Auto-Color: Backdoor Deployed via SAP NetWeaver Exploit
Auto-Color is a backdoor that was deployed in an attack against a U.S.-based chemicals company in April 2025, exploiting the critical SAP…
Auto-Color is a backdoor that was deployed in an attack against a U.S.-based chemicals company in April 2025, exploiting the critical SAP…
CVE-2025-31324 is a critical vulnerability in SAP NetWeaver that has been weaponized by China-nexus espionage clusters such as UNC5221, UNC5174, and CL-STA-0048,…
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
CoolClient is a modular backdoor used by Mustang Panda. It supports keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. The…
PATCHCORD is a previously undocumented C/C++ backdoor delivered via fake VPN installers and telecom management tools. It establishes persistence by hijacking browser…
SHEETCORD is a Go-based backdoor that uses Google Sheets API for command-and-control. It is delivered via a fake NIC website and combines…
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched Microsoft Windows…
Troy is a previously unseen backdoor deployed by the Lazarus Group in Operation Dream Job attacks. It is loaded directly into memory…
ForestTiger, also known as ScoringMathTea, is a backdoor used by Lazarus Group to provide remote access to compromised hosts. It is deployed…
GoReShell is a Windows backdoor used by the PurpleHaze threat cluster. It leverages functionalities from the reverse_ssh tool to establish reverse SSH…