Threat Hunting Power Up | Enhance Campaign Discovery With Validin and Synapse

SentinelLABS released the open-source sentinelone-validin Synapse power-up to combine Validin DNS, HTTP crawler, TLS certificate, and WHOIS data for time-aware, cross-source infrastructure analysis. Case studies on LaundryBear (Void Blizzard) and FreeDrain show how HTTP body/favicons/certificate pivots and WHOIS enrichment expand small indicator sets into broad campaign infrastructure. #LaundryBear #FreeDrain

Read More
New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

Cybersecurity researchers have uncovered malware campaigns using ClickFix social engineering tactics to deploy Amatera Stealer and NetSupport RAT, tracked under the name EVALUSION. These campaigns involve sophisticated evasion techniques and targeted phishing methods to steal sensitive data and remote control systems. #Amatera #ClickFix #EVALUSION #NetSupport…

Read More
Curly COMrades Campaign

This investigation uncovered Curly COMrades’ novel use of Hyper-V on compromised Windows 10 hosts to run a hidden Alpine Linux VM that housed custom implants CurlyShell and CurlCat, enabling covert, persistent remote access and proxying. Collaborative forensic work with the Georgian CERT revealed deployment commands, PowerShell ticket-injection and persistence scripts, and C2 infrastructure details including SSH-over-HTTP tunneling via a compromised site. #CurlyShell #CurlCat

Read More
Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT

Two interconnected 2025 campaigns used large-scale brand impersonation to deliver Gh0st RAT variants to Chinese-speaking users, evolving from simple droppers to multi-stage chains that misuse signed software and cloud-hosted payloads for evasion. The campaigns registered thousands of disposable domains, hosted payloads on specific IPs and cloud buckets, and employed DLL side-loading…

Read More
Civil society decries digital rights ‘rollback’ as European Commission pushes data protection changes

A coalition of civil society groups and trade unions is protesting the European Commission’s proposed changes to key digital laws, including GDPR and the EU AI Act, which threaten data privacy and protection standards. The proposed amendments aim to streamline regulations but are criticized for weakening protections, increasing data processing, and…

Read More
CISA and Partners Release Advisory Update on Akira Ransomware | CISA

The Cybersecurity and Infrastructure Security Agency (CISA) and partners released an updated advisory on Akira ransomware, highlighting new tactics, techniques, and indicators of compromise. The threat actors continue to target various sectors, exploiting vulnerabilities in edge devices, backup servers, and using advanced evasion and lateral movement strategies. #AkiraRansomware #Storm1567 #VulnerabilityExploitation…

Read More
RONINGLOADER: DragonBreath’s New Path to PPL Abuse

Elastic Security Labs uncovered a Chinese-language targeted campaign by Dragon Breath APT (APT-Q-27) distributing a modified gh0st RAT via trojanized NSIS installers and a unique loader dubbed RONINGLOADER. The multi-stage chain uses a signed kernel driver, WDAC policy tampering, PPL abuse of ClipUp to disable Microsoft Defender, and thread-pool based remote injection to terminate and bypass popular Chinese endpoint products. #DragonBreath #RONINGLOADER

Read More
A Rise in AI-Driven Malware

Researchers observed AI-integrated malware families that query large language models at runtime to generate code, obfuscate payloads, and adapt behavior, with notable families including PROMPTFLUX, PROMPTSTEAL, PROMPTLOCK, FRUITSHELL, and QUIETVAULT. These tools were used for persistence, reconnaissance, data exfiltration, and cross-platform encryption, with APT28 (LAMEHUG) deploying PROMPTSTEAL against Ukrainian targets. #PROMPTFLUX #PROMPTSTEAL

Read More
EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT

eSentire’s TRU discovered campaigns using ClickFix for initial access to deploy Amatera Stealer (a rebranded ACR/AcridRain) and NetSupport RAT, with Amatera leveraging advanced evasion (WoW64 syscalls, AMSI bypass) and extensive crypto-wallet/password manager theft capabilities. eSentire published decryption helpers and detection guidance, and recommends mitigations including disabling mshta.exe, removing the Run prompt, PSAT, and partnering with 24/7 MDR services. #Amatera #NetSupport

Read More