Detecting Koske malware with Wazuh

Koske is an AI-generated cryptocurrency-mining malware targeting Linux endpoints that was first identified by Aqua Nautilus in July 2025 and delivered via improperly configured JupyterLab instances using polyglot JPEGs with appended shellcode. It deploys rootkits, establishes persistence via .bashrc and systemd changes, downloads and runs multiple miners (.koske files) against mining…

Read More
Introducing YARA Rules: Search and Monitor the Internet’s Infrastructure with YARA

Validin added YARA retro hunting across its large archive of virtual host responses, allowing enterprise users to write, run, and view matches from custom YARA rules to discover and track indicators in historical web artifacts. A demonstrated use case found over 5,000 exposed OpenAI API keys in one week by searching for the OpenAI key substring. #Validin #OpenAI_api_keys

Read More
Ongoing APT35 Phishing Campaign Uncovered: Iranian Group Impersonates Video Conferencing Services

Stormshield’s CTI team uncovered new phishing infrastructure linked to APT35, an Iran-based threat group, targeting high-value targets with video conferencing-themed campaigns. Their research details new IPs, domain patterns, and tactics used by APT35, emphasizing ongoing regional espionage activities. #APT35 #CharmingKitten…

Read More
Dark Web Profile: BQTLock Ransomware – SOCRadar® Cyber Intelligence Inc.

BQTLock is a rapidly evolving Ransomware-as-a-Service (RaaS) operation emerging from the Middle East that combines aggressive extortion, wave-based decryption pricing, and political propaganda to attract affiliates and victims worldwide. The group is led by Karim Fayad (aka ZeroDayX) with ties to pro-Palestinian hacktivist groups like Liwaa Mohammed and uses techniques such as AES-256/RSA-4096 encryption, process hollowing, UAC bypass, and C2 communication over Telegram/Discord. #BQTLock #ZeroDayX

Read More
Eye of the Storm: Analyzing DarkCloud’s Latest Capabilities

eSentire’s TRU discovered a spear-phishing campaign that attempted to deliver the DarkCloud info-stealer to a manufacturing customer via a banking-themed email with a malicious ZIP containing Swift Message MT103 FT2521935SVT.exe (DarkCloud v3.2). The report details DarkCloud’s capabilities (browser/password/crypto-wallet theft, keystroke/clipboard harvesting, various exfiltration methods), distribution channels, VB6-based builder and string-encryption, sandbox/VM evasion checks, persistence, IOCs and mitigations. #DarkCloud #eSentire

Read More
New LockBit 5.0 Targets Windows, Linux, ESXi

Trend Research analyzed LockBit 5.0 source binaries and confirmed Windows, Linux, and ESXi variants that use heavy obfuscation, in-memory DLL reflection loading, anti-analysis/anti-forensics (ETW patching, service termination, event log clearing), randomized 16-character file extensions, and Russian-language/geolocation avoidance. The ESXi variant targets VMware virtualization to encrypt multiple VMs at once while Linux…

Read More
Botnet Loader-as-a-Service Infrastructure Distributing RondoDoX and Mirai Payloads

CloudSEK uncovered exposed command-and-control logs revealing a Loader-as-a-Service campaign that exploited command-injection flaws in SOHO router and IoT web interfaces and targeted enterprise apps (WebLogic, WordPress, vBulletin), deploying multi-architecture malware such as Morte and Mirai and cryptomining payloads. The operation used unsanitized POST fields, default credentials, and rotating drop hosts (e.g., 74.194.191.52, 83.252.42.112, 196.251.73.*) and showed a >230% attack spike in July–August 2025. #Morte #RondoDoX

Read More
Inside Vietnamese Threat Actor Lone None’s Copyright Takedown-Spoofing Campaign

Cofense Intelligence tracked Lone None campaigns delivering Pure Logs Stealer and a new Lone None Stealer that use copyright-takedown email lures, Telegram bot profile pages for payload delivery, and obfuscated Python-based payloads to steal cryptocurrency via clipboard replacement. The campaign abuses legitimate programs (Haihaisoft PDF Reader, certutil.exe, WinRAR), installs a staged Python interpreter in C:UsersPublicWindows (svchost.exe), and reports clipboard replacements to a Telegram bot C2. #LoneNoneStealer #PureLogsStealer #TelegramBot

Read More
Fighting Telecom Cyberattacks: Investigating a Campaign Against UK Companies

Telecom-targeted phishing campaigns surged in May–July 2025, with attackers abusing brand impersonation, DGA-like domains, and the Tycoon2FA phishing kit to harvest Microsoft credentials and bypass 2FA. ANY.RUN’s Interactive Sandbox, YARA searches, and Threat Intelligence Lookup enabled detection of malicious PDFs, phishing redirects (xjrsel.ywnhwmard[.]es), and recurring sender patterns to produce actionable IOCs…

Read More
Unit 221B Raises  Million for Threat Intel Aiding Hacker Arrests 

Unit 221B, a threat intelligence firm, has secured $5 million in seed funding to enhance its proprietary platform, eWitness, which tracks cybercriminals and supports law enforcement investigations. The company’s efforts have led to the arrest of cybercriminals, including Ethan Foltz, demonstrating its impact on disrupting cyber threats. #EWitness #CybercriminalArrests…

Read More
From MUSE to Manual: Cyberattack Analysis on European Airport Operations

On 19–20 September 2025, multiple major European airports (Heathrow, Brussels, Berlin) experienced severe disruptions to check-in, boarding, and baggage systems after an attack on Collins Aerospace’s MUSE platform, forcing manual operations, delays, and cancellations. CYFIRMA assesses Alixsec, Scattered Spider, and Rhysida as plausible actors based on prior targeting and operational history. #CollinsAerospace #MUSE #Alixsec #Rhysida

Read More
What Is Managed EDR? | Huntress

Huntress emphasizes that human-led, telemetry-driven investigations within managed EDR are essential to distinguish malicious activity from legitimate processes and to determine root cause, scope, and remediation. The post highlights real-world cases involving RMM abuse, Akira ransomware, and activity linked to the RedCurl APT, showing why proactive threat hunting and forensic artifacts like browser history matter. #ScreenConnect #Akira #RedCurl

Read More
Threat Research | Weekly Recap [21 Sep 2025]

Cybersecurity Threat Research ‘Weekly’ Recap. The report highlights a week of widespread vulnerability disclosures, supply-chain attacks, and ransomware trends, including a self-replicating npm worm (Shai-Hulud) and numerous loader, adware, and credential-stealing campaigns that span multiple platforms from Windows to macOS and mobile. It also covers APT/state-aligned operations, targeted phishing, and defensive tooling to enhance detection and response.
#Shai-Hulud #SystemBC #ChillyHell #Oyster #Kawa4096 #BlackLock #Qilin #Kimsuky #TA415 #TA415 WhirlCoil

Read More