SectopRAT (ArechClient): Remote Access Trojan Delivered via BabaDeda Loader
SectopRAT, also known as ArechClient, is a remote access trojan delivered via BabaDeda Loader. It is deployed using DLL side-loading and provides…
Malware families, payloads, loaders, ransomware and related tooling.
SectopRAT, also known as ArechClient, is a remote access trojan delivered via BabaDeda Loader. It is deployed using DLL side-loading and provides…
Rhysida is a ransomware family deployed by Vanilla Tempest (Rapid Brigantine) after initial access via Lorem Ipsum Loader. It is the primary…
Phexia Stealer is a macOS infostealer delivered via ClickFix campaigns targeting macOS users with fraudulent bot verification screens.
HellsUchecker is a backdoor delivered via EtherHiding and ClickFix campaigns, capable of executing files retrieved from C2 and reporting results back.
LockBit was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cybersecurity researchers have identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns use…
BabaDeda Loader is a malware loader first documented by Morphisec in November 2021. It uses ClickFix social engineering to deliver payloads like…
Lorem Ipsum Loader is a nascent loader and backdoor active since February 2026. It is delivered through ClickFix lures on compromised WordPress…
A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from…
easy-day-js is a malicious npm package that cloned the legitimate 'dayjs' date library. Published by user 'sergey2016', it initially appeared clean but…