⤷ Title: HTB Labs — Tier 0— “Redeemer” Machine Walkthrough | By CyberAlp0
════════════════════════
𐀪 Author: Mohamed Maher
════════════════════════
ⴵ Time: Sat, 12 Apr 2025 14:33:32 GMT
════════════════════════
⌗ Tags: #in_memory_database #hackthebox_walkthrough #hackthebox_writeup #redis #web_application_security
════════════════════════
𐀪 Author: Mohamed Maher
════════════════════════
ⴵ Time: Sat, 12 Apr 2025 14:33:32 GMT
════════════════════════
⌗ Tags: #in_memory_database #hackthebox_walkthrough #hackthebox_writeup #redis #web_application_security
Medium
HTB Labs — Tier 0— “Redeemer” Machine Walkthrough | By CyberAlp0
Hey Folks, this is CyberAlp0. Welcome to a new walkthrough powered by HTB, Tier 0, named “Redeemer.” Redeemer focuses on many aspects and…
⤷ Title: SERPENTINE#CLOUD: Stealthy Malware Campaign Leverages Cloudflare Tunnels for In-Memory RAT Delivery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Cloudflare Tunnel #cybersecurity #GuLoader #In_Memory Execution #LNK File #malware #phishing #PureLogs Stealer #rat #Remcos #Remote Access Trojan #Revenge RAT #Securonix #SERPENTINE#CLOUD #Venom RAT #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Cloudflare Tunnel #cybersecurity #GuLoader #In_Memory Execution #LNK File #malware #phishing #PureLogs Stealer #rat #Remcos #Remote Access Trojan #Revenge RAT #Securonix #SERPENTINE#CLOUD #Venom RAT #XWorm
Daily CyberSecurity
SERPENTINE#CLOUD: Stealthy Malware Campaign Leverages Cloudflare Tunnels for In-Memory RAT Delivery
The SERPENTINE#CLOUD campaign exploits Cloudflare Tunnel subdomains and LNK files to deliver in-memory RATs like AsyncRAT and Remcos, evading detection.
⤷ Title: HTB Walkthrough : Reedemer(Redis)
════════════════════════
𐀪 Author: Ahmad Sopyan
════════════════════════
ⴵ Time: Mon, 18 Aug 2025 17:52:11 GMT
════════════════════════
⌗ Tags: #hackthebox #penetration_testing #cybersecurity #redis #in_memory_database
════════════════════════
𐀪 Author: Ahmad Sopyan
════════════════════════
ⴵ Time: Mon, 18 Aug 2025 17:52:11 GMT
════════════════════════
⌗ Tags: #hackthebox #penetration_testing #cybersecurity #redis #in_memory_database
Medium
HTB Walkthrough : Reedemer(Redis)
👋 Hallo CyberExplorer!
⤷ Title: Critical 10/10 Flaw in Redis Existed Undetected for 13 Years
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 08:40:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_49844 #cybersecurity #database #in_memory #Lua #redis #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 08:40:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_49844 #cybersecurity #database #in_memory #Lua #redis #vulnerability #zero_day
Penetration Testing Tools
Critical 10/10 Flaw in Redis Existed Undetected for 13 Years
A critical 10/10 RCE flaw (CVE-2025-49844) has been found in Redis. The flaw, active for 13 years, allows unauthenticated attackers to execute arbitrary code.
⤷ Title: Brazilian Banking Trojan Uses Python WhatsApp Worm and IMAP C2 for In-Memory Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:11:04 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt Loader #Brazilian Banking Trojan #IMAP C2 #In_Memory Injection #Python #WhatsApp Worm #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:11:04 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt Loader #Brazilian Banking Trojan #IMAP C2 #In_Memory Injection #Python #WhatsApp Worm #WPPConnect
Daily CyberSecurity
Brazilian Banking Trojan Uses Python WhatsApp Worm and IMAP C2 for In-Memory Credential Theft
K7 Labs exposed a Brazilian campaign using a Python WhatsApp worm for self-propagation. The in-memory AutoIt loader deploys a banking trojan that uses IMAP email as a covert C2 channel to steal banking credentials.
⤷ Title: Hamas-Affiliated APT Ashen Lepus Unveils AshTag Malware Suite for Wider Cyber-Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #.NET malware #APT #Ashen Lepus #AshTag #cyber_espionage #Hamas #In_Memory Execution #Rclone #WIRTE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #.NET malware #APT #Ashen Lepus #AshTag #cyber_espionage #Hamas #In_Memory Execution #Rclone #WIRTE
Daily CyberSecurity
Hamas-Affiliated APT Ashen Lepus Unveils AshTag Malware Suite for Wider Cyber-Espionage
Ashen Lepus (Hamas-APT) significantly evolved during the conflict, deploying the AshTag modular .NET malware suite. It uses in-memory execution and Rclone for stealthy cyber-espionage against diplomatic targets in the Middle East.
⤷ Title: Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
Daily CyberSecurity
Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
New campaign targets Ivanti EPMM with dormant in-memory backdoors. Attackers use CVE-2026-1281 to plant "sleeper" agents. Restart servers immediately.
⤷ Title: Operation DualScript Bypasses Defenses to Hijack Crypto and Cash
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 06:02:53 +0000
════════════════════════
⌗ Tags: #Malware #banking malware #Clipboard Hijacker #Crypto theft #cybersecurity #In_Memory Payloads #infosec #living_off_the_land #Operation DualScript #Remote Access Trojan #RetroRAT #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 06:02:53 +0000
════════════════════════
⌗ Tags: #Malware #banking malware #Clipboard Hijacker #Crypto theft #cybersecurity #In_Memory Payloads #infosec #living_off_the_land #Operation DualScript #Remote Access Trojan #RetroRAT #Windows Security
Daily CyberSecurity
Operation DualScript Bypasses Defenses to Hijack Crypto and Cash
Operation DualScript uses parallel execution to bypass defenses, hijacking crypto wallets and banking data via RetroRAT and clipboard swapping.
⤷ Title: The Stealthy Evolution of the DesckVB RAT Infection Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:34:25 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #C2 #cybersecurity #DesckVB RAT #Fileless Malware #In_Memory Attack #JavaScript Trojan #Lat61 #malware #powershell #Process Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:34:25 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #C2 #cybersecurity #DesckVB RAT #Fileless Malware #In_Memory Attack #JavaScript Trojan #Lat61 #malware #powershell #Process Hijacking
Daily CyberSecurity
The Stealthy Evolution of the DesckVB RAT Infection Chain
Lat61 Team uncovers DesckVB RAT, a stealthy 2026 Trojan using in-memory .NET loaders & JS obfuscation to hijack systems and evade AV. Learn how it works.
⤷ Title: New Stealth Attack Chain Weaponizes Legitimate Remote Access Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:21:28 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #Adobe Acrobat #cybersecurity #Fileless Malware #In_Memory Execution #infosec #ScreenConnect #UAC bypass #VBScript Loader #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:21:28 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #Adobe Acrobat #cybersecurity #Fileless Malware #In_Memory Execution #infosec #ScreenConnect #UAC bypass #VBScript Loader #Zscaler ThreatLabz
Daily CyberSecurity
New Stealth Attack Chain Weaponizes Legitimate Remote Access Software
Zscaler reveals a 2026 attack chain using fake Adobe Reader lures to install ScreenConnect via in-memory execution and UAC bypass. Protect your network now!
⤷ Title: Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 12:03:35 +0000
════════════════════════
⌗ Tags: #Malware #cyber_espionage #In_Memory Injection #infosec #Kazuar Backdoor #Microsoft Threat Intelligence #Module Election #P2P Botnet #Pelmeni Dropper #Secret Blizzard #turla
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 12:03:35 +0000
════════════════════════
⌗ Tags: #Malware #cyber_espionage #In_Memory Injection #infosec #Kazuar Backdoor #Microsoft Threat Intelligence #Module Election #P2P Botnet #Pelmeni Dropper #Secret Blizzard #turla
Daily CyberSecurity
Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem
Microsoft Threat Intelligence exposes a massive overhaul of the Kazuar backdoor. Secret Blizzard weaponizes a modular, multi-tiered P2P botnet.
⤷ Title: In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
Daily CyberSecurity
In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
TrendAI exposes Banana RAT, a fileless banking trojan by SHADOW-WATER-063 that uses in-memory execution and fake UI overlays to hijack Pix-QR transfers.