Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: EDR

Threat Research

A Deep Dive into Brute Ratel C4 payloads

August 28, 2023October 17, 2025 Securonix

Brute Ratel C4 is a Red Team & Adversary Simulation software that can be considered an alternative to Cobalt Strike. This analysis focuses on a Brute Ratel badger/agent that uses API hashing, a configurable C2 with a user-agent, password, and encryption key, a…

Read More
Threat Research

Shining some light on the DarkGate loader

August 24, 2023October 17, 2025 Securonix

Two recent campaigns show DarkGate Loader being spread via phishing emails, using MSI and VBScript payloads to eventually deliver the DarkGate malware, with automated analysis identifying the actor behind it and the MaaS-style affiliate model. The campaign com…

Read More
Threat Research

Scattered Spider: The Modus Operandi

August 18, 2023October 17, 2025 Securonix

Scattered Spider (UNC3944, Scatter Swine, Muddled Libra) is a financially motivated threat actor active since May 2022, primarily targeting telecom and BPO sectors and expanding to critical infrastructure. The group relies on social engineering, signed kernel …

Read More
Threat Research

Flax Typhoon using legitimate software to quietly access Taiwanese organizations | Microsoft Security Blog

August 18, 2023October 14, 2025 Securonix

Microsoft identifies Flax Typhoon as a China-based state actor targeting Taiwanese organizations for espionage, emphasizing long-term access with minimal malware and reliance on built-in OS tools and legitimate software. The activity aims to quietly persist in…

Read More
Threat Research

Ransomware Roundup – Trash Panda and A New Minor Variant of NoCry | FortiGuard Labs

August 12, 2023October 13, 2025 Securonix

Fortinet’s FortiGuard Labs’ Ransomware Roundup highlights Trash Panda and a new minor NoCry variant, describing infection details and defenses. Trash Panda encrypts files on Windows, replaces the desktop wallpaper, and drops a politically themed ransom note. #…

Read More
Threat Research

Remote Access Trojan: Mitigating Infection Risk of Unwanted Guests

August 11, 2023October 17, 2025 Securonix

QwixxRAT is a new remote access trojan distributed via Telegram and Discord that silently infiltrates Windows devices to steal data and enable remote control. It combines broad data exfiltration, keylogging, screen and clipboard capture, and extensive anti-ana…

Read More
Threat Research

YAMA-Yet Another Memory Analyzer for malware detection – JPCERT/CC Eyes

August 9, 2023October 14, 2025 admin

YAMA is a memory-analysis tool from JPCERT/CC that detects hidden malware by scanning the live memory of Windows machines using custom YARA rules, addressing obfuscated and fileless threats. It is easy to deploy across devices and can export results in text or…

Read More
Threat Research

Attackers Distribute Malware via Freeze.rs And SYK Crypter | FortiGuard Labs

August 7, 2023October 13, 2025 Securonix

FortiGuard Labs identified a Rust injector chain that loads XWorm and Remcos via SYK Crypter, delivered through a phishing workflow starting with a malicious PDF. The operation leverages the Red Team tool Freeze.rs, Base64/LZMA encoding, and PowerShell to bypa…

Read More
Threat Research

Distribution of Malware Disguised as Coin and Investment-related Content – ASEC BLOG

August 3, 2023October 21, 2025 Securonix

ASEC reports the distribution of malware disguised as coin exchange and investment content, delivered as self-extracting executables and Word documents. The operation is attributed to the Kimsuky group, and it uses macros, scripting, and URL-based commands to …

Read More
Threat Research

Ransomware Roundup – DoDo and Proton | FortiGuard Labs

August 1, 2023October 15, 2025 Securonix

FortiGuard Labs’ bi-weekly Ransomware Roundup covers the DoDo and Proton variants, detailing their infection vectors, encryption behavior, and observed indicators, along with Fortinet protections and recommended defenses. The report highlights DoDo as a Chaos …

Read More
Threat Research

Kaspersky crimeware report: Emotet, DarkGate and LokiBot

July 31, 2023October 14, 2025 Securonix

Three crimeware families—DarkGate, LokiBot, and Emotet—are described with their infection chains and capabilities, including a four-stage DarkGate loader, a LokiBot phishing campaign, and an Emotet resurgence via OneNote attachments. The report highlights memo…

Read More
Threat Research

Cado Security Labs Encounter Novel Malware, Redis P2Pinfect

July 27, 2023October 13, 2025 Securonix

Cado Security Labs describe P2Pinfect, a Rust-based botnet targeting publicly-accessible Redis deployments with cross‑platform Linux and Windows payloads. The malware propagates via Redis replication and module loading, then uses a peer‑to‑peer C2 network, def…

Read More
Threat Research

Unpacking the Threats Within: The Hidden Dangers of .zip Domains – Avast Threat Labs

July 27, 2023October 18, 2025 Securonix

Avast Threat Labs examines how the newly popular .zip top-level domain is being abused to mislead users into thinking they are downloading files, with many examples mimicking major brands like Microsoft, Google, and Amazon. The piece also details how attackers…

Read More
Threat Research

Sneaky XWorm Uses MultiStaged Attack – Cyble

July 27, 2023October 16, 2025 Securonix

Two sentences: Cyber threat actors use multistage attacks and LOLBins to evade detection while delivering XWorm via WebDAV-enabled infrastructure, with BATLoader and VBScript stages helping drop and execute payloads. The campaign centers on XWorm’s versatility…

Read More
Threat Research

Out of the Sandbox: WikiLoader Digs Sophisticated Evasion   | Proofpoint US

July 27, 2023October 14, 2025 Securonix

Proofpoint identifies WikiLoader, a sophisticated downloader used in multiple Italian-focused campaigns, notable for its evasion techniques and modular, multi-stage chain that culminates in Ursnif delivery. The malware is thought to be rentable to multiple cyb…

Read More

Posts pagination

Previous 1 … 136 137 138 … 152 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.