⤷ Title: The SocGholish Malware Economy: Stealthy “Fake Updates” Fuel a Global Cybercrime Ecosystem
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 00:10:49 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evil Corp #FakeUpdates #IAB #initial access broker #MaaS #Malware_as_a_Service #ransomware #SocGholish #TA569
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 00:10:49 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evil Corp #FakeUpdates #IAB #initial access broker #MaaS #Malware_as_a_Service #ransomware #SocGholish #TA569
Daily CyberSecurity
The SocGholish Malware Economy: Stealthy "Fake Updates" Fuel a Global Cybercrime Ecosystem
Silent Push exposes SocGholish as a MaaS platform for Initial Access Brokers. The malware, disguised as fake updates, fuels top-tier Russian ransomware groups like Evil Corp.
⤷ Title: Practical Thread Hijacking — From Theory to Malware Code
════════════════════════
𐀪 Author: 0xc4t
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 13:34:12 GMT
════════════════════════
⌗ Tags: #red_team #development #initial_access #malware_development #ethical_hacking
════════════════════════
𐀪 Author: 0xc4t
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 13:34:12 GMT
════════════════════════
⌗ Tags: #red_team #development #initial_access #malware_development #ethical_hacking
Medium
Practical Thread Hijacking — From Theory to Malware Code
One code injection technique that often appears in malware development is thread hijacking. In summary: Thread Hijacking is a technique in…
⤷ Title: Initial Access Pot
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 11:53:56 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #initial_access #tryhackme_walkthrough #tryhackme #initial_access_pot
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 11:53:56 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #initial_access #tryhackme_walkthrough #tryhackme #initial_access_pot
Medium
Initial Access Pot
Investigate the first, Linux part of the Honeynet Collapse!
⤷ Title: Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
Daily CyberSecurity
Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
Rhysida ransomware is abusing Microsoft Trusted Signing to deploy OysterLoader (IAT) via Bing/Teams malvertising. The gang leveraged 40+ certificates to sign malware, bypassing security filters.
⤷ Title: Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and Access Resale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
Daily CyberSecurity
Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and…
Broadcom exposed a group deploying multiple RMM tools (ScreenConnect, LogMeIn, Naverisk) weeks apart to achieve redundant persistence. The likely Initial Access Broker (IAB) prepares systems for resale.
⤷ Title: Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
Penetration Testing Tools
Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
The financially motivated group Storm-0249, long known as a broker of initial access for ransomware operators, has markedly
⤷ Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Daily CyberSecurity
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
Storm-0249 IAB abuses the SentinelOne EDR process via DLL sideloading to evade detection. The group uses LoLBin tools for fileless execution and sells access to ransomware groups like LockBit.
⤷ Title: SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
Daily CyberSecurity
SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
SpaceX is interviewing investment banks for a potential 2026 IPO after its valuation nearly doubled to $800 billion in a secondary sale, fueled by Starlink's growth.
⤷ Title: Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
Daily CyberSecurity
Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
GreyNoise reveals a massive Japan-based holiday campaign: 2.5 million attacks targeting 767 CVEs to harvest access for ransomware gangs.
⤷ Title: Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
Daily CyberSecurity
Hidden in Plain Sight: TA584 Deploys "Tsundere Bot" & Invisible Registry Keys
TA584 triples activity with new "Tsundere Bot" malware. Attackers use invisible Registry keys to hide persistence. Read the Proofpoint analysis.