Cyble Research Labs analyzes Redeemer 2.0, a ransomware variant distributed via an affiliate program that shares 20% of victims’ Monero ransom with affiliates and uses a builder to tailor campaigns. Redeemer 2.0 adds an affiliate toolkit, GUI-based decrypter, …
Category: Threat Research
Over the last month a crimeware group best known as 8220 Gang has expanded their botnet to roughly 30,000 hosts globally through Linux vulnerabilities and poorly secured configurations. The infection script, IRC botnet, and updated PwnRig cryptocurrency miner …
Cyber threat actors, including state-sponsored APT groups, continue to exploit CVE-2021-44228 (Log4Shell) in unpatched VMware Horizon and Unified Access Gateway (UAG) servers to gain initial access and move laterally within organizations. They deploy loader ma…
Pegasus spyware was used against Thailand’s pro-democracy movement, with at least 30 civil society victims infected between October 2020 and November 2021, triggering Apple security notifications in November 2021 and a collaborative forensic investigation. The…
Researchers document Cloaked Ursa (APT29) campaigns that weaponize trusted cloud storage services to hide malware delivery, notably Dropbox and Google Drive. The campaigns deploy EnvyScout HTML droppers to fetch Agenda.iso payloads and use Google Drive-based e…
Resecurity reports attackers are increasingly using tools to generate malicious shortcut files (.LNK) for payload delivery, with MLNK Builder 4.2 adding AV evasion and icon masquerading. Campaigns by APT groups and cybercriminals—including Bumblebee Loader and…
Unit 42 describes a campaign targeting Elastix/Digium phones where a PHP web shell is implanted to exfiltrate data and fetch additional payloads. The activity links to a Rest Phone Apps RCE (CVE-2021-45461) and is mitigated by Palo Alto Networks WildFire and T…
Two sentences: Wordfence reports a surge of attacks targeting Kaswara Modern WPBakery Page Builder Addons exploiting CVE-2021-24284 to upload PHP files and take over sites; the plugin is closed with no patch available, leaving all versions affected. Wordfence …
Confucius, an Indian APT group, has targeted Pakistan’s government and military since 2021 using spearphishing attachments and counterfeit government portals to deliver multi-stage loaders. The operation leverages QuasarRAT and bespoke C++/C# backdoors, delive…
NCC Group analyzes Everest ransomware operations and argues a link to Black-Byte, detailing how Everest-related activity deployed during an incident response used TTPs such as RDP-based lateral movement, credential dumping, and C2 via remote tools. The report …
ApolloRAT is a Python-based Remote Access Trojan that uses Discord as its C&C server. Cyble researchers note that the RAT is compiled with Nuitka to increase evasion and that threat actors are selling it for a low price on Telegram and their site. #ApolloRAT #…
Cisco Talos reports a new campaign by the Transparent Tribe APT targeting Indian educational institutions, deploying CrimsonRAT to establish long-term access into victim networks. The operation also implicates a Pakistani hosting provider, Zain Hosting, as par…
OrBit is a new undetected Linux threat that hijacks the execution flow by loading a malicious shared object and infects all running and upcoming processes. It provides remote SSH backdoor, harvests credentials, logs TTY commands, and persists via two methods (…
Unit 42 analyzes Brute Ratel C4 (BRc4) activity tied to a Roshan_CV ISO, showing how a red-teaming tool can evade modern defenses and operate with nation-state-like tradecraft. The post covers the tool’s packaging, delivery via a LNK lure, in-memory execution,…
This joint Cybersecurity Advisory explains that Maui ransomware has been used by North Korean state-sponsored actors since May 2021 to target Healthcare and Public Health sector organizations, detailing TTPs and IOCs. It urges mitigations and reporting, and wa…