SpyPress: JavaScript Malware Used in Operation RoundPress
SpyPress is an obfuscated JavaScript-based malware used by TA458 in Operation RoundPress. It targets webmail platforms including Roundcube, Zimbra, Kerio, SOGo, and…
Malware families, payloads, loaders, ransomware and related tooling.
SpyPress is an obfuscated JavaScript-based malware used by TA458 in Operation RoundPress. It targets webmail platforms including Roundcube, Zimbra, Kerio, SOGo, and…
LONEPAGE was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
MATCHBOIL was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
MATCHWOK was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
DRAGSTARE was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
BURNYBEAR is a loader used by UAC-0099 to deliver MATCHBOIL.V2. It is executed as RemoteLibUpdater.exe and can exhaust system resources if launched…
MATCHBOIL.V2 is a modified version of the MATCHBOIL malware, a C#-based loader capable of delivering secondary payloads. It was deployed in attacks…
ZimReaper is a malicious JavaScript delivered via a half-click exploit (CVE-2025-66376) by the Laundry Bear threat actor. It harvests email communications and…
TriBack Loader is a previously undocumented Windows loader used by the JadeProx operation. It employs DLL sideloading with four infection chains, using…
AdaptixC2 is an open-source post-exploitation framework delivered by two variants of the TriBack Loader in the JadeProx operation.