GoCaracal: New Go-Based Malware Framework
GoCaracal is a previously undocumented Go-based malware framework used in a June 2026 intrusion. It provides remote shell access, payload execution, and…
GoCaracal is a previously undocumented Go-based malware framework used in a June 2026 intrusion. It provides remote shell access, payload execution, and…
This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Six npm packages use the NullReceiver technique, fetching next-stage payloads via Ethereum transactions linked to North Korean threat actors, evolving from EtherHiding.
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
Ethereum is a blockchain platform used in the EtherHiding technique to retrieve domain names from smart contracts for malicious CAPTCHA injection.
Security firm Coinspect has disclosed a crypto wallet flaw called 'Ill Bloom' that is being actively exploited by attackers. The vulnerability stems…
Ethereum is a blockchain platform used in the EtherHiding technique of the DPRK malvertising campaign. Malware extracts C2 server addresses from Ethereum…