⤷ Title: I Got Into Your Network Using a £5 Gift Card. Here’s What Your Red Team Should Check.
════════════════════════
𐀪 Author: I_AM_R00T
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 08:02:03 GMT
════════════════════════
⌗ Tags: #red_team #ethical_hacking #social_engineering #penetration_testing #lateral_movement
════════════════════════
𐀪 Author: I_AM_R00T
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 08:02:03 GMT
════════════════════════
⌗ Tags: #red_team #ethical_hacking #social_engineering #penetration_testing #lateral_movement
Medium
I Got Into Your Network Using a £5 Gift Card. Here’s What Your Red Team Should Check.
My imagination has been running on overdrive recently, and that intertwined with platforms I use for upskilling, it seems like I can’t slow…
⤷ Title: Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
Daily CyberSecurity
Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
ASEC exposed PatoRAT, a Delphi RAT that hijacks LogMeIn Resolve and PDQ Connect RMM tools. Attackers use maliciously configured installers disguised as 7-Zip/Notepad++ to gain full system control.
⤷ Title: AD Tradecraft: Certificate Services & Lateral Movement
════════════════════════
𐀪 Author: Hishamrazak
════════════════════════
ⴵ Time: Sat, 15 Nov 2025 17:44:19 GMT
════════════════════════
⌗ Tags: #lateral_movement #penetration_testing #windows #red_team #active_directory
════════════════════════
𐀪 Author: Hishamrazak
════════════════════════
ⴵ Time: Sat, 15 Nov 2025 17:44:19 GMT
════════════════════════
⌗ Tags: #lateral_movement #penetration_testing #windows #red_team #active_directory
Medium
AD Tradecraft: Certificate Services & Lateral Movement
I’m using one of the labs from vulnlab called shibuya for showcasing these techniques can be included in your real time engagement with…
⤷ Title: One Click, 42 Days: Akira Ransomware Used CAPTCHA Decoy to Destroy Cloud Backups and Cripple Storage Firm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:27:43 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #ClickFix #Cloud Backup Destruction #EDR Visibility #Howling Scorpius #lateral movement #SecTopRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:27:43 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #ClickFix #Cloud Backup Destruction #EDR Visibility #Howling Scorpius #lateral movement #SecTopRAT
Daily CyberSecurity
One Click, 42 Days: Akira Ransomware Used CAPTCHA Decoy to Destroy Cloud Backups and Cripple Storage Firm
A 42-day Akira ransomware attack started with one ClickFix CAPTCHA that deployed SectopRAT. The attackers went undetected despite EDRs, stealing 1 TB and deleting cloud storage backups.
⤷ Title: Sophisticated “The Gentlemen” Ransomware RaaS Emerges with XChaCha20 Encryption and 48 Victims in 3 Months
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Malware #Curve25519 #Cybereason #Double Extortion #lateral movement #RaaS #ransomware #The Gentlemen #XChaCha20
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Malware #Curve25519 #Cybereason #Double Extortion #lateral movement #RaaS #ransomware #The Gentlemen #XChaCha20
Daily CyberSecurity
Sophisticated "The Gentlemen" Ransomware RaaS Emerges with XChaCha20 Encryption and 48 Victims in 3 Months
Cybereason exposed The Gentlemen, a new, technically advanced Go-based RaaS using XChaCha20/Curve25519 crypto. The group claimed 48 victims in 3 months, leveraging WMI and PowerShell for propagation.
⤷ Title: BitlockMove: New PoC for Covert Lateral Movement via BitLocker DCOM Hijacking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:32:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BitlockMove #COM Hijacking #cybersecurity #DCOM #Defensive Telemetry #Lateral Movement #Proof of Concept #Red Team #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:32:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BitlockMove #COM Hijacking #cybersecurity #DCOM #Defensive Telemetry #Lateral Movement #Proof of Concept #Red Team #Windows Security
Penetration Testing Tools
BitlockMove: New PoC for Covert Lateral Movement via BitLocker DCOM Hijacking
"BitlockMove" PoC demonstrates a novel lateral movement technique abusing BitLocker DCOM/COM hijacking to execute code in a logged-in user's session without credential theft.
⤷ Title: LdrShuffle: Stealthy Code Execution via DLL EntryPoint Overwriting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:27:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Code Execution #Defensive Telemetry #DLL hijacking #Lateral Movement #LdrShuffle #Memory Injection #Red Team #Windows Loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:27:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Code Execution #Defensive Telemetry #DLL hijacking #Lateral Movement #LdrShuffle #Memory Injection #Red Team #Windows Loader
Penetration Testing Tools
LdrShuffle: Stealthy Code Execution via DLL EntryPoint Overwriting
"LdrShuffle" is a stealthy code execution technique that abuses the Windows Loader by overwriting a DLL's EntryPoint, enabling injection without creating new threads.
⤷ Title: DCOMRunAs: Covert Technique for Remote Code Execution in a Logged-on Session
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:31:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DCOM #DCOMRunAs #DLL hijacking #Lateral Movement #post_exploitation #remote code execution #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:31:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DCOM #DCOMRunAs #DLL hijacking #Lateral Movement #post_exploitation #remote code execution #Windows Security
Penetration Testing Tools
DCOMRunAs: Covert Technique for Remote Code Execution in a Logged-on Session
DCOMRunAs is a covert technique that exploits DCOM and DLL hijacking to execute payloads in the context of a remote, logged-on user's session without new process creation.
⤷ Title: FusterCluck PoC: Script Exploits RPC to Achieve Lateral Movement in Failover Clusters
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:23:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cluster API #Failover Cluster #FusterCluck #Lateral Movement #PoC #Red Team #RPC #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:23:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cluster API #Failover Cluster #FusterCluck #Lateral Movement #PoC #Red Team #RPC #Windows Security
Penetration Testing Tools
FusterCluck PoC: Script Exploits RPC to Achieve Lateral Movement in Failover Clusters
FusterCluck PoC exploits the Windows Cluster API over RPC to migrate cluster groups and achieve lateral movement across all nodes of a failover cluster.
⤷ Title: HTB CTF Write-Up: Dancing
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
Medium
HTB CTF Write-Up: Dancing
Hello, fellow nerds!