w2.js: Malicious JavaScript Payload in BdThemes Supply Chain Attack
w2.js is a JavaScript payload used in the BdThemes supply chain attack. It contacts a C2 server, creates rogue admin accounts, installs…
w2.js is a JavaScript payload used in the BdThemes supply chain attack. It contacts a C2 server, creates rogue admin accounts, installs…
PhantomGraph is a backdoor that shares code overlap with PhantomCore. It consists of two DLL modules: SysExcSvc.dll for receiving commands and exfiltrating…
HelloProxy is a hidden proxy and loader used in the HelloNet attack. It loads additional modules from a C2 server and interferes…
HelloBackdoor is a Rust-based implant discovered in systems infected by the HelloNet attack. It enables file uploads and downloads to and from…
Sliver, an open-source command-and-control (C2) framework, is deployed as the final payload on Linux systems in the malicious npm campaign. The Linux…
ENDLESSDOORS is a backdoor implant found in Zbtlink router firmware. It is based on the rctl tool and allows unauthenticated remote attackers…
rctl (remote control linux) is a simple command and control client/server tool uploaded to GitHub in 2015. It listens on port 7000…
NullReceiver is a novel command-and-control (C2) technique that encodes the C2 server IP address within the recipient address of a zero-value Ethereum…
EtherHiding is a covert technique that embeds malicious code within smart contracts on public blockchains like BNB Smart Chain or Ethereum. It…
FDMTP is a backdoor first highlighted by Trend Micro in September 2024, distributed via the PUBLOAD downloader. It establishes C2 communication, gathers…