⤷ Title: ValleyRAT Malware Hits Japanese and Chinese Users Through Email Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:21:55 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #Fileless Malware #LevelBlue #Remote Access Trojan #ValleyRAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:21:55 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #Fileless Malware #LevelBlue #Remote Access Trojan #ValleyRAT
Daily CyberSecurity
ValleyRAT Malware Hits Japanese and Chinese Users Through Email Attacks
At a glance Details Malware family ValleyRAT (Remote Access Trojan) Threat actor Often linked to SilverFox; attribution disputed and unconfirmed Targets Japanese and Chinese-speaking users, includ…
⤷ Title: Native Messaging Backdoor Turns a Chrome Extension Into a Windows Threat
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 07:30:48 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Chrome extension #DLL side_loading #Native Messaging #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 07:30:48 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Chrome extension #DLL side_loading #Native Messaging #phishing
Daily CyberSecurity
Native Messaging Backdoor Turns a Chrome Extension Into a Windows Threat
At a Glance Malware type Native Messaging backdoor with a malicious Chrome extension Threat actor Unattributed Targets / victims Italian-language email recipients Delivery vector Phishing email po…
⤷ Title: 292 Fake GitHub Repositories Deliver BoryptGrab Infostealer to Windows Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:21:34 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #BoryptGrab #brand impersonation #DLL side_loading #github #Infostealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:21:34 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #BoryptGrab #brand impersonation #DLL side_loading #github #Infostealer
Daily CyberSecurity
292 Fake GitHub Repositories Deliver BoryptGrab Infostealer to Windows Users
At a Glance Malware family BoryptGrab-lineage in-memory infostealer Threat actor Unattributed; financially motivated, likely Russian-speaking Targets Opportunistic Windows users across sectors Del…
⤷ Title: HelloNet Campaign Abuses ViPNet Update System to Hit Russian Firms
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 07:13:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Chinese APT #DLL Sideloading #HelloNet #kaspersky #malware #russia #ViPNet
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 07:13:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Chinese APT #DLL Sideloading #HelloNet #kaspersky #malware #russia #ViPNet
Daily CyberSecurity
HelloNet Campaign Abuses ViPNet Update System to Hit Russian Firms
At a glance Actor / group Suspected Chinese-speaking APT group (low confidence) Activity type Cyberespionage using malicious ViPNet update modules Targets / victims Large Russian government, energ…
⤷ Title: CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:30:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_57239 #DLL Sideloading #Foxit PDF reader #Local Privilege Escalation #proof_of_concept #SYSTEM privileges
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:30:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_57239 #DLL Sideloading #Foxit PDF reader #Local Privilege Escalation #proof_of_concept #SYSTEM privileges
Daily CyberSecurity
CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges
TL;DR A security researcher has published full details and proof-of-concept code for a Foxit PDF Reader vulnerability. Tracked as CVE-2026-57239, the flaw lets a local, unprivileged user gain NT A…
⤷ Title: TELESHIM Malware Targets Middle East Governments Through Telegram
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 08:01:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BINDCLOAK #DLL Sideloading #malware #Middle East #MIXEDKEY #Telegram C2 #TELESHIM #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 08:01:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BINDCLOAK #DLL Sideloading #malware #Middle East #MIXEDKEY #Telegram C2 #TELESHIM #Zscaler ThreatLabz
Daily CyberSecurity
TELESHIM Malware Targets Middle East Governments Through Telegram
At a glance Threat actor Unnamed group with links to East Asia (moderate-to-high confidence) Activity type Targeted intrusion and suspected espionage; DLL side-loading and Telegram C2 Targets / vi…
⤷ Title: JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 07:15:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #Beagle backdoor #China_nexus #DLL Sideloading #Group_IB #JadeProx #TriBack Loader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 07:15:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #Beagle backdoor #China_nexus #DLL Sideloading #Group_IB #JadeProx #TriBack Loader
Daily CyberSecurity
JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools
At a Glance Actor or group JadeProx, a China-nexus cluster named by Group-IB; no known group named Activity type Espionage-style intrusions, phishing, credential harvesting, tunnelling Targets A V…
⤷ Title: OceanLotus APT-C-00 Campaign Unleashes a Stealthy New Arsenal
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 14:16:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_00 #APT32 #cybersecurity #DLL Sideloading #OceanLotus
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 14:16:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_00 #APT32 #cybersecurity #DLL Sideloading #OceanLotus
Information Security News
OceanLotus APT-C-00 Campaign Unleashes a Stealthy New Arsenal
An ordinary email attachment can serve as the perilous gateway to a sophisticated attack chain when a meticulously crafted toolkit lurks behind a seemingly benign document. Recently, analysts at 3…
⤷ Title: SilverFox ValleyRAT Campaign Adds Three BYOVD Drivers to Kill Security Tools
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 06:16:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cato CTRL #DLL Sideloading #Japan #PDFCORE8.dll #Silver Fox APT #SilverFox #ValleyRAT #vulnerable drivers #Winos 4.0
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 06:16:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cato CTRL #DLL Sideloading #Japan #PDFCORE8.dll #Silver Fox APT #SilverFox #ValleyRAT #vulnerable drivers #Winos 4.0
Daily CyberSecurity
SilverFox ValleyRAT Campaign Adds Three BYOVD Drivers to Kill Security Tools
At a Glance Actor / group SilverFox (Silver Fox), a China-aligned APT tracked since about 2022 Activity type Targeted malware campaign: phishing, DLL sideloading, and BYOVD delivering ValleyRAT Ta…
⤷ Title: SilverFox ValleyRAT Attack Targets Japanese Industry via Phishing
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:38:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #DLL Sideloading #phishing attack #SilverFox #ValleyRAT
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:38:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #DLL Sideloading #phishing attack #SilverFox #ValleyRAT
Information Security News
SilverFox ValleyRAT Attack Targets Japanese Industry via Phishing
Even a seemingly mundane invoice can initiate a devastatingly complex infection chain. Recently, the notorious SilverFox threat actor orchestrated this precise deceptive scheme against a prominent…
⤷ Title: OctLurk and SilkLurk Backdoors Hit Central Asian Government Networks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 08:11:03 +0000
════════════════════════
⌗ Tags: #Malware #Central Asia Cyberattack #Chinese APT #cyber_espionage #DLL Sideloading #Kaspersky GReAT #OctLurk #PlugX #SilkLurk
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 08:11:03 +0000
════════════════════════
⌗ Tags: #Malware #Central Asia Cyberattack #Chinese APT #cyber_espionage #DLL Sideloading #Kaspersky GReAT #OctLurk #PlugX #SilkLurk
Daily CyberSecurity
OctLurk and SilkLurk Backdoors Hit Central Asian Government Networks
At a glance Field Detail Malware family OctLurk (plugin-based backdoor); SilkLurk (plugin-based backdoor); LurkProxy (network proxy utility) Threat actor Unknown group; assessed with medium confid…
⤷ Title: QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 07:02:09 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #FDMTP implant #FortiGuard Labs #QuickFox #supply chain attack #Twill Typhoon
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 07:02:09 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #FDMTP implant #FortiGuard Labs #QuickFox #supply chain attack #Twill Typhoon
Daily CyberSecurity
QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users
At a Glance Attribute Detail Malware family FDMTP implant (.NET, TouchSocket-based) Threat actor Suspected Twill Typhoon (not confirmed) Target / victims Windows users of QuickFox, mainly Chinese …