Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: EDR

Threat Research

Ransomware Roundup – Maori | FortiGuard Labs

May 8, 2023October 14, 2025 Securonix

FortiGuard Labs’ Ransomware Roundup highlights Maori, a Linux-targeting ransomware written in Go that encrypts files in the home directory and demands payment for decryption. The report notes ransom notes, contact methods via Tox and onionmail, and Fortinet pr…

Read More
Threat Research

Securonix Threat Labs Security Advisory: Latest Update: Ongoing MEME#4CHAN Attack/Phishing Campaign uses Meme-Filled Code to Drop XWorm Payloads

May 8, 2023October 16, 2025 Securonix

An unusual phishing campaign known as MEME#4CHAN delivers XWorm payloads through meme-filled PowerShell and obfuscated JavaScript, persisting for months and evolving with new payloads and obfuscation methods. The attack chain starts with phishing Word document…

Read More
Threat Research

Uncovering RedStinger – Undetected APT cyber operations in Eastern Europe since 2020

May 8, 2023October 16, 2025 Securonix

Red Stinger is an Eastern Europe–focused APT active since 2020, tracked publicly by Malwarebytes and Kaspersky under different aliases, with campaigns targeting Ukraine’s military, transportation, and critical infrastructure. The operation used a repeatable in…

Read More
Threat Research

GULoader Campaigns: A Deep Dive Analysis of a highly evasive Shellcode based loader | McAfee Blog

May 7, 2023October 16, 2025 Securonix

GuLoader (GULoader) campaigns deploy a highly evasive shellcode-based loader using NSIS-based installers delivered via malspam, incorporating XOR-encoded payloads and anti-analysis tricks. The article outlines a three-stage infection chain—shellcode deployment…

Read More
Threat Research

ASEC Weekly Malware Statistics (May 1st, 2023 – May 7th, 2023) – ASEC BLOG

May 7, 2023October 18, 2025 Securonix

ASEC’s RAPIT weekly analysis covers malware statistics from May 1–7, 2023, showing infostealers as the top category and AgentTesla leading the threat landscape. It details the main families (AgentTesla, Formbook, Amadey, GuLoader, Lokibot), their distribution,…

Read More
Threat Research

Threat Assessment: Royal Ransomware

May 4, 2023October 15, 2025 Securonix

Royal ransomware is a private group formed by former Conti members that has targeted critical infrastructure, notably healthcare, since September 2022. It uses BATLOADER to drop a Cobalt Strike beacon and has expanded to a Linux/ESXi variant, with public extor…

Read More
Threat Research

Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign

April 27, 2023October 15, 2025 Securonix

SentinelLabs reports ongoing Kimsuky operations using a new ReconShark component, delivered via targeted spear-phishing, OneDrive-hosted documents, and malicious macros. ReconShark functions as a reconnaissance tool that exfiltrates system and defense-detectio…

Read More
Threat Research

Polish Healthcare Industry Targeted by Vidar Infostealer Likely Linked to Djvu Ransomware

April 27, 2023October 15, 2025 Securonix

Two sentences summarizing the content here. EclecticIQ links a spearphishing campaign against Poland’s healthcare sector to Vidar Infostealer, with overlaps to Djvu and LockBit 2.0 ransomware activity, and describes how Vidar collects sensitive data and exfilt…

Read More
Threat Research

Chain Reaction: ROKRAT’s Missing Link – Check Point Research

April 26, 2023October 18, 2025 Securonix

Checkpoint Research tracks how ROKRAT’s deployment has evolved into LNK-based, multi-stage infection chains that bypass macro restrictions, showing a shift from documents with macros to oversized LNK loaders. The campaigns target South Korean affairs, link to …

Read More
Threat Research

Ransomware Roundup – UNIZA | FortiGuard Labs

April 24, 2023October 18, 2025 Securonix

FortiGuard Labs analyzes the UNIZA ransomware, a Windows-targeting variant that encrypts user files and displays its ransom message via the Command Prompt. It also notes the likely phishing-based infection vector, limited current spread, and Fortinet protectio…

Read More
Threat Research

Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware

April 21, 2023October 14, 2025 Securonix

BellaCiao is a highly customized dropper linked to Charming Kitten (APT35) that targets US, European, Middle Eastern, and Indian victims with victim-specific data and C2 communication. The implant combines a tailored payload, a DNS-based command channel, and m…

Read More
Threat Research

RokRAT Malware Distributed Through LNK Files (*.lnk): RedEyes (ScarCruft) – ASEC BLOG

April 21, 2023October 19, 2025 Securonix

RedEyes (ScarCruft/APT37) has expanded its toolkit by distributing RokRAT via LNK files. The LNKs trigger PowerShell to create and execute payloads in the Temp folder, download encoded data from cloud storage, and deploy RokRAT to harvest credentials. Hashtags…

Read More
Threat Research

Dog Hunt: Finding Decoy Dog Toolkit via Anomalous DNS Traffic

April 21, 2023October 17, 2025 Securonix

Infoblox identifies a rare DNS-based toolkit named Decoy Dog, built around the Pupy RAT, observed in enterprise networks through DNS beacons and encrypted DNS traffic. The report links possible Earth Berberoka activity and outlines three infrastructure models …

Read More
Threat Research

Securonix Threat Labs Security Advisory: New OCX#HARVESTER Attack Campaign Leverages Modernized More_eggs Suite to Target Victims

April 19, 2023October 16, 2025 Securonix

OCX#HARVESTER is a threat campaign by Securonix Threat Labs leveraging the More_eggs malware suite to target financial-sector victims, with activity observed from late 2022 through early 2023 and new C2 infrastructure shifts. The campaign uses image-based LNK …

Read More
Threat Research

‘AuKill’ EDR killer malware abuses Process Explorer driver

April 17, 2023October 15, 2025 Securonix

AuKill is a defense-evasion tool that exploits an outdated Microsoft Process Explorer driver to disable EDR protections and then deploys ransomware, with multiple variants observed since 2023. The technique, a BYOVD (bring-your-own vulnerable driver) approach,…

Read More

Posts pagination

Previous 1 … 140 141 142 … 152 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.