⤷ Title: Reversing EtherRAT: When Malware Uses the Blockchain for C2
════════════════════════
𐀪 Author: CHANDRA KANT BAURI
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 23:53:23 GMT
════════════════════════
⌗ Tags: #reverse_engineering #threat_intelligence #malware_analysis #infosec #malware
════════════════════════
𐀪 Author: CHANDRA KANT BAURI
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 23:53:23 GMT
════════════════════════
⌗ Tags: #reverse_engineering #threat_intelligence #malware_analysis #infosec #malware
Medium
Reversing EtherRAT: When Malware Uses the Blockchain for C2
A technical walkthrough of deobfuscating JavaScript, dumping EVM bytecode, and resolving blockchain command and control infrastructure.
⤷ Title: BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Malware #BdThemes #supply chain attack #Wordfence #wordpress security #XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Malware #BdThemes #supply chain attack #Wordfence #wordpress security #XSS
Daily CyberSecurity
BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins
At a Glance Malware family API-driven XSS supply chain implant (Biggopti banner abuse) Threat actor Suspected; linked to the ARVE and OptinMonster campaigns Targets WordPress sites running seven B…
⤷ Title: QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 07:02:09 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #FDMTP implant #FortiGuard Labs #QuickFox #supply chain attack #Twill Typhoon
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 07:02:09 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #FDMTP implant #FortiGuard Labs #QuickFox #supply chain attack #Twill Typhoon
Daily CyberSecurity
QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users
At a Glance Attribute Detail Malware family FDMTP implant (.NET, TouchSocket-based) Threat actor Suspected Twill Typhoon (not confirmed) Target / victims Windows users of QuickFox, mainly Chinese …
⤷ Title: Interlock Ransomware Abuses Volatility3 for Credential Theft
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:20:55 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #GOLD EMBRACE #Interlock ransomware #living off the land #Sophos #Volatility3
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:20:55 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #GOLD EMBRACE #Interlock ransomware #living off the land #Sophos #Volatility3
Daily CyberSecurity
Interlock Ransomware Abuses Volatility3 for Credential Theft
At a Glance Attribute Detail Malware family Interlock ransomware (double extortion) Threat actor Interlock, tracked by Sophos as GOLD EMBRACE (confirmed) Target / victims Critical infrastructure, …
⤷ Title: C3 — The Framework That Bypasses Everything
════════════════════════
𐀪 Author: Omri Baso
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:29:22 GMT
════════════════════════
⌗ Tags: #red_team #malware #hacking #cpp #evasion
════════════════════════
𐀪 Author: Omri Baso
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:29:22 GMT
════════════════════════
⌗ Tags: #red_team #malware #hacking #cpp #evasion
Medium
C3 — The Framework That Bypasses Everything
Hey, My name is Omri Baso I am a 28 years old Security Researcher from Israel — I like researching about Windows, Active Directory, Malware…
⤷ Title: Fake AI Tools Malware Targets Developers Through GitHub
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 07:42:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EtherHiding #Infostealer #MaaS #Netskope #Polygon #SmartLoader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 07:42:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EtherHiding #Infostealer #MaaS #Netskope #Polygon #SmartLoader
Daily CyberSecurity
Fake AI Tools Malware Targets Developers Through GitHub
At a glance Malware family MaaS infostealer delivered via SmartLoader (NodeJS strain among final payloads) Threat actor Operators behind TroyDen’s “lure factory” (suspected, not …
⤷ Title: DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 06:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #CountLoader #DeviceManager RAT #DOUBLECUP #EtherHiding #Loader_as_a_Service
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 06:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #CountLoader #DeviceManager RAT #DOUBLECUP #EtherHiding #Loader_as_a_Service
Daily CyberSecurity
DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT
At a Glance Attribute Detail Malware family DOUBLECUP (Loader-as-a-Service); payloads CountLoader 4.5p and DeviceManager RAT Threat actor Rognar, a Russian operator (confirmed by SOCRadar) Target …
⤷ Title: Anatomy of a Delivery-Stage Dropper: A JavaScript Malware Hidden Inside an ISO File
════════════════════════
𐀪 Author: Mohamed Sabry
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 06:55:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #infosec #malware_analysis #digital_forensics
════════════════════════
𐀪 Author: Mohamed Sabry
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 06:55:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #infosec #malware_analysis #digital_forensics
Medium
Anatomy of a Delivery-Stage Dropper: A JavaScript Malware Hidden Inside an ISO File
A digital forensics case study — how a fake “purchase order” almost bypassed Windows’ last line of defense
⤷ Title: MQTT (Message Queuing Telemetry Transport) -
════════════════════════
𐀪 Author: Aditya Singh (Elite Hacker 1337)
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 11:28:38 GMT
════════════════════════
⌗ Tags: #hacking #malware #cybersecurity #computer_science #red_team
════════════════════════
𐀪 Author: Aditya Singh (Elite Hacker 1337)
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 11:28:38 GMT
════════════════════════
⌗ Tags: #hacking #malware #cybersecurity #computer_science #red_team
Medium
Hacking ICS/SCADA : MQTT (Message Queuing Telemetry Transport)
“” is published by Aditya Singh (Elite Hacker 1337).
⤷ Title: VAD Stomping from Kernel R/W Primitive
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 21:15:00 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #malware #cybersecurity #infosec
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 21:15:00 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #malware #cybersecurity #infosec
Medium
VAD Stomping from Kernel R/W Primitive
Welcome to this new Medium post. In this one we will see how to walk the Windows VAD tree from a kernel R/W primitive, and how to abuse…