⤷ Title: Neptune RAT: Advanced Malware Targets Windows with Destructive Capabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:44:24 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cyber Threat #cybersecurity #Data Theft #malware #Neptune RAT #ransomware #Remote Access Trojan #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:44:24 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cyber Threat #cybersecurity #Data Theft #malware #Neptune RAT #ransomware #Remote Access Trojan #windows
Daily CyberSecurity
Neptune RAT: Advanced Malware Targets Windows with Destructive Capabilities
CYFIRMA researchers discovered Neptune RAT, an advanced Remote Access Trojan targeting Windows. Learn about its destructive features, evasion techniques, and distribution methods.
⤷ Title: Lumma Stealer: Unpacking Its Evasive Tactics and Complex Infection Chains
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 23 Apr 2025 00:10:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #cybersecurity #Data Theft #DLL Sideloading #fake CAPTCHA #information stealer #Lumma Stealer #malware #Malware Distribution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 23 Apr 2025 00:10:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #cybersecurity #Data Theft #DLL Sideloading #fake CAPTCHA #information stealer #Lumma Stealer #malware #Malware Distribution
Daily CyberSecurity
Lumma Stealer: Unpacking Its Evasive Tactics and Complex Infection Chains
A deep dive into Lumma Stealer's sophisticated techniques: from fake CAPTCHAs to complex infection chains designed to evade detection and steal sensitive data.
⤷ Title: TransferLoader Malware Unmasked: IPFS-Enabled Loader Deploys Ransomware and Backdoors with Obfuscation Precision
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:33:00 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #backdoor #COM hijacking #IPFS C2 #malware loader #Morpheus ransomware #TransferLoader #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:33:00 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #backdoor #COM hijacking #IPFS C2 #malware loader #Morpheus ransomware #TransferLoader #Zscaler ThreatLabz
Daily CyberSecurity
TransferLoader Malware Unmasked: IPFS-Enabled Loader Deploys Ransomware and Backdoors with Obfuscation Precision
Zscaler reveals TransferLoader: a stealthy malware using IPFS and obfuscation to drop ransomware and backdoors. A new threat in the wild since 2025.
⤷ Title: Lyrix Ransomware: New Threat Emerges with Advanced Evasion Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:02:40 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cybercrime #cybersecurity #Cyfirma #data destruction #encryption #Lyrix Ransomware #malware #ransomware #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:02:40 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cybercrime #cybersecurity #Cyfirma #data destruction #encryption #Lyrix Ransomware #malware #ransomware #windows
Daily CyberSecurity
Lyrix Ransomware: New Threat Emerges with Advanced Evasion Tactics
A new ransomware strain, Lyrix, targets Windows systems with strong encryption, anti-analysis, and data destruction techniques. Learn how to protect your data.
⤷ Title: APT36 Unleashes Advanced Phishing Against Indian Defense Personnel: New Anti-Analysis Malware & NIC Impersonation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Jun 2025 04:17:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Anti_Analysis #APT36 #Cloudflare #Credential Theft #Cyberespionage #CYFIRMA #Defense #DLL Sideloading #India #Keylogging #malware #phishing #Transparent Tribe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Jun 2025 04:17:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Anti_Analysis #APT36 #Cloudflare #Credential Theft #Cyberespionage #CYFIRMA #Defense #DLL Sideloading #India #Keylogging #malware #phishing #Transparent Tribe
Penetration Testing Tools
APT36 Unleashes Advanced Phishing Against Indian Defense Personnel: New Anti-Analysis Malware & NIC Impersonation
APT36 is targeting Indian defense personnel with sophisticated phishing, using fake NIC documents and multi-layered malware to steal sensitive data and evade analysis.
⤷ Title: SLOW#TEMPEST: Advanced Obfuscation Evades Static Analysis With CFG & Indirect Calls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #CFG #Control Flow Graph #cybersecurity #DLL side_loading #malware #Obfuscation #Sandbox Evasion #SLOW#TEMPEST #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #CFG #Control Flow Graph #cybersecurity #DLL side_loading #malware #Obfuscation #Sandbox Evasion #SLOW#TEMPEST #threat intelligence #Unit 42
Daily CyberSecurity
SLOW#TEMPEST: Advanced Obfuscation Evades Static Analysis With CFG & Indirect Calls
Unit 42 exposes SLOW#TEMPEST, a new malware variant using advanced CFG obfuscation and indirect function calls to evade static analysis, making it nearly impossible to detect.
⤷ Title: New SquidLoader Variant Unleashed: Stealthy Malware Hits Hong Kong Financial Sector Undetected
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 02:18:07 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Analysis #APT #Cobalt Strike #cybersecurity #Evasion #Financial Sector #Hong Kong #malware #phishing #SquidLoader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 02:18:07 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Analysis #APT #Cobalt Strike #cybersecurity #Evasion #Financial Sector #Hong Kong #malware #phishing #SquidLoader
Penetration Testing Tools
New SquidLoader Variant Unleashed: Stealthy Malware Hits Hong Kong Financial Sector Undetected
A new, highly evasive SquidLoader malware variant is targeting Hong Kong's financial institutions via phishing, bypassing antivirus and deploying Cobalt Strike Beacons.
⤷ Title: ToneShell Backdoor Evolves With Anti-Analysis Tricks, Continues Targeting Myanmar
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:06:53 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #anti_analysis #backdoor #china #cyber_espionage #Intezer #malware #Mustang Panda #Myanmar #ToneShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:06:53 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #anti_analysis #backdoor #china #cyber_espionage #Intezer #malware #Mustang Panda #Myanmar #ToneShell
Daily CyberSecurity
ToneShell Backdoor Evolves With Anti-Analysis Tricks, Continues Targeting Myanmar
A new report reveals a ToneShell backdoor from Mustang Panda. The malware targets Myanmar and uses anti-analysis tricks to evade detection.
⤷ Title: CERT-UA Warns: New Espionage Campaign Distributes CABINETRAT Backdoor via Signal Messenger XLL Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:56:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anti_Analysis #Backdoor #CABINETRAT #CERT_UA #Cyber Espionage #Signal #UAC_0245 #Ukraine #XLL
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:56:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anti_Analysis #Backdoor #CABINETRAT #CERT_UA #Cyber Espionage #Signal #UAC_0245 #Ukraine #XLL
Penetration Testing Tools
CERT-UA Warns: New Espionage Campaign Distributes CABINETRAT Backdoor via Signal Messenger XLL Files
CERT-UA uncovered a campaign (UAC-0245) using Signal to deliver malicious XLL files and inject the full-featured CABINETRAT backdoor. The malware evades sandboxes by checking system specs.
⤷ Title: New Stealit Infostealer Abuses Node.js SEA Feature and Telegram C2 in Malware-as-a-Service Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:46:39 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #FortiGuard #Infostealer #Malware_as_a_Service #Node.js SEA #Stealit #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:46:39 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #FortiGuard #Infostealer #Malware_as_a_Service #Node.js SEA #Stealit #Telegram C2
Daily CyberSecurity
New Stealit Infostealer Abuses Node.js SEA Feature and Telegram C2 in Malware-as-a-Service Campaign
FortiGuard Labs identified a new Stealit malware variant abusing Node.js SEA for stealthy distribution. The campaign features a public C2 panel and uses Telegram for data exfiltration.
⤷ Title: Stealth Stealer: PhantomVAI Loader Uses Steganography in Images to Inject Katz Stealer and Evade Sandboxes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 02:27:02 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #C++ #Katz Stealer #Malware_as_a_Service #PhantomVAI Loader #phishing #Process Hollowing #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 02:27:02 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #C++ #Katz Stealer #Malware_as_a_Service #PhantomVAI Loader #phishing #Process Hollowing #steganography
Daily CyberSecurity
Stealth Stealer: PhantomVAI Loader Uses Steganography in Images to Inject Katz Stealer and Evade Sandboxes
Unit 42 exposed PhantomVAI Loader, a stealthy MaaS tool that uses steganography (hiding DLL in images) and VM detection to deploy Katz Stealer in MSBuild.exe and exfiltrate crypto credentials globally.
⤷ Title: Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
Daily CyberSecurity
Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
BitSight uncovered a Lampion banking Trojan campaign using ClickFix lures and a 700MB bloatware DLL to evade AV. The VBScript loader establishes persistence via the Windows Startup folder.
⤷ Title: New Cephalus Ransomware Uses Fake AES Keys and GoLang to Thwart Analysis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #anti_analysis #Cephalus #Fake AES Key #Golang #ransomware #RDP Brute Force #VirtualLock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #anti_analysis #Cephalus #Fake AES Key #Golang #ransomware #RDP Brute Force #VirtualLock
Daily CyberSecurity
New Cephalus Ransomware Uses Fake AES Keys and GoLang to Thwart Analysis
ASEC exposed Cephalus, a Go-based RaaS group attacking RDP. The malware uses VirtualLock, XOR encryption, and a fake AES key pattern to severely complicate memory and forensic analysis.
⤷ Title: Lumma Stealer Resurfaces After Doxxing with New Browser Fingerprinting to Target High-Value Victims
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:10:06 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #browser fingerprinting #doxxing #Infostealer #Lumma Stealer #Process injection #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:10:06 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #browser fingerprinting #doxxing #Infostealer #Lumma Stealer #Process injection #Trend Micro
Daily CyberSecurity
Lumma Stealer Resurfaces After Doxxing with New Browser Fingerprinting to Target High-Value Victims
Despite a recent doxxing attempt, Lumma Stealer has resurfaced, integrating browser fingerprinting into its C&C to collect WebGL/Canvas signatures for sandbox evasion and victim assessment.
⤷ Title: npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
Daily CyberSecurity
npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
Socket exposed a new npm attack (dino_reborn) using Adspect cloaking to hide behind a fake crypto CAPTCHA for victims, while showing a polished decoy site (Offlido) to researchers.