The article argues that SOC teams should treat security telemetry as their most valuable asset and demand open data access that is free, complete, and real time. It warns that vendors who charge for export, delay delivery, or only provide partial data create lock-in and weaken incident response, with references to CrowdStrike’s 2026 Global Threat Report and Elastic’s own stance on live access. #CrowdStrike #Elastic #SIEM #SOC
Category: Threat Research
Toy Ghouls, also tracked as Bearlyfy, Laboo.boo, and Feral Wolf, is using custom backdoors that communicate through HiveMQ MQTT and the Element/Matrix platform after previously relying on public tools and leaked ransomware builders. The campaign targets Russian organizations and has been linked to GenieLocker, with infrastructure and artifacts including #ToyGhouls #GenieLocker #broker.hivemq.com #meet.element.tw.
ASEC found attack cases where threat actors used Radmin and UltraVNC to take over infected systems, then deployed Netch, CCProxy, and SoftEther VPN to turn them into proxy nodes and VPN servers. The activity involved downloads from 103.86.86[.]244 and used Chinese-language scripts and configuration files, suggesting a Chinese-speaking operator. #Radmin #UltraVNC…
Symantec reports that attackers have revived abuse of Node.js since February 2026, using the trusted node.exe runtime for persistence and execution against victims including government departments, technology companies, and hotels. In the observed campaigns, actors tied to Woodgnat/KongTuke and other threats used ClickFix, AdaptixC2, Cobalt Strike, ModeloRAT, Backdoor.Mistic, C2Looper, and EtherHiding-style Ethereum blockchain lookups to maintain access and evade defenses. #Node.js #AdaptixC2 #CobaltStrike #ModeloRAT #BackdoorMistic #C2Looper #EtherHiding #Woodgnat #KongTuke
DFIR Report identified BengalSEO, a Rajasthan-based scam operation that has used SEO poisoning, malicious lure pages, and a traffic distribution system to deliver the MayaBot malware and drive tech support fraud since at least 2015. The campaign relies on companies such as WeConnect Solutions LLC and Garage2Global, along with infrastructure spanning GitHub, Hostmaza, Cloudflare, Matomo, and numerous redirector and payload domains. #BengalSEO #MayaBot #WeConnectSolutionsLLC #Garage2Global #Hostmaza #Cloudflare #Matomo
This article turns telemetry from over 1.8 million endpoints into a practical hardening guide for remote access tools most often abused by attackers, including RDP, ScreenConnect, MeshAgent, and VNC. It recommends a tiered defense strategy of blocking, monitoring, and tightly auditing remote tools to reduce attack surface and detect attacker-deployed access quickly. #RDP #ScreenConnect #MeshAgent #VNC #AmmyyAdmin #UltraVNC #RDPWrap
CERT-AGID identified fraudulent sites impersonating PagoPA to steal personal data and payment card information by offering a fake TARI overpayment refund. The campaign used a staged online form to collect identity details, contact information, and card data for potential fraud and future phishing operations. #PagoPA #CERT-AGID #TARI
H1 2026 threat activity was dominated by abuse of legitimate tools, trusted platforms, and routine workflows, while AI mainly augmented existing intrusion tradecraft rather than replacing it. The report also highlights widespread exploitation of exposed CVEs, persistent RAT and stealware activity, evolving supply-chain compromises, NFC-based mobile fraud, and Magecart campaigns that leveraged trusted third-party services. #AsyncRAT #CobaltStrike #XWorm #Stealc #REMCOSRAT #PromptSpy #NGate #NFCShare #Magecart #ShaiHulud #TeamPCP
EtherHiding has been used on more than 5,400 compromised small-business websites to fetch payloads from BNB Smart Chain testnet smart contracts, enabling takedown-resistant delivery of ClickFix lures or a covert WebRTC command channel. Netskope says the campaign spans over 2,200 organizations worldwide and continues to grow as operators rewrite a single on-chain contract to change what victims receive. #EtherHiding #BNBSmartChain #ClickFix #WebRTC
The article explains how Azure RBAC and ABAC can be analyzed at the permission level to uncover privilege escalation paths, including a built-in role that once allowed arbitrary escalation to Owner. It also describes an undocumented ARM API for mapping permissions to roles, the discovery and remediation of the Anyscale Platform Administrator Role issue, and recommendations for reducing attack surface in Azure. #AzureRBAC #ABAC #AnyscalePlatformAdministratorRole
This report details two AI-assisted intrusion campaigns in Latin America: CL-CRI-1131 against Mexican transportation and government-related targets, and CL-CRI-1163 against Brazil’s financial sector. Attackers used living-off-the-land techniques, custom RATs, SOCKS5 tunneling tools, and exposed NextChat/LLM infrastructure to troubleshoot failures, stage scripts, and exfiltrate data. #CL-CRI-1131 #CL-CRI-1163 #NextChat #SockTz #Claude #GPT-4.1…
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Check Point Research describes Gambling Goblin, a Chinese-speaking cybercrime group linked to Earth Berberoka, as running a sustained campaign against Brazilian government and educational organizations since mid-2025. The operation uses malicious Apache modules, SEO manipulation, and a large Linux toolkit to hijack traffic, serve phishing pages that impersonate Google Play, Microsoft Store, and Amazon, and scale into Vietnamese, Spanish, and English targeting. #GamblingGoblin #EarthBerberoka #Apache #GooglePlay #MicrosoftStore #Amazon
A malicious LNK file disguised as a seafood ingredient purchase request was used to deliver a decoy HWP document while PowerShell, scheduled tasks, and external communications ran in the background. The attack exfiltrated system information, fetched additional commands from Backblaze B2, and was linked by AhnLab to Kimsuky. #Kimsuky #BackblazeB2 #AhnLab…
Netskope Threat Labs reports that Python-based NodeStealer has evolved from a Facebook credential stealer into a spyware-capable tool with keylogging, clipboard monitoring, screenshot capture, and a split Telegram C2 design. The new variant also expands Facebook Graph API collection to more than 20 endpoints, suggesting AI-assisted development and broader abuse of Facebook and Ads Manager data. #NodeStealer #NetskopeThreatLabs #Facebook #AdsManager #Telegram
MoiClient is an evasive backdoor distributed as an invoice-lure VHDX file that uses DLL side-loading, process injection, RPC-based UAC bypass, and BYOVD to evade defenses and maintain persistence. It repeatedly reappears through Task Scheduler and ultimately delivers MoiXD Stealer to steal browser information. #MoiClient #MoiXDStealer #BootRepairSys #LenovoPCManager #SumatraPDF…