TWOSTROKE: C++ Backdoor Used by Iranian Threat Actors
TWOSTROKE is a C++ backdoor attributed to Iranian threat actors, particularly Tortoiseshell and Nimbus Manticore. It allows system information collection, DLL loading,…
TWOSTROKE is a C++ backdoor attributed to Iranian threat actors, particularly Tortoiseshell and Nimbus Manticore. It allows system information collection, DLL loading,…
ENS is a blockchain-based name service used by Dysphoria for C2 resolution. The botnet uses ENS domains like m3rnbvs5d[.]eth and burrberry[.]eth to…
SNS is a blockchain-based name service on Solana used by Dysphoria for C2 resolution, with domains like 24carnforth2merseyside[.]sol supplying infrastructure records.
TELESHIM is a 32-bit Windows backdoor that abuses the Telegram API for command-and-control communication. It uses DLL side-loading via RegSchdTask.exe and AsTaskSched.dll,…
A command-and-control listener found running on the attacker's staging server alongside the Hermes agent tooling.
AdaptixC2 is a command and control framework that has been delivered through Cruciferra campaigns, including those impersonating the U.S. Social Security Administration.
The ENCFORGE campaign used GCP command-and-control servers. The operator tracked the host as a GCP target with task IDs gcp_h1 and gcp_test.
Group-IB has discovered a new espionage implant named HollowGraph that hijacks Microsoft 365 calendars for command-and-control (C2) and data exfiltration. The malware,…
HOLLOWGRAPH is a .NET NativeAOT-compiled DLL that abuses Microsoft Graph API to use Microsoft 365 calendar events as a two-way dead-drop for…
Daxin (srt64.sys) is a kernel-mode rootkit first documented by Symantec in March 2022, used in targeted attacks since 2013. It monitors incoming…