⤷ Title: Gamaredon’s PteroLNK Malware: Stealthy Espionage Tactics Uncovered
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 18 Apr 2025 00:22:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Cyberespionage #cybersecurity #Gamaredon #malware #PteroLNK #Ukraine #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 18 Apr 2025 00:22:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Cyberespionage #cybersecurity #Gamaredon #malware #PteroLNK #Ukraine #VBScript
Daily CyberSecurity
Gamaredon's PteroLNK Malware: Stealthy Espionage Tactics Uncovered
HarfangLab analysis details Gamaredon's PteroLNK malware, revealing its stealthy tactics and infrastructure used for espionage.
⤷ Title: Lampion Malware Returns with ClickFix Tactics to Target Portuguese Sectors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 May 2025 00:10:25 +0000
════════════════════════
⌗ Tags: #Malware #Infostealer #Malware Campaign #PowerShell Attacks #threat intelligence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 May 2025 00:10:25 +0000
════════════════════════
⌗ Tags: #Malware #Infostealer #Malware Campaign #PowerShell Attacks #threat intelligence #VBScript
Daily CyberSecurity
Lampion Malware Returns with ClickFix Tactics to Target Portuguese Sectors
Unit 42 uncovers a sophisticated Lampion malware campaign using ClickFix social engineering tactics to target government and financial sectors in Portugal.
⤷ Title: Horabot Malware Targets Latin America with Sophisticated Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:02:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AutoIt #Credential Theft #Fortinet #Horabot #Latin America #malware #Outlook COM #phishing #powershell #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:02:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AutoIt #Credential Theft #Fortinet #Horabot #Latin America #malware #Outlook COM #phishing #powershell #VBScript
Daily CyberSecurity
Horabot Malware Targets Latin America with Sophisticated Phishing
Horabot malware targets Latin America with fake invoices, hijacking Outlook to spread phishing emails and steal data via stealthy scripting.
⤷ Title: Obscure VBScript “sostener.vbs” Unmasked: Fuels Multi-Stage RAT Delivery, Linked to Blind Eagle APT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:18:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_36 #AsyncRAT #Blind Eagle #censys #cybersecurity #DCRat #LimeRAT #malware #Obfuscation #rat #Remcos #Remote Access Trojan #threat intelligence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:18:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_36 #AsyncRAT #Blind Eagle #censys #cybersecurity #DCRat #LimeRAT #malware #Obfuscation #rat #Remcos #Remote Access Trojan #threat intelligence #VBScript
Daily CyberSecurity
Obscure VBScript "sostener.vbs" Unmasked: Fuels Multi-Stage RAT Delivery, Linked to Blind Eagle APT
Censys uncovers "sostener.vbs," an obfuscated VBScript launching a multi-stage RAT delivery pipeline, affecting dozens and potentially linked to Blind Eagle APT.
⤷ Title: Batavia Spyware Unmasked: Covert Campaign Hits Russian Industrial & Scientific Orgs via Phishing Emails
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:51:32 +0000
════════════════════════
⌗ Tags: #Malware #Batavia #C++ #Cyber Espionage #Delphi #Industrial Sector #Kaspersky Lab #phishing #Russia #Scientific Organizations #Spyware #UAC bypass #VBScript
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:51:32 +0000
════════════════════════
⌗ Tags: #Malware #Batavia #C++ #Cyber Espionage #Delphi #Industrial Sector #Kaspersky Lab #phishing #Russia #Scientific Organizations #Spyware #UAC bypass #VBScript
Penetration Testing Tools
Batavia Spyware Unmasked: Covert Campaign Hits Russian Industrial & Scientific Orgs via Phishing Emails
Kaspersky uncovers Batavia, a new spyware hitting Russian industrial/scientific orgs since July 2024. It uses VBS scripts, WebView.exe, and javav.exe to steal data and maintain persistence.
⤷ Title: The End of an Era: Microsoft Is Finally Killing VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 03:53:34 +0000
════════════════════════
⌗ Tags: #Windows #deprecation #it #Microsoft #scripting #Technology #VBScript #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 03:53:34 +0000
════════════════════════
⌗ Tags: #Windows #deprecation #it #Microsoft #scripting #Technology #VBScript #windows
Daily CyberSecurity
The End of an Era: Microsoft Is Finally Killing VBScript
After almost 30 years, Microsoft is retiring VBScript. The legacy language will be phased out of Windows by 2027, posing a challenge for enterprises.
⤷ Title: Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
Daily CyberSecurity
Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
BitSight uncovered a Lampion banking Trojan campaign using ClickFix lures and a 700MB bloatware DLL to evade AV. The VBScript loader establishes persistence via the Windows Startup folder.
⤷ Title: Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
Daily CyberSecurity
Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
Cybereason exposed Tangerine Turkey, a VBScript worm that spreads via USB drives. It uses LOLBins (printui.exe) and Windows Defender exclusions to deploy the XMRig cryptominer for profit.
⤷ Title: Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
Daily CyberSecurity
Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
Researchers at Palo Alto Networks Unit 42 have uncovered two expansive and interconnected malware campaigns active throughout 2025, both designed to mass-distribute Gh0st RAT variants to Chinese-s…
⤷ Title: Sophisticated WhatsApp Worm Uses Fake “View Once” Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
Daily CyberSecurity
Sophisticated WhatsApp Worm Uses Fake "View Once" Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
Sophos exposed STAC3150, a campaign using fake "View Once" messages to deploy Astaroth banking trojan. The malware hijacks WhatsApp Web sessions via WPPConnect/Selenium for self-propagation.
⤷ Title: The Invisible Edge: APT28’s “Operation MacroMaze” Hijacks Browsers via Webhook Lures
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 07:31:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #Central Europe #Cyber Espionage #INCLUDEPICTURE #LAB52 #Microsoft Edge headless #Operation MacroMaze #S2 Grupo #Spear Phishing #Tech News 2026 #VBScript #webhook.site #Western Europe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 07:31:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #Central Europe #Cyber Espionage #INCLUDEPICTURE #LAB52 #Microsoft Edge headless #Operation MacroMaze #S2 Grupo #Spear Phishing #Tech News 2026 #VBScript #webhook.site #Western Europe
Penetration Testing Tools
The Invisible Edge: APT28’s "Operation MacroMaze" Hijacks Browsers via Webhook Lures
The APT28 syndicate has orchestrated a series of surgical strikes against organizations across Western and Central Europe, employing
⤷ Title: Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain security #ClickFix #cybersecurity #EtherHiding #infosec #OCRFix Botnet #Russian Malware #smart contracts #threat intelligence #VBScript Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain security #ClickFix #cybersecurity #EtherHiding #infosec #OCRFix Botnet #Russian Malware #smart contracts #threat intelligence #VBScript Malware
Daily CyberSecurity
Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain
Cybersecurity researchers uncover OCRFix, a Russian-linked botnet using EtherHiding and fake CAPTCHAs to mask its C2 servers in blockchain smart contracts.