⤷ Title: AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
Daily CyberSecurity
AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
ASEC exposed a flaw in Gunra Linux ransomware: its ChaCha20 keys are generated using an insecure time()/rand() seed, potentially allowing victims to brute-force decryption and recover files.
⤷ Title: Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
Daily CyberSecurity
Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
AhnLab exposed Beast ransomware (Monster evolution) as a new RaaS threat, with 16+ victims by August 2025. It uses ChaCha20 encryption, deletes Shadow Copies, and features a hidden GUI control panel.
⤷ Title: Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
Daily CyberSecurity
Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
AhnLab exposed Rhadamanthys Infostealer hiding in games built with the Ren'Py engine. It uses a fake 1M-second loading screen to distract victims while injecting malware via a malicious Python script.
⤷ Title: Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
Daily CyberSecurity
Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
ASEC exposed PatoRAT, a Delphi RAT that hijacks LogMeIn Resolve and PDQ Connect RMM tools. Attackers use maliciously configured installers disguised as 7-Zip/Notepad++ to gain full system control.
⤷ Title: New Yurei Ransomware Emerges: Go-Based Threat Uses ChaCha20-Poly1305 for Irreversible Double Extortion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Double Extortion #ECIES #Golang #Ransomware_as_a_Service #Yurei ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Double Extortion #ECIES #Golang #Ransomware_as_a_Service #Yurei ransomware
Daily CyberSecurity
New Yurei Ransomware Emerges: Go-Based Threat Uses ChaCha20-Poly1305 for Irreversible Double Extortion
Security researchers at AhnLab have identified Yurei, a newly emerging ransomware group first observed in early September 2025. The group operates with a classic double-extortion model, infiltrati…
⤷ Title: Trojanized VPN Installer Deploys NKNShell Backdoor, Using P2P Blockchain and MQTT Protocols for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:10:21 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain Protocol #Go malware #MQTT #NKNShell #P2P C2 #Supply Chain #VPN Installer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:10:21 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain Protocol #Go malware #MQTT #NKNShell #P2P C2 #Supply Chain #VPN Installer
Daily CyberSecurity
Trojanized VPN Installer Deploys NKNShell Backdoor, Using P2P Blockchain and MQTT Protocols for Covert C2
ASEC exposed a VPN supply chain attack deploying NKNShell, a Go-based backdoor that uses P2P NKN and MQTT for stealthy C2. The installer bypasses AMSI using AI-generated code and grants full remote access (MeshAgent, gs-netcat).
⤷ Title: Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
Daily CyberSecurity
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy "Smart Mining" Evasion
ASEC exposed PrintMiner, a Monero cryptominer spreading via USB LNK files. It uses DLL Side-Loading (printui.exe) and "Smart Mining" to suspend activity when games or Task Manager are opened.
⤷ Title: “React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
Daily CyberSecurity
“React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
A new, sophisticated malware campaign is sweeping across the internet, leveraging a recently disclosed vulnerability to install cryptocurrency-stealing software on unsuspecting servers. The AhnLab…
⤷ Title: Attackers Weaponize Legitimate RMM Tools via Fake PDFs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 02:12:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyber attacks #living_off_the_land #Malware Analysis #NinjaOne #NSIS #PDF Malware #phishing #RMM Abuse #ScreenConnect #SuperOps #Syncro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 02:12:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyber attacks #living_off_the_land #Malware Analysis #NinjaOne #NSIS #PDF Malware #phishing #RMM Abuse #ScreenConnect #SuperOps #Syncro
Daily CyberSecurity
Attackers Weaponize Legitimate RMM Tools via Fake PDFs
ASEC warns: Hackers abuse Syncro, SuperOps & NinjaOne RMM tools via fake PDF lures. Learn how this phishing campaign installs persistent backdoors.
⤷ Title: The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:31:30 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #Dropbox Abuse #Kimsuky #LNK #Malware Analysis #powershell #Python backdoor #Task Scheduler #threat intelligence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:31:30 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #Dropbox Abuse #Kimsuky #LNK #Malware Analysis #powershell #Python backdoor #Task Scheduler #threat intelligence #VBScript
Daily CyberSecurity
The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors
ASEC uncovers Kimsuky’s evolved LNK-to-Python chain abusing Dropbox for stealthy persistence. Learn how to detect this complex multi-stage backdoor.