Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: EDR

Threat Research

Out of the Sandbox: WikiLoader Digs Sophisticated Evasion   | Proofpoint US

July 27, 2023October 14, 2025 Securonix

Proofpoint identifies WikiLoader, a sophisticated downloader used in multiple Italian-focused campaigns, notable for its evasion techniques and modular, multi-stage chain that culminates in Ursnif delivery. The malware is thought to be rentable to multiple cyb…

Read More
Threat Research

Detecting Ongoing STARK#MULE Attack Campaign Targeting Victims Using US Military Document Lures

July 26, 2023October 19, 2025 Securonix

A new ongoing attack campaign tracked as STARK#MULE uses US military recruitment-themed documents to lure victims and runs malware staged from legitimate compromised Korean websites. The attack chain starts with a phishing zip/pdf lure, then PowerShell-based s…

Read More
Threat Research

Into the tank with Nitrogen

July 26, 2023October 14, 2025 Securonix

Nitrogen is a new initial-access malware campaign identified by Sophos X-Ops that leverages malvertising and impersonation of legitimate software to drop trojanized installers. The operation targets North American tech and non-profit entities to deploy second-…

Read More
Threat Research

Space Pirates: a look into the group’s unconventional techniques, new attack vectors, and tools

July 25, 2023October 15, 2025 PTsecurity-ESC

Space Pirates, a threat group active since 2017, is profiled by PT ESC with its evolving toolkit and novel attack vectors, including Deed RAT and Voidoor, plus a GitHub- and forum-based C2 approach. The report notes expanded targets in Russia and Serbia across…

Read More
Threat Research

Amadey Threat Analysis and Detections | Splunk

July 25, 2023October 15, 2025 Securonix

Amadey Trojan Stealer is a MaaS-enabled malware that has persisted since 2018, delivering multiple payloads and plugins through a botnet. The post analyzes Amadey’s anti-sandbox behavior, persistence, defense evasion, C2 communications, and data collection cap…

Read More
Threat Research

Ransomware Roundup – Cl0p | FortiGuard Labs

July 25, 2023October 18, 2025 Securonix

FortiGuard Labs reviews the Cl0p ransomware group’s activities, noting a shift from encrypting victim data to data exfiltration and extortion, often tied to high-profile vulnerabilities like MOVEit Transfer (CVE-2023-34362). The report also highlights the grou…

Read More
Threat Research

Threat Group Assessment: Mallox Ransomware

July 24, 2023October 13, 2025 Securonix

Mallox is a ransomware operation targeting Windows systems, leveraging unsecured MS-SQL servers as an entry point and using brute-force techniques to gain access. It employs a double-extortion model, steals data before encryption, and is expanding via affiliat…

Read More
Threat Research

Ransomware Roundup – Rancoz | FortiGuard Labs

July 14, 2023October 20, 2025 Securonix

Fortinet’s FortiGuard Labs analyzes the Rancoz ransomware in its Ransomware Roundup, detailing its Windows-focused encryption, ransom notes, wallpaper change, and potential links to related variants like Buddy ransomware. The report also notes limited victim s…

Read More
Threat Research

Routers from the Underground: Exposing AVrecon – Lumen

July 12, 2023October 18, 2025 CTI

Lumen Black Lotus Labs uncovered a multi-year campaign that infected SOHO routers with an ARM-targeted Linux RAT named AVrecon to build a covert residential proxy network used for activities like ad fraud and password spraying. The botnet employed a multi-stag…

Read More
Threat Research

Criminals target businesses with malicious extension for Meta’s Ads Manager and accidentally leak stolen accounts

July 7, 2023October 20, 2025 Securonix

Criminals are targeting Facebook business accounts by promoting fraudulent Ads Manager software through malicious Chrome extensions that steal login credentials and ad budgets. The campaign uses phishing pages, a disguised extension loaded locally, and data ex…

Read More
Threat Research

Kimsuky Threat Group Using Chrome Remote Desktop – ASEC BLOG

July 7, 2023October 17, 2025 Securonix

Two sentences summarizing the article: ASEC reports that the Kimsuky threat group weaponizes Chrome Remote Desktop along with AppleSeed and other remote-access tools to take control of infected machines. The campaign centers on spearphishing with disguised doc…

Read More
Threat Research

Storm-0978 attacks reveal financial and espionage motives | Microsoft Security Blog

July 6, 2023October 14, 2025 Securonix

Microsoft ties a Storm-0978 phishing operation to defense and government targets in Europe and North America, abusing CVE-2023-36884 via Word docs to deliver a RomCom backdoor and related ransomware. The campaign blends espionage-focused credential gathering w…

Read More
Threat Research

Hunting for A New Stealthy Universal Rootkit Loader

July 6, 2023October 17, 2025 Securonix

A Trend Micro analysis uncovers a new signed rootkit loader cluster that acts as a universal kernel-driver loader, enabling second-stage unsigned modules to be loaded in the target system. The activity is linked to a China-based actor (associated with FiveSys)…

Read More
Threat Research

Malicious Batch File (*.bat) Disguised as a Document Viewer Being Distributed (Kimsuky) – ASEC BLOG

July 5, 2023October 18, 2025 Securonix

A batch-file malware campaign disguises itself as document viewers (Word/HWP) and uses email distribution to download scripts tailored to the target’s anti-malware software. The operation is attributed to the Kimsuky group, leveraging Google Drive/Docs, regist…

Read More
Threat Research

Distribution of NetSupport Malware Using Email – ASEC BLOG

July 5, 2023October 14, 2025 Securonix

AhnLab’s ASEC reports NetSupport RAT distributed via spear phishing emails and phishing pages disguised as invoices, shipment documents, and purchase orders. The campaign uses a malicious JavaScript in a ZIP attachment that, once executed, downloads and runs a…

Read More

Posts pagination

Previous 1 … 137 138 139 … 152 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.