DeadLock Ransomware: Technical Analysis
DeadLock ransomware uses hybrid cryptography (Curve25519 and XChaCha20), selective encryption, and geofencing. It employs an HTML-based recovery chat that interacts with Polygon…
DeadLock ransomware uses hybrid cryptography (Curve25519 and XChaCha20), selective encryption, and geofencing. It employs an HTML-based recovery chat that interacts with Polygon…
Microsoft Threat Intelligence has uncovered a macOS ClickFix operation that uses more than 250 front-end domains to distribute malware, including MacSync and…
Cruciferra is a crypter service written in Mono, advertised on the cybercrime underground as the 'most lethal crypter' for $450 to $2,000…
SkillCloak is a technique developed by researchers at the Hong Kong University of Science and Technology that rewrites malicious AI agent skills…
BusySnake Stealer is a Python-based information stealer targeting Windows systems, used by Armored Likho. It implements evasion techniques like dynamic bytecode decryption…
Mimikatz is a well-known open-source tool for extracting credentials from Windows systems. The Blue Report 2026 shows that while classic LSASS memory…
Miasma is a multi-stage botnet loader identified in compromised AsyncAPI npm packages. It features a tasking framework with 744 modules, supporting six…