MEGA Cloud Service
MEGA is a cloud storage and file hosting service. Qilin ransomware affiliates exfiltrated data to MEGA before deploying ransomware in attacks exploiting…
MEGA is a cloud storage and file hosting service. Qilin ransomware affiliates exfiltrated data to MEGA before deploying ransomware in attacks exploiting…
Group-IB has discovered a new espionage implant named HollowGraph that hijacks Microsoft 365 calendars for command-and-control (C2) and data exfiltration. The malware,…
FileZilla is a free FTP solution. Qilin ransomware affiliates used FileZilla for data exfiltration during post-exploitation activities after exploiting CVE-2026-0257.
s5cmd is a legitimate command-line tool used for bulk file operations, often with cloud storage. In the attack, it was deployed to…
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
GraphSpy is a tool used for post-exploitation of Microsoft 365 and Entra environments, often integrated into PhaaS platforms like DEBULL. It enables…
Iranian state-sponsored hackers affiliated with the Ministry of Intelligence and Security (MOIS) have been using a previously undocumented modular command-and-control (C2) framework…
Researchers at Shandong University have unveiled a novel data exfiltration technique named TrojPix, capable of leaking sensitive information from air-gapped systems by…
TrojPix is a malware technique developed by researchers at Shandong University that exfiltrates data from air-gapped systems by modulating video cable emissions.…
An information stealer delivered alongside DEV#POPPER RAT as a second-stage payload in the PolinRider campaign. Used to exfiltrate sensitive data from compromised…