DriveSilkRAT: New RAT Using Google Drive as C2
DriveSilkRAT is a newly discovered remote access tool written in .NET/C++ that uses Google Drive as its command-and-control channel. It supports 12…
DriveSilkRAT is a newly discovered remote access tool written in .NET/C++ that uses Google Drive as its command-and-control channel. It supports 12…
CookiETagRAT is a C++-based remote access tool that uses HTTP Cookie and ETag response headers as its command-and-control mechanism to receive and…
SimpleChatProxy is a custom chat application used by attackers to communicate with victims during the StopAndProtect campaign, likely for negotiation or intimidation.
A large-scale operation turning thousands of compromised WordPress websites into infrastructure for malware delivery, C2 communications, and stolen data storage.
Cybersecurity researchers have uncovered a global cybercrime operation dubbed 'StopAndProtect' that abuses nearly 2,000 hacked WordPress websites to distribute malware, steal data,…
TWINLOOT is a modular Python implant hardened with PyArmor that uses SharePoint Online and Microsoft Teams TURN relays for command-and-control. It steals…
The Chaos ransomware group is attributed to the msaRAT malware, which uses Twilio TURN relays and headless browsers for covert C2 communication.…
TWINLOOT uses SharePoint Online as a file dead-drop for tasking via the Microsoft Graph API, polling every 15 seconds for commands.
Google Sheets is abused by SHEETCORD for command-and-control communications, allowing the threat actor to issue commands and exfiltrate data via a legitimate…
GitHub Gists is used by the HACKERAI C2 malware for command-and-control, providing a stealthy channel for tasking and data exfiltration.