⤷ Title: New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
Daily CyberSecurity
New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
Darktrace exposed TAG-150, a new MaaS operator compromising 469+ US devices in months. The group uses ClickFix to trick victims into running malicious PowerShell that deploys the CastleLoader/CastleRAT backdoor.
⤷ Title: Albiriox: The Russian ‘MaaS’ Android Trojan Redefining Mobile Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Banking Trojan #Cleafy #cybersecurity #MaaS #mobile security #On_Device Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Banking Trojan #Cleafy #cybersecurity #MaaS #mobile security #On_Device Fraud
Daily CyberSecurity
Albiriox: The Russian 'MaaS' Android Trojan Redefining Mobile Fraud
Meet Albiriox, a new Russian Android banking Trojan sold as a service. Learn how its "AcVNC" tech enables on-device fraud against 400+ global apps.
⤷ Title: Albiriox: New Android MaaS Uses VNC for Covert Remote Bank Fraud
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:10:07 +0000
════════════════════════
⌗ Tags: #Malware #Albiriox #Android malware #cybersecurity #MaaS #Mobile Banking Fraud #RadzaRat #Remote Access Trojan #VNC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:10:07 +0000
════════════════════════
⌗ Tags: #Malware #Albiriox #Android malware #cybersecurity #MaaS #Mobile Banking Fraud #RadzaRat #Remote Access Trojan #VNC
Penetration Testing Tools
Albiriox: New Android MaaS Uses VNC for Covert Remote Bank Fraud
Against the backdrop of a surge in schemes involving the remote manipulation of infected devices, a new tool
⤷ Title: Matanbuchus 3.0 Downloader Pivots to Ransomware, Using Protobufs and QuickAssist for Stealth Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:28:12 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #evasion #MaaS #Matanbuchus 3.0 #Protobufs #QuickAssist #ransomware #Zscaler
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:28:12 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #evasion #MaaS #Matanbuchus 3.0 #Protobufs #QuickAssist #ransomware #Zscaler
Daily CyberSecurity
Matanbuchus 3.0 Downloader Pivots to Ransomware, Using Protobufs and QuickAssist for Stealth Access
Zscaler exposed Matanbuchus v3.0, a MaaS downloader pivoting to ransomware. The stealthy C++ malware uses Protobufs for C2, QuickAssist for access, and time-wasting loops to bypass sandboxes.
⤷ Title: GrayBravo MaaS Deploys CastleRAT Backdoor, Hiding C2 with Steam Profile Dead Drop Resolvers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleRAT #ClickFix #Dead Drop Resolver #GrayBravo #hospitality #logistics #MaaS #Steam C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleRAT #ClickFix #Dead Drop Resolver #GrayBravo #hospitality #logistics #MaaS #Steam C2
Daily CyberSecurity
GrayBravo MaaS Deploys CastleRAT Backdoor, Hiding C2 with Steam Profile Dead Drop Resolvers
GrayBravo MaaS uses CastleRAT to target logistics/hospitality. The RAT hides its C2 by using Steam Community profiles as Dead Drop Resolvers, bypassing network monitoring.
⤷ Title: Frogblight Android Banking Trojan Targets Turkey via Fake E-Gov Smishing and WebView
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:32:19 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #Coper #Frogblight #MaaS #smishing #spyware #Turkey #WebView
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:32:19 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #Coper #Frogblight #MaaS #smishing #spyware #Turkey #WebView
Daily CyberSecurity
Frogblight Android Banking Trojan Targets Turkey via Fake E-Gov Smishing and WebView
Frogblight, a new Android banking Trojan, is targeting Turkey via smishing with fake e-government apps. It uses WebView to steal credentials and is linked to the Coper MaaS family. It is being actively developed.
⤷ Title: SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
Daily CyberSecurity
SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
SantaStealer, a new MaaS info-stealer, is being aggressively marketed on the dark web. It's a BluelineStealer rebrand that uses C code and open-source libraries to steal crypto wallets and credentials, despite having amateur anti-analysis features.
⤷ Title: The Startup Stealer: How AI and Discord Powered the Arkanix MaaS Operation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:33:57 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Arkanix Stealer #Cyber Security #Discord C2 #infosec #Kaspersky Labs #LLM_Assisted Development #MaaS #Malware_as_a_Service #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:33:57 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Arkanix Stealer #Cyber Security #Discord C2 #infosec #Kaspersky Labs #LLM_Assisted Development #MaaS #Malware_as_a_Service #threat intelligence
Daily CyberSecurity
The Startup Stealer: How AI and Discord Powered the Arkanix MaaS Operation
Kaspersky exposes Arkanix Stealer, a fast-moving MaaS operation leveraging Discord, tiered subscriptions, and AI-assisted development for quick data theft.
⤷ Title: The Fake IT Threat: “TrustConnect” Malware-as-a-Service Masquerades as Legitimate RMM Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:11:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Malware #Cyber Security #DocConnect #infosec #MaaS #Malware_as_a_Service #Proofpoint #Redline stealer #RMM Abuse #TrustConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:11:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Malware #Cyber Security #DocConnect #infosec #MaaS #Malware_as_a_Service #Proofpoint #Redline stealer #RMM Abuse #TrustConnect
Daily CyberSecurity
The Fake IT Threat: "TrustConnect" Malware-as-a-Service Masquerades as Legitimate RMM Software
Proofpoint exposes TrustConnect, a new Malware-as-a-Service masquerading as an IT tool. The AI-assisted fake RMM software replaces dismantled threats.
⤷ Title: Industrialized Theft: GoldFactory Malware Hijacks Tax Season via Fake ‘Coretax’ Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:06:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Coretax Fraud #Gigabud.RAT #GoldFactory #Group_IB #MaaS #Malware_as_a_Service #MMRat #Mobile Banking Fraud #social engineering #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:06:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Coretax Fraud #Gigabud.RAT #GoldFactory #Group_IB #MaaS #Malware_as_a_Service #MMRat #Mobile Banking Fraud #social engineering #Vishing
Daily CyberSecurity
Industrialized Theft: GoldFactory Malware Hijacks Tax Season via Fake 'Coretax' Apps
Group-IB exposes an industrialized mobile banking fraud campaign in Indonesia. GoldFactory hackers use fake Coretax apps and Gigabud.RAT to drain accounts.