From Forgotten Tool to Powerful Pivot: Using JA3 to Expose Attackers’ Infrastructure 

JA3 TLS fingerprints are still useful as durable, tool-level behavioral indicators that can reveal new malicious tooling and enable clustering of related activity when enriched with context. ANY.RUN shows how JA3 frequency analysis and TI Lookup link specific JA3 hashes to malware and exfiltration channels, e.g., Remcos and Skuld. #Remcos #Skuld…

Read More
From Extension to Infection: An In-Depth Analysis of the Evelyn Stealer Campaign Targeting Software Developers

The blog analyzes a multistage campaign that weaponized Visual Studio Code extensions to deliver the Evelyn information stealer, using a DLL downloader, a process-hollowing injector, and a final payload that harvests developer credentials and cryptocurrency data. The malware uses AES-256-CBC encryption, multiple anti-analysis checks, and FTP-based C2/exfiltration to evade detection and…

Read More
Cybersecurity News | Daily Recap [20 Jan 2026]

Daily Recap, The daily cybersecurity recap emphasizes proactive defence for 2026 with CISOs prioritizing attack surface visibility and threat hunting, while noting the ETSI AI security standard and Olympics-linked cyber risk as more connected environments emerge. The summary also highlights high-profile items across malware and threats, including Black Basta leadership and an INTERPOL Red Notice, the LOTUSLITE backdoor tied to a Mustang Panda campaign targeting the U.S. government, and notable vulnerabilities and incidents such as StealC, TamperedChef ads, RondoDox using an HPE OneView flaw, Windows Cloud PC bugs, GhostPoster extensions, the CIRO data breach, a Supreme Court hack, Iran TV hijack, and OpenAI ads. #BlackBasta #MustangPanda

Read More
The Year Ransomware Went Fully Decentralized: Cyble’s 2025 Threat Analysis

Cyble’s 2025 Threat Landscape Report highlights the resilience and evolution of cybercriminal ecosystems, particularly in ransomware operations, despite increased law enforcement efforts. The report emphasizes the shift towards extortion-only tactics, AI-assisted automation, and supply chain exploitation, affecting diverse sectors worldwide. #RansomwareEvolution #SupplyChainAttacks…

Read More
Dark Web Profile: Orion Ransomware

Orion Ransomware is a newly observed operation whose public activity is limited to a data leak site listing 13 alleged victims and affiliate recruitment messaging rather than demonstrated ransomware development or independently verified intrusions. Analysis links the operator to prior reputation-driven extortion activity associated with Babuk2, indicating recycled leak material and low confidence in original operational capability. #Orion #Babuk2

Read More
German Manufacturing Under Phishing Attacks: Tracking a Stealthy AsyncRAT Campaign 

Manufacturing companies are being actively targeted with localized invoice-themed phishing that leverages CVE-2024-43451 and WebDAV-based shortcuts to deliver AsyncRAT and XWorm. Proactive, industry- and region-specific threat hunting using ANY.RUN’s sandbox and Threat Intelligence Lookup can identify fresh samples, file hashes, malicious filenames, and hosting infrastructure (Dropbox/WebDAV) before widespread detection occurs. #AsyncRAT…

Read More

MongoBleed (CVE-2025-14847) is a critical, unauthenticated memory-disclosure vulnerability in MongoDB Server that lets remote attackers manipulate the OP_COMPRESSED uncompressedSize field to trigger oversized heap allocations and leak sensitive data such as cleartext credentials and API keys. A public proof-of-concept and confirmed active exploitation were published in late December 2025, and roughly…

Read More
Analyzing a Multi-Stage AsyncRAT Campaign via Managed Detection and Response

Threat actors abused Cloudflare’s free-tier TryCloudflare tunnels and legitimate Python environments to host WebDAV servers and deliver the AsyncRAT remote access trojan, using double-extension phishing lures and living-off-the-land techniques for persistence. The campaign installs an embedded Python runtime, executes ne.py to APC-inject shellcode from new.bin into explorer.exe, and persists via startup…

Read More
From Hypothesis to Action: Proactive Threat Hunting with Elastic Security — Elastic Security Labs

Elastic Security enables hypothesis-driven threat hunting by unifying telemetry, providing AI-assisted ES|QL queries, machine learning, and integrated response to rapidly detect and remediate emerging techniques such as Living Off the Land Binaries. A RAG-powered AI Assistant, agentic workflows, Elastic Security Labs research, and entity analytics let analysts hunt across clusters, validate anomalies like rundll32.exe execution, and operationalize detections at scale. #TOLLBOOTH #LOLBins

Read More
Detecting and responding to Cephalus ransomware with Wazuh

Cephalus ransomware surfaced in mid‑August 2025, targets Windows endpoints via exposed RDP accounts lacking MFA, and performs stealthy local encryption, data exfiltration, and Volume Shadow Copy deletion to hinder recovery. The article demonstrates detection and automated response using Wazuh (Sysmon integration, custom detection rules, File Integrity Monitoring, YARA rules, and Active…

Read More
Where is the EDR? Silver C2 running from firewalls

Researchers discovered exposed Sliver C2 databases and logs in open directories, linking a threat actor that exploited multiple FortiWeb appliances and used React2Shell (CVE-2025-55182) to deploy Sliver and FRP to expose local services. Analysis shows Sliver implants, C2 domains, FRP and a renamed microsocks proxy (cups-lpd) persisted via systemd/supervisord on outdated FortiWeb devices, highlighting a major visibility blindspot. #Sliver #FortiWeb

Read More