Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Bitter APT continues to target Bangladesh | SECUINFRA Falcon Team

June 22, 2022October 16, 2025 Securonix

Bitter (T-APT-17) continues to target Bangladesh, employing a multi-stage infection chain beginning with an Excel Maldoc that exploits CVE-2018-0798 to drop additional payloads. The operation culminates in Almond RAT, a .NET-based backdoor that uses AES-CBC en…

Read More
Threat Research

Securonix Threat Labs Initial Coverage Advisory: Analysis and Detection of BumbleBee Loader Using Securonix

June 22, 2022October 13, 2025 Securonix

BumbleBee is a new loader actively used to deliver payloads via phishing campaigns and to establish an initial foothold in target networks. The analysis highlights its living-off-the-land techniques, notably using a Microsoft-signed odbcconf.exe to indirectly …

Read More
Threat Research

Case of Attack Exploiting AnyDesk Remote Tool (Cobalt Strike and Meterpreter) – ASEC BLOG

June 22, 2022October 25, 2025 Securonix

MS-SQL servers are commonly targeted by attackers who gain control and install malware, including coin miners and ransomware. The article details a case where attackers deploy Cobalt Strike and Meterpreter on vulnerable MS-SQL servers to install AnyDesk for re…

Read More
Threat Research

Rise of LNK (Shortcut files) Malware | McAfee Blog

June 22, 2022October 14, 2025 McAfee

An LNK file is a Windows Shortcut that serves as a pointer to open a file, folder, or application. LNK files are based on the Shell Link binary file format, which holds information used to access another data object. McAfee Labs has seen a rise in malware being delivered using LNK…

Read More
Threat Research

Update: IconBurst npm software supply chain attack grabs data from apps and websites

June 21, 2022October 14, 2025 Securonix

Two sentences summarizing the content: ReversingLabs uncovered a widespread npm software supply chain attack where malicious JavaScript packages were published to steal form data from apps and websites. The campaign used typosquatting to impersonate legitimate…

Read More
Threat Research

DarkComet RAT Returns with New TTPS – Detection & Response – Security Investigation

June 21, 2022October 16, 2025 Securonix

DarkComet RAT has re-emerged with new TTPS-based detection and response coverage, highlighting its capabilities as a stealthy remote access Trojan that can spy on systems, steal credentials, and add infected machines to a botnet. The article outlines a multi-s…

Read More
Threat Research

VSingle malware that obtains C2 server information from GitHub – JPCERT/CC Eyes

June 21, 2022October 17, 2025 Securonix

VSingle, a Lazarus-linked malware, has been updated to fetch C2 server information from GitHub instead of relying solely on hard-coded C2 endpoints. The Linux variant uses wget for C2 communication, stores responses in /tmp/.sess_* files, and dynamically disco…

Read More
Threat Research

Cyble – Xloader Returns With New Infection Technique

June 21, 2022October 14, 2025 Securonix

Cyble Research Labs analyzed Xloader’s updated infection technique, detailing a multi-stage chain that starts with a phishing email delivering a PDF attachment, then traverses through embedded XLSX and an RTF-triggered dropper to load a final Xloader payload. …

Read More
Threat Research

GlowSand – InQuest

June 20, 2022October 13, 2025 Securonix

GlowSand describes a Ukraine-focused, multi-stage malware campaign leveraging documents with malicious macros to download staged payloads. It uses geofenced infrastructure and persistence via a scheduled task to maintain access and conduct system discovery and…

Read More
Threat Research

The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefact

June 20, 2022October 13, 2025 Securonix

SessionManager is an IIS backdoor tied to the GELSEMIUM activity cluster that persists on compromised servers by loading a malicious IIS module after ProxyLogon-type exploits. It enables reading/writing files, remote command execution, and HTTP-based command-a…

Read More
Threat Research

Raccoon Stealer v2 – Part 1: The return of the dead

June 17, 2022October 16, 2025 Securonix

Raccoon Stealer v2 marks a notable revival of the information stealer brand, with early signs of life detected in 2022 as servers and administration panels surfaced. SEKOIA.IO documents a refreshed build, renewed distribution, and a plan to scale behind a rede…

Read More
Threat Research

YTStealer Malware: “YouTube Cookies! Om Nom Nom Nom”

June 17, 2022October 15, 2025 Securonix

YTStealer is a YouTube authentication cookie stealer marketed on the dark web, designed to harvest credentials and channel data from creators. It evades analysis with sandbox checks, uses headless browser automation to validate cookies and collect YouTube Stud…

Read More
Threat Research

Cyble – PennyWise Stealer: An Evasive Infostealer Leveraging YouTube To Infect Users

June 17, 2022October 15, 2025 Securonix

Cyble Research Labs uncovered PennyWise, a new evasive infostealer that targets 30+ Chrome-based and 5+ Mozilla-based browsers as well as crypto wallets, with updated version 1.3.4 already observed in the wild. The malware is distributed via YouTube campaigns …

Read More
Threat Research

Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit

June 16, 2022October 15, 2025 Securonix

Black Basta expanded its repertoire by employing QakBot as an entry point and using the PrintNightmare flaw to perform privileged file operations. It also leveraged the Coroxy backdoor and Netcat for lateral movement across networks. #BlackBasta #QakBot

Read More
Threat Research

Ukraine Targeted by Dark Crystal RAT (DCRat) | FortiGuard Labs

June 16, 2022October 14, 2025 Securonix

Two Ukrainian targets were hit by emails delivering malicious documents that leveraged a Follina-like vulnerability and malicious macros to drop a DCRat variant. FortiGuard Labs notes the campaign revolves around Dark Crystal RAT (DCRat) with multi-stage infec…

Read More

Posts pagination

Previous 1 … 514 515 516 … 535 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.