⤷ Title: Sophisticated IIS Malware Targets South Korean Web Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 May 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 May 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
Daily CyberSecurity
Sophisticated IIS Malware Targets South Korean Web Servers
A sophisticated campaign deployed malicious IIS modules on South Korean web servers, enabling traffic control and backdoor access. Suspected Chinese actor.
⤷ Title: Atomic Stealer Malware Targets macOS Users with Fake Evernote Crack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 10 May 2025 00:10:25 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Atomic Stealer #cybersecurity #Evernote #Information stealing #macOS #malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 10 May 2025 00:10:25 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Atomic Stealer #cybersecurity #Evernote #Information stealing #macOS #malware
Daily CyberSecurity
Atomic Stealer Malware Targets macOS Users with Fake Evernote Crack
Atomic Stealer malware is targeting macOS users, disguised as a cracked Evernote download, stealing passwords and data.
⤷ Title: Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
Daily CyberSecurity
Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
A sophisticated malware campaign targets Korean Internet cafés with Gh0st RAT and CoinMiner, hijacking systems for crypto mining. ASEC urges immediate action.
⤷ Title: ViperSoftX Resurfaces: Stealthy Crypto-Stealing Malware Hits Global Users!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Jun 2025 00:21:22 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ClipBanker #cryptocurrency #Cybercrime #malware #powershell #PureCrypter #PureHVNC #Quasar RAT #security alert #TesseractStealer #ViperSoftX
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Jun 2025 00:21:22 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ClipBanker #cryptocurrency #Cybercrime #malware #powershell #PureCrypter #PureHVNC #Quasar RAT #security alert #TesseractStealer #ViperSoftX
Daily CyberSecurity
ViperSoftX Resurfaces: Stealthy Crypto-Stealing Malware Hits Global Users!
ViperSoftX, a stealthy malware, is actively spreading via fake software to steal cryptocurrency and enable remote control, affecting users globally.
⤷ Title: Kimsuky APT Group Abuses HWP and AnyDesk for Covert Remote Surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Jun 2025 00:01:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #AnyDesk #APT #ASEC #backdoor #cybersecurity #dropbox #HWP #Kimsuky #living_off_the_land #North Korea #phishing #Remote Access #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Jun 2025 00:01:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #AnyDesk #APT #ASEC #backdoor #cybersecurity #dropbox #HWP #Kimsuky #living_off_the_land #North Korea #phishing #Remote Access #spear_phishing
Daily CyberSecurity
Kimsuky APT Group Abuses HWP and AnyDesk for Covert Remote Surveillance
Kimsuky APT is using HWP documents and stealthy AnyDesk backdoors in a new phishing campaign to infiltrate systems under the guise of academic collaboration.
⤷ Title: MySQL Servers Under Attack: Threat Actors Exploiting UDFs to Inject Gh0stRAT, XWorm & Zoho Agents
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:30:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyberattack #cybersecurity #database security #Gh0stRAT #HpLoader #mysql #Remote Access Trojan #UDF #User Defined Functions #XWorm #Zoho ManageEngine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:30:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyberattack #cybersecurity #database security #Gh0stRAT #HpLoader #mysql #Remote Access Trojan #UDF #User Defined Functions #XWorm #Zoho ManageEngine
Daily CyberSecurity
MySQL Servers Under Attack: Threat Actors Exploiting UDFs to Inject Gh0stRAT, XWorm & Zoho Agents
Threat actors are actively compromising poorly managed MySQL servers, using UDFs to inject Gh0stRAT, XWorm, HpLoader, and legitimate Zoho agents for full system control and data theft.
⤷ Title: IIS & Linux Servers Hit by WogRAT, MeshAgent, & SuperShell Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 00:15:46 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #cyberattack #lateral movement #Linux #malware #MeshAgent #privilege escalation #south korea #SUPERSHELL #Web Shells #Windows IIS #WogRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 00:15:46 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #cyberattack #lateral movement #Linux #malware #MeshAgent #privilege escalation #south korea #SUPERSHELL #Web Shells #Windows IIS #WogRAT
Daily CyberSecurity
IIS & Linux Servers Hit by WogRAT, MeshAgent, & SuperShell Malware
ASEC uncovers sophisticated attacks targeting South Korean Windows IIS and Linux systems, deploying WogRAT, MeshAgent, and SuperShell for cyber-espionage and lateral movement.
⤷ Title: Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Linux #ASEC #cybersecurity #HoneyPot #malware #proxy #Remote Access #Sing_box #ssh #threat actor #Tinyproxy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Linux #ASEC #cybersecurity #HoneyPot #malware #proxy #Remote Access #Sing_box #ssh #threat actor #Tinyproxy
Daily CyberSecurity
Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations
ASEC uncovers attacks on Linux servers installing legitimate proxy software (TinyProxy, Sing-box) to hijack resources for covert operations, bypassing traditional malware detection.
⤷ Title: XwormRAT Resurfaces with Steganography-Powered Attack Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:08:48 +0000
════════════════════════
⌗ Tags: #Malware #.NET Loader #ASEC #cybersecurity #Image Hiding #malware #phishing #powershell #rat #Remote Access Trojan #steganography #XwormRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:08:48 +0000
════════════════════════
⌗ Tags: #Malware #.NET Loader #ASEC #cybersecurity #Image Hiding #malware #phishing #powershell #rat #Remote Access Trojan #steganography #XwormRAT
Daily CyberSecurity
XwormRAT Resurfaces with Steganography-Powered Attack Chain
ASEC uncovers XwormRAT delivered via phishing emails using steganography, hiding sophisticated .NET malware within JPG images for stealthy execution and full system control.
⤷ Title: Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
Daily CyberSecurity
Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
GeoServer's RCE flaw (CVE-2024-36401) is actively exploited to deploy NetCat reverse shells and XMRig CoinMiners on Windows/Linux, hijacking resources.
⤷ Title: YouTube Downloader Sites Are Now Hiding Proxyware to Hijack Your Bandwidth
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 Aug 2025 00:10:43 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Cybercrime #cybersecurity #internet bandwidth #malware #proxyware #social engineering #youtube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 Aug 2025 00:10:43 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Cybercrime #cybersecurity #internet bandwidth #malware #proxyware #social engineering #youtube
Daily CyberSecurity
YouTube Downloader Sites Are Now Hiding Proxyware to Hijack Your Bandwidth
A new report reveals that malicious YouTube video downloader sites are tricking users into installing Proxyware, a type of malware that hijacks network bandwidth.
⤷ Title: AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
Daily CyberSecurity
AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
ASEC exposed a flaw in Gunra Linux ransomware: its ChaCha20 keys are generated using an insecure time()/rand() seed, potentially allowing victims to brute-force decryption and recover files.
⤷ Title: Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
Daily CyberSecurity
Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
AhnLab exposed Beast ransomware (Monster evolution) as a new RaaS threat, with 16+ victims by August 2025. It uses ChaCha20 encryption, deletes Shadow Copies, and features a hidden GUI control panel.
⤷ Title: Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
Daily CyberSecurity
Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
AhnLab exposed Rhadamanthys Infostealer hiding in games built with the Ren'Py engine. It uses a fake 1M-second loading screen to distract victims while injecting malware via a malicious Python script.
⤷ Title: Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
Daily CyberSecurity
Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
ASEC exposed PatoRAT, a Delphi RAT that hijacks LogMeIn Resolve and PDQ Connect RMM tools. Attackers use maliciously configured installers disguised as 7-Zip/Notepad++ to gain full system control.
⤷ Title: New Yurei Ransomware Emerges: Go-Based Threat Uses ChaCha20-Poly1305 for Irreversible Double Extortion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Double Extortion #ECIES #Golang #Ransomware_as_a_Service #Yurei ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Double Extortion #ECIES #Golang #Ransomware_as_a_Service #Yurei ransomware
Daily CyberSecurity
New Yurei Ransomware Emerges: Go-Based Threat Uses ChaCha20-Poly1305 for Irreversible Double Extortion
Security researchers at AhnLab have identified Yurei, a newly emerging ransomware group first observed in early September 2025. The group operates with a classic double-extortion model, infiltrati…
⤷ Title: Trojanized VPN Installer Deploys NKNShell Backdoor, Using P2P Blockchain and MQTT Protocols for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:10:21 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain Protocol #Go malware #MQTT #NKNShell #P2P C2 #Supply Chain #VPN Installer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:10:21 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain Protocol #Go malware #MQTT #NKNShell #P2P C2 #Supply Chain #VPN Installer
Daily CyberSecurity
Trojanized VPN Installer Deploys NKNShell Backdoor, Using P2P Blockchain and MQTT Protocols for Covert C2
ASEC exposed a VPN supply chain attack deploying NKNShell, a Go-based backdoor that uses P2P NKN and MQTT for stealthy C2. The installer bypasses AMSI using AI-generated code and grants full remote access (MeshAgent, gs-netcat).
⤷ Title: Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
Daily CyberSecurity
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy "Smart Mining" Evasion
ASEC exposed PrintMiner, a Monero cryptominer spreading via USB LNK files. It uses DLL Side-Loading (printui.exe) and "Smart Mining" to suspend activity when games or Task Manager are opened.
⤷ Title: “React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
Daily CyberSecurity
“React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
A new, sophisticated malware campaign is sweeping across the internet, leveraging a recently disclosed vulnerability to install cryptocurrency-stealing software on unsuspecting servers. The AhnLab…
⤷ Title: Attackers Weaponize Legitimate RMM Tools via Fake PDFs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 02:12:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyber attacks #living_off_the_land #Malware Analysis #NinjaOne #NSIS #PDF Malware #phishing #RMM Abuse #ScreenConnect #SuperOps #Syncro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 02:12:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyber attacks #living_off_the_land #Malware Analysis #NinjaOne #NSIS #PDF Malware #phishing #RMM Abuse #ScreenConnect #SuperOps #Syncro
Daily CyberSecurity
Attackers Weaponize Legitimate RMM Tools via Fake PDFs
ASEC warns: Hackers abuse Syncro, SuperOps & NinjaOne RMM tools via fake PDF lures. Learn how this phishing campaign installs persistent backdoors.