Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: EDR

Threat Research

Cyber Espionage in India: Decoding APT-36’s New Linux Malware Campaign

April 14, 2023October 16, 2025 Securonix

Uptycs researchers uncovered Poseidon, a Linux backdoor tied to APT-36 (Transparent Tribe), delivered via a tainted Kavach 2FA tool to compromise Indian government-related systems. Poseidon functions as a versatile backdoor offering keystroke logging, screen c…

Read More
Threat Research

in2al5d p3in4er is Almost Completely Undetectable

April 13, 2023October 14, 2025 Securonix

The in2al5d p3in4er loader is a highly evasive component that powers Aurora’s delivery chain. Morphisec explains its anti-VM checks, runtime payload decryption, process hollowing, and decoy-website/social-engineering techniques that rely on YouTube distributio…

Read More
Threat Research

Nation-state threat actor Mint Sandstorm refines tradecraft to attack high-value targets | Microsoft Security Blog

April 13, 2023October 15, 2025 Securonix

Mint Sandstorm (PHOSPHORUS) has refined its tradecraft, weaponizing new-day vulnerabilities and conducting targeted phishing to access high-value targets in energy and transportation sectors. The group develops bespoke tooling (Drokbk, Soldier, CharmPower) and…

Read More
Threat Research

Technical Analysis of Trigona Ransomware

April 12, 2023October 13, 2025 Securonix

Trigona is a Delphi-based ransomware that encrypts files using RSA and AES with a novel residual block termination, adds a multi-step decryption workflow, and recently gained a data wiper capability. ThreatLabz notes overlap in tactics with BlackCat/ALPHV, but…

Read More
Threat Research

Zaraza Bot Credential Stealer Targets Browser Passwords – Uptycs

April 12, 2023October 17, 2025 Securonix

Uptycs researchers identified Zaraza bot, a credential-stealing malware that uses Telegram as its command-and-control channel to collect browser credentials and other sensitive data. It targets 38 web browsers and transmits stolen information to a Telegram ser…

Read More
Threat Research

Read The Manual Locker: A Private RaaS Provider

April 11, 2023October 16, 2025 Securonix

RTM Locker operates as a ransomware-as-a-service with affiliates under strict governance, aiming to stay under the radar and monetize rather than seek headlines. The article provides a technical deep dive into their Windows ransomware, including panel operatio…

Read More
Threat Research

ASEC Weekly Malware Statistics (April 3rd, 2023 – April 9th, 2023) – ASEC BLOG

April 10, 2023October 15, 2025 Securonix

ASEC’s RAPIT weekly analysis (Apr 3–9, 2023) shows backdoors as the dominant category (61.1%), followed by infostealers (20.8%), downloaders (16.9%), and ransomware (1.1%). RedLine leads the threat list with over half of detections, with AgentTesla, GuLoader, …

Read More
Threat Research

Linux – focus on a cryptomining attack dubbed color1337 – TEHTRIS

April 6, 2023October 14, 2025 Securonix

TEHTRIS Threat Hunters document illicit cryptomining activity targeting Linux-based machines, observed on a France-hosted honeypot in January. The campaign, named Color1337, toggles between full-capacity cryptomining using diicot and rebound reconnaissance via…

Read More
Threat Research

Beijing Calling: About Chinese APTs | SECUINFRA

April 5, 2023October 20, 2025 Securonix

Two paragraphs summarize ongoing Chinese APT activity against EU governments and businesses, highlighting groups, tools, and defensive recommendations. The report details APT27, APT31, APT15, and Mustang Panda campaigns, including Linux and Windows backdoors a…

Read More
Threat Research

Rilide: A New Malicious Browser Extension for Stealing Cryptocurrencies | Trustwave

April 4, 2023October 16, 2025 Securonix

Trustwave SpiderLabs uncovered Rilide, a new malware strain that hijacks Chromium-based browsers by disguising itself as a Google Drive extension and performing a wide range of actions such as monitoring history, taking screenshots, and injecting scripts to st…

Read More
Threat Research

CryptoClippy Speaks Portuguese

April 3, 2023October 14, 2025 Securonix

Unit 42 uncovered CryptoClippy, a cryptocurrency clipper that targets Portuguese speakers by watching the clipboard for wallet addresses and replacing them with attacker-controlled addresses. The campaign delivers multi-stage PowerShell loaders via malvertisin…

Read More
Threat Research

Genesis Market No Longer Feeds The Evil Cookie Monster

April 1, 2023October 15, 2025 Securonix

Genesis Market, a major underground marketplace for stolen credentials, browser fingerprints, and cookies, was disrupted by a multinational law enforcement operation spanning 17 countries, leading to takedown notices and arrests or contacts with users. The pos…

Read More
Threat Research

3CX Supply Chain Compromise Leads to ICONIC Incident

March 30, 2023October 13, 2025 Volexity

Volexity analyzed a supply-chain compromise of the 3CX Desktop App in which a malicious ffmpeg library inserted into signed installers decoded encrypted blobs, fetched staged payloads, and reflectively loaded a 64-bit information-stealer dubbed ICONIC/ICONICST…

Read More
Threat Research

Ransomware Roundup – Dark Power and PayMe100USD Ransomware | FortiGuard Labs

March 30, 2023October 14, 2025 Securonix

Fortinet FortiGuard Labs’ bi-weekly Ransomware Roundup highlights Dark Power and PayME100USD, outlining their file-encrypting behavior on Windows and the actor’s apparent data-leak threats, with Fortinet-provided protections and best practices. The report note…

Read More
Threat Research

Tracking the CHM Malware Using EDR – ASEC BLOG

March 28, 2023October 16, 2025 Securonix

ASEC reports a CHM-based APT technique where threat actors use Compiled HTML Help Files to execute malware via hh.exe, download a PowerShell script, and run it through mshta.exe. The operation culminates in persistence via the Run registry key and C2 communica…

Read More

Posts pagination

Previous 1 … 141 142 143 … 152 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.