⤷ Title: TAG-124: A Deep Dive into the Traffic Distribution System Powering Malware Campaigns
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Wed, 05 Feb 2025 01:50:10 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #CleanUpLoader #D3F@ck Loader #Interlock #Rhysida #SocGholish #TA866/Asylum Ambuscade #TAG_124 #traffic distribution system
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Wed, 05 Feb 2025 01:50:10 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #CleanUpLoader #D3F@ck Loader #Interlock #Rhysida #SocGholish #TA866/Asylum Ambuscade #TAG_124 #traffic distribution system
Cybersecurity News
TAG-124: A Deep Dive into the Traffic Distribution System Powering Malware Campaigns
Uncover the TAG-124 traffic distribution system used by cybercriminals to spread malware, phishing pages, and fake browser updates.
⤷ Title: Intrinsec Links Eye Pyramid C2 to Ransomware Networks in New Infrastructure Mapping Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 02 May 2025 00:14:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #Cobalt Strike #Eye Pyramid #Intrinsec #RansomHub #Ransomware C2 #Rhysida #Vice Society
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 02 May 2025 00:14:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #Cobalt Strike #Eye Pyramid #Intrinsec #RansomHub #Ransomware C2 #Rhysida #Vice Society
Daily CyberSecurity
Intrinsec Links Eye Pyramid C2 to Ransomware Networks in New Infrastructure Mapping Report
Intrinsec reveals shared infrastructure between Eye Pyramid C2 and ransomware groups like Rhysida and Vice Society in new threat intelligence report.
⤷ Title: Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
Daily CyberSecurity
Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
Rhysida ransomware is abusing Microsoft Trusted Signing to deploy OysterLoader (IAT) via Bing/Teams malvertising. The gang leveraged 40+ certificates to sign malware, bypassing security filters.
⤷ Title: OysterLoader: Multi-Stage Loader Evolves to Evade Detection and Deliver Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:27:06 +0000
════════════════════════
⌗ Tags: #Malware #API hammering #Broomstick #C# malware #CleanUp #Custom LZMA #Malware Analysis #OysterLoader #Rhysida ransomware #Sekoia TDR #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:27:06 +0000
════════════════════════
⌗ Tags: #Malware #API hammering #Broomstick #C# malware #CleanUp #Custom LZMA #Malware Analysis #OysterLoader #Rhysida ransomware #Sekoia TDR #steganography
Daily CyberSecurity
OysterLoader: Multi-Stage Loader Evolves to Evade Detection and Deliver Ransomware
OysterLoader malware uses custom LZMA & steganography to evade tools. Linked to Rhysida ransomware, it hides in fake IT installers.
⤷ Title: Digital Terrorism in Oklahoma: Lucky Star Casino Chain Shuts Down as Tribes Refuse $700K Ransom
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:31:01 +0000
════════════════════════
⌗ Tags: #Malware #casino cyberattack #Cheyenne and Arapaho Tribes #digital forensics #Governor Reggie Wassana #Lucky Star Casino #Oklahoma gaming #ransom refusal #Rhysida ransomware #Tech News 2026 #tribal gaming security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:31:01 +0000
════════════════════════
⌗ Tags: #Malware #casino cyberattack #Cheyenne and Arapaho Tribes #digital forensics #Governor Reggie Wassana #Lucky Star Casino #Oklahoma gaming #ransom refusal #Rhysida ransomware #Tech News 2026 #tribal gaming security
Penetration Testing Tools
Digital Terrorism in Oklahoma: Lucky Star Casino Chain Shuts Down as Tribes Refuse $700K Ransom
Operations at one of the preeminent gaming establishments of the Cheyenne and Arapaho Tribes in Oklahoma, USA, have
⤷ Title: Microsoft Smashes “Fox Tempest” Cyber Syndicate Selling Cryptographic Cover for Ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:17:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Code Validation Bypass #Fox Tempest Malware Signing #Malvertising SEO Poisoning #Microsoft Artifact Signing Abuse #OpFauxSign Takedown #Phantom Azure Developer Tenancies #Rhysida Ransomware Deployment #Short_Lived 72_Hour Certificates #SignSpace Cloud Seizure #Vanilla Tempest Co_Conspirator
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:17:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Code Validation Bypass #Fox Tempest Malware Signing #Malvertising SEO Poisoning #Microsoft Artifact Signing Abuse #OpFauxSign Takedown #Phantom Azure Developer Tenancies #Rhysida Ransomware Deployment #Short_Lived 72_Hour Certificates #SignSpace Cloud Seizure #Vanilla Tempest Co_Conspirator
Penetration Testing Tools
Microsoft Smashes "Fox Tempest" Cyber Syndicate Selling Cryptographic Cover for Ransomware
Microsoft has initiated formal civil litigation against the fraudulent syndicate operating the Fox Tempest enterprise, an illicit infrastructure
⤷ Title: Microsoft Dismantles “Fox Tempest” Code-Signing Network Fueling Global Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 07:11:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Code_Signing Certificate #Cyber Security #Fox Tempest #infosec #Malware_Signing_as_a_Service #Microsoft DCU #MSaaS #Resecurity #Rhysida ransomware #Vanilla Tempest
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 07:11:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Code_Signing Certificate #Cyber Security #Fox Tempest #infosec #Malware_Signing_as_a_Service #Microsoft DCU #MSaaS #Resecurity #Rhysida ransomware #Vanilla Tempest
Daily CyberSecurity
Microsoft Dismantles "Fox Tempest" Code-Signing Network Fueling Global Ransomware
Microsoft's DCU and Resecurity have disrupted Fox Tempest, a major MSaaS ring that forged code-signing certificates for ransomware delivery.
⤷ Title: Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 08:33:14 +0000
════════════════════════
⌗ Tags: #Malware #Hive0163 #IBM X_Force #Interlock ransomware #InterlockRAT #JunkFiction #NodeSnake #ransomware ecosystem #Rhysida ransomware #Supper backdoor #Tomb crypter
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 08:33:14 +0000
════════════════════════
⌗ Tags: #Malware #Hive0163 #IBM X_Force #Interlock ransomware #InterlockRAT #JunkFiction #NodeSnake #ransomware ecosystem #Rhysida ransomware #Supper backdoor #Tomb crypter
Daily CyberSecurity
Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem
IBM X-Force links the Interlock and Rhysida ransomware ecosystem through shared malware like Supper, NodeSnake, and overlapping crypters.