⤷ Title: Google Dismantles UNC2814’s Global Espionage Network Fueled by Google Sheets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:00:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #C2 #China_nexus #Command and Control #cyber_espionage #Google Sheets API #Google Threat Intelligence Group #GRIDTIDE #infosec #Mandiant #Telecommunications Security #UNC2814
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:00:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #C2 #China_nexus #Command and Control #cyber_espionage #Google Sheets API #Google Threat Intelligence Group #GRIDTIDE #infosec #Mandiant #Telecommunications Security #UNC2814
Daily CyberSecurity
Google Dismantles UNC2814’s Global Espionage Network Fueled by Google Sheets
Google and Mandiant disrupt UNC2814, a China-nexus group using the GRIDTIDE backdoor to hide command-and-control traffic inside Google Sheets across 42 nations.
⤷ Title: Understanding Sliver C2 Framework: Beacon and Session Modes
════════════════════════
𐀪 Author: Allen Ace
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 14:14:47 GMT
════════════════════════
⌗ Tags: #penetration_testing #command_and_control #cybersecurity #security_research #ethical_hacking
════════════════════════
𐀪 Author: Allen Ace
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 14:14:47 GMT
════════════════════════
⌗ Tags: #penetration_testing #command_and_control #cybersecurity #security_research #ethical_hacking
Medium
Understanding Sliver C2 Framework: Beacon and Session Modes
Implant Architecture and Design Philosophy
⤷ Title: The Dark Side of Telegram: How Cybercriminals Weaponize Bot APIs for Stealthy Data Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 01:54:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #C2 Infrastructure #Cofense #Command and Control #cybersecurity #data exfiltration #infosec #malware #phishing #Telegram Bot API #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 01:54:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #C2 Infrastructure #Cofense #Command and Control #cybersecurity #data exfiltration #infosec #malware #phishing #Telegram Bot API #threat intelligence
Daily CyberSecurity
The Dark Side of Telegram: How Cybercriminals Weaponize Bot APIs for Stealthy Data Exfiltration
A new Cofense report reveals how hackers abuse legitimate Telegram Bot APIs to create stealthy Command and Control (C2) centers for data exfiltration.
⤷ Title: 2 Zero-Days in sliver! What if I found your Sliver payload?
════════════════════════
𐀪 Author: skove
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 20:39:50 GMT
════════════════════════
⌗ Tags: #red_teaming #bug_bounty #red_team #sliverc2 #command_and_control
════════════════════════
𐀪 Author: skove
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 20:39:50 GMT
════════════════════════
⌗ Tags: #red_teaming #bug_bounty #red_team #sliverc2 #command_and_control
Medium
2 Zero-Days in sliver! What if I found your Sliver payload?
I’ve been working on a feature to allow operators to move a running implant between servers on the fly; no fresh builds, no re-execution.
⤷ Title: Beyond the URL: How “Cookie-Gated” Web Shells Hide Silent RCE in Plain Sight
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:30:29 +0000
════════════════════════
⌗ Tags: #Malware #Command and Control #Cyber Security #File Integrity Monitoring #HTTP Cookies #infosec #Microsoft Defender #persistence #PHP Malware #rce #Stealth C2 #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:30:29 +0000
════════════════════════
⌗ Tags: #Malware #Command and Control #Cyber Security #File Integrity Monitoring #HTTP Cookies #infosec #Microsoft Defender #persistence #PHP Malware #rce #Stealth C2 #Web Shell
Daily CyberSecurity
Beyond the URL: How "Cookie-Gated" Web Shells Hide Silent RCE in Plain Sight
Microsoft Defender unmasks a stealthy PHP web shell hiding C2 logic in HTTP cookies. Learn how "cookie-gating" bypasses logs to maintain persistent RCE.
⤷ Title: The Open Vault: How a Flaw in the Rhadamanthys Control Panel Saved 70,000 Victims
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 08:10:08 +0000
════════════════════════
⌗ Tags: #Malware #API Vulnerability #C2 Server #Command and Control #cybersecurity #Infostealer #malware #Rhadamanthys #SANS CTI Summit 2026 #threat intelligence #Victim Notification
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 08:10:08 +0000
════════════════════════
⌗ Tags: #Malware #API Vulnerability #C2 Server #Command and Control #cybersecurity #Infostealer #malware #Rhadamanthys #SANS CTI Summit 2026 #threat intelligence #Victim Notification
Penetration Testing Tools
The Open Vault: How a Flaw in the Rhadamanthys Control Panel Saved 70,000 Victims
A vulnerability within the control panel of the Rhadamanthys infostealer unexpectedly provided a rare opportunity to safeguard victims,
⤷ Title: The Invisible Storefront: How Obfuscated PHP Scripts Hijack Joomla Sites for SEO Spam
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 09:07:16 +0000
════════════════════════
⌗ Tags: #Malware #Cloaking #Command and Control #Cyber Forensics #Index.php Hack #joomla #malware analysis #PHP Obfuscation #Search Engine Penalty #SEO Spam #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 09:07:16 +0000
════════════════════════
⌗ Tags: #Malware #Cloaking #Command and Control #Cyber Forensics #Index.php Hack #joomla #malware analysis #PHP Obfuscation #Search Engine Penalty #SEO Spam #web security
Penetration Testing Tools
The Invisible Storefront: How Obfuscated PHP Scripts Hijack Joomla Sites for SEO Spam
A website administrator utilizing the Joomla platform observed a perplexing phenomenon: myriad surreptitious links to third-party merchandise had
⤷ Title: Domain Fronting: Hiding C2 Behind CDNs
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:56:08 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #hacking #cybersecurity #command_and_control #domain_fronting
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:56:08 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #hacking #cybersecurity #command_and_control #domain_fronting
Medium
Domain Fronting: Hiding C2 Behind CDNs
What is Domain Fronting?
⤷ Title: Net Closed: Interpol’s Operation Ramz Bags 200 Cybercriminals and Smashes 53 Command Servers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:35:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Command and Control Server Seizure #Cybercrime Arrests 2026 #Human Trafficking Scam Network #Interpol Operation Ramz #Middle East Cyber Crime #Operation Red Card 2.0 #Operation Synergia III #Phishing_as_a_Service Node Dismantled #Private Sector Threat Intelligence #Sovereign Nation Law Enforcement
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:35:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Command and Control Server Seizure #Cybercrime Arrests 2026 #Human Trafficking Scam Network #Interpol Operation Ramz #Middle East Cyber Crime #Operation Red Card 2.0 #Operation Synergia III #Phishing_as_a_Service Node Dismantled #Private Sector Threat Intelligence #Sovereign Nation Law Enforcement
Information Security News
Net Closed: Interpol's Operation Ramz Bags 200 Cybercriminals and Smashes 53 Command Servers - Information Security News
Interpol has coordinated the apprehension of over 200 individuals implicated in a sophisticated cybercrime matrix operating across the Middle East and North Africa. Designated as Operation Ramz, the multi-jurisdictional law enforcement surge spanned 13...
⤷ Title: The Strategic Encroachment of Red Lamassu Across the Eurasian Telecommunications Landscape
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 06:37:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Black Lotus Labs threat intelligence #command and control infrastructure #DLL side loading vulnerability #JFMBackdoor Windows exploit #proxy network routing #PwC Threat Intelligence #Red Lamassu cyber espionage #Showboat Linux malware #state sponsored hacking Asia #telecom supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 06:37:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Black Lotus Labs threat intelligence #command and control infrastructure #DLL side loading vulnerability #JFMBackdoor Windows exploit #proxy network routing #PwC Threat Intelligence #Red Lamassu cyber espionage #Showboat Linux malware #state sponsored hacking Asia #telecom supply chain attack
Information Security News
Red Lamassu Cyber Espionage: Malware Targets Telecom Cores
State-backed Red Lamassu cyber espionage operations weaponize Showboat and JFMBackdoor malware to quietly penetrate and control telecom network infrastructure.
⤷ Title: Introducción a Sliver C2
════════════════════════
𐀪 Author: TheRealCiscoo
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 00:47:33 GMT
════════════════════════
⌗ Tags: #red_teaming #command_and_control #red_team #hacking #pentesting
════════════════════════
𐀪 Author: TheRealCiscoo
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 00:47:33 GMT
════════════════════════
⌗ Tags: #red_teaming #command_and_control #red_team #hacking #pentesting
⤷ Title: Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 06:30:20 +0000
════════════════════════
⌗ Tags: #Malware #Aeternum #Blockchain Botnet #Command and Control #Cryptojacking #Polygon #Telegram C2 #XMRig #XWorm
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 06:30:20 +0000
════════════════════════
⌗ Tags: #Malware #Aeternum #Blockchain Botnet #Command and Control #Cryptojacking #Polygon #Telegram C2 #XMRig #XWorm
Daily CyberSecurity
Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts
At a glance Malware family Aeternum (blockchain-based C2 botnet loader) Threat actor Unconfirmed; blockchain activity links to an operator using the moniker “LenAI” (suspected, not con…