Netskope Threat Labs reported a NodeJS-based MaaS infostealer campaign delivered through ClickFix and trojanized GitHub repositories that impersonated AI and developer resources. The operation used a multi-stage SmartLoader chain with EtherHiding on the Polygon blockchain to resolve C2 at runtime and targeted developers across North America, Asia, and Southern Europe. #NetskopeThreatLabs #SmartLoader #EtherHiding #Polygon #ClickFix #Claude #ComfyUI #GitHub
Category: Threat Research
Zscaler details BINDCLOAK, a new 64-bit modular Windows backdoor that appears to be a variant of OctLurk and was delivered through MIXEDKEY in a multi-stage attack against government entities in the Middle East. The report also links the campaign to shared C2 infrastructure, reflective DLL loading, token abuse, and encrypted TLS-over-TCP communications used by the same threat actor behind OctLurk. #BINDCLOAK #OctLurk #MIXEDKEY #TELESHIM #cert.hypersnet.com #about.blsouqs.com #ftabnews.com
Bitdefender researchers uncovered a Java-based malware campaign that impersonates an “undetected” Xeno Roblox script executor and spreads through gaming forums and Discord communities. The payload steals browser cookies, Discord, Roblox and Minecraft accounts, crypto-wallet and payment data, while also enabling keylogging, webcam access, desktop streaming, file manipulation, PowerShell execution, and remote…
An exposed server tied to a Russia-nexus operator exposed months of activity showing high-volume initial access brokerage, broad exploitation of appliances, credential theft, and full Active Directory compromise across many sectors worldwide. The same operator later used Sliver C2 for targeted collection against Ukrainian defence and aerospace organisations, including theft from Git repositories and imagery from thousands of exposed IP cameras, with the activity aligning to AIVD/MIVD warnings about Russian camera surveillance. #Sliver #AIVD #MIVD #Fortinet #F5 #Citrix #SonicWall #SAP #HikVision #Neo-reGeorg
Larva-24009 has continued phishing campaigns since at least 2023, using LNK files to deliver PowerShell backdoors and later deploy tools such as QuasarRAT, UltraVNC, and NirSoft utilities. The 2026 activity shows the same core malware and file-name patterns as earlier cases, with credential theft, screenshots, keylogging, and Telegram-based reporting used to…
Octagon is a multi-stage Android threat that impersonated the BH Alert emergency app to target users in Bahrain and deploy dynamically loaded DEX/JAR payloads. It abuses VPN, Accessibility, and AccountManager/Sync Adapter features to persist, capture credentials, intercept data, and communicate with a C2 server at 209[.]99[.]184[.]50:4444. #BHAlert #Octagon #com.kisa.octagonpanel #com.kit.kitty #ZfChs.dex #ZGdSEl.jar #alertbh.info
Elastic Security 9.5 introduces Alert Zero tools that help SOC teams reduce alert fatigue by automating triage, correlating related alerts, and embedding investigations into existing workflows while keeping analysts in control. The update centers on Security alert analysis, Attack Discovery, and Elastic Workflows, with support for custom models, inspectable agent reasoning, and approved detection-gap remediation. #ElasticSecurity #AttackDiscovery #ElasticWorkflows #ESQL #VirusTotal
XCSSET v40 is a heavily updated macOS malware family that uses memory-resident execution, polymorphism, and supply-chain infection through poisoned Xcode projects to target developers. It also adds browser hijacking, Telegram trojanizing, defense evasion, and a rotating C2 infrastructure across domains, IPs, and endpoints. #XCSSET #Xcode #GoogleChrome #Telegram #Apple…
Google Threat Intelligence Group (GTIG) reports a sharp rise in open source software supply chain compromise in 2025 and early 2026, including major campaigns tied to UNC6780, MIDNIGHT NEPTUNE, and UNC4899. The article also outlines detailed mitigation guidance for protecting ecosystems such as PyPI, npm, Docker Hub, GitHub Actions, and developer pipelines from package poisoning, credential theft, and workflow abuse. #UNC6780 #MIDNIGHTNEPTUNE #UNC4899 #axios #PyPI #npm #DockerHub #GitHubActions
The article explains how Kaspersky Anti Targeted Attack (KATA) uses Network Anomaly Detection to identify Kerberoasting and DNS tunneling by spotting deviations from normal Kerberos and DNS behavior rather than relying on signatures. It also shows how prebuilt NAD rules, variables, and SQL-based logic help reduce false positives and surface actionable alerts for attacks that blend into legitimate network traffic. #KATA #Kerberoasting #DNStunneling #Kerberos #DNS
Sekoia researchers analyzed a new ErrTraffic ClickFix campaign that targeted WordPress servers, used fake AI tool lures, and hid C&C infrastructure in blockchain-based networks. Their DNS and WHOIS investigation uncovered 71 domains, multiple malicious IPs, typosquatting clusters, and possible links to the LenAI MaaS operator and the Aeternum botnet. #ErrTraffic #ClickFix #LenAI #Aeternum
CERT-AGID identified a phishing campaign that impersonates “Il Portale dell’Automobilista” through the typosquatted domain illportaledelautomobilista[.]org, which appears prominently in Google search results. The fake site steals personal and driver-license data such as codice fiscale, numero patente, and expiration date, while CERT-AGID has requested takedown actions and alerted Google and the Ministry of Infrastructure and Transport. #CERTAGID #IlPortaledellAutomobilista #MinisterodelleInfrastruttureeDeiTrasporti #illportaledelautomobilistaorg
The article explains that operational scripts on customer endpoints should be governed like production software, whether they are cloned, hand-written, or AI-generated. It highlights two scaling models—template reuse and AI-assisted authoring—showing that Acronis built-in scripts are heavily cloned while AI-generated scripts are increasingly common in some markets, requiring different governance controls for each. #Acronis #NISTSP800-53 #CISControlsv8 #OWASP #ENISA
The article describes OctLurk, SilkLurk, and LurkProxy, three closely related implants used since January 2025 against government and other organizations across Central Asia and the Syrian Arab Republic, with victim-specific loaders and heavy obfuscation. The same campaign also included credential theft, keylogging, browser password theft, network scanning, remote access, and the later deployment of PlugX, while infrastructure overlap and shared artifacts suggest a Chinese-speaking threat actor. #OctLurk #SilkLurk #LurkProxy #PlugX
AtlasRAT is a modular Windows RAT delivered through a four-stage in-memory loader chain, beginning with a Delphi executable disguised as AGE Flash Player and ending in TLS-based, ChaCha20-encrypted command-and-control with plugin execution, offline keylogging, and DLL injection into WeChat processes. Analysis suggests a builder-based malware framework with multiple versions and branches,…