⤷ Title: SocGholish and RansomHub: Sophisticated Attack Campaign Targeting Corporate Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 00:36:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #backdoor #cyberattack #eSentire #FakeUpdates #Infostealer #initial access #malware #Python #RansomHub #ransomware #SocGholish
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 00:36:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #backdoor #cyberattack #eSentire #FakeUpdates #Infostealer #initial access #malware #Python #RansomHub #ransomware #SocGholish
Daily CyberSecurity
SocGholish and RansomHub: Sophisticated Attack Campaign Targeting Corporate Networks
eSentire TRU discovers a campaign combining SocGholish malware with RansomHub affiliates, using fake updates and Python backdoors to compromise networks.
⤷ Title: New Malware Duo HijackLoader & DeerStealer Surge: Bypassing Defenses for Data Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:22:39 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cybersecurity #Data Theft #DeerStealer #eSentire #HijackLoader #malware #phishing #ransomware #social engineering #Threat Response Unit #TRU
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:22:39 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cybersecurity #Data Theft #DeerStealer #eSentire #HijackLoader #malware #phishing #ransomware #social engineering #Threat Response Unit #TRU
Daily CyberSecurity
New Malware Duo HijackLoader & DeerStealer Surge: Bypassing Defenses for Data Theft
HijackLoader and DeerStealer are surging, using ClickFix social engineering and sophisticated evasion to bypass defenses and exfiltrate sensitive data.
⤷ Title: SilentRoute: Trojanized SonicWall VPN Client Used to Steal Enterprise Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 00:00:31 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #eSentire #malware #NetExtender #phishing #SilentRoute #SonicWall #supply chain attack #vpn
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 00:00:31 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #eSentire #malware #NetExtender #phishing #SilentRoute #SonicWall #supply chain attack #vpn
Daily CyberSecurity
SilentRoute: Trojanized SonicWall VPN Client Used to Steal Enterprise Credentials
Microsoft and eSentire expose SilentRoute, a backdoored SonicWall SSL VPN NetExtender client distributed via SEO poisoning, stealing credentials and breaching networks.
⤷ Title: Interlock Ransomware Strikes: eSentire Exposes Multi-Stage Payload and ClickFix Social Engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 00:10:37 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cybersecurity #eSentire #Interlock #malware #NodeSnake #powershell #ransomware #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 00:10:37 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cybersecurity #eSentire #Interlock #malware #NodeSnake #powershell #ransomware #social engineering
Daily CyberSecurity
Interlock Ransomware Strikes: eSentire Exposes Multi-Stage Payload and ClickFix Social Engineering
eSentire exposes Interlock, a new ransomware group using multi-stage payloads and the ClickFix social engineering technique to deploy ransomware and backdoors via compromised websites.
⤷ Title: Is This a Rebrand? New Sinobi Ransomware Group Shows Code Overlap with Lynx
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:33:02 +0000
════════════════════════
⌗ Tags: #Malware #active directory #cybersecurity #eSentire #Hacking #lynx #ransomware #Ransomware_as_a_Service #Sinobi Group #SonicWall
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:33:02 +0000
════════════════════════
⌗ Tags: #Malware #active directory #cybersecurity #eSentire #Hacking #lynx #ransomware #Ransomware_as_a_Service #Sinobi Group #SonicWall
Daily CyberSecurity
Is This a Rebrand? New Sinobi Ransomware Group Shows Code Overlap with Lynx
A new report links Sinobi Group ransomware to Lynx, a potential rebrand. The group is using strong encryption and targeting compromised SonicWall VPN credentials to gain access.
⤷ Title: NightshadeC2 Botnet Is Using “UAC Prompt Bombing” to Bypass Defenses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:09:34 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #eSentire #hacking #malware #NightshadeC2 #uac
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:09:34 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #eSentire #hacking #malware #NightshadeC2 #uac
Penetration Testing Tools
NightshadeC2 Botnet Is Using "UAC Prompt Bombing" to Bypass Defenses
A new botnet called NightshadeC2 uses "UAC Prompt Bombing" to force users to approve malicious actions, bypassing Windows Defender and analysis sandboxes.
⤷ Title: DarkCloud Stealer Evolves: New VB6 Obfuscation and Crypto Wallet Theft Make Malware More Dangerous Than Ever
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 00:26:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallets #cybersecurity #DarkCloud Stealer #eSentire #evasion #Infostealer #malware #Obfuscation #VB6
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 00:26:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallets #cybersecurity #DarkCloud Stealer #eSentire #evasion #Infostealer #malware #Obfuscation #VB6
Daily CyberSecurity
DarkCloud Stealer Evolves: New VB6 Obfuscation and Crypto Wallet Theft Make Malware More Dangerous Than Ever
A new DarkCloud infostealer variant uses VB6 obfuscation and anti-analysis techniques to steal credentials and crypto wallets from MetaMask, Exodus, and more.
⤷ Title: New Rust Backdoor ChaosBot Uses Discord as Covert C2 Channel to Target Financial Services
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:18:03 +0000
════════════════════════
⌗ Tags: #Malware #C2 #ChaosBot #Command and Control #Discord #DLL Sideloading #eSentire #Financial services #Rust
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:18:03 +0000
════════════════════════
⌗ Tags: #Malware #C2 #ChaosBot #Command and Control #Discord #DLL Sideloading #eSentire #Financial services #Rust
Daily CyberSecurity
New Rust Backdoor ChaosBot Uses Discord as Covert C2 Channel to Target Financial Services
eSentire discovered ChaosBot, a Rust-based malware deployed via DLL sideloading that uses Discord channels as a covert C2 platform to perform reconnaissance and command execution.
⤷ Title: North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:12:27 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cybersecurity #DEV#POPPER #eSentire TRU #GitHub Malware #infosec #North Korean APT #OmniStealer #Remote Access Trojan #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:12:27 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cybersecurity #DEV#POPPER #eSentire TRU #GitHub Malware #infosec #North Korean APT #OmniStealer #Remote Access Trojan #supply chain attack
Daily CyberSecurity
North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets
eSentire exposes DEV#POPPER, a North Korean RAT hiding in GitHub repos. It uses blockchain to deploy OmniStealer, targeting crypto and dev secrets.
⤷ Title: The Cyber Nexus: Iranian Group ‘Muddy Water’ Caught Deploying Russian ‘Tsundere’ Botnet via EtherHiding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 01:11:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #cybersecurity #eSentire TRU #Ethereum Blockchain #EtherHiding #Malware_as_a_Service #Muddy Water #Russian Malware #threat intelligence #Tsundere Botnet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 01:11:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #cybersecurity #eSentire TRU #Ethereum Blockchain #EtherHiding #Malware_as_a_Service #Muddy Water #Russian Malware #threat intelligence #Tsundere Botnet
Daily CyberSecurity
The Cyber Nexus: Iranian Group 'Muddy Water' Caught Deploying Russian 'Tsundere' Botnet via EtherHiding
eSentire TRU reveals Iranian group Muddy Water deploying the Russian-linked Tsundere botnet, utilizing Ethereum smart contracts for stealthy C2 communication.
⤷ Title: STX RAT: The New Financial Predator Hiding in the “Start of Text”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 09:00:35 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Ghosting #encryption #eSentire #Financial Cybersecurity #HVNC #infosec #malware #rat #Stealth Malware #STX RAT #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 09:00:35 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Ghosting #encryption #eSentire #Financial Cybersecurity #HVNC #infosec #malware #rat #Stealth Malware #STX RAT #threat intelligence
Daily CyberSecurity
STX RAT: The New Financial Predator Hiding in the "Start of Text"
eSentire TRU uncovers STX RAT, a modular Trojan targeting finance with HVNC, AMSI Ghosting, and advanced encryption. Secure your perimeter—learn how it works.
⤷ Title: SEO Poisoning & NativeAOT: Unmasking the “Kong RAT” Campaign Targeting IT Professionals
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 08:13:58 +0000
════════════════════════
⌗ Tags: #Malware #.NET 10.0 NativeAOT #Alibaba Cloud OSS #cyber_espionage #eSentire TRU #FinalShell #infosec #IT security #Kong RAT #malware #SEO Poisoning #Trojanized Installers #Xshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 08:13:58 +0000
════════════════════════
⌗ Tags: #Malware #.NET 10.0 NativeAOT #Alibaba Cloud OSS #cyber_espionage #eSentire TRU #FinalShell #infosec #IT security #Kong RAT #malware #SEO Poisoning #Trojanized Installers #Xshell
Daily CyberSecurity
SEO Poisoning & NativeAOT: Unmasking the "Kong RAT" Campaign Targeting IT Professionals
Kong RAT: A year-long SEO poisoning campaign targeting developers with trojanized SSH/VPN tools and .NET NativeAOT stealth. Learn how to stay protected.