Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
Flying Eagle is an Android remote access trojan (RAT) framework that supports payment-password and keystroke capture, screen recording, camera access, and phishing…
Tengu is a Mirai-derived IoT malware that uses Telnet brute-force to hijack devices, enabling DoS attacks, data exfiltration, and proxy functionality. It…
NightLedger is a Windows backdoor used by Nimbus Manticore, as detailed in a Kaspersky report. It is used to maintain persistent access…
BridgeHead is a custom WebSocket tunneler used by Nimbus Manticore to maintain persistent access to compromised systems. It is part of the…
ArcBridge is another custom WebSocket tunneler used by Nimbus Manticore. It facilitates secure communications between compromised hosts and C2 infrastructure, helping the…
TWOSTROKE is a C++ backdoor attributed to Iranian threat actors, particularly Tortoiseshell and Nimbus Manticore. It allows system information collection, DLL loading,…
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update Ravie LakshmananJul 27, 2026Malware / Cyber Attack Cybersecurity researchers have flagged…
Cybersecurity researchers at Zscaler ThreatLabz have uncovered a malicious campaign targeting government entities in the Middle East, attributed to an East Asian…
Bun is a JavaScript runtime that the worm's stage one downloads (version 1.3.13) to execute a compiled credential-stealing bundle.