Toy Ghouls’ new toy: the GenieLocker ransomware

GenieLocker is a custom ransomware family used by Toy Ghouls against Russian organizations, especially in manufacturing, with Windows, Linux, and ESXi variants active since March 2026. The group used stolen OpenVPN credentials for entry, deployed tools like Mimikatz and PsExec, and encrypted systems without evidence of data theft or double extortion. #GenieLocker #ToyGhouls #Bearlyfy #Labubu #Laboo.boo #Mimikatz #PsExec #OpenVPN

Read More
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)

AhnLab reports that a state-sponsored group abused vulnerabilities in Korean financial security software from 2025 through the first half of 2026 to deliver backdoors via watering hole and spear-phishing attacks, while many compromised Korean websites were used as infection points. The analysis also finds overlap with Gunra ransomware incidents and names…

Read More
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

Two beta npm releases in the @joyfill namespace were found to contain an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to resolve hidden payloads, with one branch leading to a 77 KB Node.js remote-access trojan. The compromised packages were @joyfill/layouts and @joyfill/components, and the recovered code overlaps with the PolinRider loader and DEV#POPPER family while also dropping related infrastructure for a Python infostealer linked to OmniStealer. #Joyfill #PolinRider #DEVPOPPER #OmniStealer

Read More
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

TA488 launched a July 2026 campaign exploiting CVE-2026-42897 in Outlook Web Access to deliver the browser-based implant OWAReaper against government, telecommunications, finance, hospitality, and aerospace targets. OWAReaper provides stealthy persistence, credential theft, command execution, and exfiltration through HTTPS or DNS, using infrastructure such as acocdn[.]com, asecdns[.]com, dnsrecursive[.]eu, and tdndns[.]com. #TA488 #OWAReaper…

Read More
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN

ASEC found Larva-26009 targeting MS-SQL servers to deploy VShell, GotoHTTP, SoftEther, and XMRig, using remote control and proxy tools to maintain access and mine cryptocurrency. The attack also involved web shells, credential theft attempts, privilege escalation utilities, and cloud-based infrastructure to obscure command-and-control activity. #Larva26009 #VShell #GotoHTTP #SoftEther #XMRig…

Read More
Advanced Search & YARA Improvements

The Advanced Search update adds network filters, letting users query CIDR blocks in IP-related fields and constrain results by ASN or CIDR with the new WITH network option. The YARA interface now emphasizes newly observed indicators and total indicator counts, replacing the old total-matches-per-day chart to give analysts better visibility into rule impact. #CIDR #ASN #YARA

Read More
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

Unknown threat actors used a multi-package npm campaign to impersonate Alibaba private packages and deliver a staged downloader that ultimately deployed a targeted RAT against developers using Alibaba Group tools. The final payload enabled data theft, remote command execution, lateral movement through DingTalk, and platform-specific persistence across macOS, Windows, and Linux. #lib-mtop #aone-cli #DingTalk #AlibabaGroup

Read More
Notes from Underground: Adversarial Prompt Injection

Threat actors are increasingly discussing and selling indirect prompt injection (IDPI) tools on underground forums, with generators for email, PDF, calendar invite, and webpage attack content. The activity suggests near-future abuse of hidden prompts in mail, documents, calendar invites, and malvertising to manipulate AI agents and exfiltrate data. #IndirectPromptInjection #TycoonPhaaS #OWASP…

Read More
Mirage Kitten targets Middle East and Africa region with new malware

Mirage Kitten (also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore) deployed custom malware including the NightLedger backdoor and the ArcBridge and BridgeHead WebSocket tunnelers to conduct targeted espionage against aerospace, aviation, defense, and telecom victims in the Middle East, Europe, and Africa. The campaign used spear-phishing, fake recruitment portals, and proxy-aware tunneling infrastructure to maintain access, exfiltrate data, and hide command-and-control traffic. #MirageKitten #UNC1549 #NightLedger #ArcBridge #BridgeHead

Read More
Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities.

The report examines the Zedxion, Zedcex, ZedPay, and BZ Group network as a layered financial architecture spanning the United Kingdom and the United Arab Emirates, with durable domains, token infrastructure, and corporate shells that persist while legal entities are cycled. It also highlights sanctions-evasion concerns tied to Babak Morteza Zanjani, Elizabeth Newman, OFAC designations, and alleged links to the IRGC. #Zedxion #Zedcex #ZedPay #BZGroup #BabakMortezaZanjani #ElizabethNewman #OFAC #IRGC

Read More
Detection primitives for eBPF rootkits

Linux eBPF rootkits such as VoidLink, LinkPro, and the Atomic Arch campaign use rare helpers to hide sockets, obscure their own programs, and kill ptrace-based debuggers before the kernel finishes processing them. The article shows that defenders should focus on load-time fingerprinting of eBPF programs because helpers like bpf_probe_write_user(), bpf_override_return(), and bpf_send_signal() reveal malicious intent before the rootkit can conceal itself. #VoidLink #LinkPro #AtomicArch #bpf_probe_write_user #bpf_override_return #bpf_send_signal

Read More
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

Since late March 2026, a large-scale campaign has used heavily obfuscated JScript droppers, Lua/AutoIt loaders, and fileless execution to deploy RATs and infostealers such as Agent Tesla, Remcos, XWorm, Snake Keylogger, and Best Private LOGGER. The attackers impersonate trusted companies to deliver phishing lures, then use disguised .ttf files, Donut shellcode, and layered anti-analysis techniques to gain control of infected Windows systems and exfiltrate data. #AgentTesla #Remcos #XWorm #SnakeKeylogger #BestPrivateLOGGER #LuaJIT #AutoIt

Read More