Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled Malware

SentinelLABS research identified multiple examples of malware that embed prompts and API keys to leverage LLMs at runtime, including a likely early LLM-enabled sample dubbed MalTerminal and LameHug (PROMPTSTEAL) linked to APT28. The team found prompt structures, embedded HuggingFace and OpenAI keys, and reuse of standard API libraries that enabled reliable hunting by API-key and prompt detection. #MalTerminal #LameHug

Read More
Akira Ransomware Exploits SonicWall VPN

The threat actor gained access via a compromised SonicWall VPN, discovered plaintext Huntress recovery codes on a user desktop, used them to log into the Huntress portal, remediate incident reports, and uninstall agents while Akira ransomware was executed on a workstation. Proper handling of recovery codes and credentials is critical to prevent MFA bypass and suppression of detection; this incident involved Akira, a malicious IP 104.238.221[.]69, and the Huntress platform. #Akira #104.238.221[.]69

Read More
Tracking AsyncRAT via Trojanized ScreenConnect and Open Directories

Attackers abused ConnectWise ScreenConnect installers and open directories to stage and deliver AsyncRAT and a custom PowerShell RAT using dual execution paths, repacked installers, and aggressive scheduled tasks for persistence. Infrastructure included multiple open-directory hosts, /Bin/ ClickOnce redirect chains, and high-ephemeral port C2s enabling resilient, evasive AsyncRAT operations. #AsyncRAT #ScreenConnect

Read More
What We Know About the NPM Supply Chain Attack

Trend Research describes a targeted NPM supply chain attack where threat actors phished maintainer accounts to inject malicious code into widely used JavaScript packages, leading to credential theft, secret exfiltration, and cryptocurrency diversion. The report details a self-replicating worm called Shai-hulud and related Cryptohijacker payloads, provides attack chain analysis and mitigation…

Read More
Silent Push Raises  Million for Threat Intelligence Platform

Silent Push, a threat intelligence company based in Virginia, has raised $10 million in Series B funding to expand its global reach and enhance its platform. The company’s platform offers proactive threat detection by identifying malicious infrastructure and providing indicators of future compromise to help organizations defend against cyber threats. #SilentPush…

Read More
Introducing Dashboard Feeds and Daily PTR Scanning | Validin

Validin introduced Dashboard Feeds (Threat Indicator Feed and Project Updates Feed) to surface newly reported IOCs and team activity directly on the homepage, improving analyst workflows and situational awareness. They also added daily PTR (reverse DNS) scanning across IPv4 to capture short-lived reverse DNS entries, illustrated by detection of rotating PTR records for 91.247.36[.]102, including free.friendhosting[.]net. #91.247.36.102 #free.friendhosting.net

Read More
ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT

Sysdig TRT discovered a new Go-based remote access trojan named ZynorRAT that uses a Telegram bot as its command-and-control channel to perform file exfiltration, system enumeration, screenshots, persistence via systemd, process control, and arbitrary shell execution on Linux (with an incomplete Windows build). Analysis of binaries, Telegram chats, VirusTotal submissions, and network telemetry suggests the developer is Turkish, actively refining the RAT, and likely preparing it for sale on underground markets. #ZynorRAT #lraterrorsbot

Read More
Eggstreme Fileless Malware Cyberattack in APAC

A Chinese APT compromised a Philippine military company using a new fileless malware framework called EggStreme that injects payloads into memory and abuses DLL sideloading for persistent espionage. The core EggStremeAgent backdoor (with an injected EggStremeKeylogger) supports 58 commands for reconnaissance, lateral movement, and data exfiltration. #EggStreme #EggStremeAgent…

Read More
EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks

EvilAI is an active global campaign that disguises Node.js-based trojans as legitimate AI or productivity applications—using professional UIs and code-signing—to steal browser credentials, maintain AES-encrypted C2 communications, and persist via scheduled tasks, registry Run keys, and Start Menu shortcuts. Telemetry shows rapid, widespread infections across Europe, the Americas, and AMEA, heavily…

Read More