Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: EDR

Threat Research

Threat analysis: Malicious npm package mimics Material Tailwind CSS tool

September 20, 2022October 17, 2025 Securonix

Two sentences summarizing the article: ReversingLabs details a malicious npm package masquerading as Material Tailwind that installs via a postinstall script to download a password-protected ZIP containing a Windows executable. The campaign employs obfuscated …

Read More
Threat Research

Ransomware Roundup: Ragnar Locker Ransomware | FortiGuard Labs

September 14, 2022October 14, 2025 Securonix

Fortinet’s Ragnar Locker Ransomware Roundup explains that Ragnar Locker encrypts files, exfiltrates data, and uses double extortion to pressure victims, including negotiations via a Tor-based site and leaking stolen information on a “Wall of Shame.” It also no…

Read More
Threat Research

From the Front Lines | Slam! Anatomy of a Publicly-Available Ransomware Builder

September 12, 2022October 14, 2025 Securonix

Publicly available Slam Ransomware Builder lowers the barrier to entry for cybercriminals by offering free tooling, while presenting credible threats to enterprises. The article details Slam’s features, capabilities, and indicators of compromise to help defend…

Read More
Threat Research

TA453 Uses Impersonation to Capitalize on FOMO | Proofpoint US

September 2, 2022October 15, 2025 Securonix

TA453, an Iran-aligned actor, expanded its social engineering with Multi-Persona Impersonation (MPI), using multiple actor-controlled personas within a single email thread to boost campaign credibility. The technique targets researchers and nuclear security do…

Read More
Threat Research

The Curious Case of “Monti” Ransomware: A Real-World Doppelganger

September 1, 2022October 14, 2025 Securonix

Monti ransomware gang emerged during a July 2022 incident, encrypting 21 servers after exploiting Log4Shell in a VMware Horizon setup and leveraging both traditional Conti-like TTPs and new tooling. The operation highlighted Monti’s mimicry of Conti, its use o…

Read More
Threat Research

MagicRAT: Lazarus’ latest gateway into victim networks

September 1, 2022October 13, 2025 Securonix

Cisco Talos identifies a new Lazarus Group remote access trojan named MagicRAT, deployed after exploiting publicly exposed VMware Horizon platforms. The malware, linked to TigerRAT and Lazarus infrastructure, includes persistence, reconnaissance, and the hosti…

Read More
Threat Research

#StopRansomware: Vice Society | CISA

August 30, 2022October 15, 2025 Securonix

Joint FBI/CISA/MS-ISAC advisory details Vice Society’s ransomware operations, highlighting their methods, IOCs, and recommended mitigations for education-sector defenders. It notes that Vice Society uses variants such as Hello Kitty/Five Hands and Zeppelin and…

Read More
Threat Research

DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa – Check Point Research

August 29, 2022October 16, 2025 Securonix

DangerousSavanna is a two-year campaign targeting financial institutions in French-speaking Africa, employing spear-phishing and a diverse set of infection chains to deploy PoshC2 and AsyncRAT. The operation features evolving lures, modular payloads, and exten…

Read More
Threat Research

BianLian Ransomware Gang Gives It a Go!

August 26, 2022October 13, 2025 Securonix

BianLian emerged as a relatively new ransomware actor deploying Go-based malware and using LOL (Living off the Land) techniques to move laterally while evading EDR during encryption. They exploited initial access vectors like ProxyShell and SonicWall VPNs, rap…

Read More
Threat Research

Raspberry Robin and Dridex: Two Birds of a Feather

August 26, 2022October 13, 2025 Securonix

IBM X-Force/MDR analysis connects Raspberry Robin infections with the Dridex malware and the Russia-based Evil Corp, revealing shared loader structures, anti-analysis techniques, and a workflow that leverages USB-based initial access. The report traces the inf…

Read More
Threat Research

Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems

August 23, 2022October 16, 2025 Securonix

Securonix Threat Labs uncovered a Golang-based GO#WEBBFUSCATOR campaign that leverages a James Webb image and obfuscated Go payloads to infect targets. The attack chain starts with a phishing Office attachment, downloads a malicious template, and uses DNS-base…

Read More
Threat Research

BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar

August 22, 2022October 14, 2025 Securonix

BlueSky ransomware is an emerging threat observed since mid-2022 that spreads through trojanized downloads and phishing emails, with rapid encryption and outbound lateral movement in Windows environments. It uses multi-stage PowerShell droppers, SMB-based prop…

Read More
Threat Research

Kimsuky’s GoldDragon cluster and its C2 operations

August 18, 2022October 18, 2025 Securonix

Kimsuky’s GoldDragon cluster is a multi-stage operation targeting Korea-related entities, evolving rapidly with new infection chains and a layered C2 network. The campaign starts with spear-phishing and uses HTML Application (HTA), VBScript, and mshta to fetch…

Read More
Threat Research

VileRAT: DeathStalker’s continuous strike at foreign and cryptocurrency exchanges

August 2, 2022October 15, 2025 Securonix

DeathStalker’s VileRAT campaign targets foreign exchange and cryptocurrency venues with a multi-stage infection chain, involving spearphishing, DOTM remote templates, VBA macro stomping, VileDropper and VileLoader loaders, and a Python-based VileRAT. The repor…

Read More
Threat Research

APT-C-35: New Windows Framework Revealed

August 2, 2022October 16, 2025 Securonix

Morphisec Labs details DoNot Team (APT-C-35) updates to their Windows framework (YTY/Jaca), including new modules, a shellcode loader, and an upgraded browser stealer, with a focus on modular delivery and evasion techniques. The post also highlights infection …

Read More

Posts pagination

Previous 1 … 148 149 150 … 152 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.