⤷ Title: Kimsuky APT Uses JavaScript Loader and Certutil to Achieve Minute-by-Minute Persistence via Windows Scheduled Task
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:06:35 +0000
════════════════════════
⌗ Tags: #Malware #APT #Certutil #Espionage #JavaScript Loader #Kimsuky #living_off_the_land #Scheduled Task #Themes.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:06:35 +0000
════════════════════════
⌗ Tags: #Malware #APT #Certutil #Espionage #JavaScript Loader #Kimsuky #living_off_the_land #Scheduled Task #Themes.js
Daily CyberSecurity
Kimsuky APT Uses JavaScript Loader and Certutil to Achieve Minute-by-Minute Persistence via Windows Scheduled Task
Kimsuky APT is using a Themes.js JavaScript loader and certutil LOLBIN to gain minute-by-minute persistence via a Windows Scheduled Task. The APT is targeting think tanks for espionage.
⤷ Title: Inside the Rapid Evolution of the BlankGrabber Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:15:56 +0000
════════════════════════
⌗ Tags: #Malware #BlankGrabber #Browser Secrets #Certutil #Cyber Security #data exfiltration #Discord Security #github #info_stealer #Python Malware #Splunk Threat Research #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:15:56 +0000
════════════════════════
⌗ Tags: #Malware #BlankGrabber #Browser Secrets #Certutil #Cyber Security #data exfiltration #Discord Security #github #info_stealer #Python Malware #Splunk Threat Research #Telegram C2
Daily CyberSecurity
Inside the Rapid Evolution of the BlankGrabber Stealer
Splunk unmasks BlankGrabber: a modular Python info stealer using Discord and GitHub to swipe credentials and Discord tokens. Learn how to stay protected.
⤷ Title: The Python Predator: PXA Stealer Surges 10% as it Targets Global Finance and Crypto in 2026
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 01:00:09 +0000
════════════════════════
⌗ Tags: #Malware #Certutil #Crypto Stealer #CyberProof #Financial Cyberattacks #infosec #Keylogging #LOLBins #Malware Analysis #phishing #PXA Stealer #Q1 2026 #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 01:00:09 +0000
════════════════════════
⌗ Tags: #Malware #Certutil #Crypto Stealer #CyberProof #Financial Cyberattacks #infosec #Keylogging #LOLBins #Malware Analysis #phishing #PXA Stealer #Q1 2026 #Telegram C2
Daily CyberSecurity
The Python Predator: PXA Stealer Surges 10% as it Targets Global Finance and Crypto in 2026
PXA Stealer activity surges in Q1 2026, targeting global finance. Learn how this Python-based malware uses Telegram and LOLBins to hijack crypto and banking data.
⤷ Title: Living Off The Registry: Master AD CS Enumeration with the Native LOLBAS Toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:38:36 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD CS #certreq.exe #certutil.exe #Credential Theft #LOLBAS #NET Framework #Pentesting #PowerShell #red teaming #RSAT #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:38:36 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD CS #certreq.exe #certutil.exe #Credential Theft #LOLBAS #NET Framework #Pentesting #PowerShell #red teaming #RSAT #Windows Security
Penetration Testing Tools
Living Off The Registry: Master AD CS Enumeration with the Native LOLBAS Toolkit
Exploit Active Directory Certificate Services using only built-in Windows tools. No 3rd-party binaries—just certreq, certutil, and native PowerShell power.