SynkLoader: A Modular Malware Distributed via Microsoft Teams Phishing
SynkLoader is a Python-based loader distributed through Microsoft Teams phishing, presenting as a PowerShell Cleaner. It installs multiple modules including a fake…
SynkLoader is a Python-based loader distributed through Microsoft Teams phishing, presenting as a PowerShell Cleaner. It installs multiple modules including a fake…
Cybersecurity researchers have uncovered a new Python-based implant framework called TWINLOOT that abuses trusted Microsoft services for command-and-control (C2) operations. The malware,…
A now-patched vulnerability in Azure Cosmos DB could have allowed an attacker to escape the service's Gremlin query sandbox and gain full…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
Threat actors associated with the DragonForce ransomware group have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to…
Backdoor.Turn is a Go-based remote access trojan used by DragonForce ransomware to hide C2 traffic inside Microsoft Teams relay infrastructure via QUIC…
TWINLOOT and other malware abuse Microsoft Teams TURN servers to relay WebRTC DataChannels for interactive operator access.