Defending against malware persistence techniques with Wazuh

Malware persistence techniques allow attackers to maintain long-term access to compromised systems by utilizing various methods such as scheduled tasks, startup scripts, and account manipulation. Protecting systems requires a layered defense approach, and tools like Wazuh help detect and respond to these threats effectively. #MITREATTACK #PersistenceTechniques

Read More
APT36: Targets Indian BOSS Linux Systems with Weaponized AutoStart Files

CYFIRMA reports an APT36 campaign using weaponized .desktop shortcut files to deliver GO-written ELF payloads targeting BOSS Linux systems, enabling covert download, execution, persistence, and C2 communication with domains like securestore[.]cv and modgovindia[.]space. The operation leverages spear-phishing archives and tailored delivery to Indian government targets, resulting in data exfiltration and persistent access. #APT36 #securestore.cv #modgovindia.space

Read More
Investigation Report: APT36 Malware Campaign Using Desktop Entry Files and Google Drive Payload Delivery

APT36 used a malicious Linux .desktop file inside a ZIP attachment to download and execute a Go-based dropper from Google Drive, then open a decoy PDF in Firefox to mask the compromise. The dropper performs anti-analysis checks, establishes persistence, and attempts WebSocket C2 connections to ws://seemysitelive.store:8080/ws. #APT36 #seemysitelive.store

Read More
Think before you ClickFix: Analyzing the ClickFix social engineering technique

ClickFix is a social-engineering technique that tricks users into copying, pasting, and executing malicious commands (via Run, PowerShell, Terminal, etc.) to deliver in-memory loaders, infostealers, RATs, and rootkits across Windows and macOS. Microsoft observed widespread campaigns delivering payloads such as Lumma Stealer, Lampion, MintsLoader, Latrodectus, and AMOS and recommends user education, device hardening, and Defender XDR protections. #LummaStealer #Lampion

Read More
Falcon Platform Prevents COOKIE SPIDER’s SHAMOS Delivery on macOS

Between June and August 2025, COOKIE SPIDER’s SHAMOS (an AMOS variant) was distributed via malvertising and malicious one-line installation commands to target macOS users across many countries, with CrowdStrike Falcon blocking attempts to compromise over 300 customer environments. The campaign used Base64-obfuscated URLs and Bash scripts to bypass Gatekeeper, capture credentials…

Read More
Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware

Warlock ransomware exploited unpatched, internet-facing Microsoft SharePoint servers to upload web shells, achieve remote code execution, escalate privileges, and perform extensive credential theft and lateral movement before deploying ransomware that appends .x2anylock and exfiltrates data via RClone. Trend observed use of tools like Mimikatz, renamed Cloudflare tunneling binaries, and a KillAV…

Read More
Experts Find AI Browsers Can Be Tricked by PromptFix Exploit to Run Malicious Hidden Prompts

Cybersecurity researchers have unveiled PromptFix, a technique that fools AI models into executing malicious actions embedded in fake CAPTCHA checks or invisible prompts on web pages. This method enables AI-driven browsers and assistants to unknowingly perform scams, automating tasks like online shopping and phishing attacks, creating a new complex scam landscape…

Read More
Salty 2FA: Undetected PhaaS from Storm-1575 Hitting US and EU Industries 

Salty 2FA is a newly identified Phishing-as-a-Service framework that uses multi-stage obfuscated JavaScript, a distinct domain pattern combining .??.com compound domains with .ru infrastructure, and behavioral techniques to steal Microsoft 365 credentials and bypass multiple 2FA methods. Analysis mapped its execution chain, evasion methods, and wide-ranging targets, with notable examples including…

Read More
Dark Web Profile: Void Blizzard

Void Blizzard (aka Laundry Bear) is a Russian state-sponsored group active since at least 2024 that targets NATO/EU governments, defense contractors, and critical infrastructure using credential theft, phishing (including QR-based AitM), and “living off the land” cloud abuse. Dutch AIVD/MIVD and Microsoft exposed their methods after attacks such as the September 2024 Dutch police compromise and an April 2025 spear-phishing campaign using Evilginx and a typosquatted domain. #VoidBlizzard #Evilginx

Read More
Hunt.io Exposes and Analyzes ERMAC V3.0 Banking Trojan Full Source Code Leak

Hunt.io obtained the full ERMAC V3.0 source code in March 2024, revealing a Laravel/PHP backend, React frontend, Golang exfiltration server, and an obfuscated Android builder/backdoor that targets 700+ banking, shopping, and cryptocurrency apps. The leak exposed critical weaknesses (hardcoded JWT, static admin token, default credentials, open registration) and linked source artifacts to active C2, exfiltration, and builder infrastructure. #ERMAC #Ermac_v3

Read More
Inside Grammarly’s AI-driven automation with the MCP Server for Wiz

Grammarly adopted Wiz and the Wiz Model Context Protocol (MCP) Server to scale cloud visibility, automate incident triage, and integrate LLMs into security workflows, reducing investigation time from 30–45 minutes to under four minutes per ticket. The company expanded MCP use to threat hunting, detection engineering, and knowledge automation while following principles of starting small, iterating with real-world data, and keeping humans in the loop. #WizMCP #Grammarly

Read More
Securing LLM Superpowers: Navigating the Wild West of MCP

The Model Context Protocol (MCP) standardizes LLM access to external tools and data, enabling powerful integrations but introducing supply-chain and runtime security risks such as tool poisoning, session hijacking, cross‑server manipulation, ANSI escape injection, and typosquatting. The post outlines MCP architecture, common transports and flows, real-world use cases, and recommended priorities for stronger authentication, governance, and monitoring. #ModelContextProtocol #ANSIescape

Read More
SANS Cyber Threat Hunting Survey 2025

The 2025 SANS Threat Hunting Survey reveals a growing trend toward in-house threat hunting capabilities, with organizations prioritizing agility and integration despite challenges like cloud visibility and skilled staffing shortages. Key findings include the prevalence of business email compromise, rising nation-state threats, and the increasing use of living off the land techniques among threat actors. #SANS2025 #ThreatHunting #BusinessEmailCompromise #LivingOffTheLand

Read More