⤷ Title: Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
Daily CyberSecurity
Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
Cybereason exposed Tangerine Turkey, a VBScript worm that spreads via USB drives. It uses LOLBins (printui.exe) and Windows Defender exclusions to deploy the XMRig cryptominer for profit.
⤷ Title: AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
Daily CyberSecurity
AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
Oligo exposed ShadowRay 2.0, a massive, evolving campaign using AI-generated malware to turn 230K exposed Ray AI clusters into a self-propagating cryptomining and DDoS botnet.
⤷ Title: Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
Daily CyberSecurity
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy "Smart Mining" Evasion
ASEC exposed PrintMiner, a Monero cryptominer spreading via USB LNK files. It uses DLL Side-Loading (printui.exe) and "Smart Mining" to suspend activity when games or Task Manager are opened.
⤷ Title: React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:12:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptomining #CVE_2025_55182 #DevSecOps #GreyNoise #Patch Alert #React #React Server Components #Remote Code Execution #reverse shell #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:12:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptomining #CVE_2025_55182 #DevSecOps #GreyNoise #Patch Alert #React #React Server Components #Remote Code Execution #reverse shell #Web Security
Daily CyberSecurity
React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks
Critical React flaw CVE-2025-55182 (CVSS 10.0) under mass exploitation. Two IPs drive 56% of attacks deploying miners & shells. Upgrade to v19.0.1+ now.
⤷ Title: Study Finds ROME AI Agent Attempted Cryptomining Without Instructions
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 14:10:08 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #Machine Learning #Security #Agentic AI #AI #Ai Chatbot #arXiv #Cryptomining #Cybersecurity #Machine Le #ROME AI
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 14:10:08 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #Machine Learning #Security #Agentic AI #AI #Ai Chatbot #arXiv #Cryptomining #Cybersecurity #Machine Le #ROME AI
Hackread
Study Finds ROME AI Agent Attempted Cryptomining Without Instructions
A study found the ROME AI agent attempted cryptocurrency mining without instructions during training, raising questions about monitoring AI systems.
⤷ Title: The Crypto-Con: Unmasking the Multi-Layered “REF1695” Mining Operation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 03:00:20 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #CNB Bot #Cost Per Action Fraud #CPA Fraud #cryptomining #Elastic Security Labs #infosec #Malware Analysis #Monero #REF1695 #Themida #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 03:00:20 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #CNB Bot #Cost Per Action Fraud #CPA Fraud #cryptomining #Elastic Security Labs #infosec #Malware Analysis #Monero #REF1695 #Themida #XMRig
Daily CyberSecurity
The Crypto-Con: Unmasking the Multi-Layered "REF1695" Mining Operation
Elastic Security Labs unmasks REF1695, a threat actor using the CNB Bot and custom XMRig loaders for Monero mining and CPA fraud. Is your server a silent miner?
⤷ Title: Phorpiex’s New P2P Upgrade Makes This 15-Year-Old Botnet Unstoppable
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 08:16:41 +0000
════════════════════════
⌗ Tags: #Malware #Bitsight #botnet #cryptomining #cybersecurity #Hybrid C2 #infosec #LFI Scanning #P2P Malware #Phorpiex #RSA Encryption #Trik #Twizt
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 08:16:41 +0000
════════════════════════
⌗ Tags: #Malware #Bitsight #botnet #cryptomining #cybersecurity #Hybrid C2 #infosec #LFI Scanning #P2P Malware #Phorpiex #RSA Encryption #Trik #Twizt
Daily CyberSecurity
Phorpiex’s New P2P Upgrade Makes This 15-Year-Old Botnet Unstoppable
Bitsight unmasks the Phorpiex "Twizt" variant: a self-healing P2P botnet with RSA-encrypted payloads and LFI scanners. See how this 2011 threat stays relevant.
⤷ Title: Active Exploitation in the Wild: Critical Qinglong Bypasses Fuel Covert Cryptomining Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 01:01:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cryptomining #CVE_2026_3965 #CVE_2026_4047 #cybersecurity #Express.js #infosec #Qinglong #rce #Snyk #Task Management
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 01:01:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cryptomining #CVE_2026_3965 #CVE_2026_4047 #cybersecurity #Express.js #infosec #Qinglong #rce #Snyk #Task Management
Daily CyberSecurity
Active Exploitation in the Wild: Critical Qinglong Bypasses Fuel Covert Cryptomining Campaign
Snyk warns of active in-the-wild exploitation of the Qinglong platform. Two authentication bypass flaws grant attackers RCE to deploy .fullgc cryptominers.
⤷ Title: AI Honeypots Snare Decentralized Cryptominer Dropper
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 06:03:24 +0000
════════════════════════
⌗ Tags: #Malware #Akamai SIRT #cryptomining #Go malware #libp2p #Ollama Security #P2P Malware #threat intelligence #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 06:03:24 +0000
════════════════════════
⌗ Tags: #Malware #Akamai SIRT #cryptomining #Go malware #libp2p #Ollama Security #P2P Malware #threat intelligence #XMRig
Daily CyberSecurity
AI Honeypots Snare Decentralized Cryptominer Dropper
Akamai SIRT uncovers a new P2P cryptominer malware threat. Learn how Ollama endpoint attacks use decentralized libp2p networks to evade detection.
⤷ Title: AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:19:50 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Crypto #Amazon #Amazon Bedrock #Bedrock AI #Cryptomining #Cyber Attack #Cybersecurity #Darktrace #Malware #SSH #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:19:50 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Crypto #Amazon #Amazon Bedrock #Bedrock AI #Cryptomining #Cyber Attack #Cybersecurity #Darktrace #Malware #SSH #Vulnerability
Hackread
AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity.
⤷ Title: XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
Daily CyberSecurity
XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
At a glance Field Detail Malware family Modified XMRig 6.25.0 botnet implant (marked “PRIVATE VERSION FOR BOTNET”), cross-compiled with musl libc Threat actor Unidentified; campaign tr…