FREAKYPOLL: Python Backdoor
FREAKYPOLL is a Python-based backdoor deployed in the UAC-0145 campaign, providing remote access to infected systems.
FREAKYPOLL is a Python-based backdoor deployed in the UAC-0145 campaign, providing remote access to infected systems.
COWARDDUCK is a full-featured Android backdoor distributed via messaging apps, disguised as security tools. It exfiltrates contacts, files, and geolocation using Dropbox…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
GHETTOVIBE is a VBS file saved in the Startup autorun directory, delivered through fake CAPTCHA checks in the UAC-0145 campaign targeting Ukrainian…
SCOUTCURL is a PowerShell script used by UAC-0145 to perform basic reconnaissance by harvesting details about infected machines.
FLUIDLEECH is a loader used in the UAC-0145 campaign, disguised as software for removing computer viruses to trick users.
LOADLOOP is a loader used alongside FLUIDLEECH in the UAC-0145 campaign to deliver additional malware payloads.
ViteVenom is a malware campaign discovered by Checkmarx that uses seven malicious scoped npm packages to deliver a RAT via blockchain-based C2…
ChainVeil is a previous malware campaign that used unscoped typosquat npm packages and a four-tier blockchain C2 infrastructure to deliver a remote…
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Ravie LakshmananJul 17, 2026Malware / Threat Intelligence Cybersecurity researchers have attributed the…