CastleLoader: Malware Loader Associated with GrayBravo
CastleLoader is a malware loader used by the GrayBravo threat cluster to deliver payloads such as CastleStealer. It has been observed in…
Malware families, payloads, loaders, ransomware and related tooling.
CastleLoader is a malware loader used by the GrayBravo threat cluster to deliver payloads such as CastleStealer. It has been observed in…
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors tampered with the official release channels…
Gh0st RAT is a well-known remote access trojan that has been used by various cybercriminal and state-sponsored groups. It offers extensive remote…
ValleyRAT, also known as Winos 4.0, is a variant of Gh0st RAT that provides remote access, C2 communication, and post-compromise capabilities. It…
A new active campaign is targeting WhatsApp Desktop and WhatsApp Web users across multiple countries, including Malaysia, Brazil, India, Mexico, Singapore, the…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…
A known JavaScript malware associated with the Contagious Interview campaign. Delivered via malicious packages and extensions, it searches for configuration files and…
InvisibleFerret is a Python backdoor deployed by the Fake Font campaign. It steals cryptocurrency wallets, browser credentials, and establishes persistent access on…
MYRA is a full-featured Linux RAT delivered via a malicious npm package 'apintergrationpost', claiming to be a Node.js integration client for red…
FortigateSniffer is a Golang-based tool used in the FortiBleed campaign to passively intercept authentication traffic from compromised FortiGate firewalls. It leverages the…