PLEASE_READ_ME Ransomware Campaign
A ransomware campaign that compromised over 250,000 MySQL databases by brute-forcing weak credentials, highlighting the risk of exposed databases.
Malware families, payloads, loaders, ransomware and related tooling.
A ransomware campaign that compromised over 250,000 MySQL databases by brute-forcing weak credentials, highlighting the risk of exposed databases.
Cybersecurity researchers have uncovered a coordinated malware campaign on the JetBrains Marketplace involving 15 malicious plugins that exfiltrate AI provider API keys.…
PromptSnatcher is a data collection operation involving two Chrome ad blocker extensions that capture users' conversations with AI chatbots from platforms like…
Havoc is a post-exploitation framework used by attackers, including the 'Poisson' operator, to deploy the Demon agent for command and control.
The Demon agent is the implant component of the Havoc framework, used for in-memory execution and persistence on compromised systems.
RustDesk is an open-source remote desktop software that Armored Likho installs on compromised machines. The stealer prompts victims to enter credentials, then…
A 70-line Python keylogger was deployed by the attacker to capture keystrokes, storing them locally for manual retrieval, targeting banking and email…
Akira ransomware has been observed using RustDesk in recent intrusions, highlighting the abuse of legitimate tools for malicious purposes.
An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to promote a cryptocurrency clipboard hijacker.…
A Rust-based cryptocurrency clipboard hijacker that targets Windows and macOS systems. It monitors the clipboard for wallet address patterns and substitutes them…