Sodinokibi Ransomware Group Overview
Sodinokibi is the malware variant associated with the REvil ransomware group, used in attacks from April 2019 to July 2021. It is…
Sodinokibi is the malware variant associated with the REvil ransomware group, used in attacks from April 2019 to July 2021. It is…
SugarLocker is a ransomware variant developed by the Shtazi-IT dev shop, linked to the sanctioned Aleksandr Ermakov. It was sold with a…
ThumbcacheService is a DLL used in conjunction with GoSerpent malware to collect sensitive files from compromised systems. It supplements the backdoor with…
QuarksDumpLocalHash is a tool used to extract local account password hashes from the SAM registry hive. It was deployed in the GoSerpent…
Stowaway is a proxy and remote access tool with SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based…
TmcLoader is a C++ loader module that contains an encrypted payload called TmcPayload. It was used in the GoSerpent campaign to exfiltrate…
TmcPayload is an encrypted payload deployed by TmcLoader to exfiltrate stored sensitive data from victim machines. It was part of the evolved…
McMx RAT is a basic Go-based proxy and remote access tool that is a lightweight version of GoSerpent. It includes capabilities such…
GoSerpent is a previously undocumented Go-based backdoor and remote access trojan (RAT) used in cyber attacks targeting Southeast Asian government and diplomatic…
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories Ravie LakshmananJul 16, 2026Hacking News / Cybersecurity News A…