HelloBackdoor: Rust Implant for File Transfer and Command Execution
HelloBackdoor is a Rust-based implant discovered in systems infected by the HelloNet attack. It enables file uploads and downloads to and from…
HelloBackdoor is a Rust-based implant discovered in systems infected by the HelloNet attack. It enables file uploads and downloads to and from…
SilentRaid, also known as MystRodX or TrustFall, is a C++-based implant linked to previous attacks. Kaspersky found infrastructure overlaps between this campaign…
ChonkyChicken is a fully featured implant that expands on TinyEgg with browser credential theft, live browser session control using Chrome DevTools Protocol…
TonRAT is a Node.js-based implant used in a phishing campaign targeting hotels. It resolves C2 domains via the TON blockchain API and…
The Demon agent is the implant component of the Havoc framework, used for in-memory execution and persistence on compromised systems.
The phishing campaign downloads a legitimate Node.js v24.13.0 runtime from nodejs.org to execute the TonRAT implant in user space.