Lucid Stealer is a Node.js SEA-based information-stealing malware that hides its payload with encryption, obfuscation, false certificate-like data, and UAC bypass behavior while collecting browser credentials, wallet data, Discord tokens, screenshots, and keystrokes. It uses PowerShell, a malicious Node.js native module, and WebSocket/HTTP POST communication to contact lucidstealer[.]one, with the analysis also noting shared infrastructure containing AsyncRAT and promotion through a Telegram channel. #LucidStealer #Nodejs #AsyncRAT #Telegram
Category: Threat Research
A loader chain starting from a ClickFix lure abuses signed IBM SPSS IDE, decoy DLLs, and EnumTimeFormatsEx to deliver the BabaDeda stage and the CNCMachineRMS remote administration implant. CNCMachineRMS uses custom scripting, a unified config/C2 container, and multiple stealth features to provide shell access, file management, screen capture, persistence, and local account backdoor capabilities. #ClickFix #IBMSPSSIDE #WinWrapIDE #BabaDeda #CNCMachineRMS
Zscaler ThreatLabz identified Abyssos, a new modular C++ RAT that supports credential theft, file exfiltration, VNC-based remote access, and additional capabilities delivered through C2 modules. The malware uses custom TCP communication, strong AES-based encryption, and multiple obfuscation and anti-analysis techniques to hinder detection and reverse engineering. #Abyssos #Zscaler #ThreatLabz
TXTBOOK is a targeted dependency confusion campaign that published 993 malicious npm packages under T-Bankās private internal namespace, with earlier activity on PyPI and infrastructure tied to DNS-based payload staging and Sliver implants. CloudSEKās analysis traced the operation through staging domains, command-and-control servers, and victim-gating hostnames that confirm the malware was designed to run inside T-Bankās internal network. #TXTBOOK #TBank #CloudSEK #Sliver #PyPI #npm
Researchers used a fake DeFi startup, Ballena Azul LTD / Blue Whale LTD, to recruit suspected Famous Chollima operatives and observe how a DPRK IT worker operation behaves after hire. The investigation exposed forged identities, remote access workflows, AI-assisted tooling, mule bank accounts, AstrillVPN exit nodes, and multiple operativesā infrastructure and…
FortiGuard Labs tracked a supply chain attack against QuickFox that trojanized a Windows Electron installer, used a fake `cdns3[.]51quickfox[.]cn` domain, and delivered a JavaScript loader that deployed the FDMTP implant for persistent access. The campaign has been active since at least August 2025, shows ongoing infrastructure development, and uses guardrails plus DLL sideloading to target specific Windows endpoints while avoiding re-infection. #QuickFox #FDMTP #TwillTyphoon
A new WordPress core flaw called XSS2Shell (CVE-2026-64638) enables reflected pre-authentication XSS on the login page and can be chained into PHP code execution under specific conditions. WordPress versions through 7.0.2 and multiple earlier branches are affected, with public PoC code already circulating and urgent patching recommended for Italian public administration sites. #WordPress #XSS2Shell #CVE-2026-64638 #CERT-AGID #pwn.ai
Elastic Security analyzed a macOS developer endpoint where Claude Code and related coding-agent activity parented credentialed HTTP requests, reverse tunnels, and LaunchAgent persistence across free tunnel services like localhost[.]run, Cloudflare Quick Tunnels, and ngrok. The article highlights how these dual-use behaviors can resemble legitimate local admin access while still producing high-severity outcomes that are difficult to triage. #ClaudeCode #Cursor #CloudflareQuickTunnels #ngrok #localhostrun
Varonis Threat Labs disclosed RovoBlast, a one-click attack against Atlassian Rovo that injects attacker-controlled instructions through a crafted link and can make the assistant treat external parameters as trusted session input. The flaw can expose data across Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, and other connected systems, and Atlassian…
Genians Security Center researchers uncovered a new APT37 campaign using NarwhalRAT to steal data through keylogging, screen capturing, USB data collection, and remote code execution. The intrusion likely began with spearphishing emails and malicious LNK files, while the operators used a Korean relay server and the pCloud API in a dual C&C structure to support the attack. #APT37 #NarwhalRAT #pCloud
LevelBlue OpsCTI identified a large-scale phishing campaign that impersonates trusted apps and services to trick victims into installing unauthorized ConnectWise ScreenConnect clients through fake update and installation flows. The campaign uses compromised sites, attacker-controlled hosts, Amazon S3, Cloudflare R2, Telegram telemetry, and reused infrastructure artifacts to deliver remote access payloads and expand hunting opportunities. #ConnectWiseScreenConnect #GoogleMeet #MicrosoftStore #AppleAppStore #TelegramBotAPI
The article explains why agent health assurance is becoming a business-critical requirement for MSPs, since installed agents and related services can still be degraded and cause loss of visibility, manual recovery work, and service interruptions. It also outlines how Acronis is building toward controlled self-recovery and platform-level observability across RMM, backup, EDR, anti-malware, updates, and remote access, with stronger health visibility and safer remediation workflows. #Acronis #RMM #EDR #CyberFit
ChainDrop is a self-propagating npm worm that infected hundreds of packages, stole developer and cloud credentials, and republished itself through compromised npm tokens while also targeting GitHub Actions and AI coding tool environments. Its operators used Ethereum-based C2 resolution and could silently rotate infrastructure without updating the malware, with evidence linking…
Google Threat Intelligence Group tracks UNC6671 as an active extortion operation that uses vishing, AiTM credential theft, and SaaS exfiltration while operating across multiple brands including BlackFile, Redact, Pink, Helix, and Falcon. The report also details shared infrastructure, shifting targeting toward financial and legal sectors, and a Bitcoin-based ransom operation that continued even after the alleged BlackFile shutdown. #UNC6671 #BlackFile #Redact #Pink #Helix #Falcon
Team Cymru validated active Cluster A phishing infrastructure linked to Push Securityās research on ShinyHunters and BlackFile, confirming Mevspace-hosted domains, a Doko-branded artifact, and recurring victim-themed naming patterns. The analysis surfaced more than 40 additional domains and highlighted how phishing panels are built from hosted infrastructure, certificates, exposed services, and reusable…