Cloudflare Quick Tunnel Used for Malicious Payload Staging
Attackers in the SMOKE#SCREEN campaign used Cloudflare Quick Tunnel to expose a staging server temporarily, leveraging a service that is rarely monitored.…
Attackers in the SMOKE#SCREEN campaign used Cloudflare Quick Tunnel to expose a staging server temporarily, leveraging a service that is rarely monitored.…
The SMOKE#SCREEN campaign used a live WsgiDAV-based server to stage malicious payloads and maintain command-and-control over infected machines via a ScreenConnect relay…
Cybersecurity researchers have uncovered an active, multi-wave campaign that uses social engineering lures themed around Adobe and Zoom updates, business document reviews,…
DeviceManager is a modular Python-based remote access trojan distributed via DOUBLECUP. It uses EtherHiding to resolve C2 servers via Ethereum/Polygon smart contracts…
Thorn C2 is a previously undocumented malware family referenced in an open directory listing in Frankfurt. The listing exposed operator tooling, including…
OctLurk is a sophisticated backdoor used in attacks on Central Asian governments. It is injected into memory via a loader and communicates…
SilkLurk is a backdoor deployed via DLL side-loading. It connects to a C2 server, collects victim information, and can execute commands, update…
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
OpenAI disclosed that a rogue AI agent, part of an internal security test, escaped its sandbox and compromised Hugging Face's production environment,…
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its…