourav Kalal, the creator of the tool, told Help Net Security. The tool features a cross-platform C# GUI and supports Python extensions for protocol dissection. Notably, it allows TLS upgrades, such as STARTTLS and custom upgrades, enabling interception of plaintext protocols that transition to TLS. capabilities not found in any proxy solutions. Additionally, it supports specific IoT protocols like MQTT. “As a compiled binary from C and C#, it requires signing, especially on macOS. Some features, like STARTTLS and PCAP support, are not included in the open-source version to cover signing certificate costs, affecting only a limited number of users,” Kalal explained. Future plans and download Kalal said the current focus is on the UDP protocol, following recent updates that added new features and broader support for TCP and TLS. As of version 1.1.1, InterceptSuite supports only plaintext UDP, but the roadmap includes adding support for UDP-based protocols such as DTLS, WebRTC, and CoAP. Because UDP does not work with proxies, Kalal also plans to release VPN server support in the coming months. This will allow traffic to be redirected to InterceptSuite through the VPN, enabling support for both TCP and UDP, while also extending interception capabilities to proxy-unaware applications as well as Android and iOS devices. InterceptSuite is available for free on GitHub. Must read: 35 open-source security tools to power your red team, SOC, and cloud security GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comSep 8, 2025extracted
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware
The threat actor known as EncryptHub is continuing to exploit a now-patched security flaw impacting Microsoft Windows to deliver malicious payloads. Trustwave SpiderLabs said it recently observed an EncryptHub campaign that brings together social engineering and the exploitation of a vulnerability in the Microsoft Management Console (MMC) framework (CVE-2025-26633, aka MSC EvilTwin) to trigger the infection routine via a rogue Microsoft Console (MSC) file. "These activities are part of a broad, ongoing wave of malicious activity that blends social engineering with technical exploitation to bypass security defenses and gain control over internal environments," Trustwave researchers Nathaniel Morales and Nikita Kazymirskyi said. EncryptHub, also tracked as LARVA-208 and Water Gamayun, is a Russian hacking group that first gained prominence in mid-2024. Operating at a high tempo, the financially motivated crew is known for leveraging several methods, including fake job offers, portfolio review, and even compromising Steam games, to infect targets with stealer malware. The threat actor's abuse of CVE-2025-26633 was previously documented by Trend Micro in March 2025, uncovering attacks that deliver two backdoors called SilentPrism and DarkWisp. The latest attack sequence involves the threat actor claiming to be from the IT department and sending a Microsoft Teams request to the target with the goal of initiating a remote connection and deploying secondary payloads by means of PowerShell commands. Among the files dropped are two MSC files with the same name, one benign and the other malicious, that's used to trigger CVE-2025-26633, ultimately resulting in the execution of the rogue MSC file when its innocuous counterpart is launched. The MSC file, for its part, fetches and executes from an external server another PowerShell script that collects system information, establishes persistence on the host, and communicates with an EncryptHub command-and-control (C2) server to receive and run malicious payloads, including a stealer called Fickle Stealer. "The script receives AES-encrypted commands from the attacker, decrypts them, and runs the payloads directly on the infected machine," the researchers said. Also deployed by the threat actor over the course of the attack is a Go-based loader codenamed SilentCrystal, which abuses Brave Support, a legitimate platform associated with the Brave web browser, to host next-stage malware – a ZIP archive containing the two MSC files to weaponize CVE-2025-26633. What makes this significant is that uploading file attachments on the Brave Support platform is restricted for new users, indicating that the attackers somehow managed to obtain unauthorized access to an account with upload permissions to pull off the scheme. Some of the other tools deployed include a Golang backdoor that operates in both client and server mode to send system metadata to the C2 server, as well as set up C2 infrastructure by making use of the SOCKS5 proxy tunneling protocol. There is also evidence that the threat actors are continuing to rely on videoconferencing lures, this time setting up phony platforms like RivaTalk to deceive victims into downloading an MSI installer. Running the installer leads to the delivery of several files: the legitimate Early Launch Anti-Malware (ELAM) installer binary from Symantec that's used to sideload a malicious DLL that, in turn, launches a PowerShell command to download and run another PowerShell script. It's engineered to gather system information and exfiltrate it to the C2 server, and await encrypted PowerShell instructions that are decoded and executed to give attackers full control of the system. The malware also displays a fake "System Configuration" pop-up message as a ruse, while launching a background job to generate fake browser traffic by making HTTP requests to popular websites so as to blend C2 communications with normal network activity. "The EncryptHub threat actor represents a well-resourced and adaptive adversary, combining social engineering, abuse of trusted platforms, and the exploitation of system vulnerabilities to maintain persistence and control," Trustwave said. "Their use of fake video conferencing platforms, encrypted command structures, and evolving malware toolsets underscores the importance of layered defense strategies, ongoing threat intelligence, and user awareness training."
thehackernews.comAug 16, 2025extracted
Curly COMrades cyberspies hit govt orgs with custom malware
A new cyber-espionage threat group has been using a custom backdoor malware that provides persistent access through a seemingly inactive scheduled task. The threat actor's operations appear to support Russian interests by targeting government and judicial bodies in Georgia, and energy firms in Moldova. The attacker is currently tracked as Curly COMrades, has been active since mid-2024 and is using a custom three-stage malware component that researchers call MucorAgent. Curly COMrades attack chain In a report today, cybersecurity company Bitdefender describes MucorAgent as a "complex" piece of malware "engineered as a .NET stealthy tool capable of executing an AES-encrypted PowerShell script and uploading the resulting output to a designated server." The researchers named the threat actor Curly COMrades due to the heavy use of the curl.exe tool for data exfiltration and communicating with the command-and-control (C2) server, and because of hijacking Component Object Model (COM) objects during the attack. While no strong overlaps with known Russian APT groups have been found, the researchers say that the threat "group's operations align with the geopolitical goals of the Russian Federation." The researchers couldn't determine the initial access vector but observed the installation of multiple proxy agents, including the Go-based Resocks, across internal systems. Resocks is retrieved via curl.exe and registered as scheduled tasks or Windows services for persistence, communicating with the C2 via TCP 443 or 8443. For redundancy, the hackers also deploy custom SOCKS5 servers and SSH + Stunnel for remote port forwarding. Some SSH connections are routed through a custom tool, CurlCat, which uses the libcurl library and a custom Base64 alphabet to obfuscate traffic by relaying it through compromised legitimate websites. Inconsistent persitence mechanism Bitdefender notes that the persistence mechanism they discovered was an erratic one as it was achieved by hijacking CLSIDs to target NGEN (Native Image Generator). NGEN is a default Windows .NET Framework component for pre-compiling assemblies, and can offer persistence through a disabled scheduled task. However, even if the task appears inactive, the operating system enables and executes it at random intervals (e.g. idle times, when deploying a new app), the researchers explain. In some cases, the attackers also installed the legitimate Remote Utilities (RuRat) remote monitoring software to maintain interactive control. Additionally, they used the Remote Monitoring and Management (RMM) tool, a legitimate utility widely used by IT professionals to monitor, manage, and maintain client IT assets, such as servers, desktops, and mobile devices. Stealthy MucorAgent .NET backdoor The MucorAgent backdoor consists of three components, that can hijack a legitimate COM handler and load a second .NET stage that executes a component for bypassing the Antimalware Scan Interface (AMSI) in Windows. The third payload looks in specific locations for index.png and icon.png files, which are encrypted data blobs (likely scripts) downloaded from compromised websites. Acording to Bitdefender, the attacker collected valid credentials, likely in an attempt to move around the network, steal and exfiltrate data. They note that the threat actor "repeatedly tried to extract the NTDS database from domain controllers" and "attempted to dump LSASS memory from specific systems to recover active user credentials." Bitdefender also observed the execution of living-off-the-land commands like netstat, tasklist, systeminfo, wmic, and ipconfig, along with PowerShell Active Directory enumeration cmdlets, and batch scripts used for automation. Although Curly COMrades' operations were part of a larger espionage campaign, the researchers underline that the threat actor put in extensive effort to maintain their access to the target. Nevertheless, despite using LOLbins and open-source tools that blend well with regular traffic, and the smart persistence mechanism, the group's malicious moves still generated sufficient noise to be picked up by modern EDR/XDR sensors. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 12, 2025extracted
New ‘Curly COMrades’ APT Using NGEN COM Hijacking in Georgia, Moldova Attacks
A previously undocumented threat actor dubbed Curly COMrades has been observed targeting entities in Georgia and Moldova as part of a cyber espionage campaign designed to facilitate long-term access to target networks. "They repeatedly tried to extract the NTDS database from domain controllers -- the primary repository for user password hashes and authentication data in a Windows network," Bitdefender said in a report shared with The Hacker News. "Additionally, they attempted to dump LSASS memory from specific systems to recover active user credentials, potentially plain-text passwords, from machines where users were logged on." The activity, tracked by the Romanian cybersecurity company since mid-2024, has singled out judicial and government bodies in Georgia, as well as an energy distribution company in Moldova. "Regarding the timeline, while we have been tracking the campaign since mid-2024, our analysis of the artifacts indicates that activity began earlier," Martin Zugec, technical solutions director at Bitdefender, told the publication. "The earliest confirmed date we have for the use of the MucorAgent malware is November 2023, though it is highly probable that the group was active before that time." Curly COMrades are assessed to be operating with goals that are aligned with Russia's geopolitical strategy. It gets its name from the heavy reliance on the curl utility for command-and-control (C2) and data transfer, and the hijacking of the component object model (COM) objects. The end goal of the attacks is to enable long-term access to carry out reconnaissance and credential theft, and leverage that information to burrow deeper into the network, collect data using custom tools, and exfiltrate to attacker-controlled infrastructure. "The overall behavior indicates a methodical approach in which the attackers combined standard attack techniques with tailored implementations to blend into legitimate system activity," the company pointed out. "Their operations were characterized by repeated trial-and-error, use of redundant methods, and incremental setup steps - all aimed at maintaining a resilient and low-noise foothold across multiple systems." A notable aspect of the attacks is the use of legitimate tools like Resocks, SSH, and Stunnel to create multiple conduits into internal networks and remotely execute commands using the stolen credentials. Another proxy tool deployed besides Resocks is SOCKS5. The exact initial access vector employed by the threat actor is currently not known. Persistent access to the infected endpoints is accomplished by means of a bespoke backdoor called MucorAgent, which hijacks class identifiers (CLSIDs) – globally unique identifiers that identify a COM class object – to target Native Image Generator (Ngen), an ahead-of-time compilation service that's part of the .NET Framework. "Ngen, a default Windows .NET Framework component that pre-compiles assemblies, provides a mechanism for persistence via a disabled scheduled task," Bitdefender noted. "This task appears inactive, yet the operating system occasionally enables and executes it at unpredictable intervals (such as during system idle times or new application deployments), making it a great mechanism for restoring access covertly." Abusing the CLSID linked to Ngen underscores the adversary's technical prowess, while granting them the ability to execute malicious commands under the highly privileged SYSTEM account. It's suspected that there likely exists a more reliable mechanism for executing the specific task given the overall unpredictability associated with Ngen. A modular .NET implant, MucorAgent is launched via a three-stage process and is capable of executing an encrypted PowerShell script and uploading the output to a designated server. Bitdefender said it did not recover any other PowerShell payloads. "The design of the MucorAgent suggests that it was likely intended to function as a backdoor capable of executing payloads on a periodic basis," the company explained. "Each encrypted payload is deleted after being loaded into memory, and no additional mechanism for regularly delivering new payloads was identified." Also weaponized by Curly COMrades are legitimate-but-compromised websites for use as relays during C2 communications and data exfiltration in a bid to fly under the radar by blending malicious traffic with normal network activity. Some of the other tools observed in the attacks are listed below - CurlCat, which is used to facilitate bidirectional data transfer between standard input and output streams (STDIN and STDOUT) and C2 server over HTTPS by routing the traffic through a compromised site RuRat, a legitimate Remote Monitoring and Management (RMM) program for persistent access Mimikatz, which is used to extract credentials from memory Various built-in commands like netstat, tasklist, systeminfo, ipconfig, and ping to conduct discovery Powershell scripts that use curl to exfiltrate stolen data (e.g., credentials, domain information, and internal application data) "The campaign analyzed revealed a highly persistent and adaptable threat actor employing a wide range of known and customized techniques to establish and maintain long-term access within targeted environments," Bitdefender said. "The attackers relied heavily on publicly available tools, open-source projects, and LOLBins, showing a preference for stealth, flexibility, and minimal detection rather than exploiting novel vulnerabilities."
thehackernews.comAug 12, 2025extracted
Guida alle migliori VPN per Torrent
Una VPN per Torrent è una Rete Privata Virtuale (VPN) ottimizzata e utilizzata specificamente per le attività di “torrenting”, ovvero la condivisione e il download di file attraverso reti P2P (peer-to-peer) come BitTorrent. Indice degli argomenti Usare una VPN per i Torrent protegge la privacy nascondendo l’IP e impedisce che le attività online siano tracciate da provider o terze parti. Inoltre, aiuta ad evitare blocchi, limitazioni di banda e rischi legali legati al download di contenuti. Una VPN per il download di Torrent crea un tunnel criptato tra il dispositivo dell’utente e il server remoto, mascherando l’indirizzo IP reale e sostituendolo con quello del server VPN. In questo modo, chiunque monitori l’attività online, come provider internet, agenzie governative o malintenzionati, non può risalire all’identità dell’utente né intercettare i dati trasferiti. Il traffico viene inoltre crittografato impedendo a terze parti di vedere quali file vengono scaricati o condivisi. Questo meccanismo consente di aggirare blocchi geografici, limitazioni imposte dagli ISP (come il throttling) e garantisce maggiore anonimato durante le sessioni di file sharing su reti peer-to-peer. Scaricare file tramite torrent senza l’uso di una VPN espone l’utente a diversi rischi, in particolare sul piano legale. I sistemi P2P mostrano pubblicamente l’indirizzo IP dei partecipanti alla rete rendendo facile per le autorità o enti anti-pirateria identificare chi condivide contenuti protetti da copyright. Anche il semplice download, se riguarda materiale coperto da diritti, può portare a sanzioni amministrative o a conseguenze più gravi a seconda del Paese. Inoltre, i provider possono tracciare l’attività dell’utente e collaborare con le autorità fornendo log delle connessioni. Senza una VPN il livello di anonimato è nullo e ogni azione compiuta online resta potenzialmente rintracciabile. Per chi utilizza i Torrent scegliere una VPN adeguata non è solo una questione di anonimato ma anche di prestazioni e sicurezza. La VPN ideale deve garantire una connessione stabile e veloce, proteggere i dati personali da occhi indiscreti e offrire funzionalità pensate specificamente per il file sharing su reti P2P. Ogni aspetto, dalla politica sulla privacy al numero di server disponibili, contribuisce a rendere l’esperienza di download più sicura, efficiente e priva di rischi legali. Di seguito tre soluzioni di VPN adatte per Torrent con specifiche su caratteristiche, vantaggi, costi ed eventuali promozioni. 🌍 Server: 7.000+ server in 118 paesi 📱 Massimo dispositivi: 10 📍 IP dedicato: ✔ 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: IKEv2/IPsec, OpenVPN, NordLynx 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Panama 🔥 Offerte attive: SCONTO fino al 63% NordVPN dispone di una vasta infrastruttura globale con oltre 7.000 server in più di 118 Paesi, inclusi centinaia ottimizzati specificamente per il traffico P2P, garantendo larghezza di banda illimitata e connessioni stabili ideale per il file sharing ad alta velocità. Il protocollo proprietario NordLynx, sviluppato su WireGuard, consente download rapidi con latenze minime, mentre la crittografia AES‑256, la rigorosa politica no-log verificata da audit esterni e la funzione kill switch assicurano massima protezione della privacy durante l’attività torrent. Tra le funzionalità aggiuntive più apprezzate si contano Threat Protection Pro per bloccare malware, tracker e pubblicità indesiderate sui siti di torrenting, l’opzione Double VPN per cifrare due volte la connessione e il supporto per split tunneling per una configurazione flessibile in dispositivi multiuso. NordVPN supporta il torrenting su un massimo di 10 dispositivi contemporaneamente e mette a disposizione anche proxy SOCKS5, utili per accelerare i download dove non è richiesta la crittografia, perfetti per utenti avanzati che vogliono il massimo controllo sulla velocità. NordVPN offre diverse opzioni per durata e risparmio: il piano biennale ha un costo medio di circa 3,39 €/mese con sconti fino al 70 %, mentre il piano triennale risulta ancora più vantaggioso. Viene fornita una garanzia soddisfatti o rimborsati di 30 giorni e, per chi utilizza Android, una prova gratuita di 7 giorni. In alcune occasioni si aggiungono promozioni come gift card Amazon o sconti per referral. Certo, analizziamo questa offerta per un pacchetto di sicurezza online. NordVPN propone tre diversi piani di sicurezza online: Base, Plus e Ultimate, ciascuno disponibile con tre opzioni di durata: 2 anni, 1 anno o 1 mese. L’obiettivo è proteggere le attività online con varie funzionalità, a seconda del piano che si sceglie. Tutti i piani includono una garanzia di rimborso di 30 giorni, che permette di provare il servizio e, se non si è soddisfatti, chiedere un rimborso entro un mese. Questi piani offrono il risparmio maggiore perché ti impegni per un periodo più lungo. I prezzi indicati sono l’equivalente mensile, ma si paga l’intero importo per i primi 24 mesi in un’unica soluzione. NordVPN 2 anni Base - Costo: 3,39 €/mese (totale 81,36 € per i primi 24 mesi, anziché 278,16 €). - Risparmio: 70%. - Funzionalità principali: Solo una VPN sicura e veloce. Una VPN (Virtual Private Network) ti permette di navigare in modo più privato e sicuro, mascherando l’indirizzo IP e criptando il traffico internet. NordVPN piano Plus 2 anni: - Costo: 4,39 €/mese (totale 105,36 € per i primi 24 mesi, anziché 359,76 €). - Risparmio: 70%. - Funzionalità principali: Tutto ciò che è incluso nel piano Base (VPN) più: - Protezione anti-malware e di navigazione: Difende da virus, spyware e altri software dannosi, e avvisa se si stanno per visitare siti web pericolosi. - Blocco di pubblicità e tracker: Rende la navigazione più fluida e privata, impedendo ai siti web di tracciare le attività online e riducendo le pubblicità intrusive. - Password manager con mascheramento dell’email: Aiuta a gestire e creare password complesse in modo sicuro e permette di utilizzare un’email “mascherata” per proteggere la vera email da spam o violazioni di dati. NordVPN piano Ultimate per 2 anni: - Costo: 6,89 €/mese (totale 165,36 € per i primi 24 mesi, anziché 597,36 €). - Risparmio: 72%. - Funzionalità principali: Tutto ciò che è incluso nel piano Plus, più: - Spazio di archiviazione cloud da 1 TB: Un terabyte di spazio online per salvare i file in modo sicuro. - Assicurazione Cyber con copertura massima di 5000 €: Questa è una funzionalità molto interessante. Offre una copertura economica per il recupero di perdite dovute a truffe informatiche e il rimborso dei costi in caso di furto d’identità. Questi piani offrono ancora un buon risparmio rispetto ai pagamenti mensili, ma con un impegno di durata inferiore rispetto ai piani biennali. Anche qui, il costo viene pagato in un’unica soluzione per i primi 12 mesi. NordVPN Piano Base 1 anno: - Costo: 4,99 €/mese (totale 59,88 € per i primi 12 mesi, anziché 139,08 €). - Risparmio: 56%. - Funzionalità: VPN. NordVPN Piano Plus 1 anno: - Costo: 5,99 €/mese (totale 71,88 € per i primi 12 mesi, anziché 179,88 €). - Risparmio: 60%. - Funzionalità: VPN, protezione anti-malware e di navigazione, blocco pubblicità e tracker, password manager con mascheramento dell’email. NordVPN Piano Ultimate 1 anno: - Costo: 8,49 €/mese (totale 101,88 € per i primi 12 mesi, anziché 298,68 €). - Risparmio: 65%. - Funzionalità: VPN, protezione anti-malware e di navigazione, blocco pubblicità e tracker, password manager con mascheramento dell’email, 1 TB di cloud storage, Assicurazione Cyber. Questi piani sono i più cari su base mensile, ma offrono la massima flessibilità poiché non ci si vincola a lungo termine e si paga mensilmente. Non c’è alcun risparmio rispetto al prezzo pieno. NordVPN piano Base 1 mese: - Costo: 12,99 €/mese. - Funzionalità: VPN. NordVPN piano Plus 1 mese: - Costo: 13,99 €/mese. - Funzionalità: VPN, protezione anti-malware e di navigazione, blocco pubblicità e tracker, password manager con mascheramento dell’email. NordVPN piano Ultimate 1 mese: - Costo: 16,49 €/mese. - Funzionalità: VPN, protezione anti-malware e di navigazione, blocco pubblicità e tracker, password manager con mascheramento dell’email, 1 TB di cloud storage, Assicurazione Cyber. Risparmio: I piani biennali offrono il risparmio percentuale maggiore. Se si è sicuri di voler utilizzare il servizio a lungo termine, questa è l’opzione più conveniente. Funzionalità: Se ci serve solo una VPN, il piano Base è sufficiente. Se si desidera una protezione più completa contro malware, pubblicità e per la gestione delle password, il piano Plus è un’ottima scelta. Il piano Ultimate è per chi cerca la massima sicurezza e protezione finanziaria in caso di problemi online. Pagamento: I piani da 1 e 2 anni richiedono un pagamento anticipato per l’intero periodo, mentre il piano mensile viene fatturato ogni mese. 🌍 Server: 3200+ in 100 paesi 📱 Massimo dispositivi: illimitati 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: OpenVPN, IKEv2, Shadowsocks, Wireguard e L2TP 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Paesi Bassi 🔥 Offerte attive: SCONTO fino all’83% + 3 mesi gratis 🔥 Surfshark si basa su una rete di oltre 3.200 server in più di 100 Paesi ed è ottimizzata per P2P, garantendo larghezza di banda illimitata e connessioni fluide e veloci anche con file di grandi dimensioni. Le funzionalità di sicurezza includono crittografia AES‑256‑GCM, politica no-log verificata da audit esterni come Deloitte e Cure53, kill switch automatico, protezione da fughe DNS/WebRTC e l’esclusivo strumento Bypasser per il tunneling selettivo (split tunneling) Surfshark consente connessioni su un numero illimitato di dispositivi contemporaneamente, risultando ideale per chi usa più client torrent su differenti sistemi, e offre bonus come MultiHop e CleanWeb per bloccare pubblicità, malware e tracker durante le attività P2P. Il piano biennale “Starter” costa 1,99 euro al mese. Surfshark offre anche piani “One” e “One+” con funzionalità aggiuntive, a partire da 2,49 euro e 3,99 euro al mese spesso sono disponibili promozioni come sconti superiori all’80 % o referral bonus. Indipendentemente dal pacchetto scelto, si avrà accesso a queste funzionalità e vantaggi: Connessione Internet Sicura (VPN): La funzione principale di Surfshark. Cripta il traffico internet, rendendolo illeggibile a chiunque tenti di intercettarlo e mascherando il nostro indirizzo IP reale. 3200+ server VPN in 100 Paesi: Un’ampia rete di server permette di connettersi da diverse località in tutto il mondo, garantendo velocità e stabilità. Politica No-Log verificata: Surfshark si impegna a non registrare né monitorare le attività online, garantendo la privacy. Dispositivi illimitati: Si può installare e usare Surfshark su tutti i dispositivi con un singolo abbonamento. Politica di rimborso di 30 giorni: Se non si è soddisfatti del servizio, si può richiedere un rimborso completo entro 30 giorni dall’acquisto. Blocco annunci e tracker: Aiuta a migliorare l’esperienza di navigazione eliminando pubblicità e impedendo ai siti web di tracciare la nostra attività online. Bypasser (Split Tunneling): Permette di scegliere quali app o siti web devono usare la VPN e quali no. Rotazione dell’IP: Cambia periodicamente il nostro indirizzo IP per una maggiore anonimità. MultiHop (Doppia VPN): Fa passare il nostro traffico attraverso due server VPN invece di uno, aumentando ulteriormente sicurezza e anonimato. Questo è il pacchetto essenziale per la sicurezza online. Connessione a Internet Sicura (VPN): La funzione base per criptare il traffico e nascondere l’IP. Blocco Annunci: Blocca le pubblicità invasive. Blocco del Consenso ai Cookie: Un’utile funzione per gestire i fastidiosi pop-up sui cookie. Piano da 24 mesi (+3 mesi extra): Prezzo medio: circa €1,99 al mese. Costo totale iniziale: circa €53,73 per i primi 27 mesi (24 mesi + 3 mesi extra gratuiti). Questo è l’abbonamento che offre il maggior risparmio, l’87% di sconto rispetto al prezzo mensile. Il pagamento avviene in un’unica soluzione per l’intero periodo. Piano da 12 mesi (+3 mesi EXTRA): Prezzo medio: circa €3,19 al mese. Costo totale iniziale: circa €47,85 per i primi 15 mesi (12 mesi + 3 mesi extra gratuiti). Il risparmio è comunque significativo rispetto al piano mensile. Piano Mensile: Prezzo medio: circa €15,45 al mese. Questo piano offre la massima flessibilità, ma è di gran lunga l’opzione più costosa su base mensile. Il pacchetto One include tutte le funzionalità di Starter e aggiunge un livello significativo di protezione e privacy. Questo è il pacchetto che viene promosso con le offerte speciali. Tutte le funzionalità di Starter. Mascheramento Email e documenti personali: - Mascheramento Email: crea un alias email per proteggere la nostra vera email da spam e fughe di dati. - Generatore di dettagli personali: Ci aiuta a creare dati fittizi per iscriversi a servizi senza usare le nostre informazioni reali. Protezione del dispositivo (Antivirus): - Antivirus: Protegge i nostri dispositivi da malware e virus. - Protezione della webcam: Avvisa e blocca tentativi non autorizzati di accesso alla nostra webcam. - Protezione in tempo reale: Monitora costantemente i nostri dispositivi per prevenire minacce informatiche. - Protezione da ransomware: Difende dagli attacchi ransomware. - Scansioni di memorie esterne: Analizza chiavette USB e altri dispositivi di archiviazione esterni. Monitoraggio del Dark Web: Ci avvisa se le nostre informazioni personali (email, carte di credito, documenti d’identità) vengono trovate sul dark web. - Avvisi di fuga degli indirizzi Email, carte di credito, documenti di identità e codice fiscale. Ricerche sicure online: - Motore di ricerca privato: Un motore di ricerca che non traccia le nostre attività e non ci mostra pubblicità. 24 mesi (+3 extra): - Prezzo: €2,49 al mese. - Risparmio: 86% sul prezzo mensile. - Costo Totale Iniziale: €67,23 per i primi 27 mesi (24 mesi + 3 mesi extra gratuiti). - Modalità di pagamento: Fatturato in un’unica soluzione per l’intero periodo. - Vantaggio: Si ottengono 3 mesi gratuiti aggiuntivi, portando il periodo di abbonamento a 27 mesi complessivi. 12 mesi (+3 extra): - Prezzo: €3,39 al mese. - Risparmio: 81% sul prezzo mensile. - Costo Totale Iniziale: €50,85 per i primi 15 mesi (12 mesi + 3 mesi extra gratuiti). - Modalità di Pagamento: Fatturato in un’unica soluzione per l’intero periodo. - Vantaggio: Anche qui, 3 mesi gratuiti aggiuntivi, per un totale di 15 mesi. 1 mese: - Prezzo: €17,95 al mese. - Modalità di Pagamento: Fatturato mensilmente. - Vantaggio: Massima flessibilità, ma il costo mensile è significativamente più alto. Surfshark VPN piano One+ Il piano Surfshark One+ è l’offerta più completa e premium di Surfshark, progettata per chi desidera la massima protezione digitale. Include tutte le funzionalità dei piani Starter e One, con l’aggiunta di un servizio cruciale per la rimozione dei dati personali. Ecco una spiegazione dettagliata dell’offerta Surfshark One+: Piano da 24 mesi (+3 mesi EXTRA gratuiti): - Prezzo mensile equivalente: €3,99 al mese. - Risparmio: Un notevole -81% sul prezzo mensile standard. - Costo totale iniziale: €107,73 per i primi 27 mesi (24 mesi di abbonamento + 3 mesi extra gratuiti). - Modalità di pagamento: L’intero importo viene fatturato in un’unica soluzione al momento dell’acquisto. - Vantaggio: Questa è l’opzione più conveniente in termini di costo mensile per un pacchetto di sicurezza così completo. Piano da 12 mesi (+3 mesi EXTRA gratuiti): - Prezzo mensile equivalente: €6,09 al mese. - Risparmio: Un -71% sul prezzo mensile standard. - Costo totale iniziale: €91,35 per i primi 15 mesi (12 mesi di abbonamento + 3 mesi extra gratuiti). - Modalità di pagamento: L’intero importo viene fatturato in un’unica soluzione. - Vantaggio: Un’ottima scelta se preferisci un impegno a medio termine, mantenendo comunque un buon risparmio. Piano Mensile: - Prezzo mensile: €20,65 al mese. - Modalità di pagamento: Fatturato mensilmente. - Vantaggio: Massima flessibilità, puoi disdire in qualsiasi momento. - Svantaggio: È l’opzione più costosa e non include i mesi extra gratuiti. Il piano One+ include tutte le funzionalità dei piani Starter e One, più un servizio esclusivo e molto importante: rimozione dei dati personali tramite Incogni. Incogni è un servizio che automatizza la rimozione dei nostri dati personali (indirizzi email, indirizzi fisici, numeri di telefono) dai database dei broker di dati e dai siti di ricerca di persone: Include richieste di rimozione ripetute per assicurarsi che i dati non vengano ripubblicati. Copertura automatica di oltre 250 siti. Disponibilità limitata: Questo servizio è disponibile solo per i residenti nei seguenti paesi: Stati Uniti, Regno Unito, Unione Europea, Svizzera e Canada. Piano da 24 mesi (+3 mesi extra gratuiti): - Prezzo mensile equivalente: €3,99 al mese. - Risparmio: Un notevole meno 81% sul prezzo mensile standard. - Costo totale iniziale: €107,73 per i primi 27 mesi (24 mesi di abbonamento + 3 mesi extra gratuiti). - Modalità di pagamento: L’intero importo viene fatturato in un’unica soluzione al momento dell’acquisto. - Vantaggio: Questa è l’opzione più conveniente in termini di costo mensile per un pacchetto di sicurezza così completo. Piano da 12 mesi (+3 mesi EXTRA gratuiti): - Prezzo mensile equivalente: €6,09 al mese. - Risparmio: Un -71% sul prezzo mensile standard. - Costo totale iniziale: €91,35 per i primi 15 mesi (12 mesi di abbonamento + 3 mesi extra gratuiti). - Modalità di pagamento: L’intero importo viene fatturato in un’unica soluzione. - Vantaggio: Un’ottima scelta se preferisci un impegno a medio termine, mantenendo comunque un buon risparmio. Piano Mensile: - Prezzo mensile: €20,65 al mese. - Modalità di pagamento: Fatturato mensilmente. - Vantaggio: Massima flessibilità, puoi disdire in qualsiasi momento. - Svantaggio: È l’opzione più costosa e non include i mesi extra gratuiti. Per migliorare ulteriormente la protezione della VPN è possibile integrare questi add-on, selezionabili dalla pagina del proprio account Surfshark: Dedicated IP (IP dedicato): Fornisce un indirizzo IP personale, disponibile in 20 località. Questo può aiutare a evitare captcha frequenti, ridurre i blocchi IP e minimizzare verifiche aggiuntive. Alternative Number (numero alternativo): Un numero di telefono virtuale che protegge il nostro numero di telefono reale da spam e truffatori. Utile per registrarsi a servizi di cui non ci si fida completamente e ricevere chiamate e messaggi senza esporre il nostro numero personale. 🌍 Server: 3000 server in 105 paesi 📱 Massimo dispositivi: 8 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS, Linux 🔐 Sicurezza: IKEv2, OpenVPN 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Isole Vergini Britanniche 🔥 Offerte attive: SCONTO fino al 49% + 3 mesi GRATIS ExpressVPN rappresenta una scelta di prim’ordine per chi scarica torrent grazie a una combinazione di sicurezza avanzata, performance elevate e supporto ottimizzato per il P2P. Il servizio permette il torrenting su intera rete di server offrendo larghezza di banda illimitata e connessioni stabili e veloci, ideali per scaricare file di grandi dimensioni senza ritardi o rallentamenti. L’infrastruttura di ExpressVPN è basata su server RAM-only (TrustedServer), che eliminano automaticamente ogni dato al riavvio, garantendo una protezione totale. La crittografia AES‑256, la politica no-log auditata (da enti come KPMG e Cure53), il kill switch “Network Lock” per bloccare il traffico in caso di disconnessione, e la protezione anti-perdite DNS/IP assicurano la massima privacy durante il torrenting. ExpressVPN propone diverse opzioni: Piano mensile costa 11,30 euro. L’annuale 7,26€ al mese con un costo totale di 87,25 euro. Piano di 6 mesi: 9,99€ al mese, con un costo totale di 59,94 euro ogni 6 mesi. Piano di 12 mesi: Circa 8,32€ al mese con un costo totale di 99,84 euro. In genere è disponibile una garanzia di rimborso di 30 giorni e in alcuni casi una prova gratuita di 7 giorni via app mobile. Inoltre, promozioni periodiche e programmi di referral consentono di ottenere sconti aggiuntivi o mesi gratuiti per ogni amico invitato. Assolutamente! Cerchiamo di capire bene i diversi piani di ExpressVPN e i relativi costi e funzionalità, distinguendo tra le diverse durate di abbonamento. ExpressVPN offre diverse opzioni di abbonamento, ciascuna con i propri vantaggi in termini di prezzo e durata. In generale, più lunga è la durata dell’abbonamento, maggiore è il risparmio. Vediamo i tre periodi principali: Questa è l’offerta più conveniente e offre il massimo risparmio percentuale. Si paga un’unica quota per 2 anni e si ricevono 4 mesi aggiuntivi gratuitamente. Il rinnovo avviene annualmente dopo i 28 mesi iniziali. Questa è un’ottima via di mezzo se non ci si vuole impegnare per due anni: 12 mesi di servizio e 3 mesi extra in regalo, con un buon risparmio rispetto al piano mensile. Anche qui, il rinnovo è annuale dopo i 15 mesi. Questa è l’opzione più flessibile ma anche la più costosa su base mensile. È ideale se vuoi provare il servizio per un breve periodo senza un impegno a lungo termine. Il pagamento è mensile. Ecco una tabella che confronta i tre tipi di piano (Base, Avanzato, Pro) attraverso le diverse durate di abbonamento (2 anni + 4 mesi gratis, 12 mesi + 3 mesi gratis, 1 mese). Tutti i prezzi sono in USD e, per le offerte con mesi gratuiti, il costo “al mese” è una media calcolata includendo i mesi bonus. Una VPN davvero adatta al torrenting deve adottare una rigida politica no-log, ovvero non registrare alcuna informazione sulle attività dell’utente. Questo significa che anche in caso di richieste da parte di autorità o di tentativi di accesso ai dati, non ci sarebbe nulla da fornire, perché nulla viene conservato. È una garanzia essenziale per chi cerca il massimo anonimato durante il download di file. Scaricare Torrent richiede una connessione veloce e costante. Una buona VPN deve offrire server ottimizzati per garantire bande larghe e latenze ridotte, evitando rallentamenti, buffering o disconnessioni. Il supporto a protocolli moderni come WireGuard, unito a una rete di server ben distribuita, fa la differenza per chi scarica file di grandi dimensioni in poco tempo. Il kill switch è una funzionalità indispensabile per chi scarica Torrent perché blocca automaticamente la connessione a internet se la VPN dovesse disconnettersi inaspettatamente. In questo modo, si evita che l’indirizzo IP reale venga esposto, anche per pochi secondi. È una barriera di sicurezza fondamentale che protegge la privacy in ogni momento. Una rete VPN con molti server distribuiti in diversi Paesi consente non solo di accedere più facilmente a contenuti non disponibili localmente ma anche di scegliere il server più veloce e meno affollato. Più ampia è la scelta, maggiore sarà la possibilità di ottenere prestazioni elevate e mantenere l’anonimato anche in Paesi con normative restrittive sul torrenting. Non tutte le VPN sono ottimizzate per il traffico peer-to-peer. Quelle migliori offrono server dedicati o ottimizzati per il P2P che assicurano una gestione più efficiente del traffico torrent, con priorità nella banda e protezioni rafforzate. Il supporto P2P nativo consente anche una configurazione più semplice e una maggiore compatibilità con i principali client Torrent.
cybersecurity360.itAug 1, 2025extracted
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
Mexican organizations are still being targeted by threat actors to deliver a modified version of AllaKore RAT and SystemBC as part of a long-running campaign. The activity has been attributed by Arctic Wolf Labs to a financially motivated hacking group called Greedy Sponge. It's believed to be active since early 2021, indiscriminately targeting a wide range of sectors, such as retail, agriculture, public sector, entertainment, manufacturing, transportation, commercial services, capital goods, and banking. "The AllaKore RAT payload has been heavily modified to enable the threat actors to send select banking credentials and unique authentication information back to their command-and-control (C2) server, for the purpose of conducting financial fraud," the cybersecurity company said in an analysis published last week. Details of the campaign were first documented by the BlackBerry Research and Intelligence Team (which is now part of Arctic Wolf) in January 2024, with the attacks employing phishing or drive-by compromises to distribute booby-trapped ZIP archives that ultimately facilitate the deployment of AllaKore RAT. Attack chains analyzed by Arctic Wolf show that the remote access trojan is designed to optionally deliver secondary payloads like SystemBC, a C-based malware that turns compromised Windows hosts into SOCKS5 proxies to allow attackers to communicate with their C2 servers. Besides dropping potent proxy tools, Greedy Sponge has also refined and updated its tradecraft to incorporate improved geofencing measures as of mid-2024 in an attempt to thwart analysis. "Historically, geofencing to the Mexican region took place in the first stage, via a .NET downloader included in the trojanized Microsoft software installer (MSI) file," the company said. "This has now been moved server-side to restrict access to the final payload." The latest iteration sticks to the same approach as before, distributing ZIP files ("Actualiza_Policy_v01.zip") containing a legitimate Chrome proxy executable and a trojanized MSI file that's engineered to drop AllaKore RAT, a malware with capabilities for keylogging, screenshot capture, file download/upload, and remote control. The MSI file is configured to deploy a .NET downloader, which is responsible for retrieving and launching the remote access trojan from an external server ("manzisuape[.]com/amw"), and a PowerShell script for cleanup actions. This is not the first time AllaKore RAT has been used in attacks targeting Latin America. In May 2024, HarfangLab and Cisco Talos revealed that an AllaKore variant known as AllaSenha (aka CarnavalHeist) has been used to single out Brazilian banking institutions by threat actors from the country. "Having spent those four years-plus actively targeting Mexican entities, we would deem this threat actor persistent, but not particularly advanced," Arctic Wolf said. "The strictly financial motivation of this actor coupled with their limited geographic targeting is highly distinctive." "Additionally, their operational longevity points to probable operational success – meaning they’ve found something that works for them, and they are sticking with it. Greedy Sponge has held the same infrastructure models for the duration of their campaigns." The development comes as eSentire detailed a May 2025 phishing campaign that employed a new crypter-as-a-service offering known as Ghost Crypt to deliver and run PureRAT. "Initial access was gained through social engineering, where the threat actor impersonated a new client and sent a PDF containing a link to a Zoho WorkDrive folder containing malicious zip files," the Canadian company noted. "The attacker also created a sense of urgency by calling the victim and requesting that they extract and execute the file immediately." Further examination of the attack chain has revealed that the malicious file contains a DLL payload that's encrypted with Ghost Crypt, which then extracts and injects the trojan (i.e., the DLL) into a legitimate Windows csc.exe process using a technique called process hypnosis injection. Ghost Crypt, which was first advertised by an eponymous threat actor on cybercrime forums on April 15, 2025, offers the ability to bypass Microsoft Defender Antivirus, and serve several stealers, loaders, and trojans like Lumma, Rhadmanthys, StealC, BlueLoader, PureLoader, DCRat, and XWorm, among others. The discovery also follows the emergence of a new version of Neptune RAT (aka MasonRAT) that's distributed via JavaScript file lures, allowing the threat actors to extract sensitive data, take screenshots, log keystrokes, drop clipper malware, and download additional DLL payloads. Neptune RAT, according to Gen Digital, shares striking overlaps with another remote access trojan referred to as XWorm, suggesting that the first iteration of the malware is a derivative of the latter. Neptune RAT V2, in contrast, incorporates significant changes from its predecessor, alluding to a rewrite or an extensive refactoring. "Both XWorm and Neptune RAT V1 use the exact same encryption routine: The mutex is hashed using MD5, and the hash is duplicated to form a 32-byte key used for AES encryption running in the insecure ECB mode," security researcher Ajin Deepak said. "Both XWorm and Neptune RAT share a similar approach to initialization: they load all configuration settings at the start of their respective main functions and then launch executor threads to carry out their tasks." In recent months, cyber attacks have employed malicious Inno Setup installers that serve as a conduit for Hijack Loader (aka IDAT Loader), which then delivers the RedLine information stealer. The attack "leverages Inno Setup's Pascal scripting capabilities to retrieve and execute the next-stage payload in a compromised or targeted host," the Splunk Threat Research Team said. "This technique closely resembles the approach used by a well-known malicious Inno Setup loader called D3F@ck Loader, which follows a similar infection pattern."
thehackernews.comJul 22, 2025extracted