⤷ Title: The Friend Request from Pyongyang: How APT37 Hijacks Facebook to Deploy RokRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:40:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT37 #Code Cave Injection #Facebook Phishing #Fileless Malware #Genians Security Center #North Korean APT #PE Patching #RokRAT #social engineering #Wondershare PDFelement #Zoho WorkDrive
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:40:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT37 #Code Cave Injection #Facebook Phishing #Fileless Malware #Genians Security Center #North Korean APT #PE Patching #RokRAT #social engineering #Wondershare PDFelement #Zoho WorkDrive
Daily CyberSecurity
The Friend Request from Pyongyang: How APT37 Hijacks Facebook to Deploy RokRAT
APT37 pivots to Facebook social engineering, using Wondershare PDFelement "code caves" to deploy RokRAT. Learn how they bypass EDR with memory-only payloads.
⤷ Title: RondoDox Botnet Hijacks Everything from IoT to Fortnite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 02:01:00 +0000
════════════════════════
⌗ Tags: #Malware #anti_debugging #Bitsight #botnet #dos attack #Fileless Malware #infosec #IoT security #Malware Analysis #Monero mining #Nanomites #RondoDox #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 02:01:00 +0000
════════════════════════
⌗ Tags: #Malware #anti_debugging #Bitsight #botnet #dos attack #Fileless Malware #infosec #IoT security #Malware Analysis #Monero mining #Nanomites #RondoDox #XMRig
Daily CyberSecurity
RondoDox Botnet Hijacks Everything from IoT to Fortnite
BitSight unmasks RondoDox: a modular botnet using "nanomites" to dodge debuggers while hijacking 18 architectures for Monero mining and gaming DoS attacks.
⤷ Title: PureRAT Unmasked: The Stealthy, Multi-Stage “Dynamic Loader” Targeting Windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
Daily CyberSecurity
PureRAT Unmasked: The Stealthy, Multi-Stage "Dynamic Loader" Targeting Windows
Trellix uncovers PureRAT, a modular Trojan hiding malware in PNG images. Learn how it uses steganography and fileless delivery to bypass Windows security.
⤷ Title: Inside the Stealthy Evolution of Vidar Infostealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 07:06:31 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Crypto theft #cybersecurity #Fileless Malware #infosec #Infostealer #living_off_the_land #malware #social engineering #Telegram C2 #Vidar
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 07:06:31 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Crypto theft #cybersecurity #Fileless Malware #infosec #Infostealer #living_off_the_land #malware #social engineering #Telegram C2 #Vidar
Daily CyberSecurity
Inside the Stealthy Evolution of Vidar Infostealer
Vidar infostealer evolves into a fileless 2026 threat. From fake CAPTCHAs to "Claude Code" leaks, see how it steals crypto and passwords via Telegram C2.
⤷ Title: New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:11:06 +0000
════════════════════════
⌗ Tags: #Malware #AWS Credentials #DevOps Security #eBPF Rootkit #Fileless Malware #infosec #Linux RAT #npm Security #PyPI #QLNX #Quasar Linux #supply chain attack #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:11:06 +0000
════════════════════════
⌗ Tags: #Malware #AWS Credentials #DevOps Security #eBPF Rootkit #Fileless Malware #infosec #Linux RAT #npm Security #PyPI #QLNX #Quasar Linux #supply chain attack #Trend Micro
Daily CyberSecurity
New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens
Trend Micro uncovers QLNX, a fileless Linux RAT targeting AWS, NPM, and Kubernetes keys. Learn how its eBPF rootkit hides from even the deepest system scans.
⤷ Title: The InstallFix Trap: Fake Claude AI Google Ads Drop Fileless RedLine Malware on Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 06:11:33 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #Anthropic #Claude AI #ClickFix #cybersecurity #Fileless Malware #Google Ads Phishing #infosec #InstallFix #Redline stealer #Threat Intel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 06:11:33 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #Anthropic #Claude AI #ClickFix #cybersecurity #Fileless Malware #Google Ads Phishing #infosec #InstallFix #Redline stealer #Threat Intel
Daily CyberSecurity
The InstallFix Trap: Fake Claude AI Google Ads Drop Fileless RedLine Malware on Developers
Beware of InstallFix: Fake Claude AI Google Ads trick users into running fileless scripts that deploy RedLine Stealer to steal passwords and crypto.
⤷ Title: Fileless Python Malware Uses Humanitarian Lures to Deploy Full-Spectrum Surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 06:11:11 +0000
════════════════════════
⌗ Tags: #Malware #CRIL #Cyberespionage #Cyble #Fileless Malware #GitHub abuse #infosec #phishing #Pyarmor #Python Malware #social engineering #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 06:11:11 +0000
════════════════════════
⌗ Tags: #Malware #CRIL #Cyberespionage #Cyble #Fileless Malware #GitHub abuse #infosec #phishing #Pyarmor #Python Malware #social engineering #threat intelligence
Daily CyberSecurity
Fileless Python Malware Uses Humanitarian Lures to Deploy Full-Spectrum Surveillance
CRIL exposes a cyberespionage campaign using fake humanitarian aid forms to deploy fileless Python malware via GitHub for full-spectrum surveillance.
⤷ Title: CountLoader Malware Weaponizes EtherHiding to Deploy Stealth Crypto Clippers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 09:15:54 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #CountLoader #Crypto theft #Cryptocurrency Clipper #Cyber Security #EtherHiding #Fileless Malware #infosec #McAfee Labs #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 09:15:54 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #CountLoader #Crypto theft #Cryptocurrency Clipper #Cyber Security #EtherHiding #Fileless Malware #infosec #McAfee Labs #threat intelligence
Daily CyberSecurity
CountLoader Malware Weaponizes EtherHiding to Deploy Stealth Crypto Clippers
McAfee Labs exposes a massive CountLoader campaign using EtherHiding and AMSI bypass to drop stealthy cryptocurrency clippers. Secure your assets!
⤷ Title: Under the PyInstaller Mask: Point Wild Exposes XWorm V7.4 Stealth Loader and AMSI Bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:49:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection Plugins #AES Encrypted C2 Configuration #AMSI Bypass In_Memory Execution #Fileless Remote Administrative Trojan #Hidden System File Attributes #Point Wild Threat Intelligence #PyInstaller Loader Forensic #Runtime Windows API Resolving #Win.Kernel_Svc_AJ8iOw.exe #XWorm V7.4 Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:49:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection Plugins #AES Encrypted C2 Configuration #AMSI Bypass In_Memory Execution #Fileless Remote Administrative Trojan #Hidden System File Attributes #Point Wild Threat Intelligence #PyInstaller Loader Forensic #Runtime Windows API Resolving #Win.Kernel_Svc_AJ8iOw.exe #XWorm V7.4 Malware
Information Security News
Under the PyInstaller Mask: Point Wild Exposes XWorm V7.4 Stealth Loader and AMSI Bypass - Information Security News
Threat intelligence architects at Point Wild have dissectively mapped a contemporary XWorm V7.4 infection pipeline, demonstrating how a seemingly innocuous, Python-based installation package systematically mutates into a formidable remote administrative implant.…
⤷ Title: China-Linked Hackers Deploy “TencShell” Backdoor via Faux Web Font Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:45:33 +0000
════════════════════════
⌗ Tags: #Malware #Cato CTRL Threat Research #Donut Shellcode In_Memory Execution #Fileless Position_Independent Code #Rshell Framework Customization #State_Sponsored Cyber Espionage #Tencent API Impersonation #TencShell Backdoor Malware #Third_Party Identity Compromise #Web Font Masquerading #Windows Registry Persistence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:45:33 +0000
════════════════════════
⌗ Tags: #Malware #Cato CTRL Threat Research #Donut Shellcode In_Memory Execution #Fileless Position_Independent Code #Rshell Framework Customization #State_Sponsored Cyber Espionage #Tencent API Impersonation #TencShell Backdoor Malware #Third_Party Identity Compromise #Web Font Masquerading #Windows Registry Persistence
Information Security News
China-Linked Hackers Deploy "TencShell" Backdoor via Faux Web Font Files - Information Security News
In April 2026, threat intelligence specialists at Cato CTRL neutralized a sophisticated network intrusion attempt targeting a major multinational manufacturing enterprise. The adversaries sought to establish a persistent foothold within the corporate perimeter…
⤷ Title: Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 21 May 2026 10:18:11 +0000
════════════════════════
⌗ Tags: #Security #Malware #Microsoft #Cyber Attack #Cybersecurity #Fileless #LOLBIN #MSHTA #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 21 May 2026 10:18:11 +0000
════════════════════════
⌗ Tags: #Security #Malware #Microsoft #Cyber Attack #Cybersecurity #Fileless #LOLBIN #MSHTA #Vulnerability
Hackread
Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks
Despite Internet Explorer’s retirement, hackers are abusing the legacy MSHTA utility in stealthy fileless malware attacks targeting Windows users.
⤷ Title: In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
Daily CyberSecurity
In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
TrendAI exposes Banana RAT, a fileless banking trojan by SHADOW-WATER-063 that uses in-memory execution and fake UI overlays to hijack Pix-QR transfers.
⤷ Title: Global Malicious AI Installer Campaign Targets Developer Workstations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude Code #developer security #EclecticIQ #Fileless Malware #Gemini CLI #Infostealer Campaign #SEO Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude Code #developer security #EclecticIQ #Fileless Malware #Gemini CLI #Infostealer Campaign #SEO Poisoning
⤷ Title: Advanced Lazarus Memory-Only Toolset Deeply Analyzed by Fox-IT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 06:33:06 +0000
════════════════════════
⌗ Tags: #Malware #DPAPILoader #Fileless Malware #Fox_IT #Lazarus Group #Memory_Only Malware #RemotePE #RemotePELoader #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 06:33:06 +0000
════════════════════════
⌗ Tags: #Malware #DPAPILoader #Fileless Malware #Fox_IT #Lazarus Group #Memory_Only Malware #RemotePE #RemotePELoader #threat intelligence
Daily CyberSecurity
Advanced Lazarus Memory-Only Toolset Deeply Analyzed by Fox-IT
Fox-IT uncovers a sophisticated Lazarus memory-only toolset used to compromise financial firms via an evasive three-stage malware pipeline.
⤷ Title: PureLogs Info Stealer Campaign Exploits Trusted Windows Process
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:02:45 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #FortiGuard Labs #info_stealer #Phishing Campaign #Process Hollowing #PureLogs #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:02:45 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #FortiGuard Labs #info_stealer #Phishing Campaign #Process Hollowing #PureLogs #threat intelligence
Daily CyberSecurity
PureLogs Info Stealer Campaign Exploits Trusted Windows Process
FortiGuard Labs exposes a highly evasive PureLogs info stealer campaign utilizing process hollowing and fileless execution.
⤷ Title: Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 30 May 2026 17:13:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #AI #Artificial Intelligence #Claude Code #Cyber Attack #Cybersecurity #Developers #Fileless #Infostealer #SEO Poisoning
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 30 May 2026 17:13:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #AI #Artificial Intelligence #Claude Code #Cyber Attack #Cybersecurity #Developers #Fileless #Infostealer #SEO Poisoning
Hackread
Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users
Fake Anthropic websites are being used to target Claude Code users with a fileless infostealer campaign that steals browser credentials and evades detection.
⤷ Title: Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 10:46:42 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Scams and Fraud #Cyber Attack #Cybersecurity #Fileless #Fraud #PureLogs #Scam #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 10:46:42 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Scams and Fraud #Cyber Attack #Cybersecurity #Fileless #Fraud #PureLogs #Scam #Windows
Hackread
Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives
Hackers are using fake purchase order emails and process hollowing to deploy fileless PureLogs malware to steal Windows users' browser, crypto, and Discord data.
⤷ Title: Remcos RAT Delivered by a Steganographic Loader in Phishing Emails
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 06:12:01 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #India #K7 Security Labs #Loader_as_a_Service #phishing #Process Hollowing #Remcos RAT #steganographic loader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 06:12:01 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #India #K7 Security Labs #Loader_as_a_Service #phishing #Process Hollowing #Remcos RAT #steganographic loader
Daily CyberSecurity
Remcos RAT Delivered by a Steganographic Loader in Phishing Emails
A steganographic loader hides Remcos RAT inside a bitmap and runs it in memory. K7 ties the fileless campaign to India via fake GST lures.
⤷ Title: ValleyRAT Malware Hits Japanese and Chinese Users Through Email Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:21:55 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #Fileless Malware #LevelBlue #Remote Access Trojan #ValleyRAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:21:55 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #Fileless Malware #LevelBlue #Remote Access Trojan #ValleyRAT
Daily CyberSecurity
ValleyRAT Malware Hits Japanese and Chinese Users Through Email Attacks
At a glance Details Malware family ValleyRAT (Remote Access Trojan) Threat actor Often linked to SilverFox; attribution disputed and unconfirmed Targets Japanese and Chinese-speaking users, includ…
⤷ Title: Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
Daily CyberSecurity
Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
Malware family PureLog Stealer (delivered by the Veil#Drop framework) Threat actor Not attributed by Securonix Targets Windows users; victim count not disclosed Delivery vector Malicious JavaScrip…