⤷ Title: UNC5174: Chinese Threat Actor Deploys New VShell RAT in Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:33:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese Threat Actor #cybersecurity #malware #threat actor #UNC5174 #VShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:33:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese Threat Actor #cybersecurity #malware #threat actor #UNC5174 #VShell
Daily CyberSecurity
UNC5174: Chinese Threat Actor Deploys New VShell RAT in Campaign
A new campaign by Chinese threat actor UNC5174 uses the VShell RAT. Sysdig TRT reports on the group's shift to open-source tools and evasion tactics.
⤷ Title: Operation DRAGONCLONE: China Mobile Tietong Hit by Advanced APT Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:27:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China Mobile Tietong #China_aligned threat actors #Cyberespionage #cybersecurity #DLL Sideloading #Earth Lamia #UNC5174 #VELETRIX #VShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:27:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China Mobile Tietong #China_aligned threat actors #Cyberespionage #cybersecurity #DLL Sideloading #Earth Lamia #UNC5174 #VELETRIX #VShell
Daily CyberSecurity
Operation DRAGONCLONE: China Mobile Tietong Hit by Advanced APT Attack
Seqrite Labs uncovers Operation DRAGONCLONE, a sophisticated APT campaign targeting China Mobile Tietong with VELETRIX and VShell malware.
⤷ Title: From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
Daily CyberSecurity
From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
JPCERT/CC details a sophisticated, ongoing malware campaign exploiting Ivanti Connect Secure (CVE-2025-0282, -22457) using MDifyLoader, Cobalt Strike, vshell, and Fscan for stealthy persistent access.
⤷ Title: A New Linux Malware Hides in Plain Sight by Weaponizing File Names
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 00:30:12 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 00:30:12 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
Daily CyberSecurity
A New Linux Malware Hides in Plain Sight by Weaponizing File Names
A new report reveals a dangerous Linux malware campaign that uses malicious filenames to execute a stealthy, fileless attack without the victim's knowledge.
⤷ Title: Weaponizing Filenames: Trellix Uncovers Stealthy Linux Malware Delivering VShell Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 02:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 02:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
Penetration Testing Tools
Weaponizing Filenames: Trellix Uncovers Stealthy Linux Malware Delivering VShell Backdoor
A new report reveals a dangerous Linux malware campaign that uses malicious filenames to execute a stealthy, fileless attack without the victim's knowledge.
⤷ Title: Stealth Innovation: LinkPro Linux Rootkit Hides via eBPF and Activates with Magic TCP Packet on Kubernetes Nodes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:28:28 +0000
════════════════════════
⌗ Tags: #Malware #eBPF #Kubernetes #LinkPro #Linux Rootkit #Magic Packet #Stealth C2 #TCP #VShell #XDP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:28:28 +0000
════════════════════════
⌗ Tags: #Malware #eBPF #Kubernetes #LinkPro #Linux Rootkit #Magic Packet #Stealth C2 #TCP #VShell #XDP
Penetration Testing Tools
Stealth Innovation: LinkPro Linux Rootkit Hides via eBPF and Activates with Magic TCP Packet on Kubernetes Nodes
Synacktiv exposed LinkPro, an advanced Linux rootkit using eBPF to cloak activity on Kubernetes nodes. It is activated by a "magic" TCP packet (window size 54321) to establish covert remote control.
⤷ Title: Cisco Talos Unmasks UAT-8302’s Global Government Espionage Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:01:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China_nexus #Cisco Talos #CloudSorcerer #Cyberespionage #Earth Estries #Microsoft Graph API #NetDraft #Nosy Door #Threat Intel #UAT_8302 #VShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:01:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China_nexus #Cisco Talos #CloudSorcerer #Cyberespionage #Earth Estries #Microsoft Graph API #NetDraft #Nosy Door #Threat Intel #UAT_8302 #VShell
Daily CyberSecurity
Cisco Talos Unmasks UAT-8302’s Global Government Espionage Network
Cisco Talos exposes UAT-8302, a China-linked APT group infiltrating governments via NetDraft and CloudSorcerer. Learn how they share tools with notorious APTs.
⤷ Title: UNK_MassTraction Exploits Roundcube Webmail to Hit University Physics Departments
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 14:03:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_aligned #CVE_2024_42009 #CVE_2025_49113 #cyber_espionage #IceCube #Roundcube #UNK_MassTraction #VShell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 14:03:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_aligned #CVE_2024_42009 #CVE_2025_49113 #cyber_espionage #IceCube #Roundcube #UNK_MassTraction #VShell
Daily CyberSecurity
UNK_MassTraction Exploits Roundcube Webmail to Hit University Physics Departments
At a glance Actor UNK_MassTraction — suspected China-aligned espionage cluster Activity Roundcube exploitation for credential theft, webshells, and the VShell backdoor Targets Physics and engineer…