BabaDeda Loader: A Stealthy Malware Loader Targeting Education and Finance
BabaDeda Loader is a malware loader first documented by Morphisec in November 2021. It uses ClickFix social engineering to deliver payloads like…
BabaDeda Loader is a malware loader first documented by Morphisec in November 2021. It uses ClickFix social engineering to deliver payloads like…
EtherRAT is a remote access trojan (RAT) delivered via the Potemkin loader in ClickFix campaigns. It is used alongside RMMProject for credential…
SectopRAT, also known as ArechClient, is a remote access trojan delivered via BabaDeda Loader. It is deployed using DLL side-loading and provides…
A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from…
AnyDesk is a remote desktop application used by DeadLock for remote control of compromised hosts. It is a legitimate tool that is…
Gh0st RAT is a well-known remote access trojan that has been used by various cybercriminal and state-sponsored groups. It offers extensive remote…
ValleyRAT is a custom remote access trojan associated with the Silver Fox threat actor. It has been used in prior campaigns and…
MYRA is a full-featured Linux RAT delivered via a malicious npm package 'apintergrationpost', claiming to be a Node.js integration client for red…
Agent Tesla is a commodity remote access trojan (RAT) that has been distributed through the Cruciferra crypter service. It is used for…
XWorm is a remote access trojan that has been delivered through Cruciferra campaigns, including those impersonating the U.S. Social Security Administration. It…