GenieLocker is a custom ransomware family used by Toy Ghouls against Russian organizations, especially in manufacturing, with Windows, Linux, and ESXi variants active since March 2026. The group used stolen OpenVPN credentials for entry, deployed tools like Mimikatz and PsExec, and encrypted systems without evidence of data theft or double extortion. #GenieLocker #ToyGhouls #Bearlyfy #Labubu #Laboo.boo #Mimikatz #PsExec #OpenVPN
Category: Threat Research
Astaroth (aka Guildma) operators added a WhatsApp Web spambot in Q4 2025, shifting from email-based distribution to automated messaging that turns infected victims into unwilling propagators of the malware. The analysis shows strong code overlap with the Vareg (aka WATER SACI, Eternidade) spambot and confirms Brazil-focused targeting through contact filtering, Portuguese…
AhnLab reports that a state-sponsored group abused vulnerabilities in Korean financial security software from 2025 through the first half of 2026 to deliver backdoors via watering hole and spear-phishing attacks, while many compromised Korean websites were used as infection points. The analysis also finds overlap with Gunra ransomware incidents and names…
CERT-AGID identified a new sextortion campaign circulating internationally since April 2026 and observed for the first time in Italy, with scammers impersonating ShinyHunters. The emails claim to have compromising material and demand $2,000 in Bitcoin within 48 hours, but ShinyHunters denied any involvement. #ShinyHunters #CERTAGID
Two beta npm releases in the @joyfill namespace were found to contain an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to resolve hidden payloads, with one branch leading to a 77 KB Node.js remote-access trojan. The compromised packages were @joyfill/layouts and @joyfill/components, and the recovered code overlaps with the PolinRider loader and DEV#POPPER family while also dropping related infrastructure for a Python infostealer linked to OmniStealer. #Joyfill #PolinRider #DEVPOPPER #OmniStealer
TA488 launched a July 2026 campaign exploiting CVE-2026-42897 in Outlook Web Access to deliver the browser-based implant OWAReaper against government, telecommunications, finance, hospitality, and aerospace targets. OWAReaper provides stealthy persistence, credential theft, command execution, and exfiltration through HTTPS or DNS, using infrastructure such as acocdn[.]com, asecdns[.]com, dnsrecursive[.]eu, and tdndns[.]com. #TA488 #OWAReaper…
ASEC found Larva-26009 targeting MS-SQL servers to deploy VShell, GotoHTTP, SoftEther, and XMRig, using remote control and proxy tools to maintain access and mine cryptocurrency. The attack also involved web shells, credential theft attempts, privilege escalation utilities, and cloud-based infrastructure to obscure command-and-control activity. #Larva26009 #VShell #GotoHTTP #SoftEther #XMRig…
The Advanced Search update adds network filters, letting users query CIDR blocks in IP-related fields and constrain results by ASN or CIDR with the new WITH network option. The YARA interface now emphasizes newly observed indicators and total indicator counts, replacing the old total-matches-per-day chart to give analysts better visibility into rule impact. #CIDR #ASN #YARA
Unknown threat actors used a multi-package npm campaign to impersonate Alibaba private packages and deliver a staged downloader that ultimately deployed a targeted RAT against developers using Alibaba Group tools. The final payload enabled data theft, remote command execution, lateral movement through DingTalk, and platform-specific persistence across macOS, Windows, and Linux. #lib-mtop #aone-cli #DingTalk #AlibabaGroup
Threat actors are increasingly discussing and selling indirect prompt injection (IDPI) tools on underground forums, with generators for email, PDF, calendar invite, and webpage attack content. The activity suggests near-future abuse of hidden prompts in mail, documents, calendar invites, and malvertising to manipulate AI agents and exfiltrate data. #IndirectPromptInjection #TycoonPhaaS #OWASP…
Mirage Kitten (also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore) deployed custom malware including the NightLedger backdoor and the ArcBridge and BridgeHead WebSocket tunnelers to conduct targeted espionage against aerospace, aviation, defense, and telecom victims in the Middle East, Europe, and Africa. The campaign used spear-phishing, fake recruitment portals, and proxy-aware tunneling infrastructure to maintain access, exfiltrate data, and hide command-and-control traffic. #MirageKitten #UNC1549 #NightLedger #ArcBridge #BridgeHead
The report examines the Zedxion, Zedcex, ZedPay, and BZ Group network as a layered financial architecture spanning the United Kingdom and the United Arab Emirates, with durable domains, token infrastructure, and corporate shells that persist while legal entities are cycled. It also highlights sanctions-evasion concerns tied to Babak Morteza Zanjani, Elizabeth Newman, OFAC designations, and alleged links to the IRGC. #Zedxion #Zedcex #ZedPay #BZGroup #BabakMortezaZanjani #ElizabethNewman #OFAC #IRGC
Linux eBPF rootkits such as VoidLink, LinkPro, and the Atomic Arch campaign use rare helpers to hide sockets, obscure their own programs, and kill ptrace-based debuggers before the kernel finishes processing them. The article shows that defenders should focus on load-time fingerprinting of eBPF programs because helpers like bpf_probe_write_user(), bpf_override_return(), and bpf_send_signal() reveal malicious intent before the rootkit can conceal itself. #VoidLink #LinkPro #AtomicArch #bpf_probe_write_user #bpf_override_return #bpf_send_signal
The article explains how Azure VM extension abuse can be used to execute code by deploying the legitimate Salt Minion extension and pointing it to a rogue Salt Master. It shows how an attacker can run commands as root, steal a managed identity token, and evade detection by blending in with normal administrative activity. #SaltMinion #Salt #AzureVM
Since late March 2026, a large-scale campaign has used heavily obfuscated JScript droppers, Lua/AutoIt loaders, and fileless execution to deploy RATs and infostealers such as Agent Tesla, Remcos, XWorm, Snake Keylogger, and Best Private LOGGER. The attackers impersonate trusted companies to deliver phishing lures, then use disguised .ttf files, Donut shellcode, and layered anti-analysis techniques to gain control of infected Windows systems and exfiltrate data. #AgentTesla #Remcos #XWorm #SnakeKeylogger #BestPrivateLOGGER #LuaJIT #AutoIt