SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Unknown threat actors are leveraging the ScreenConnect remote access tool to deploy and execute AsyncRAT as part of a massive, multi-domain, multi-language…
Unknown threat actors are leveraging the ScreenConnect remote access tool to deploy and execute AsyncRAT as part of a massive, multi-domain, multi-language…
Cybersecurity researchers have identified a new multi-stage malware delivery attack chain, dubbed VEIL#DROP, that leverages social engineering and Google's Blogger platform to…
Security researcher Bert-Jan Pals analyzed roughly 3,000 live ClickFix payloads and presented findings at OrangeCon in early June, publishing details on June…
Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services.…
PteroPaste is used by Gamaredon to weaponize USB drives and download additional PowerShell payloads via an encrypted channel.
PteroDee is a PowerShell tool used by Gamaredon to fetch and execute PowerShell payloads in memory.
PteroCache is a PowerShell tool used by Gamaredon to fetch and execute PowerShell payloads in memory.
PteroOdd is a PowerShell tool used by Gamaredon to fetch a single PowerShell payload using the Telegra.ph API, likely in collaboration with…
Microsoft has issued a warning about an active phishing campaign targeting hotels and hospitality organizations across Europe and Asia since April 2026.…
Cabbage RAT, also known as CageyChameleon, is a PowerShell-based remote access trojan used by North Korean threat actors for credential and data…