Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Pivoting on a SharpExt to profile Kimsuky panels for great good

July 29, 2022October 16, 2025 Securonix

SharpExt is a browser-extension malware used by Kimsuky to steal emails and attachments, as detailed by Volexity and related researchers. The campaign maps to older activity, leverages a large network of domains for delivery and C2, and targets US, Europe, and…

Read More
Threat Research

A new botnet Orchard Generates DGA Domains with Bitcoin Transaction Information

July 29, 2022October 15, 2025 Securonix

Orchard is a botnet family that uses DGA technology to generate C2 domains, incorporating Bitcoin wallet transaction data as inputs to the DGA to increase unpredictability. It has evolved across three versions since 2021, combining hardcoded DuckDNS domains wi…

Read More
Threat Research

Adversary Quest 2022: 4 CATAPULT SPIDER eCrime Challenges | CrowdStrike

July 28, 2022October 16, 2025 Securonix

Researchers analyze CrowdStrike’s Adversary Quest 2022 CATAPULT SPIDER track, which centers on a Dogecoin-driven ransomware campaign leveraging CHM phishing, encoded PowerShell, and a Dogecoin-based C2. The storyline uncovers multi-stage payloads, a vulnerable…

Read More
Threat Research

Flying in the clouds: APT31 renews its attacks on Russian companies through cloud storage

July 28, 2022October 16, 2025 Securonix

APT31 renewed its attacks on Russian media and energy companies by leveraging a malicious document that loads a VMProtect-packed payload, linking the activity to the APT31 toolkit. The campaign uses cloud storage services (notably Yandex.Disk) as C2 to blend i…

Read More
Threat Research

GwisinLocker ransomware targets South Korean industrial and pharma firms

July 28, 2022October 16, 2025 Securonix

GwisinLocker.Linux is a Linux-based ransomware variant linked to the Gwisin threat actor, targeting South Korean industrial and pharmaceutical firms. It encrypts files using per-file AES keys (with RSA-wrapped keys), stores keys in .mcrgnx0 files, appends .mcr…

Read More
Threat Research

Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware

July 27, 2022October 14, 2025 Securonix

Projector Libra (EXOTIC LILY) distributes Bumblebee via email campaigns that use file-sharing services to deliver malware, replacing the previous loader BazarLoader. The campaign chains ISO images with Windows shortcuts to execute Bumblebee, often followed by …

Read More
Threat Research

So RapperBot, What Ya Bruting For? | FortiGuard Labs

July 27, 2022October 15, 2025 Securonix

FortiGuard Labs tracks RapperBot, a rapidly evolving IoT malware family that borrows heavily from Mirai but switches from Telnet to SSH brute forcing for initial access on Linux devices. The campaign shows notable persistence and credential-access capabilities…

Read More
Threat Research

Woody RAT: A new feature-rich malware spotted in the wild

July 27, 2022October 13, 2025 Securonix

Woody Rat is a new feature-rich Remote Access Trojan active in the wild for at least a year, attributed to a threat actor targeting Russian entities. It spreads via archive file spearphishing and weaponized Office documents using the Follina vulnerability (CVE…

Read More
Threat Research

Word File Provided as External Link When Replying to Attacker’s Email (Kimsuky) – ASEC BLOG

July 27, 2022October 14, 2025 Securonix

ASEC has observed ongoing distribution of North Korea–related Word files used in Kimsuky campaigns, including variants that rely on mshta. Attackers impersonate Korean organizations to trigger a follow-up email with a link to download a malicious Word document…

Read More
Threat Research

Attackers leveraging Dark Utilities “C2aaS” platform in malware campaigns

July 27, 2022October 15, 2025 Securonix

Dark Utilities is a C2-as-a-Service platform released in early 2022 that provides remote access, DDoS, and cryptocurrency mining capabilities, with payloads for Windows, Linux, and Python hosted on IPFS to resist takedowns. Since launch, malware samples have r…

Read More
Threat Research

ROADSWEEP Ransomware – Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations

July 27, 2022October 15, 2025 Securonix

ROADSWEEP encrypts files across discovered drives using RC4 and marks them with a .lck extension, then performs a wipe with a self-delete to cover its tracks. The activity is part of a broader campaign involving ZEROCLEAR and CHIMNEYSWEEP, tied to a politicall…

Read More
Threat Research

Cyble – LOLI Stealer – Golang-based InfoStealer Spotted In The Wild

July 26, 2022October 19, 2025 Securonix

LOLI Stealer is a Golang-based infostealer sold via a MaaS model, capable of stealing passwords, cookies, wallet data, and screenshots from infected machines. Cyble Research Labs tracked LOLI Stealer and its evolving capabilities, including data exfiltration t…

Read More
Threat Research

IcedID leverages PrivateLoader

July 26, 2022October 15, 2025 Securonix

IcedID is evolving its delivery by using PrivateLoader as a load service, with SmokeLoader handling payloads and DNS-based C2 activity to fetch additional modules. The report ties together multiple loaders, ransomware and stealer payloads, and questions why ma…

Read More
Threat Research

Deception at a scale

July 26, 2022October 17, 2025 Securonix

VirusTotal’s Deception at scale report analyzes how malware abuses trust by hiding in legitimate installers, signing certificates, and masquerading as popular applications to deliver malicious payloads. It highlights social engineering trends and practical tec…

Read More
Threat Research

Robin Banks might be robbing your bank

July 26, 2022October 15, 2025 Securonix

Robin Banks is a phishing-as-a-service (PhaaS) platform that sells ready-made phishing kits targeting financial information for users in the U.S., U.K., Canada, and Australia. IronNet researchers observed a large-scale June 2022 campaign using Robin Banks to s…

Read More

Posts pagination

Previous 1 … 464 465 466 … 489 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.