E4del and PINHOLE RATs Abuse FTP Banners as Dead Drop Resolvers
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Threat actors are increasingly acquiring expired domains—known as "dropcatch domains"—to inherit their reputation and traffic, redirecting victims to scams and malware. According…
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as…
Matryoshka is a Rust-based backdoor family deployed in attacks on law firms. It comes in two variants: one uses HTTP-based communication for…
Cybersecurity researchers at Zscaler ThreatLabz have uncovered a malicious campaign targeting government entities in the Middle East, attributed to an East Asian…
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are…
A command-and-control listener found running on the attacker's staging server alongside the Hermes agent tooling.
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…