HellsUchecker: Backdoor Delivered via EtherHiding and ClickFix
HellsUchecker is a backdoor delivered via EtherHiding and ClickFix campaigns, capable of executing files retrieved from C2 and reporting results back.
Malware families, payloads, loaders, ransomware and related tooling.
HellsUchecker is a backdoor delivered via EtherHiding and ClickFix campaigns, capable of executing files retrieved from C2 and reporting results back.
LockBit was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cybersecurity researchers have identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns use…
BabaDeda Loader is a malware loader first documented by Morphisec in November 2021. It uses ClickFix social engineering to deliver payloads like…
Lorem Ipsum Loader is a nascent loader and backdoor active since February 2026. It is delivered through ClickFix lures on compromised WordPress…
A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from…
easy-day-js is a malicious npm package that cloned the legitimate 'dayjs' date library. Published by user 'sergey2016', it initially appeared clean but…
A ransomware campaign that compromised over 250,000 MySQL databases by brute-forcing weak credentials, highlighting the risk of exposed databases.
Cybersecurity researchers have uncovered a coordinated malware campaign on the JetBrains Marketplace involving 15 malicious plugins that exfiltrate AI provider API keys.…
PromptSnatcher is a data collection operation involving two Chrome ad blocker extensions that capture users' conversations with AI chatbots from platforms like…