Projector Libra (EXOTIC LILY) distributes Bumblebee via email campaigns that use file-sharing services to deliver malware, replacing the previous loader BazarLoader. The campaign chains ISO images with Windows shortcuts to execute Bumblebee, often followed by …
Category: Threat Research
FortiGuard Labs tracks RapperBot, a rapidly evolving IoT malware family that borrows heavily from Mirai but switches from Telnet to SSH brute forcing for initial access on Linux devices. The campaign shows notable persistence and credential-access capabilities…
Woody Rat is a new feature-rich Remote Access Trojan active in the wild for at least a year, attributed to a threat actor targeting Russian entities. It spreads via archive file spearphishing and weaponized Office documents using the Follina vulnerability (CVE…
LOLI Stealer is a Golang-based infostealer sold via a MaaS model, capable of stealing passwords, cookies, wallet data, and screenshots from infected machines. Cyble Research Labs tracked LOLI Stealer and its evolving capabilities, including data exfiltration t…
IcedID is evolving its delivery by using PrivateLoader as a load service, with SmokeLoader handling payloads and DNS-based C2 activity to fetch additional modules. The report ties together multiple loaders, ransomware and stealer payloads, and questions why ma…
VirusTotal’s Deception at scale report analyzes how malware abuses trust by hiding in legitimate installers, signing certificates, and masquerading as popular applications to deliver malicious payloads. It highlights social engineering trends and practical tec…
Robin Banks is a phishing-as-a-service (PhaaS) platform that sells ready-made phishing kits targeting financial information for users in the U.S., U.K., Canada, and Australia. IronNet researchers observed a large-scale June 2022 campaign using Robin Banks to s…
LockBit operators have been observed abusing legitimate security tools to load Cobalt Strike beacons, deploying a living-off-the-land approach to evade defenses. The campaign pivots on using MpCmdRun.exe to decrypt and load a weaponized DLL, following prior si…
This analysis details how Emotet intrusion employs obfuscated Excel macros to download and run an Emotet loader, which is then executed via regsvr32 for payload deployment. It highlights how the loader stores an encrypted payload in its resources, uses a Windo…
RedLine Stealer is a data-collection malware distributed as cracked software that harvests browser data, cryptocurrency wallet credentials, and other applications, then exfiltrates the results via SOAP to a hard-coded C2 server. The report details its deployme…
Threat actors impersonate Atomic Wallet with a phishing site to deliver Mars Stealer, a credential-theft malware. The campaign uses a staged download chain, PowerShell, AES decryption, and a Discord-hosted payload that exfiltrates data to a C2 server. #MarsSte…
Cisco Talos uncovered Manjusaka, a new offensive framework advertised as an imitation of Cobalt Strike, featuring Rust-based implants for Windows and Linux and a Go-based C2 with a Simplified Chinese UI that can generate configured implants. A COVID-19 themed …
Trend Micro researchers analyze a new SolidBit variant that disguises itself as legitimate gaming/social apps on GitHub to lure victims and recruit ransomware-as-a-service affiliates. The campaign features multi-stage infection (Rust LoL Accounts Checker -> Lo…
Industrial Spy is a relatively new ransomware group that emerged in April 2022, starting with data extortion and later adding encryption for double extortion. The group operates a dark web marketplace to exfiltrate and monetize stolen data, while its ransomwar…
BPFDoor is a Linux/Unix backdoor that uses Berkeley Packet Filters (BPF) to filter data through sockets and support multiple C2 protocols (TCP, UDP, ICMP), enabling stealthy remote access. The BPFDoor campaign is attributed to the Chinese threat actor Red Mens…