CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks

From Sept–Dec 2024 JPCERT/CC observed incidents using CrossC2 (a C/C++-based Cross-platform Cobalt Strike Beacon/builder) together with tools like PsExec, Plink, SystemBC, and a custom Nim loader dubbed ReadNimeLoader to deploy Cobalt Strike Beacons across multiple countries. The campaign shows overlaps with BlackBasta-related infrastructure and techniques, and JPCERT/CC published a CrossC2 config parser to aid analysis. #CrossC2 #ReadNimeLoader

Read More
Odyssey MacOS Stealer

Researchers observed a ClickFix phishing campaign targeting macOS that delivers an AppleScript-based stealer (Odyssey Stealer) via a fake CAPTCHA and terminal “base64 -d | bash” command, harvesting browsers, crypto wallets, Keychain items, and files before exfiltrating to a remote server. IOCs and protections show the infrastructure centered on 45.146.130[.]131 and the phishing domain tradingviewen[.]com. #OdysseyStealer #tradingviewen #45.146.130.131

Read More
REVENANT : EXECUTIONLESS, SELF-ASSEMBLING THREAT HIDDEN IN SYSTEM ENTROPY

REVENANT describes a five-stage, fileless attack methodology that persists across endpoints, application UI resources, clipboard history, AI model context, and telemetry channels to evade traditional detection. The research demonstrates how font downloads, clipboard sequences, localization tampering, AI prompt poisoning, and crash-report exfiltration can be chained to achieve stealthy persistence and covert data transfer. #REVENANT #Tesseract

Read More
Adobe Patch Tuesday Fixes Over 60 Vulnerabilities Across 13 Products

Adobe has released a comprehensive security update fixing over 60 vulnerabilities across its software, including critical issues in Adobe Commerce, Substance 3D, Illustrator, Photoshop, and other products. While no active exploits are known, immediate patching is recommended to prevent risks like code execution, DoS, and privilege escalation. #AdobeCommerce #Substance3D #Illustrator #Photoshop…

Read More
AI-Generated NPM Malware Targeting Developers

ENHANCED STEALTH WALLETDRAINER is a malicious NPM package (@kodane/patch-manager) that installs hidden scripts, achieves persistence, connects to a public C2, and drains Solana wallets using a hard-coded RPC and destination address. Analysis suggests the package and documentation were AI-generated to appear legitimate while abusing NPM to spread; notable IOCs include the C2 domain and Solana address. #ENHANCEDSTEALTHWALLETDRAINER

Read More
Unmasking the Viral Evolution of the ClickFix Browser-Based Threat

In early 2024, attackers evolved from ClearFake’s fake browser update malware delivery to the more effective ClickFix fake captcha technique, leading to widespread credential theft. This evolution demonstrates sophisticated propagation, social engineering narratives, and technical evasion strategies, including abuse of trusted platforms like Google Scripts and cross-platform payloads. #ClearFake #ClickFix #LummaStealer…

Read More
Unmasking SocGholish: Silent Push Untangles the Malware Web Behind the “Pioneer of Fake Updates” and Its Operator, TA569

SocGholish, operated by TA569, is a Malware-as-a-Service platform that sells access to compromised systems using deceptive fake browser update lures and Traffic Distribution Systems (TDSs) such as Parrot TDS and Keitaro TDS. Its infrastructure supports various financially motivated threat actors, including Russian groups like Evil Corp (DEV-0243) and UNC2165, and is…

Read More