Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Green Stone – InQuest

July 22, 2022October 16, 2025 Securonix

Two-sentence summary: A newly identified family of malicious documents from Iran, dubbed Green Stone, embeds an executable payload (nvidiax.exe) delivered via a macro and executes it after unpacking from base64-encoded content. The malware hides itself, gather…

Read More
Threat Research

A Convoluted Infection Chain Using Excel – InQuest

July 22, 2022October 15, 2025 Securonix

Two-sentence summary: An in-depth look at a convoluted infection chain embedded in an Excel document that lures users to enable macros, then unleashes a multi-stage payload across embedded worksheets. The campaign uses obfuscated .NET loaders (Tupak, Chimchim)…

Read More
Threat Research

SharpTongue Deploys Clever Mail-Stealing Browser Extension “SHARPEXT”

July 21, 2022October 18, 2025 Securonix

SHARPEXT is a clever post-exploitation browser extension used by SharpTongue (often associated with Kimsuky) to inspect and exfiltrate data from a victim’s webmail (Gmail and AOL) as users browse. The attackers deploy SHARPEXT by modifying browser preferences …

Read More
Threat Research

How to analyze Linux malware – A case study of Symbiote

July 21, 2022October 15, 2025 Securonix

Symbiote hooks libc and libpcap to hide its activity on Linux, including hiding processes, files, and network connections. It steals credentials from SSH/SCP by hooking the libc read function, encrypts them with RC4, stores them locally, and exfiltrates via DN…

Read More
Threat Research

Threat analysis: Follina exploit fuels ‘live-off-the-land’ attacks

July 21, 2022October 20, 2025 Securonix

Two-sentence summary: An in-depth analysis shows how the Follina exploit (CVE-2022-30190) is weaponized to achieve remote code execution via MSDT and to enable persistent, live-off-the-land attacker activity using native Windows tools. The report details three…

Read More
Threat Research

Gootkit Loader’s Updated Tactics and Fileless Delivery of Cobalt Strike

July 21, 2022October 15, 2025 Securonix

Gootkit loader now employs more advanced fileless techniques to drop Cobalt Strike, using SEO-poisoned compromised websites and legal document templates to lure victims. The attack chain involves registry stuffing, memory-only execution via PowerShell, and a C…

Read More
Threat Research

Cyble – Targeted Attacks Being Carried Out Via DLL SideLoading

July 21, 2022October 15, 2025 Securonix

Threat actors are leveraging DLL sideloading in legitimate Microsoft applications to deliver a Cobalt-Strike beacon. The dropped DLL is loaded from application folders and communicates with a C2 URL hosted on CloudFront to enable beacon operations. #QakBot #Co…

Read More
Threat Research

Threat Actors Leveraging Microsoft Applications via DLL SideLoading – Detection & Response – Security Investigation

July 20, 2022October 16, 2025 Securonix

Threat actors abuse DLL sideloading to run malicious code through legitimate Microsoft applications (Teams and OneDrive), dropping and loading a malicious DLL that communicates with a remote C2 and leverages Cobalt Strike Beacon for post‑exploitation. The camp…

Read More
Threat Research

On the FootSteps of Hive Ransomware – Yoroi

July 20, 2022October 18, 2025 Securonix

Yoroi’s ZLab tracks Hive (TH-313) ransomware and its evolution from Go-based payloads to Rust-based variants under a Double Extortion/RaaS model, highlighting its expanding victimology including healthcare and critical infrastructure. The report details increa…

Read More
Threat Research

eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID

July 20, 2022October 16, 2025 Securonix

Gootloader is a Malware-as-a-Service (MaaS) offering that is spread through SEO poisoning to distribute malicious payloads, such as IcedID. Threat actors have begun using IcedID, a former banking trojan, since it’s a stealthier option compared to Cobalt Strike…

Read More
Threat Research

IcedID (Bokbot) with Dark VNC and Cobalt Strike

July 19, 2022October 16, 2025 Securonix

TA551/Monster Libra (aka SVCReady) has been distributing IcedID (Bokbot) alongside SVCReady since 2022, with campaigns that used password-protected archives and ISO images to drop malware and scripts. The infection chain led to DarkVNC activity and Cobalt Stri…

Read More
Threat Research

LockBit Ransomware Group Augments Its Latest Variant, LockBit 3.0, With BlackMatter Capabilities

July 18, 2022October 14, 2025 Securonix

LockBit 3.0, dubbed LockBit Black, shows Clear borrowings from BlackMatter, including API harvesting, anti-debugging, and a suite of configuration flags that govern encryption and lateral movement. The variant deepens LockBit’s capabilities with BlackMatter-li…

Read More
Threat Research

CosmicStrand: the discovery of a sophisticated UEFI firmware rootkit

July 18, 2022October 13, 2025 Securonix

CosmicStrand is a sophisticated UEFI firmware rootkit attributed to a Chinese-speaking threat actor, designed to persist from the earliest boot stages and deploy kernel- and user-mode payloads. It achieves durable persistence by implanting in firmware (CSMCORE…

Read More
Threat Research

Cyble – Luca Stealer Source Code Leaked On A Cybercrime Forum

July 16, 2022October 16, 2025 Securonix

Cyble Research Labs analyzed Luca Stealer, a Rust-based stealer targeting Chromium browsers, crypto wallets, chat apps, and games, whose source code leaked on a cybercrime forum in July 2022. Since then, the malware has seen multiple updates and wider adoption…

Read More
Threat Research

OODA: X-Ops Takes On Burgeoning SQL Server Attacks

July 15, 2022October 13, 2025 Securonix

Sophos X-Ops describes a coordinated Observe-Orient-Decide-Act loop among SophosLabs, SecOps, MTR, and Sophos AI to study and disrupt a wave of Microsoft SQL Server attacks leveraging old RCE CVEs and delivering Remcos or various ransomware families including …

Read More

Posts pagination

Previous 1 … 511 512 513 … 535 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.