Google exposes BadAudio malware used in APT24 espionage campaigns

China-linked APT24 hackers have been using the sophisticated and previously undocumented BadAudio malware in a three-year espionage campaign targeting Windows systems. Their methods evolved over time, including spearphishing, supply-chain compromises, and website injections to evade detection and conduct targeted espionage activities. #APT24 #BadAudio #CobaltStrike

Read More
Threat Intelligence Automation

Automated threat intelligence enables machine-speed detection, enrichment, and response to indicators of compromise, reducing mean time to detect and respond while freeing analysts from repetitive tasks. Recorded Future’s Intelligence Cloud delivers this capability through continuous data collection, ML-driven risk scoring, and integrations with SIEM, SOAR, and EDR to enable real-time defensive actions. #RecordedFuture #InsiktGroup

Read More
The Future of Malware is LLM-powered

Netskope Threat Labs validated that GPT-3.5-Turbo and GPT-4 can be coerced into generating malicious Python code, demonstrating the architectural feasibility of LLM-powered malware while also showing generated code often fails operational reliability tests. Preliminary GPT-5 tests show improved code effectiveness but stronger guardrails, highlighting a trade-off between capability and safety. #GPT3_5_Turbo #GPT4 #GPT5

Read More
Cooking up trouble: How TamperedChef uses signed apps to deliver stealthy payloads

Acronis TRU tracked a global malvertising and SEO-driven campaign named “TamperedChef” that distributes digitally signed fake installers which persist via scheduled tasks and execute heavily obfuscated JavaScript backdoors with remote code execution and HTTPS-based C2. The operators use U.S.-registered shell companies to acquire and rotate code-signing certificates, short-lived domain registrations, and malvertising/SEO to hide infrastructure and quickly recover after takedowns. #TamperedChef #Obfuscator_io

Read More
ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves

Recent cybersecurity incidents reveal a rise in international espionage, targeted hacking campaigns, and vulnerabilities in widely used systems and devices. These stories highlight the ongoing efforts of governments, cybercriminals, and security researchers to adapt and respond to new online threats. #LinkedInEspionage #OracleVulnerability…

Read More
Masked in Memory: A Hidden .PYC fragment utilises cvtres.exe to communicate with C&C

K7 Labs analyzed a Python-based multi-stage obfuscated malware that unpacks a large filler blob to reveal a small marshalled .pyc which performs process injection into cvtres.exe and loads a downloaded .NET component for persistent C2. The infection uses disguised archives and bundled Python runtime (ntoskrnl.exe) to reconstruct and execute payloads from cloud-hosted files and maintain an encrypted RAT-like channel. #cvtres.exe #ntoskrnl.exe

Read More
European Commission ‘simplification’ proposal would weaken GDPR, AI regulations

The European Commission proposes to loosen data protection and AI regulations in the EU under the Digital Omnibus, aiming to boost innovation and reduce red tape. Critics argue that these changes will reduce privacy protections and favor big tech at the expense of smaller companies and consumers. #GDPR #AIAct #EuropeanUnion #DataPrivacyProtection…

Read More
AI-Enhanced Tuoni Framework Targets Major US Real Estate Firm

The article details a sophisticated cyberattack on a US real estate company using the Tuoni C2 framework, employing techniques such as social engineering, steganography, and in-memory execution. It highlights the growing use of AI-assisted loaders and modular frameworks by threat actors to evade detection and complicate defense efforts. #TuoniC2 #Steganography…

Read More
Dark Web Profile: Sarcoma Ransomware

Sarcoma is a fast-emerging ransomware group (late 2024) that combines data theft with encryption and aggressive double-extortion tactics, targeting mid-market and larger organizations—especially in manufacturing, technology and construction—primarily in the United States, Italy and Canada. The group operates a controlled RaaS-style model, targets Windows, Linux and ESXi environments, and uses techniques including credential theft, zero-day exploits, anti-recovery steps and public leak pressure. #Sarcoma #ChaCha20

Read More
Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem

UNC1549 targeted aerospace, aviation, and defense sectors using spear-phishing and compromised third‑party relationships to gain access, then deployed custom backdoors (TWOSTROKE, DEEPROOT, LIGHTRAIL, GHOSTLINE, POLLBLEND, MINIBIKE) and tunneling tools to maintain stealthy persistence and C2 using Azure and SSH reverse tunnels. The group used credential theft (DCSYNCER.SLICK, CRASHPAD, TRUSTTRAP), DLL search order hijacking, and long-lived stealth techniques to exfiltrate sensitive data and pivot through suppliers. #UNC1549 #TWOSTROKE

Read More
Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense

Researchers from Israel’s INDA have uncovered SpearSpecter, a sophisticated cyber-espionage campaign allegedly linked to Iranian threat actors working for IRGC-IO, targeting high-level government and defense officials. The operation employs social engineering, fileless malware, and cloud-based command-and-control channels to infiltrate its targets. #IRGCIO #SpearSpecter…

Read More