⤷ Title: Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
Daily CyberSecurity
Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
Threat actors abuse Microsoft’s mavinject.exe to inject malicious DLLs into trusted processes, evading detection in stealthy APT campaigns.
⤷ Title: Sophisticated IIS Malware Targets South Korean Web Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 May 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 May 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
Daily CyberSecurity
Sophisticated IIS Malware Targets South Korean Web Servers
A sophisticated campaign deployed malicious IIS modules on South Korean web servers, enabling traffic control and backdoor access. Suspected Chinese actor.
⤷ Title: Atomic Stealer Malware Targets macOS Users with Fake Evernote Crack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 10 May 2025 00:10:25 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Atomic Stealer #cybersecurity #Evernote #Information stealing #macOS #malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 10 May 2025 00:10:25 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Atomic Stealer #cybersecurity #Evernote #Information stealing #macOS #malware
Daily CyberSecurity
Atomic Stealer Malware Targets macOS Users with Fake Evernote Crack
Atomic Stealer malware is targeting macOS users, disguised as a cracked Evernote download, stealing passwords and data.
⤷ Title: Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
Daily CyberSecurity
Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
A sophisticated malware campaign targets Korean Internet cafés with Gh0st RAT and CoinMiner, hijacking systems for crypto mining. ASEC urges immediate action.
⤷ Title: ViperSoftX Resurfaces: Stealthy Crypto-Stealing Malware Hits Global Users!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Jun 2025 00:21:22 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ClipBanker #cryptocurrency #Cybercrime #malware #powershell #PureCrypter #PureHVNC #Quasar RAT #security alert #TesseractStealer #ViperSoftX
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Jun 2025 00:21:22 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ClipBanker #cryptocurrency #Cybercrime #malware #powershell #PureCrypter #PureHVNC #Quasar RAT #security alert #TesseractStealer #ViperSoftX
Daily CyberSecurity
ViperSoftX Resurfaces: Stealthy Crypto-Stealing Malware Hits Global Users!
ViperSoftX, a stealthy malware, is actively spreading via fake software to steal cryptocurrency and enable remote control, affecting users globally.
⤷ Title: Kimsuky APT Group Abuses HWP and AnyDesk for Covert Remote Surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Jun 2025 00:01:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #AnyDesk #APT #ASEC #backdoor #cybersecurity #dropbox #HWP #Kimsuky #living_off_the_land #North Korea #phishing #Remote Access #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Jun 2025 00:01:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #AnyDesk #APT #ASEC #backdoor #cybersecurity #dropbox #HWP #Kimsuky #living_off_the_land #North Korea #phishing #Remote Access #spear_phishing
Daily CyberSecurity
Kimsuky APT Group Abuses HWP and AnyDesk for Covert Remote Surveillance
Kimsuky APT is using HWP documents and stealthy AnyDesk backdoors in a new phishing campaign to infiltrate systems under the guise of academic collaboration.
⤷ Title: MySQL Servers Under Attack: Threat Actors Exploiting UDFs to Inject Gh0stRAT, XWorm & Zoho Agents
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:30:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyberattack #cybersecurity #database security #Gh0stRAT #HpLoader #mysql #Remote Access Trojan #UDF #User Defined Functions #XWorm #Zoho ManageEngine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:30:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyberattack #cybersecurity #database security #Gh0stRAT #HpLoader #mysql #Remote Access Trojan #UDF #User Defined Functions #XWorm #Zoho ManageEngine
Daily CyberSecurity
MySQL Servers Under Attack: Threat Actors Exploiting UDFs to Inject Gh0stRAT, XWorm & Zoho Agents
Threat actors are actively compromising poorly managed MySQL servers, using UDFs to inject Gh0stRAT, XWorm, HpLoader, and legitimate Zoho agents for full system control and data theft.
⤷ Title: IIS & Linux Servers Hit by WogRAT, MeshAgent, & SuperShell Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 00:15:46 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #cyberattack #lateral movement #Linux #malware #MeshAgent #privilege escalation #south korea #SUPERSHELL #Web Shells #Windows IIS #WogRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 00:15:46 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #cyberattack #lateral movement #Linux #malware #MeshAgent #privilege escalation #south korea #SUPERSHELL #Web Shells #Windows IIS #WogRAT
Daily CyberSecurity
IIS & Linux Servers Hit by WogRAT, MeshAgent, & SuperShell Malware
ASEC uncovers sophisticated attacks targeting South Korean Windows IIS and Linux systems, deploying WogRAT, MeshAgent, and SuperShell for cyber-espionage and lateral movement.
⤷ Title: Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Linux #ASEC #cybersecurity #HoneyPot #malware #proxy #Remote Access #Sing_box #ssh #threat actor #Tinyproxy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Linux #ASEC #cybersecurity #HoneyPot #malware #proxy #Remote Access #Sing_box #ssh #threat actor #Tinyproxy
Daily CyberSecurity
Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations
ASEC uncovers attacks on Linux servers installing legitimate proxy software (TinyProxy, Sing-box) to hijack resources for covert operations, bypassing traditional malware detection.
⤷ Title: XwormRAT Resurfaces with Steganography-Powered Attack Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:08:48 +0000
════════════════════════
⌗ Tags: #Malware #.NET Loader #ASEC #cybersecurity #Image Hiding #malware #phishing #powershell #rat #Remote Access Trojan #steganography #XwormRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:08:48 +0000
════════════════════════
⌗ Tags: #Malware #.NET Loader #ASEC #cybersecurity #Image Hiding #malware #phishing #powershell #rat #Remote Access Trojan #steganography #XwormRAT
Daily CyberSecurity
XwormRAT Resurfaces with Steganography-Powered Attack Chain
ASEC uncovers XwormRAT delivered via phishing emails using steganography, hiding sophisticated .NET malware within JPG images for stealthy execution and full system control.