Cybersecurity researchers have uncovered new components in the Cavern (aka Cav3rn) command-and-control (C2) framework, used by Iranian nation-state hackers in attacks targeting…
DeviceManager is a modular Python-based remote access trojan distributed via DOUBLECUP. It uses EtherHiding to resolve C2 servers via Ethereum/Polygon smart contracts…
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into…
LabubaRAT is a previously undocumented Rust-based remote access trojan (RAT) that masquerades as NVIDIA software. It supports multiple communication methods including HTTPS,…
HOLLOWGRAPH uses DNS tunneling to refresh Microsoft Entra ID (Azure AD) credentials used for Graph API authentication, highlighting a novel technique for…