⤷ Title: The End of an Era: Microsoft Is Finally Killing VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 03:53:34 +0000
════════════════════════
⌗ Tags: #Windows #deprecation #it #Microsoft #scripting #Technology #VBScript #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 03:53:34 +0000
════════════════════════
⌗ Tags: #Windows #deprecation #it #Microsoft #scripting #Technology #VBScript #windows
Daily CyberSecurity
The End of an Era: Microsoft Is Finally Killing VBScript
After almost 30 years, Microsoft is retiring VBScript. The legacy language will be phased out of Windows by 2027, posing a challenge for enterprises.
⤷ Title: Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
Daily CyberSecurity
Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
BitSight uncovered a Lampion banking Trojan campaign using ClickFix lures and a 700MB bloatware DLL to evade AV. The VBScript loader establishes persistence via the Windows Startup folder.
⤷ Title: Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
Daily CyberSecurity
Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
Cybereason exposed Tangerine Turkey, a VBScript worm that spreads via USB drives. It uses LOLBins (printui.exe) and Windows Defender exclusions to deploy the XMRig cryptominer for profit.
⤷ Title: Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
Daily CyberSecurity
Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
Researchers at Palo Alto Networks Unit 42 have uncovered two expansive and interconnected malware campaigns active throughout 2025, both designed to mass-distribute Gh0st RAT variants to Chinese-s…
⤷ Title: Sophisticated WhatsApp Worm Uses Fake “View Once” Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
Daily CyberSecurity
Sophisticated WhatsApp Worm Uses Fake "View Once" Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
Sophos exposed STAC3150, a campaign using fake "View Once" messages to deploy Astaroth banking trojan. The malware hijacks WhatsApp Web sessions via WPPConnect/Selenium for self-propagation.
⤷ Title: The Invisible Edge: APT28’s “Operation MacroMaze” Hijacks Browsers via Webhook Lures
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 07:31:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #Central Europe #Cyber Espionage #INCLUDEPICTURE #LAB52 #Microsoft Edge headless #Operation MacroMaze #S2 Grupo #Spear Phishing #Tech News 2026 #VBScript #webhook.site #Western Europe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 07:31:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #Central Europe #Cyber Espionage #INCLUDEPICTURE #LAB52 #Microsoft Edge headless #Operation MacroMaze #S2 Grupo #Spear Phishing #Tech News 2026 #VBScript #webhook.site #Western Europe
Penetration Testing Tools
The Invisible Edge: APT28’s "Operation MacroMaze" Hijacks Browsers via Webhook Lures
The APT28 syndicate has orchestrated a series of surgical strikes against organizations across Western and Central Europe, employing
⤷ Title: Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain security #ClickFix #cybersecurity #EtherHiding #infosec #OCRFix Botnet #Russian Malware #smart contracts #threat intelligence #VBScript Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain security #ClickFix #cybersecurity #EtherHiding #infosec #OCRFix Botnet #Russian Malware #smart contracts #threat intelligence #VBScript Malware
Daily CyberSecurity
Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain
Cybersecurity researchers uncover OCRFix, a Russian-linked botnet using EtherHiding and fake CAPTCHAs to mask its C2 servers in blockchain smart contracts.
⤷ Title: The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:31:30 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #Dropbox Abuse #Kimsuky #LNK #Malware Analysis #powershell #Python backdoor #Task Scheduler #threat intelligence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:31:30 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #Dropbox Abuse #Kimsuky #LNK #Malware Analysis #powershell #Python backdoor #Task Scheduler #threat intelligence #VBScript
Daily CyberSecurity
The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors
ASEC uncovers Kimsuky’s evolved LNK-to-Python chain abusing Dropbox for stealthy persistence. Learn how to detect this complex multi-stage backdoor.
⤷ Title: New Phishing Campaign Abuses GitHub to Target South Korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:01:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyberespionage #FortiGuard Labs #Github C2 #infosec #LNK malware #LotL #Mirae Asset 3.0 #phishing #powershell #south korea #VBScript #XenoRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:01:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyberespionage #FortiGuard Labs #Github C2 #infosec #LNK malware #LotL #Mirae Asset 3.0 #phishing #powershell #south korea #VBScript #XenoRAT
Daily CyberSecurity
New Phishing Campaign Abuses GitHub to Target South Korea
FortiGuard Labs unmasks a South Korean espionage wave abusing the GitHub API for C2 and using LNK files to stay invisible. Protect your network from LotL.
⤷ Title: New Stealth Attack Chain Weaponizes Legitimate Remote Access Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:21:28 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #Adobe Acrobat #cybersecurity #Fileless Malware #In_Memory Execution #infosec #ScreenConnect #UAC bypass #VBScript Loader #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:21:28 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #Adobe Acrobat #cybersecurity #Fileless Malware #In_Memory Execution #infosec #ScreenConnect #UAC bypass #VBScript Loader #Zscaler ThreatLabz
Daily CyberSecurity
New Stealth Attack Chain Weaponizes Legitimate Remote Access Software
Zscaler reveals a 2026 attack chain using fake Adobe Reader lures to install ScreenConnect via in-memory execution and UAC bypass. Protect your network now!
⤷ Title: Fake RVTools Installer Deploys Modular Python RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:01:03 +0000
════════════════════════
⌗ Tags: #Malware #Code Signing Abuse #Modular Python RAT #RVTools Scam #Sectigo Certificate #VBScript Obfuscation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:01:03 +0000
════════════════════════
⌗ Tags: #Malware #Code Signing Abuse #Modular Python RAT #RVTools Scam #Sectigo Certificate #VBScript Obfuscation
Daily CyberSecurity
Fake RVTools Installer Deploys Modular Python RAT
A fake RVTools installer campaign distributes a modular Python RAT. Learn how this malware uses signed certificates to evade security controls.
⤷ Title: WhatsApp VBS Campaign Installs ManageEngine RMM for Remote Access
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 03:11:44 +0000
════════════════════════
⌗ Tags: #Malware #kaspersky #Malware Campaign #ManageEngine Endpoint Central #RMM Abuse #VBScript #WhatsApp
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 03:11:44 +0000
════════════════════════
⌗ Tags: #Malware #kaspersky #Malware Campaign #ManageEngine Endpoint Central #RMM Abuse #VBScript #WhatsApp
Information Security News
WhatsApp VBS Campaign Installs ManageEngine RMM for Remote Access
Trust in a familiar sender keeps turning into a weak point. A new campaign against WhatsApp users builds on exactly that bet. The attackers send malicious files from already-hijacked accounts. The…
⤷ Title: WhatsApp Malware Campaign Spreads RMM Software
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 09:00:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #kaspersky #VBScript #WhatsApp Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 09:00:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #kaspersky #VBScript #WhatsApp Malware
Daily CyberSecurity
WhatsApp Malware Campaign Spreads RMM Software
A new WhatsApp malware campaign uses a multi-stage VBScript infection chain to silently install RMM software on victim devices across multiple countries.