PhantomFS: Open-Source Windows Honeypot Using Projected File System
PhantomFS is a free open-source Windows honeypot that uses the Projected File System to project decoy files in memory. When accessed, it…
PhantomFS is a free open-source Windows honeypot that uses the Projected File System to project decoy files in memory. When accessed, it…
PsExec is a Microsoft Sysinternals tool used for remote command execution. Qilin ransomware affiliates used PsExec for lateral movement via administrative shares…
Cybersecurity researchers at Infoblox have uncovered a threat actor tracked as Lurking Lizard, operating an end-to-end malicious residential proxy business since at…
WireVPN is a malware-laced VPN application used by Lurking Lizard to recruit devices into a residential proxy botnet. Available on Android, macOS,…
Cybersecurity researchers at LevelBlue have identified a new Java-based remote access trojan (RAT) named QuimaRAT, which is capable of targeting Windows, Linux,…
QuimaRAT is a Java-based remote access trojan (RAT) advertised under a malware-as-a-service (MaaS) model, capable of targeting Windows, Linux, and macOS. It…
Quima Control, also known as QuimaRAT, is a remote administration tool with 74 Windows and 46 macOS and Linux modules. It is…
A previously undocumented threat actor, Armored Likho, has been attributed to cyber attacks targeting government agencies and the electric power sector across…
CVE-2025-9491 is a now-patched Windows shortcut vulnerability (ZDI-CAN-25373) that allows remote code execution. Addressed by Microsoft in November 2025 Patch Tuesday, it…
BusySnake Stealer is a Python-based information stealer targeting Windows systems, used by Armored Likho. It implements evasion techniques like dynamic bytecode decryption…