Matryoshka: A Rust-Based Backdoor with Dual C2 Mechanisms
Matryoshka is a Rust-based backdoor family deployed in attacks on law firms. It comes in two variants: one uses HTTP-based communication for…
Matryoshka is a Rust-based backdoor family deployed in attacks on law firms. It comes in two variants: one uses HTTP-based communication for…
NightLedger is a previously undocumented Windows backdoor deployed by Nimbus Manticore. It supports reconnaissance, command execution, file operations, process discovery, and screenshot…
BINDCLOAK is a 64-bit C++ implant that contacts an external server for command-and-control. It is the final payload in the attack chain,…
LogMeIn is a remote access and support software. Qilin ransomware affiliates used LogMeIn for reconnaissance and remote access during post-exploitation activities after…
SCOUTCURL is a PowerShell script used by UAC-0145 to perform basic reconnaissance by harvesting details about infected machines.
SharpShares is a C#-based utility for enumerating network shares. It was used by the attacker to find user-accessible data repositories.
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Datadog Security Labs has uncovered several overlapping campaigns that leverage dormant GitHub accounts—some created two to five years ago—to systematically enumerate corporate…
Iranian state-sponsored hackers affiliated with the Ministry of Intelligence and Security (MOIS) have been using a previously undocumented modular command-and-control (C2) framework…
An IP address from ProtonVPN service (159.26.98[.]241) was observed in the initial reconnaissance phase of the attempted exploitation of CVE-2026-20896, though no…