Two-sentence summary: A newly identified family of malicious documents from Iran, dubbed Green Stone, embeds an executable payload (nvidiax.exe) delivered via a macro and executes it after unpacking from base64-encoded content. The malware hides itself, gather…
Category: Threat Research
Two-sentence summary: An in-depth look at a convoluted infection chain embedded in an Excel document that lures users to enable macros, then unleashes a multi-stage payload across embedded worksheets. The campaign uses obfuscated .NET loaders (Tupak, Chimchim)…
SHARPEXT is a clever post-exploitation browser extension used by SharpTongue (often associated with Kimsuky) to inspect and exfiltrate data from a victim’s webmail (Gmail and AOL) as users browse. The attackers deploy SHARPEXT by modifying browser preferences …
Symbiote hooks libc and libpcap to hide its activity on Linux, including hiding processes, files, and network connections. It steals credentials from SSH/SCP by hooking the libc read function, encrypts them with RC4, stores them locally, and exfiltrates via DN…
Two-sentence summary: An in-depth analysis shows how the Follina exploit (CVE-2022-30190) is weaponized to achieve remote code execution via MSDT and to enable persistent, live-off-the-land attacker activity using native Windows tools. The report details three…
Gootkit loader now employs more advanced fileless techniques to drop Cobalt Strike, using SEO-poisoned compromised websites and legal document templates to lure victims. The attack chain involves registry stuffing, memory-only execution via PowerShell, and a C…
Threat actors are leveraging DLL sideloading in legitimate Microsoft applications to deliver a Cobalt-Strike beacon. The dropped DLL is loaded from application folders and communicates with a C2 URL hosted on CloudFront to enable beacon operations. #QakBot #Co…
Threat actors abuse DLL sideloading to run malicious code through legitimate Microsoft applications (Teams and OneDrive), dropping and loading a malicious DLL that communicates with a remote C2 and leverages Cobalt Strike Beacon for post‑exploitation. The camp…
Yoroi’s ZLab tracks Hive (TH-313) ransomware and its evolution from Go-based payloads to Rust-based variants under a Double Extortion/RaaS model, highlighting its expanding victimology including healthcare and critical infrastructure. The report details increa…
Gootloader is a Malware-as-a-Service (MaaS) offering that is spread through SEO poisoning to distribute malicious payloads, such as IcedID. Threat actors have begun using IcedID, a former banking trojan, since it’s a stealthier option compared to Cobalt Strike…
TA551/Monster Libra (aka SVCReady) has been distributing IcedID (Bokbot) alongside SVCReady since 2022, with campaigns that used password-protected archives and ISO images to drop malware and scripts. The infection chain led to DarkVNC activity and Cobalt Stri…
LockBit 3.0, dubbed LockBit Black, shows Clear borrowings from BlackMatter, including API harvesting, anti-debugging, and a suite of configuration flags that govern encryption and lateral movement. The variant deepens LockBit’s capabilities with BlackMatter-li…
CosmicStrand is a sophisticated UEFI firmware rootkit attributed to a Chinese-speaking threat actor, designed to persist from the earliest boot stages and deploy kernel- and user-mode payloads. It achieves durable persistence by implanting in firmware (CSMCORE…
Cyble Research Labs analyzed Luca Stealer, a Rust-based stealer targeting Chromium browsers, crypto wallets, chat apps, and games, whose source code leaked on a cybercrime forum in July 2022. Since then, the malware has seen multiple updates and wider adoption…
Sophos X-Ops describes a coordinated Observe-Orient-Decide-Act loop among SophosLabs, SecOps, MTR, and Sophos AI to study and disrupt a wave of Microsoft SQL Server attacks leveraging old RCE CVEs and delivering Remcos or various ransomware families including …