⤷ Title: New Malware Uses Windows Character Map for Cryptomining
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 13:16:05 +0000
════════════════════════
⌗ Tags: #Security #Cryptocurrency #Malware #Autolt #Cryptojacking #Cryptominer #Cryptomining #Cyber Attack #Darktrace #NBMiner #PowerShell #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 13:16:05 +0000
════════════════════════
⌗ Tags: #Security #Cryptocurrency #Malware #Autolt #Cryptojacking #Cryptominer #Cryptomining #Cyber Attack #Darktrace #NBMiner #PowerShell #Windows
Hackread
New Malware Uses Windows Character Map for Cryptomining
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: ShadowV2 Botnet Uses Misconfigured AWS Docker for DDoS-For-Hire Service
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 13:58:21 +0000
════════════════════════
⌗ Tags: #Security #Malware #AWS #Botnet #Cyber Crime #Cybersecurity #Darktrace #DDoS_for_Hire #Docker #Misconfiguration #ShadowV2
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 13:58:21 +0000
════════════════════════
⌗ Tags: #Security #Malware #AWS #Botnet #Cyber Crime #Cybersecurity #Darktrace #DDoS_for_Hire #Docker #Misconfiguration #ShadowV2
Hackread
ShadowV2 Botnet Uses Misconfigured AWS Docker for DDoS-For-Hire Service
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Akira Ransomware Revives SonicWall Flaw CVE-2024-40766, Uses ‘UnPAC the Hash’ to Breach Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:09:24 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #Credential Theft #CVE_2024_40766 #Darktrace #SonicWall #UnPAC the Hash #VMware ESXi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:09:24 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #Credential Theft #CVE_2024_40766 #Darktrace #SonicWall #UnPAC the Hash #VMware ESXi
Daily CyberSecurity
Akira Ransomware Revives SonicWall Flaw CVE-2024-40766, Uses 'UnPAC the Hash' to Breach Networks
Akira ransomware is actively exploiting the unpatched/misconfigured SonicWall flaw (CVE-2024-40766) and using the rare "UnPAC the Hash" Kerberos technique for lateral movement.
⤷ Title: DragonForce Ransomware Strikes Manufacturing Sector with Brute-Force, Exfiltrating Data Over SSH to Russian Host
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:12:11 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force #Darktrace #DragonForce #Manufacturing #openvas #RaaS #ransomware #SSH Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:12:11 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force #Darktrace #DragonForce #Manufacturing #openvas #RaaS #ransomware #SSH Exfiltration
Daily CyberSecurity
DragonForce Ransomware Strikes Manufacturing Sector with Brute-Force, Exfiltrating Data Over SSH to Russian Host
Darktrace exposed a DragonForce RaaS attack on a manufacturer. The multi-phase intrusion used brute force and OpenVAS for recon, then exfiltrated data over SSH to a Russian-based malicious host.
⤷ Title: Next-Gen Threat: Xillen Stealer v4 Targets 100+ Browsers/70+ Wallets with Polymorphic Evasion and DevOps Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Malware #AI Evasion #Darktrace #Kubernetes Secrets #Polymorphic Engine #Rust malware #steganography #Xillen Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Malware #AI Evasion #Darktrace #Kubernetes Secrets #Polymorphic Engine #Rust malware #steganography #Xillen Stealer
Daily CyberSecurity
Next-Gen Threat: Xillen Stealer v4 Targets 100+ Browsers/70+ Wallets with Polymorphic Evasion and DevOps Theft
Darktrace exposed Xillen Stealer v4/v5, a new MaaS threat using Rust polymorphism and an AIEvasionEngine to target 100+ browsers and Kubernetes/DevOps secrets. It uses steganography for exfiltration.
⤷ Title: New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
Daily CyberSecurity
New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
Darktrace exposed TAG-150, a new MaaS operator compromising 469+ US devices in months. The group uses ClickFix to trick victims into running malicious PowerShell that deploys the CastleLoader/CastleRAT backdoor.
⤷ Title: Lazarus Group Embed New BeaverTail Variant in Developer Tools
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 18:37:56 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Security #BeaverTail #Crypto #Cyber Attack #Cybersecurity #Darktrace #Lazarus #Malware #North Korea #security
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 18:37:56 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Security #BeaverTail #Crypto #Cyber Attack #Cybersecurity #Darktrace #Lazarus #Malware #North Korea #security
Hackread
Lazarus Group Embed New BeaverTail Variant in Developer Tools
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Phantom in the Machine: Inside Salt Typhoon’s “SnappyBee” Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:27:36 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Persistent Threat #Cobalt Strike #Darktrace #Deed RAT #Demodex #DLL side_loading #Earth Estries #Malware Analysis #Salt Typhoon #SNAPPYBEE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:27:36 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Persistent Threat #Cobalt Strike #Darktrace #Deed RAT #Demodex #DLL side_loading #Earth Estries #Malware Analysis #Salt Typhoon #SNAPPYBEE
Daily CyberSecurity
Phantom in the Machine: Inside Salt Typhoon’s "SnappyBee" Backdoor
Darktrace dissects SnappyBee (Deed RAT), a stealthy Salt Typhoon backdoor. Learn how it uses DLL side-loading & memory hooking to evade modern AV.
⤷ Title: The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:41:43 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #Compatibility Wizard #cybersecurity #Darktrace #infosec #macOS Malware #Node.js Loader #phishing #social engineering #TCC Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:41:43 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #Compatibility Wizard #cybersecurity #Darktrace #infosec #macOS Malware #Node.js Loader #phishing #social engineering #TCC Bypass
Daily CyberSecurity
The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC
Mac users, often confident in the “walled garden” security of their devices, are facing a new threat that doesn’t rely on cracking code, but on cracking human trust. A new invest…
⤷ Title: The Rise of Vibecoding: AI-Generated Malware Exploits React2Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:27:57 +0000
════════════════════════
⌗ Tags: #Malware #AI_generated malware #artificial intelligence #CloudyPots #CVE_2025_55182 #Darktrace #Docker Security #Monero mining #React2Shell #Vibecoding #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:27:57 +0000
════════════════════════
⌗ Tags: #Malware #AI_generated malware #artificial intelligence #CloudyPots #CVE_2025_55182 #Darktrace #Docker Security #Monero mining #React2Shell #Vibecoding #XMRig
Daily CyberSecurity
The Rise of Vibecoding: AI-Generated Malware Exploits React2Shell
Darktrace detects AI-generated "vibecoding" malware exploiting React2Shell (CVE-2025-55182). Attackers use AI to deploy XMRig miners on Docker.
⤷ Title: ZionSiphon: The “Defanged” Malware Aiming for the Water Supply
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 01:01:16 +0000
════════════════════════
⌗ Tags: #Malware #Critical Infrastructure #Darktrace #Desalination Security #ICS Malware #Industrial Sabotage #infosec #Israel #Modbus #OT Security #Water Treatment #ZionSiphon
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 01:01:16 +0000
════════════════════════
⌗ Tags: #Malware #Critical Infrastructure #Darktrace #Desalination Security #ICS Malware #Industrial Sabotage #infosec #Israel #Modbus #OT Security #Water Treatment #ZionSiphon
Daily CyberSecurity
ZionSiphon: The "Defanged" Malware Aiming for the Water Supply
Darktrace uncovers ZionSiphon, a malware strain targeting water treatment via Modbus logic. Discover the new frontier of Israel-focused industrial sabotage.
⤷ Title: New DDoS Botnet Exploits Jenkins to Target Gaming Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 09:10:36 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CI/CD security #cyber_espionage #Darktrace #ddos #Game Server Security #Gaming Industry #Groovy Script #infosec #Jenkins #rce #UDP flood
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 09:10:36 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CI/CD security #cyber_espionage #Darktrace #ddos #Game Server Security #Gaming Industry #Groovy Script #infosec #Jenkins #rce #UDP flood
Daily CyberSecurity
New DDoS Botnet Exploits Jenkins to Target Gaming Servers
Darktrace uncovers a new DDoS botnet hijacking Jenkins servers to target game servers. Protect your CI/CD pipeline from specialized gaming-layer attacks.
⤷ Title: Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 01 May 2026 17:21:29 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Botnet #Cyber Attack #Cybersecurity #Darktrace #DDOS #Malware #RCE
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 01 May 2026 17:21:29 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Botnet #Cyber Attack #Cybersecurity #Darktrace #DDOS #Malware #RCE
Hackread
Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers
A new campaign shows misconfigured Jenkins servers abused to deploy a DDoS botnet targeting gaming systems, with Valve Corporation infrastructure in focus.
⤷ Title: Twill Typhoon Exploits CDN Masquerading and DLL Sideloading to Breach APJ Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 May 2026 06:17:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET RAT #APJ Cyber Espionage #CDN Masquerading #Chinese APT #Cyber Security #Darktrace #DLL Sideloading #infosec #living_off_the_land #malware #Memory injection #Twill Typhoon
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 May 2026 06:17:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET RAT #APJ Cyber Espionage #CDN Masquerading #Chinese APT #Cyber Security #Darktrace #DLL Sideloading #infosec #living_off_the_land #malware #Memory injection #Twill Typhoon
Daily CyberSecurity
Twill Typhoon Exploits CDN Masquerading and DLL Sideloading to Breach APJ Networks
Darktrace exposes Chinese APT Twill Typhoon’s latest campaign using DLL sideloading and Yahoo/Apple CDN lookalikes to deploy a modular .NET RAT.
⤷ Title: Twill Typhoon RAT Campaign Uses DLL Side Loading to Target APJ Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:02:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #China_nexus #Darktrace #DLL Sideloading #Remote Access Trojan #Twill Typhoon
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:02:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #China_nexus #Darktrace #DLL Sideloading #Remote Access Trojan #Twill Typhoon
Daily CyberSecurity
Twill Typhoon RAT Campaign Uses DLL Side Loading to Target APJ Networks
A stealthy Twill Typhoon RAT campaign targets APJ organizations. Discover how this threat exploits DLL side loading tradecraft to evade security.
⤷ Title: AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:19:50 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Crypto #Amazon #Amazon Bedrock #Bedrock AI #Cryptomining #Cyber Attack #Cybersecurity #Darktrace #Malware #SSH #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:19:50 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Crypto #Amazon #Amazon Bedrock #Bedrock AI #Cryptomining #Cyber Attack #Cybersecurity #Darktrace #Malware #SSH #Vulnerability
Hackread
AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity.