Gen Threat Labs identified WordlistLoader, a new loader used in ClearFake campaigns to deliver Amatera Stealer through fake CAPTCHA and ClickFix-style infection chains. The report also details major Amatera changes through version 4.3.3-alpha1, including stronger obfuscation, WoW64/Heaven’s Gate syscall hardening, x64 syscall trampolines, and a redesigned Application-Bound Encryption bypass. #WordlistLoader #AmateraStealer #ClearFake #FakeCaptchas #ClickFix #HeavensGate #WoW64 #PoolParty
Category: Threat Research
Scammers are using fake AML wallet-checking sites that mimic legitimate services like AMLBot to trick users into connecting wallets and approving malicious transactions. The scheme relies on fake progress screens, fabricated fees, and misleading “Clean, Low Risk” results to steal crypto or gain access to token permissions. #AMLBot #AML Check #Browser…
Microsoft Threat Intelligence uncovered a multistage intrusion campaign targeting hospitality and hotel organizations in Europe and Asia, especially Japan, using photo-themed ZIP archives and fake image shortcut files to launch an attack chain with PowerShell, a Node.js implant, persistence, and C&C activity. The campaign also abused Calendly and Google redirect links for phishing and yielded extensive IoCs, including domains, IPs, and related artifacts linked to infrastructure such as photo-26653[.]cfd and zloapobikahy23[.]bond. #Microsoft #Calendly #Google #Nodejs #PowerShell #photo-26653cfd #zloapobikahy23bond
StopAndProtect is a large-scale operation that combines file encryption, data theft, and multiple spreading and control components while abusing thousands of hacked WordPress sites for infrastructure. OPSEC failures exposed victim logs, screenshots, source code, and evidence that the campaign affected thousands of IPs across regions, with most activity seen in the US, Russia, and India. #StopAndProtect #WordPress #ClickFix #SilentEncryptor #SilentDataCollector
This article explains how malware uses blockchain dead drop resolvers to fetch command-and-control pointers at runtime from smart contracts on EVM chains, Solana, and TON instead of hardcoding them. It highlights families such as ChainDrop, TroyDen, DeadLock, CLEARSHORT, JADESNOW, GlassWorm, SalatStealer, and TONResolver, and shows how Netskope detects these blockchain RPC patterns. #ChainDrop #TroyDen #DeadLock #CLEARSHORT #JADESNOW #GlassWorm #SalatStealer #TONResolver #Ethereum #Polygon #BNBSmartChain #Solana #TON
AhnLab SEcurity intelligence Center found Larva-26010 targeting Korean web servers and MS-SQL servers to install SoftEther VPN, likely to turn infected systems into covert VPN/C&C infrastructure. The intrusion chain also included discovery commands, registry changes for WDigest credential theft, and follow-on deployment of CLR SqlShell and web shells. #Larva26010 #SoftEtherVPN #MSSQL…
CERT-AGID identified a phishing campaign that abuses the branding of the Fascicolo Sanitario Elettronico, Ministry of Health, Department for Digital Transformation, and Ministry of Economy and Finance to steal personal and payment card data. The fake site lures victims with a supposed 19% pharmacy refund and then collects identity details and card information before showing a fabricated “in processing” confirmation. #CERT-AGID #FascicoloSanitarioElettronico #MinisteroDellaSalute #MinisteroDEconomiaEDelleFinanze
Insikt Group identified multiple PurpleDelta clusters tied to North Korean IT workers, likely based in China, that used fabricated personas, AI tools, and remote-access tradecraft to obtain and hold jobs at more than 1,100 companies. The operators applied for work at scale, recorded internal meetings, coordinated through Telegram and Slack, and used services such as ChatGPT, AnyDesk, and TrustID Card to support ongoing insider-risk activity. #PurpleDelta #ChatGPT #AnyDesk #Telegram #Slack #TrustIDCard
Acronis’ 2026 patch-quality analysis shows that software severity and real-world install behavior are different signals, with Chrome and Adobe PDF standing out as the top testing priorities for SMB Windows fleets. The report also finds that patch risk is concentrated in a small set of products, and that monthly warning rates can swing sharply, so MSPs should combine vendor severity with deployment telemetry before rolling out updates. #GoogleChrome #AdobePDF #MicrosoftWindowsServer #Node.js #MicrosoftEdge #MicrosoftOffice
Mandiant describes AVDH, an agentic vulnerability discovery harness that combines LLMs, structured orchestration, and human expertise to find and validate software flaws at scale. In real-world use, it uncovered over 100 critical vulnerabilities in two days, contributed to 12 assigned CVEs, and identified an RCE in a client web application source code. #AVDH #Mandiant #CodeMender #GoogleAntigravity #GoogleAgentDevelopmentKit #GeminiFlashLite #CVE-2026-13242 #CVE-2026-55803
Varonis Threat Labs discovered CoSnitch, a critical one-click flaw in Microsoft Copilot Personal that can silently execute attacker prompts, exfiltrate data, and poison persistent memory through trusted AI workflows. The research also introduced “meta-hacking,” where Copilot was manipulated into revealing its own weaknesses, and Microsoft patched the issue on August 18,…
ASEC identified a phishing campaign that impersonated a sales team member to deliver the malicious attachment 7200_Quantum_Enterprise_LLC_SSO-0661.GZ, which contained an injector that disables security software and deploys PhantomStealer. The attack used UAC bypass, BYOVD, and process hollowing to run with elevated privileges, terminate security products, and steal credentials, browser data, and…
Mirage2FA is a phishing-as-a-service toolkit that steals Microsoft 365 credentials and authenticated sessions using Adversary-in-the-Middle attacks to bypass MFA. ANY.RUN found the campaign is heavily concentrated in the United States and targets industries such as Technologies, Manufacturing, and Education, with thousands of potential compromise events between 2024 and 2026. #Mirage2FA #Microsoft365…
A 12 August 2026 White House memorandum authorizes vetted private US companies to conduct government-directed cyber surveillance and effects operations against criminal groups abroad, creating new jurisdictional and telemetry-sharing risks for non-US organizations. The article argues that European hospitals, grid operators, and municipalities must now ask not just where their data sits, but whose authority controls the security tools they use. #WhiteHouse #CLOUDAct #NIS2 #CADA
Seqrite tracked Operation QUICSILVER, a China-nexus campaign targeting Myanmar government personnel with a Burmese-language lure delivered in a disguised VHD file. The operation uses a malicious LNK, ftp.exe, split-payload reconstruction, and a Go backdoor named QUICAgent that communicates via Cloudflare Workers and QUIC while using RC4 encryption. #QUICAgent #OperationQUICSILVER #CloudflareWorkers #ftp.exe