⤷ Title: XWorm 6.0 Unleashed: New Variant Uses AMSI Bypass & Critical Process Trick to Evade Detection and Crash Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 08:08:28 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #Evasion #malware #persistence #RAT #Remote Access Trojan #XWorm #XWorm 6.0
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 08:08:28 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #Evasion #malware #persistence #RAT #Remote Access Trojan #XWorm #XWorm 6.0
Penetration Testing Tools
XWorm 6.0 Unleashed: New Variant Uses AMSI Bypass & Critical Process Trick to Evade Detection and Crash Systems
Netskope uncovers XWorm 6.0, a new variant using VBScript droppers, AMSI bypass, and critical process marking to evade detection and force system reboots if terminated.
⤷ Title: Plague Backdoor: New Linux Malware Infiltrates Authentication Stack, Evading Detection for a Year
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 03:23:20 +0000
════════════════════════
⌗ Tags: #Linux #Malware #Authentication #Backdoor #cybersecurity #Evasion #Linux malware #PAM #Plague #ssh #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 03:23:20 +0000
════════════════════════
⌗ Tags: #Linux #Malware #Authentication #Backdoor #cybersecurity #Evasion #Linux malware #PAM #Plague #ssh #threat intelligence
Penetration Testing Tools
Plague Backdoor: New Linux Malware Infiltrates Authentication Stack, Evading Detection for a Year
A new backdoor, Plague, disguised as a Linux PAM component, evaded detection for over a year. It grants attackers persistent SSH access and leaves no forensic trail.
⤷ Title: New PXA Stealer Campaign Hits 62 Countries with Stealthy DLL Sideloading and Telegram Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:21:09 +0000
════════════════════════
⌗ Tags: #Malware #cloudflare #cybersecurity #DLL Sideloading #evasion #Infostealer #malware #PXA Stealer #SentinelOne #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:21:09 +0000
════════════════════════
⌗ Tags: #Malware #cloudflare #cybersecurity #DLL Sideloading #evasion #Infostealer #malware #PXA Stealer #SentinelOne #Telegram
Daily CyberSecurity
New PXA Stealer Campaign Hits 62 Countries with Stealthy DLL Sideloading and Telegram Exfiltration
SentinelLABS and Beazley expose PXA Stealer, a Python-based infostealer campaign targeting 62 countries with stealthy DLL sideloading, decoy files, and Telegram-based data exfiltration.
⤷ Title: The Evolution of Evasion: Raspberry Robin Malware Upgrades with New Encryption & UAC Bypass Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:10:15 +0000
════════════════════════
⌗ Tags: #Malware #ChaCha20 #CVE_2024_38196 #cybersecurity #evasion #Local Privilege Escalation #malware #Obfuscation #Raspberry Robin #tor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:10:15 +0000
════════════════════════
⌗ Tags: #Malware #ChaCha20 #CVE_2024_38196 #cybersecurity #evasion #Local Privilege Escalation #malware #Obfuscation #Raspberry Robin #tor
Daily CyberSecurity
The Evolution of Evasion: Raspberry Robin Malware Upgrades with New Encryption & UAC Bypass Exploit
ThreatLabz reveals the evolution of Raspberry Robin malware, now featuring stronger encryption, complex obfuscation, and a new privilege escalation exploit to bypass detection.
⤷ Title: BYOVD Attack: A New AV Killer Exploits a Legitimate Driver to Neutralize Defenses for MedusaLocker Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:31:56 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AV Killer #Brazil #BYOVD #cybersecurity #evasion #MedusaLocker #ransomware #ThrottleStop.sys #Windows Kernel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:31:56 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AV Killer #Brazil #BYOVD #cybersecurity #evasion #MedusaLocker #ransomware #ThrottleStop.sys #Windows Kernel
Daily CyberSecurity
BYOVD Attack: A New AV Killer Exploits a Legitimate Driver to Neutralize Defenses for MedusaLocker Ransomware
A recent incident response operation in Brazil has revealed a stealthy and destructive threat abusing the trusted architecture of the Windows kernel. In its latest analysis, Kaspersky Labs exposed…
⤷ Title: DarkCloud Rises: New Fileless Stealer Uses PowerShell & Process Hollowing to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:01:00 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DarkCloud #evasion #fileless #Fortinet #Infostealer #malware #powershell #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:01:00 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DarkCloud #evasion #fileless #Fortinet #Infostealer #malware #powershell #Process Hollowing
Daily CyberSecurity
DarkCloud Rises: New Fileless Stealer Uses PowerShell & Process Hollowing to Evade Detection
Researchers from Fortinet’s FortiGuard Labs detected a new DarkCloud campaign deploying a stealthy, fileless payload through a sophisticated phishing and PowerShell-based attack chain. DarkCloud —…
⤷ Title: HijackLoader: The Stealthy Malware Loader Powering Modern Cyberattacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Sep 2025 02:00:32 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cybersecurity #evasion techniques #HijackLoader #Lumma Stealer #MaaS #malware loader #Malware_as_a_Service #Seqrite #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Sep 2025 02:00:32 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cybersecurity #evasion techniques #HijackLoader #Lumma Stealer #MaaS #malware loader #Malware_as_a_Service #Seqrite #threat intelligence
Daily CyberSecurity
HijackLoader: The Stealthy Malware Loader Powering Modern Cyberattacks
A new report reveals HijackLoader, a Malware-as-a-Service loader. It uses advanced evasion and anti-analysis techniques to deliver stealers and other payloads.
⤷ Title: The Art of Digital Evasion: How Attackers Hide in Plain Sight
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 08:35:29 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evasion #hacking #HP Wolf Security #Living_off_the_land #LOTL #Lumma Stealer #malware #Threat Actors #XWorm
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 08:35:29 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evasion #hacking #HP Wolf Security #Living_off_the_land #LOTL #Lumma Stealer #malware #Threat Actors #XWorm
Penetration Testing Tools
The Art of Digital Evasion: How Attackers Hide in Plain Sight
A new report from HP Wolf Security reveals how cybercriminals are using "living-off-the-land" tactics and hiding malware in images and SVG files to evade detection.
⤷ Title: LNK Stomping: Attackers Bypass Windows Security by Stripping the ‘Mark of the Web’
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
Daily CyberSecurity
LNK Stomping: Attackers Bypass Windows Security by Stripping the 'Mark of the Web'
A vulnerability dubbed "LNK Stomping" (CVE-2024-38217) is actively used to strip the 'Mark of the Web' from LNK files, bypassing Windows security policies.
⤷ Title: DarkCloud Stealer Evolves: New VB6 Obfuscation and Crypto Wallet Theft Make Malware More Dangerous Than Ever
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 00:26:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallets #cybersecurity #DarkCloud Stealer #eSentire #evasion #Infostealer #malware #Obfuscation #VB6
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 00:26:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallets #cybersecurity #DarkCloud Stealer #eSentire #evasion #Infostealer #malware #Obfuscation #VB6
Daily CyberSecurity
DarkCloud Stealer Evolves: New VB6 Obfuscation and Crypto Wallet Theft Make Malware More Dangerous Than Ever
A new DarkCloud infostealer variant uses VB6 obfuscation and anti-analysis techniques to steal credentials and crypto wallets from MetaMask, Exodus, and more.