Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: SSO

Threat Research

Adversary Quest 2022: 4 CATAPULT SPIDER eCrime Challenges | CrowdStrike

July 28, 2022October 16, 2025 Securonix

Researchers analyze CrowdStrike’s Adversary Quest 2022 CATAPULT SPIDER track, which centers on a Dogecoin-driven ransomware campaign leveraging CHM phishing, encoded PowerShell, and a Dogecoin-based C2. The storyline uncovers multi-stage payloads, a vulnerable…

Read More
Threat Research

GwisinLocker ransomware targets South Korean industrial and pharma firms

July 28, 2022October 16, 2025 Securonix

GwisinLocker.Linux is a Linux-based ransomware variant linked to the Gwisin threat actor, targeting South Korean industrial and pharmaceutical firms. It encrypts files using per-file AES keys (with RSA-wrapped keys), stores keys in .mcrgnx0 files, appends .mcr…

Read More
Threat Research

Cyble – LOLI Stealer – Golang-based InfoStealer Spotted In The Wild

July 26, 2022October 19, 2025 Securonix

LOLI Stealer is a Golang-based infostealer sold via a MaaS model, capable of stealing passwords, cookies, wallet data, and screenshots from infected machines. Cyble Research Labs tracked LOLI Stealer and its evolving capabilities, including data exfiltration t…

Read More
Threat Research

Emotet Downloader Document Uses Regsvr32 for Execution

July 25, 2022October 18, 2025 Securonix

This analysis details how Emotet intrusion employs obfuscated Excel macros to download and run an Emotet loader, which is then executed via regsvr32 for payload deployment. It highlights how the loader stores an encrypted payload in its resources, uses a Windo…

Read More
Threat Research

A Detailed Analysis of the RedLine Stealer

July 25, 2022October 17, 2025 Securonix

RedLine Stealer is a data-collection malware distributed as cracked software that harvests browser data, cryptocurrency wallet credentials, and other applications, then exfiltrates the results via SOAP to a hard-coded C2 server. The report details its deployme…

Read More
Threat Research

SharpTongue Deploys Clever Mail-Stealing Browser Extension “SHARPEXT”

July 21, 2022October 18, 2025 Securonix

SHARPEXT is a clever post-exploitation browser extension used by SharpTongue (often associated with Kimsuky) to inspect and exfiltrate data from a victim’s webmail (Gmail and AOL) as users browse. The attackers deploy SHARPEXT by modifying browser preferences …

Read More
Threat Research

Gootkit Loader’s Updated Tactics and Fileless Delivery of Cobalt Strike

July 21, 2022October 15, 2025 Securonix

Gootkit loader now employs more advanced fileless techniques to drop Cobalt Strike, using SEO-poisoned compromised websites and legal document templates to lure victims. The attack chain involves registry stuffing, memory-only execution via PowerShell, and a C…

Read More
Threat Research

Threat Actors Leveraging Microsoft Applications via DLL SideLoading – Detection & Response – Security Investigation

July 20, 2022October 16, 2025 Securonix

Threat actors abuse DLL sideloading to run malicious code through legitimate Microsoft applications (Teams and OneDrive), dropping and loading a malicious DLL that communicates with a remote C2 and leverages Cobalt Strike Beacon for post‑exploitation. The camp…

Read More
Threat Research

eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID

July 20, 2022October 16, 2025 Securonix

Gootloader is a Malware-as-a-Service (MaaS) offering that is spread through SEO poisoning to distribute malicious payloads, such as IcedID. Threat actors have begun using IcedID, a former banking trojan, since it’s a stealthier option compared to Cobalt Strike…

Read More
Threat Research

Google ads lead to major malvertising campaign

July 7, 2022October 20, 2025 Securonix

Fraudsters abused Google’s ad network to redirect users searching for popular brands to a network of tech-support scam pages, effectively hijacking browser sessions through malvertising. The operation used cloaking, multi-stage redirects, and iframe-based brow…

Read More
Threat Research

YamaBot Malware Used by Lazarus – JPCERT/CC Eyes

July 7, 2022October 16, 2025 admin

YamaBot, linked to Lazarus, targets both Linux and Windows with HTTP-based C2 communication and RC4-based encoding for configuration and commands. The report details Linux and Windows variants, their C2 interactions, commands, and the infrastructure and hashes…

Read More
Threat Research

Lightning Framework: New “Swiss Army Knife” Linux Malware

July 6, 2022October 14, 2025 Securonix

Lightning Framework is a modular, undetected Linux malware framework with a downloader, core, and multiple plugins, including rootkit-capable components, that can communicate with a threat actor via a malleable C2 configuration. It leverages typosquatting, per…

Read More
Threat Research

New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails

July 5, 2022October 17, 2025 Securonix

Fortinet’s FortiGuard Labs documented a phishing campaign delivering a new QakBot variant via an attached HTML file that auto-executes to drop a ZIP, load a loader, and ultimately run QakBot within a Windows process. The analysis details the infection chain fr…

Read More
Threat Research

From the Front Lines | 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts

June 30, 2022October 14, 2025 Securonix

Over the last month a crimeware group best known as 8220 Gang has expanded their botnet to roughly 30,000 hosts globally through Linux vulnerabilities and poorly secured configurations. The infection script, IRC botnet, and updated PwnRig cryptocurrency miner …

Read More
Threat Research

Climbing Mount Everest: Black-Byte Bytes Back?

June 24, 2022October 13, 2025 Securonix

NCC Group analyzes Everest ransomware operations and argues a link to Black-Byte, detailing how Everest-related activity deployed during an incident response used TTPs such as RDP-based lateral movement, credential dumping, and C2 via remote tools. The report …

Read More

Posts pagination

Previous 1 … 516 517 518 … 523 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.