⤷ Title: StealC V2: ThreatLabz Unveils the Evolution of a Stealthy Info-Stealer and Malware Loader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:35:49 +0000
════════════════════════
⌗ Tags: #Malware #Amadey #C2 Protocol #Credential Theft #Malware Analysis #MSI Loader #PowerShell Malware #RC4 Encryption #ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:35:49 +0000
════════════════════════
⌗ Tags: #Malware #Amadey #C2 Protocol #Credential Theft #Malware Analysis #MSI Loader #PowerShell Malware #RC4 Encryption #ThreatLabz
Daily CyberSecurity
StealC V2: ThreatLabz Unveils the Evolution of a Stealthy Info-Stealer and Malware Loader
ThreatLabz reveals StealC V2—an evolving info-stealer with encrypted C2, MSI and PowerShell payloads, and a rule-driven control panel for targeted attacks.
⤷ Title: Rockwell Automation Patches Privilege Escalation and Denial-of-Service Flaws Across FactoryTalk and ArmorStart Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 00:00:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_9067 #FactoryTalk #ICS security #MSI Repair #OT Security #privilege escalation #Rockwell Automation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 00:00:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_9067 #FactoryTalk #ICS security #MSI Repair #OT Security #privilege escalation #Rockwell Automation
Daily CyberSecurity
Rockwell Automation Patches Privilege Escalation and Denial-of-Service Flaws Across FactoryTalk and ArmorStart Systems
Rockwell patched a flaw (CVE-2025-9067) in FactoryTalk Linx allowing SYSTEM privilege escalation via MSI repair hijacking. Other flaws risk file deletion and DoS in ICS environments.
⤷ Title: Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:19:48 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #Cybercrime Marketplace #Ethereum Smart Contract #kaspersky #MSI Installer #Node.js Botnet #Tsundere
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:19:48 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #Cybercrime Marketplace #Ethereum Smart Contract #kaspersky #MSI Installer #Node.js Botnet #Tsundere
Daily CyberSecurity
Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace
Kaspersky exposed Tsundere, a Node.js botnet using an Ethereum smart contract for unkillable C2 updates. The system includes a cybercrime marketplace and spreads via fake MSI game installers for RCE.
⤷ Title: Early-Boot Attack: UEFI Flaw in ASRock, ASUS, & MSI Boards Lets Hackers Bypass OS Security via PCIe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASRock #ASUS #CVE_2025_14304 #DMA Protection #Gigabyte #Hardware Vulnerability #IOMMU #Motherboard Security #MSI #PCIe #UEFI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASRock #ASUS #CVE_2025_14304 #DMA Protection #Gigabyte #Hardware Vulnerability #IOMMU #Motherboard Security #MSI #PCIe #UEFI
Daily CyberSecurity
Early-Boot Attack: UEFI Flaw in ASRock, ASUS, & MSI Boards Lets Hackers Bypass OS Security via PCIe
A critical UEFI flaw in ASRock, ASUS, and MSI motherboards fails to enable IOMMU, allowing pre-boot memory access via PCIe devices.
⤷ Title: The Installer Trap: New SetupHijack Tool Bypasses Windows UAC via Race Conditions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 04:16:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Authenticode #Cybersecurity 2026 #MSBuild #MSI Exploitation #privilege escalation #Race Condition #red teaming #SetupHijack #UAC bypass #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 04:16:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Authenticode #Cybersecurity 2026 #MSBuild #MSI Exploitation #privilege escalation #Race Condition #red teaming #SetupHijack #UAC bypass #Windows Security
Information Security News
The Installer Trap: New SetupHijack Tool Bypasses Windows UAC via Race Conditions
SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows installer and update processes. It targets scenarios where privileged installers or upda…