UNC3886: Use of VMCI Sockets for Persistence
UNC3886 is a threat group documented by Mandiant that used VMware VMCI sockets for persistence between compromised ESXi hosts and guest VMs.…
UNC3886 is a threat group documented by Mandiant that used VMware VMCI sockets for persistence between compromised ESXi hosts and guest VMs.…
Swarmer, released by Praetorian, converts Windows Registry export files into hive files to replace NTUSER.MAN, enabling stealthy HKCU registry keys without admin…
Threat actors are actively exploiting a critical directory-traversal vulnerability in Broadcom's VMware vCenter, tracked as CVE-2026-59310 (CVSS 9.8), to gain persistent remote…
The China-nexus APT used reverse_ssh binaries to maintain persistent access to compromised vCenter instances.
The magic-login backdoor is a persistence module installed in the mu-plugins directory that allows unauthenticated administrative entry via a URL parameter targeting…
The backdoor used in the Alibaba supply chain attack targets Wukong, an enterprise collaboration application, by injecting malicious code to achieve persistence…
The backdoor used in the Alibaba supply chain attack targets Qoder, an enterprise collaboration application, by injecting malicious code to maintain persistence…
The final-stage payload is a complex backdoor equipped with comprehensive command execution, arbitrary file upload/download, host reconnaissance, payload staging, and lateral movement…
The final-stage backdoor in the Alibaba supply chain attack injects malicious code into DingTalk, a popular enterprise collaboration app, to maintain persistence…
Pandora RC is a remote access tool used by the attackers to establish remote access to victim machines. It is a legitimate…