LokiBot Resurfaces in New Phishing Campaign
A new email phishing campaign delivers LokiBot via JavaScript attachments. LokiBot harvests credentials from password managers like 1Password, Enpass, and KeePass, and…
Malware families, payloads, loaders, ransomware and related tooling.
A new email phishing campaign delivers LokiBot via JavaScript attachments. LokiBot harvests credentials from password managers like 1Password, Enpass, and KeePass, and…
TheMoon is a malware family that infected years-old Linksys and Cisco routers, turning them into residential proxies sold by services like 5socks…
5socks was a residential proxy service that used TheMoon malware-infected routers to provide proxy access. It was taken down by the FBI…
Anyproxy was a residential proxy service that used TheMoon malware-infected routers to provide proxy access. It was taken down by the FBI…
A new malware family named AryStinger, discovered by QiAnXin's XLab, has infected at least 4,300 legacy routers to create a distributed reconnaissance…
AryStinger is an IoT botnet that targets poorly secured servers and IoT devices to co-opt them into a DDoS network. It is…
The KV-botnet was a larger botnet that included the JDY cluster. It was taken down by the U.S. government in early 2024,…
Cybersecurity researchers from Elastic Security Labs have disclosed a new campaign that delivers the CastleStealer information stealer via a previously unreported malware…
OXLOADER was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CastleStealer is a .NET-based information stealer that targets credentials and sensitive data. It has been distributed alongside CastleLoader in campaigns using ClickFix…