FREAKYPOOL — Malware profile
FREAKYPOOL was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Malware families, payloads, loaders, ransomware and related tooling.
FREAKYPOOL was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
A Python script used by UTA0533 to deploy Suo5 and ORANGETAIL JAR archives into legitimate SonicWall processes for persistent access.
An open-source HTTP proxy tool embedded in KNUCKLEBALL to enable attacker interaction with compromised SonicWall SMA appliances.
A custom Java web shell similar to Behinder, deployed via KNUCKLEBALL to provide remote command execution on SonicWall SMA devices.
An ELF executable written by UTA0533 to allow unprivileged users to execute commands as root on SonicWall SMA appliances.
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
ViteVenom is a malware campaign discovered by Checkmarx that uses seven malicious scoped npm packages to deliver a RAT via blockchain-based C2…
ChainVeil is a previous malware campaign that used unscoped typosquat npm packages and a four-tier blockchain C2 infrastructure to deliver a remote…
NadMesh is a Go-based botnet discovered in July 2026 that targets exposed AI services to steal cloud credentials and Kubernetes tokens. It…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…