⤷ Title: SERPENTINE#CLOUD: Stealthy Malware Campaign Leverages Cloudflare Tunnels for In-Memory RAT Delivery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Cloudflare Tunnel #cybersecurity #GuLoader #In_Memory Execution #LNK File #malware #phishing #PureLogs Stealer #rat #Remcos #Remote Access Trojan #Revenge RAT #Securonix #SERPENTINE#CLOUD #Venom RAT #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Cloudflare Tunnel #cybersecurity #GuLoader #In_Memory Execution #LNK File #malware #phishing #PureLogs Stealer #rat #Remcos #Remote Access Trojan #Revenge RAT #Securonix #SERPENTINE#CLOUD #Venom RAT #XWorm
Daily CyberSecurity
SERPENTINE#CLOUD: Stealthy Malware Campaign Leverages Cloudflare Tunnels for In-Memory RAT Delivery
The SERPENTINE#CLOUD campaign exploits Cloudflare Tunnel subdomains and LNK files to deliver in-memory RATs like AsyncRAT and Remcos, evading detection.
⤷ Title: New JS#SMUGGLER Campaign Drops NetSupport RAT Through Infected Sites
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 18:16:40 +0000
════════════════════════
⌗ Tags: #Malware #Security #Cyber Attack #Cybersecurity #JS#SMUGGLER #NetSupport Manager #PowerShell #RAT #Securonix
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 18:16:40 +0000
════════════════════════
⌗ Tags: #Malware #Security #Cyber Attack #Cybersecurity #JS#SMUGGLER #NetSupport Manager #PowerShell #RAT #Securonix
Hackread
New JS#SMUGGLER Campaign Drops NetSupport RAT Through Infected Sites
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Fileless Evasion: Multi-Stage Campaign Deploys NetSupport RAT via Obfuscated HTA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:36:59 +0000
════════════════════════
⌗ Tags: #Malware #Corporate Attack #cybersecurity #Fileless Malware #HTA #JavaScript #NetSupport RAT #PowerShell #Remote Access Trojan #Securonix
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:36:59 +0000
════════════════════════
⌗ Tags: #Malware #Corporate Attack #cybersecurity #Fileless Malware #HTA #JavaScript #NetSupport RAT #PowerShell #Remote Access Trojan #Securonix
Penetration Testing Tools
Fileless Evasion: Multi-Stage Campaign Deploys NetSupport RAT via Obfuscated HTA
Researchers at Securonix have uncovered a multi-layered malware campaign designed to surreptitiously deploy the NetSupport RAT remote access
⤷ Title: The ClickFix Trap: PHALT#BLYX Targets Hotels with Fake Blue Screens and DCRat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 00:18:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Booking.com Scam #BSOD Malware #ClickFix #Cyber Espionage 2026 #DCRat #Hospitality Security #PHALT#BLYX #Securonix #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 00:18:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #Booking.com Scam #BSOD Malware #ClickFix #Cyber Espionage 2026 #DCRat #Hospitality Security #PHALT#BLYX #Securonix #social engineering
Daily CyberSecurity
The ClickFix Trap: PHALT#BLYX Targets Hotels with Fake Blue Screens and DCRat
A sophisticated new cyber-espionage campaign is targeting the hospitality industry, turning everyday booking management into a nightmare scenario. Securonix threat researchers have uncovered a ste…
⤷ Title: The ClickFix Trap: PHALT#BLYX Uses Fake BSODs to Hijack Hotel Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 08:44:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #BSOD #ClickFix #DcRAT #Hospitality Security #Living_off_the_land #MSBuild #PHALT#BLYX #PowerShell #Securonix #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 08:44:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #BSOD #ClickFix #DcRAT #Hospitality Security #Living_off_the_land #MSBuild #PHALT#BLYX #PowerShell #Securonix #Social Engineering
Information Security News
The ClickFix Trap: PHALT#BLYX Uses Fake BSODs to Hijack Hotel Systems
Notifications regarding Booking.com cancellations involving substantial financial transactions appear as mere routine for hospitality providers. Yet, such correspondence serves as the harbinger fo…
⤷ Title: SHADOW#REACTOR Malware Builds Remcos RAT via Text Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 00:27:15 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Fileless Malware #living_off_the_land #Malware Analysis #MSBuild #powershell #Remcos RAT #Securonix #SHADOW#REACTOR #Text_Based Payload
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 00:27:15 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Fileless Malware #living_off_the_land #Malware Analysis #MSBuild #powershell #Remcos RAT #Securonix #SHADOW#REACTOR #Text_Based Payload
Daily CyberSecurity
SHADOW#REACTOR Malware Builds Remcos RAT via Text Files
Securonix reveals SHADOW#REACTOR: A stealthy framework using "text-only" fragments to deploy Remcos RAT in memory via MSBuild. Avoids disk detection.
⤷ Title: Shadows in the RAM: The SHADOW#REACTOR Campaign Unleashes Remcos RAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 08:09:03 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #Cyber Security #Fileless Attack #LOLBins #Malware 2026 #MSBuild #PowerShell #Remcos RAT #Securonix #SHADOW#REACTOR #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 08:09:03 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #Cyber Security #Fileless Attack #LOLBins #Malware 2026 #MSBuild #PowerShell #Remcos RAT #Securonix #SHADOW#REACTOR #threat intelligence
Penetration Testing Tools
Shadows in the RAM: The SHADOW#REACTOR Campaign Unleashes Remcos RAT
Adversaries have orchestrated a sophisticated campaign utilizing a multi-stage infection vector to deploy the Remcos RAT, a remote
⤷ Title: The Self-Parsing Ghost: Inside Deep#Door’s Stealthy Python Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 08:15:01 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #bore.pub #Credential Theft #cybersecurity #Deep#Door #infosec #Malware Analysis #Python RAT #Remote Access Trojan #Securonix #TCP Tunneling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 08:15:01 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #bore.pub #Credential Theft #cybersecurity #Deep#Door #infosec #Malware Analysis #Python RAT #Remote Access Trojan #Securonix #TCP Tunneling
Daily CyberSecurity
The Self-Parsing Ghost: Inside Deep#Door’s Stealthy Python Backdoor
Meta Description (152 Characters)Securonix uncovers Deep#Door: a self-contained Python RAT that uses TCP tunneling and obfuscated scripts to bypass traditional defense. Secure your systems now.
⤷ Title: Attackers Hijack Trusted RMM Tools to Create Invisible, Permanent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 08:15:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #infosec #living_off_the_land #persistence #phishing #RMM Hijacking #Safe Mode #ScreenConnect #Securonix #SimpleHelp #social engineering #Threat Hunting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 08:15:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #infosec #living_off_the_land #persistence #phishing #RMM Hijacking #Safe Mode #ScreenConnect #Securonix #SimpleHelp #social engineering #Threat Hunting
Daily CyberSecurity
Attackers Hijack Trusted RMM Tools to Create Invisible, Permanent Backdoors
Securonix exposes an 80+ organization breach using "self-healing" RMM tools and Safe Mode persistence. Standard antivirus is blind—learn how to hunt it!
⤷ Title: Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
Daily CyberSecurity
Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
Malware family PureLog Stealer (delivered by the Veil#Drop framework) Threat actor Not attributed by Securonix Targets Windows users; victim count not disclosed Delivery vector Malicious JavaScrip…
⤷ Title: SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 08:02:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloudflare Tunnel #phishing #RMM Abuse #ScreenConnect #Securonix #SMOKE#SCREEN
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 08:02:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloudflare Tunnel #phishing #RMM Abuse #ScreenConnect #Securonix #SMOKE#SCREEN
Daily CyberSecurity
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
At a Glance Attribute Detail Actor / group Unattributed threat actor (tracked by Securonix as SMOKE#SCREEN) Activity type Multi-wave phishing and RMM abuse for remote access Targets / victims Wind…