⤷ Title: Practical Thread Hijacking — From Theory to Malware Code
════════════════════════
𐀪 Author: 0xc4t
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 13:34:12 GMT
════════════════════════
⌗ Tags: #red_team #development #initial_access #malware_development #ethical_hacking
════════════════════════
𐀪 Author: 0xc4t
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 13:34:12 GMT
════════════════════════
⌗ Tags: #red_team #development #initial_access #malware_development #ethical_hacking
Medium
Practical Thread Hijacking — From Theory to Malware Code
One code injection technique that often appears in malware development is thread hijacking. In summary: Thread Hijacking is a technique in…
⤷ Title: Initial Access Pot
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 11:53:56 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #initial_access #tryhackme_walkthrough #tryhackme #initial_access_pot
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 11:53:56 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #initial_access #tryhackme_walkthrough #tryhackme #initial_access_pot
Medium
Initial Access Pot
Investigate the first, Linux part of the Honeynet Collapse!
⤷ Title: Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
Daily CyberSecurity
Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
Rhysida ransomware is abusing Microsoft Trusted Signing to deploy OysterLoader (IAT) via Bing/Teams malvertising. The gang leveraged 40+ certificates to sign malware, bypassing security filters.
⤷ Title: Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and Access Resale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
Daily CyberSecurity
Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and…
Broadcom exposed a group deploying multiple RMM tools (ScreenConnect, LogMeIn, Naverisk) weeks apart to achieve redundant persistence. The likely Initial Access Broker (IAB) prepares systems for resale.
⤷ Title: Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
Penetration Testing Tools
Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
The financially motivated group Storm-0249, long known as a broker of initial access for ransomware operators, has markedly
⤷ Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Daily CyberSecurity
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
Storm-0249 IAB abuses the SentinelOne EDR process via DLL sideloading to evade detection. The group uses LoLBin tools for fileless execution and sells access to ransomware groups like LockBit.
⤷ Title: SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
Daily CyberSecurity
SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
SpaceX is interviewing investment banks for a potential 2026 IPO after its valuation nearly doubled to $800 billion in a secondary sale, fueled by Starlink's growth.
⤷ Title: Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
Daily CyberSecurity
Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
GreyNoise reveals a massive Japan-based holiday campaign: 2.5 million attacks targeting 767 CVEs to harvest access for ransomware gangs.
⤷ Title: Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
Daily CyberSecurity
Hidden in Plain Sight: TA584 Deploys "Tsundere Bot" & Invisible Registry Keys
TA584 triples activity with new "Tsundere Bot" malware. Attackers use invisible Registry keys to hide persistence. Read the Proofpoint analysis.
⤷ Title: The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
Daily CyberSecurity
The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
Group-IB reveals ShadowSyndicate is evolving. The cybercrime cluster now rotates SSH keys to hide its infrastructure. Is it a BPH or IAB?
⤷ Title: The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
Penetration Testing Tools
The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
Security analysts at ReliaQuest have unmasked a sophisticated phishing campaign wherein adversaries secrete remote access mechanisms within an
⤷ Title: Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
Daily CyberSecurity
Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
New campaign targets Ivanti EPMM with dormant in-memory backdoors. Attackers use CVE-2026-1281 to plant "sleeper" agents. Restart servers immediately.
⤷ Title: Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
Penetration Testing Tools
Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
The compromise of a perimeter network appliance can swiftly shepherd a malefactor toward domain controllers and the enterprise’s
⤷ Title: Signed, Trusted, and Abused: Proxy Execution via WebView2
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #C2 #How_To #Matthew Eidelberg #Red Team #DLL sideloading #initial access
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #C2 #How_To #Matthew Eidelberg #Red Team #DLL sideloading #initial access
Black Hills Information Security, Inc.
Signed, Trusted, and Abused: Proxy Execution via WebView2 - Black Hills Information Security, Inc.
An offensive security perspective on Microsoft Edge WebView2 Runtime, including architectural weaknesses, existing vulnerabilities, and exploitation methods.
⤷ Title: “Lorem Ipsum” Loader Weaponizing Microsoft Teams via SEO Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:12:47 +0000
════════════════════════
⌗ Tags: #Malware #BlueVoyant #Code Signing #Cyber Security #DLL Sideloading #infosec #initial access broker #JFIF C2 #Lorem Ipsum Malware #Microsoft Teams #SEO Poisoning #Threat Intel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:12:47 +0000
════════════════════════
⌗ Tags: #Malware #BlueVoyant #Code Signing #Cyber Security #DLL Sideloading #infosec #initial access broker #JFIF C2 #Lorem Ipsum Malware #Microsoft Teams #SEO Poisoning #Threat Intel
Daily CyberSecurity
"Lorem Ipsum" Loader Weaponizing Microsoft Teams via SEO Poisoning
BlueVoyant unmasks "Lorem Ipsum": a well-funded campaign using SEO poisoning and signed MS Teams installers to deploy stealthy backdoors via image files.
⤷ Title: KongTuke Abandoning “ClickFix” to Launch Direct Microsoft Teams Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 12:06:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix Lure #Cyber Security #EDR evasion #Help_Desk Impersonation #infosec #initial access broker #KongTuke #Microsoft Teams phishing #ModeloRAT #Script Execution Delay #WinPython Portable
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 12:06:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix Lure #Cyber Security #EDR evasion #Help_Desk Impersonation #infosec #initial access broker #KongTuke #Microsoft Teams phishing #ModeloRAT #Script Execution Delay #WinPython Portable
Daily CyberSecurity
KongTuke Abandoning "ClickFix" to Launch Direct Microsoft Teams Attacks
ReliaQuest warns Initial Access Broker "KongTuke" is abusing external Microsoft Teams chats to deploy the highly resilient ModeloRAT. Audit tenants now!
⤷ Title: The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
Information Security News
The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
North Korea’s adversarial presence within the digital theater has transcended the legacy paradigm of isolated, decentralized hacking collectives. Per comprehensive threat intelligence compiled by …
⤷ Title: Romanian Hacker Sentenced to Prison Following Government Cyberattacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:54:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CCIPS #Cybercrime #Department of Justice #FBI Investigation #identity theft #initial access broker #Network Intrusion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:54:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CCIPS #Cybercrime #Department of Justice #FBI Investigation #identity theft #initial access broker #Network Intrusion
Daily CyberSecurity
Romanian Hacker Sentenced to Prison Following Government Cyberattacks
A Romanian hacker sentenced to prison following an identity theft conviction and selling access to a US government network infrastructure.