Avast Threat Labs uncovered a targeted zero-day in Google Chrome (CVE-2022-2294) used in the wild to attack Avast users in the Middle East, including Lebanese journalists. The campaign combined watering hole attacks, a Chrome WebRTC exploit chain, and a BYOVD …
Category: Threat Research
Cyble Research Labs uncovered a new Qakbot playbook that uses DLL sideloading and a multi-stage delivery chain, including HTML-embedded ZIPs and an ISO with a disguised LNK file to trigger execution. The campaign evolves with legitimate apps loading malicious …
YamaBot, linked to Lazarus, targets both Linux and Windows with HTTP-based C2 communication and RC4-based encoding for configuration and commands. The report details Linux and Windows variants, their C2 interactions, commands, and the infrastructure and hashes…
The ASEC analysis tracks attacks against vulnerable Atlassian Confluence Servers exploiting CVE-2021-26084 and CVE-2022-26134, leading to WebShell deployment and coin-mining payloads on unpatched systems. Multiple threat actors and malware families—such as 822…
Threat researchers observed a new attack campaign named STIFF#BIZON targeting high-value targets in the Czech Republic, Poland, and other countries, with artifacts possibly linked to North Korea’s APT37 (Konni). The campaign uses a multi-stage infection chain …
Cisco Talos uncovered a GoMet backdoor campaign targeting a Ukrainian software development firm, with indicators pointing toward Russian state-sponsored actors or their interests. The GoMet variant is a modified open-source backdoor capable of cross-OS deploym…
Fraudsters abused Google’s ad network to redirect users searching for popular brands to a network of tech-support scam pages, effectively hijacking browser sessions through malvertising. The operation used cloaking, multi-stage redirects, and iframe-based brow…
The report details UNC1151’s spearphishing campaign targeting Ukrainian entities, delivering a multi-stage malware chain including GRIMPLANT, GRAPHSTEEL, BEACON, and MICROBACKDOOR via CHM and lure documents. It documents how Go-based droppers download modules,…
Lightning Framework is a modular, undetected Linux malware framework with a downloader, core, and multiple plugins, including rootkit-capable components, that can communicate with a threat actor via a malleable C2 configuration. It leverages typosquatting, per…
LockBit 3.0 (aka LockBit Black) is an evolved ransomware capable of aggressive anti-analysis and evasion, rapid encryption, and expanded data-leak and affiliate-management features. The piece provides a technical dive into its payload behavior, persistence, ge…
TA4563 is a threat actor using the EvilNum backdoor to target European DeFi, cryptocurrency, and forex entities, with campaigns evolving in how they deliver the malware and evade defenses. EvilNum functions as a backdoor for data theft and loading additional p…
CloudMensis is a macOS backdoor that spies on victims by exfiltrating documents, keystrokes, and screen captures, and communicates with its operators exclusively via public cloud storage services. It uses a two-stage architecture where the first stage download…
Fortinet’s FortiGuard Labs documented a phishing campaign delivering a new QakBot variant via an attached HTML file that auto-executes to drop a ZIP, load a loader, and ultimately run QakBot within a Windows process. The analysis details the infection chain fr…
Amadey Bot is a information-stealing malware that also acts as a downloader for additional payloads when commanded by a C2 server, and it has been spread via SmokeLoader as part of downloader activity. It targets systems through disguise in software cracks, th…
NukeSped RAT is a Windows-based remote access trojan attributed to the Lazarus Group that uses phishing Word documents with malicious macros to drop staged payloads. It exfiltrates data, captures keystrokes and screenshots, and downloads additional payloads, e…