Technical Analysis of Lucid Stealer : Execution, Capabilities, and C2 Infrastructure

Lucid Stealer is a Node.js SEA-based information-stealing malware that hides its payload with encryption, obfuscation, false certificate-like data, and UAC bypass behavior while collecting browser credentials, wallet data, Discord tokens, screenshots, and keystrokes. It uses PowerShell, a malicious Node.js native module, and WebSocket/HTTP POST communication to contact lucidstealer[.]one, with the analysis also noting shared infrastructure containing AsyncRAT and promotion through a Telegram channel. #LucidStealer #Nodejs #AsyncRAT #Telegram

Read More
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

A loader chain starting from a ClickFix lure abuses signed IBM SPSS IDE, decoy DLLs, and EnumTimeFormatsEx to deliver the BabaDeda stage and the CNCMachineRMS remote administration implant. CNCMachineRMS uses custom scripting, a unified config/C2 container, and multiple stealth features to provide shell access, file management, screen capture, persistence, and local account backdoor capabilities. #ClickFix #IBMSPSSIDE #WinWrapIDE #BabaDeda #CNCMachineRMS

Read More
Abyssos: Technical Analysis of a New Modular RAT

Zscaler ThreatLabz identified Abyssos, a new modular C++ RAT that supports credential theft, file exfiltration, VNC-based remote access, and additional capabilities delivered through C2 modules. The malware uses custom TCP communication, strong AES-based encryption, and multiple obfuscation and anti-analysis techniques to hinder detection and reverse engineering. #Abyssos #Zscaler #ThreatLabz

Read More
TXTBOOK A Supply Chain Heist, Rehearsed in Public

TXTBOOK is a targeted dependency confusion campaign that published 993 malicious npm packages under T-Bank’s private internal namespace, with earlier activity on PyPI and infrastructure tied to DNS-based payload staging and Sliver implants. CloudSEK’s analysis traced the operation through staging domains, command-and-control servers, and victim-gating hostnames that confirm the malware was designed to run inside T-Bank’s internal network. #TXTBOOK #TBank #CloudSEK #Sliver #PyPI #npm

Read More
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

Researchers used a fake DeFi startup, Ballena Azul LTD / Blue Whale LTD, to recruit suspected Famous Chollima operatives and observe how a DPRK IT worker operation behaves after hire. The investigation exposed forged identities, remote access workflows, AI-assisted tooling, mule bank accounts, AstrillVPN exit nodes, and multiple operatives’ infrastructure and…

Read More
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

FortiGuard Labs tracked a supply chain attack against QuickFox that trojanized a Windows Electron installer, used a fake `cdns3[.]51quickfox[.]cn` domain, and delivered a JavaScript loader that deployed the FDMTP implant for persistent access. The campaign has been active since at least August 2025, shows ongoing infrastructure development, and uses guardrails plus DLL sideloading to target specific Windows endpoints while avoiding re-infection. #QuickFox #FDMTP #TwillTyphoon

Read More
XSS2Shell: New WordPress Core Vulnerability Could Enable Remote Code Execution

A new WordPress core flaw called XSS2Shell (CVE-2026-64638) enables reflected pre-authentication XSS on the login page and can be chained into PHP code execution under specific conditions. WordPress versions through 7.0.2 and multiple earlier branches are affected, with public PoC code already circulating and urgent patching recommended for Italian public administration sites. #WordPress #XSS2Shell #CVE-2026-64638 #CERT-AGID #pwn.ai

Read More
Living off the coding agent: Two tales of tunnels and LaunchAgents

Elastic Security analyzed a macOS developer endpoint where Claude Code and related coding-agent activity parented credentialed HTTP requests, reverse tunnels, and LaunchAgent persistence across free tunnel services like localhost[.]run, Cloudflare Quick Tunnels, and ngrok. The article highlights how these dual-use behaviors can resemble legitimate local admin access while still producing high-severity outcomes that are difficult to triage. #ClaudeCode #Cursor #CloudflareQuickTunnels #ngrok #localhostrun

Read More
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data

Varonis Threat Labs disclosed RovoBlast, a one-click attack against Atlassian Rovo that injects attacker-controlled instructions through a crafted link and can make the assistant treat external parameters as trusted session input. The flaw can expose data across Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, and other connected systems, and Atlassian…

Read More
APT37 Strikes Again, This Time with NarwhalRAT

Genians Security Center researchers uncovered a new APT37 campaign using NarwhalRAT to steal data through keylogging, screen capturing, USB data collection, and remote code execution. The intrusion likely began with spearphishing emails and malicious LNK files, while the operators used a Korean relay server and the pCloud API in a dual C&C structure to support the attack. #APT37 #NarwhalRAT #pCloud

Read More
Beyond ā€˜Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

LevelBlue OpsCTI identified a large-scale phishing campaign that impersonates trusted apps and services to trick victims into installing unauthorized ConnectWise ScreenConnect clients through fake update and installation flows. The campaign uses compromised sites, attacker-controlled hosts, Amazon S3, Cloudflare R2, Telegram telemetry, and reused infrastructure artifacts to deliver remote access payloads and expand hunting opportunities. #ConnectWiseScreenConnect #GoogleMeet #MicrosoftStore #AppleAppStore #TelegramBotAPI

Read More
Advancing toward agent health and self-recovery for MSP operations

The article explains why agent health assurance is becoming a business-critical requirement for MSPs, since installed agents and related services can still be degraded and cause loss of visibility, manual recovery work, and service interruptions. It also outlines how Acronis is building toward controlled self-recovery and platform-level observability across RMM, backup, EDR, anti-malware, updates, and remote access, with stronger health visibility and safer remediation workflows. #Acronis #RMM #EDR #CyberFit

Read More
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Google Threat Intelligence Group tracks UNC6671 as an active extortion operation that uses vishing, AiTM credential theft, and SaaS exfiltration while operating across multiple brands including BlackFile, Redact, Pink, Helix, and Falcon. The report also details shared infrastructure, shifting targeting toward financial and legal sectors, and a Bitcoin-based ransom operation that continued even after the alleged BlackFile shutdown. #UNC6671 #BlackFile #Redact #Pink #Helix #Falcon

Read More
Behind the Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry

Team Cymru validated active Cluster A phishing infrastructure linked to Push Security’s research on ShinyHunters and BlackFile, confirming Mevspace-hosted domains, a Doko-branded artifact, and recurring victim-themed naming patterns. The analysis surfaced more than 40 additional domains and highlighted how phishing panels are built from hosted infrastructure, certificates, exposed services, and reusable…

Read More