Zero Trust has become a crucial element of modern cybersecurity architecture, with AI playing a vital role in enabling adaptive access and threat detection. By 2026, over 80% of organizations plan to adopt Zero Trust strategies, leveraging AI for automation, risk evaluation, and policy enforcement. #ZeroTrust #AIinCybersecurity…
Tag: THREAT HUNTING
Auto-color is a stealthy Linux backdoor targeting government institutions and universities, designed for persistence and evasion by masquerading as a color-enhancement utility. Detection methods using the open source Wazuh platform, including Security Configuration Assessment and SysmonForLinux integration, are demonstrated to identify and alert on Auto-color malware activities. #Auto-color #Wazuh #SysmonForLinux…
Malware notifications reported by MS-ISAC decreased 18% from Q1 to Q2 2025, with SocGholish remaining the most prevalent malware, accounting for 31% of detections. New and returning malware such as VenomRAT, ClearFake, Mirai, and NanoCore contributed to ongoing threats using various infection vectors like malvertisement and malspam. #SocGholish #VenomRAT #MSISAC…
A recent phishing campaign exploited Booking.com’s official messaging system to send fraudulent messages and steal credit card details using cleverly disguised domains and multi-stage redirects. The investigation uncovered extensive infrastructure, including redirector and phishing content domains, alongside associated malware files and threat actor Telegram accounts. #BookingPhishing #BookingConfirmationID #TelegramOperators
The Octalyn Forensic Toolkit is a C++ and Delphi-based credential stealer disguised as a forensic research tool, capable of extracting browser data, cryptocurrency wallets, and social media tokens, with data exfiltration conducted via Telegram. Its modular design, persistence mechanisms, and obfuscated payloads make it a significant threat when misused by malicious actors. #OctalynForensicToolkit #TelegramBuild.exe #CredentialStealer
The DoNot APT group, active since 2016 and linked to India, has targeted governmental and diplomatic entities using sophisticated multi-stage malware campaigns involving spear-phishing and custom malware such as LoptikMod. A recent campaign against a European foreign affairs ministry utilized malicious Google Drive links and scheduled tasks to maintain persistence and exfiltrate sensitive data. #DoNotAPT #LoptikMod #TrellixAdvancedResearchCenter
Validin provides extensive HTTP/S response data that enables threat analysts to discover related malicious domains and infrastructure by pivoting on features like favicon hashes, HTTP redirects, and HTML content. The platform helps identify phishing campaigns, malicious browser extension C2 domains, and fake app download sites through detailed feature correlation and exploration. #Validin #ClickFix #MaliciousExtensions #PhishingDomains
DomainTools Investigations analyzed one month of nameserver activity from the Russian bulletproof hosting service DDoS-Guard, revealing extensive malicious campaigns targeting gambling, cryptocurrency users, and digital asset platforms. Their research highlights the use of sophisticated domain obfuscation, fast flux techniques, and frequent transfers between registrars to evade detection. #DDoSGuard #CounterStrikeGO #YieldNest
This report analyzes a malware campaign hosted on GitHub that disguises the Lumma Stealer payload as legitimate tools like “Free VPN for PC” and “Minecraft Skin Changer.” The malware uses advanced obfuscation, process injection, and DLL side-loading techniques to evade detection while communicating with multiple C2 domains. #LummaStealer #GitHubMalware #LaunchExe
Researchers at ReversingLabs uncovered a sophisticated supply chain attack compromising the ETHcode VS Code extension through a malicious GitHub pull request that introduced a deceptive dependency. This attack demonstrates the risks posed by software supply chain vulnerabilities in trusted developer tools and emphasizes the need for thorough review of new contributors and dependencies. #ETHcode #keythereum-utils #7finney
Unit 42 researchers identified a campaign by the group TGR-CRI-0045 exploiting leaked ASP.NET Machine Keys to perform View State deserialization attacks on IIS servers, enabling in-memory execution of malicious payloads with minimal forensic traces. The group, attributed with medium confidence to Gold Melody, targeted organizations across various industries in the US…
NSFOCUS Fuying Lab has uncovered a new cross-platform botnet called “hpingbot” that targets Windows and Linux/IoT systems, demonstrating innovative tactics for stealth and efficiency. This evolving threat is characterized by its frequent updates, use of Pastebin, and reliance on hping3 for DDoS attacks, indicating a sophisticated and long-term operational approach. #hpingbot…
A new cross-platform botnet family named hpingbot, developed in Go language, is rapidly spreading and evolving with capabilities to launch DDoS attacks using the hping3 tool and distribute arbitrary payloads via Pastebin. The botnet shows strong innovation with independent propagation modules, multiple persistence mechanisms, and frequent updates, posing a significant threat as a potential long-term malware operation with risks of distributing advanced threats like ransomware or APT components. #hpingbot #hping3 #Pastebin
Since July 2024, the Batavia spyware campaign has targeted Russian industrial enterprises through malicious email attachments disguised as contracts, leading to a multi-stage infection process and data exfiltration. The malware comprises a VBS downloader script and two executable files that steal internal documents and system information. #Batavia #WebView.exe #javav.exe
Adaptive AI in SOC platforms offers dynamic, real-time threat analysis and triage, surpassing static pre-trained models that are limited to predefined use cases. This approach enhances threat detection, improves response times, and reduces workload for security teams. #Radiant #AdaptiveAI…