CloudMensis is a macOS backdoor that spies on victims by exfiltrating documents, keystrokes, and screen captures, and communicates with its operators exclusively via public cloud storage services. It uses a two-stage architecture where the first stage download…
Tag: SPYWARE
Pegasus spyware was used against Thailand’s pro-democracy movement, with at least 30 civil society victims infected between October 2020 and November 2021, triggering Apple security notifications in November 2021 and a collaborative forensic investigation. The…
Researchers document Black Basta’s observed TTPs during a recent incident response, detailing lateral movement, defense evasion, discovery, and encryption activities against Hyper-V environments and Veeam backups. The post also provides a technical breakdown o…
The campaign distributes malicious documents that abuse an XML-driven download chain and legitimate payload hosting to deliver staged malware. It culminates with data-stealing payloads (Arkei Stealer and Eternity Stealer), using macro-based loaders and C2/down…
ModifiedElephant is a decade-long threat actor targeting India-based human rights activists, defenders, academics, and lawyers to plant incriminating digital evidence for arrests. The group relies on spearphishing with publicly available remote access trojans …
Earth Karkaddan (APT36) is analyzed through its use of CrimsonRAT on Windows and CapraRAT/ObliqueRAT on Android, detailing infection chains based on spear-phishing, USB worms, and malicious macros. The piece also covers C2 communications, persistence mechanism…
Donot Team (also known as APT-C-35 and SectorE02) is a long-running South Asia-focused threat actor linked to Windows and Android malware, with Amnesty International alleging links to an Indian cybersecurity company that may sell spyware or hackers-for-hire se…
Anomalous, short-lived spyware campaigns targeted ICS environments, spreading via compromised corporate mailboxes and SMTP-based C2 to harvest credentials. The report reveals thousands of abused corporate email accounts, extensive credential marketplaces, and …
In September, Russian companies faced the problem of malicious software disguised as accounting documents. The launch of the virus led to leaks of personal data of users and the connection their computers to the botnet. Check Point company claims that 15.3% of Russian Internet users received such le…
Specialists of the Russian company Dr Web found malicious software that threatens the MacOS operating system, which allows attackers to download and execute any Python code on the user’s device. In addition, sites distributing this malware also infected Windows users with a dangerous spyware Trojan….