Cybersecurity researchers at Acronis Threat Research Unit (TRU) have uncovered a new campaign targeting individuals and organizations in Cambodia with an open-source…
AcronisAcronis Threat Research UnitAMSI BypassBYOVD
A newly documented Windows backdoor named SLEEPWALKER has been detailed by independent malware researcher Dominik Reichel. The implant remains dormant in memory…
SLEEPWALKER is a Windows backdoor that remains dormant until receiving a crafted network packet. It executes commands in a custom 23-instruction bytecode…
ESET Management Agent is a Windows executable (ERAAgent.exe) that SLEEPWALKER abuses via DLL side-loading. The backdoor impersonates dpapi.dll and loads each time…
Fortinet FortiGuard Labs has disclosed a long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese…
A suspected Chinese-speaking threat actor has been conducting a series of cyber attacks against government organizations in Central Asia since January 2025.…
Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as…
Active Directory reconnaissanceBlackpoint Cybercommand-and-controlCVE-2026-50522