⤷ Title: Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
Daily CyberSecurity
Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
Cybereason exposed Tangerine Turkey, a VBScript worm that spreads via USB drives. It uses LOLBins (printui.exe) and Windows Defender exclusions to deploy the XMRig cryptominer for profit.
⤷ Title: Legacy Malware Resurfaces: DarkComet RAT Uses Bitcoin Wallet Lure to Deploy UPX-Packed Payload
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:10:56 +0000
════════════════════════
⌗ Tags: #Malware #Bitcoin Lure #DarkComet #Keylogging #Legacy Malware #persistence #rat #Remote Access Trojan #UPX Packer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:10:56 +0000
════════════════════════
⌗ Tags: #Malware #Bitcoin Lure #DarkComet #Keylogging #Legacy Malware #persistence #rat #Remote Access Trojan #UPX Packer
Daily CyberSecurity
Legacy Malware Resurfaces: DarkComet RAT Uses Bitcoin Wallet Lure to Deploy UPX-Packed Payload
A new campaign is using Bitcoin wallet lures to distribute DarkComet RAT. The UPX-packed trojan gains persistence via a fake explorer.exe binary and uses keylogging and remote control to steal data.
⤷ Title: Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and Access Resale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
Daily CyberSecurity
Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and…
Broadcom exposed a group deploying multiple RMM tools (ScreenConnect, LogMeIn, Naverisk) weeks apart to achieve redundant persistence. The likely Initial Access Broker (IAB) prepares systems for resale.
⤷ Title: Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #File Transfer #LNK File #Patchwork #persistence #StreamSpy #WebSocket C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #File Transfer #LNK File #Patchwork #persistence #StreamSpy #WebSocket C2
Daily CyberSecurity
Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
Patchwork APT deployed StreamSpy, a new trojan that uses WebSocket for covert C2 and HTTP for file transfer, blending malicious activity with web traffic to evade detection during espionage operations.
⤷ Title: CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
Daily CyberSecurity
CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
CISA/NSA exposed BRICKSTORM, a Chinese state-sponsored backdoor targeting VMware vCenter/ESXi and ADFS servers. The self-restarting malware used DoH and nested TLS for 18 months of persistent espionage.
⤷ Title: APT-C-53 Hits Ukraine: New Attack Exploits WinRAR Flaw for Persistence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 04:06:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #360 Threat Intelligence #APT_C_53 #CVE_2025_8088 #Cyber Espionage #Directory Traversal #HTA #malware #persistence #Ukraine #Winrar
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 04:06:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #360 Threat Intelligence #APT_C_53 #CVE_2025_8088 #Cyber Espionage #Directory Traversal #HTA #malware #persistence #Ukraine #Winrar
Penetration Testing Tools
APT-C-53 Hits Ukraine: New Attack Exploits WinRAR Flaw for Persistence
APT-C-53 has once again intensified its distribution of malicious attachments targeting organizations in Ukraine. The latest wave of
⤷ Title: Locked Out of the Cloud: Hackers Use AWS Termination Protection to Hijack ECS for Unstoppable Crypto Mining
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon ECS #Amazon GuardDuty #AWS #AWS Lambda #Cloud Security #Cryptojacking #EC2 #IAM Security #persistence #Termination Protection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon ECS #Amazon GuardDuty #AWS #AWS Lambda #Cloud Security #Cryptojacking #EC2 #IAM Security #persistence #Termination Protection
Daily CyberSecurity
Locked Out of the Cloud: Hackers Use AWS Termination Protection to Hijack ECS for Unstoppable Crypto Mining
Hackers are weaponizing AWS termination protection to lock defenders out while they mine crypto on hijacked ECS/EC2 resources using a malicious Docker image.
⤷ Title: Understanding Persistence Techniques in Penetration Testing
════════════════════════
𐀪 Author: Jay Vanyi
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 20:12:05 GMT
════════════════════════
⌗ Tags: #penetration_testing #persistence #offensive_security #cybersecurity #threat_hunting
════════════════════════
𐀪 Author: Jay Vanyi
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 20:12:05 GMT
════════════════════════
⌗ Tags: #penetration_testing #persistence #offensive_security #cybersecurity #threat_hunting
Medium
Understanding Persistence Techniques in Penetration Testing
A breakdown of the persistence methods attackers rely on and what defenders need to understand to fully remediate intrusions.
⤷ Title: Venom C2: The Dependency-Free Python Framework for Stealthy Persistence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 04:47:54 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AES Encryption #Command and Control #cybersecurity #InfoSec 2026 #Pentesting Tools #persistence #python 3 #red teaming #Reverse SSH #Venom C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 04:47:54 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AES Encryption #Command and Control #cybersecurity #InfoSec 2026 #Pentesting Tools #persistence #python 3 #red teaming #Reverse SSH #Venom C2
Penetration Testing Tools
Venom C2: The Dependency-Free Python Framework for Stealthy Persistence
Venom C2 is a Jan 2026 dependency-free Python framework for red team persistence. Control remote systems via encrypted JSON without installing packages.
⤷ Title: Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Asterisk #CVE_2025_64328 #EncystPHP #FortiGuard Labs #FreePBX #INJ3CTOR3 #Malware Analysis #persistence #VoIP Security #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Asterisk #CVE_2025_64328 #EncystPHP #FortiGuard Labs #FreePBX #INJ3CTOR3 #Malware Analysis #persistence #VoIP Security #Web Shell
Daily CyberSecurity
Silent Intruder: "EncystPHP" Web Shell Burrows into FreePBX Systems
INJ3CTOR3 hackers target FreePBX with EncystPHP web shell via CVE-2025-64328. Malware uses cron jobs for persistence. Patch immediately.