⤷ Title: Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
Daily CyberSecurity
Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
Threat actors abuse Microsoft’s mavinject.exe to inject malicious DLLs into trusted processes, evading detection in stealthy APT campaigns.
⤷ Title: Fundamental Web Security Broken: New Attacks Bypass Same-Origin Policy via HTTP/2 & SXG
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 27 May 2025 00:32:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #CrossPUSH #CrossSXG #cybersecurity #HTTP/2 #Same_Origin Policy #Signed HTTP Exchange #SOP #SXG #Web Security #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 27 May 2025 00:32:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #CrossPUSH #CrossSXG #cybersecurity #HTTP/2 #Same_Origin Policy #Signed HTTP Exchange #SOP #SXG #Web Security #XSS
Daily CyberSecurity
Fundamental Web Security Broken: New Attacks Bypass Same-Origin Policy via HTTP/2 & SXG
New CrossPUSH & CrossSXG attacks exploit HTTP/2 and SXG to bypass Same-Origin Policy, enabling XSS and cookie manipulation.
⤷ Title: Signed Drivers Fueling Kernel Attacks: 620+ Malicious Drivers & 80+ Compromised Certs Target Windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 03:03:59 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Digital Signatures #EV Certificates #Group_IB #kernel #malware #ransomware #Signed Drivers #WHCP #windows #Windows Hardware Compatibility Program
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 03:03:59 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Digital Signatures #EV Certificates #Group_IB #kernel #malware #ransomware #Signed Drivers #WHCP #windows #Windows Hardware Compatibility Program
Penetration Testing Tools
Signed Drivers Fueling Kernel Attacks: 620+ Malicious Drivers & 80+ Compromised Certs Target Windows
Group-IB exposes 620+ malicious digitally signed drivers and 80+ compromised certificates since 2020, fueling stealthy Windows kernel attacks and bypassing security defenses.
⤷ Title: Malware Disguised as SteamCleaner Uses Valid Signature to Inject Node.js RCE Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:22:09 +0000
════════════════════════
⌗ Tags: #Malware #anti_sandbox #InnoSetup #Node.js RCE #proxyware #Remote Code Execution #Signed Malware #SteamCleaner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:22:09 +0000
════════════════════════
⌗ Tags: #Malware #anti_sandbox #InnoSetup #Node.js RCE #proxyware #Remote Code Execution #Signed Malware #SteamCleaner
Daily CyberSecurity
Malware Disguised as SteamCleaner Uses Valid Signature to Inject Node.js RCE Backdoor
ASEC exposed a SteamCleaner malware clone signed with a valid certificate. It installs a Node.js RCE backdoor via InnoSetup, evades sandboxes, and is suspected of running Proxyware for profit.
⤷ Title: TamperedChef Malvertising Uses US Shell Companies to Sign Trojanized Apps with Valid Certificates, Deploying Stealth Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:42:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Code_Signing Certificate #JavaScript Backdoor #Malvertising #Scheduled Task #SEO Poisoning #Signed Trojan #TamperedChef
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:42:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Code_Signing Certificate #JavaScript Backdoor #Malvertising #Scheduled Task #SEO Poisoning #Signed Trojan #TamperedChef
Daily CyberSecurity
TamperedChef Malvertising Uses US Shell Companies to Sign Trojanized Apps with Valid Certificates, Deploying Stealth Backdoor
Acronis exposed TamperedChef, a global campaign using US shell companies to sign trojanized apps. The malware deploys a stealthy, obfuscated JavaScript backdoor via a scheduled task for long-term persistence.
⤷ Title: Kerberos Attacks: Silver Ticket
════════════════════════
𐀪 Author: Hacer Dalkiran
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 11:54:48 GMT
════════════════════════
⌗ Tags: #kerberos #signed #hackthebox_writeup #active_directory_attack #silver_ticket
════════════════════════
𐀪 Author: Hacer Dalkiran
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 11:54:48 GMT
════════════════════════
⌗ Tags: #kerberos #signed #hackthebox_writeup #active_directory_attack #silver_ticket
Medium
Kerberos Attacks: Silver Ticket
Kerberos is designed to make authentication in Active Directory seamless and secure. In practice, however, a single weak service account…
⤷ Title: Signed Messages — TryHackMe
════════════════════════
𐀪 Author: Nolan Stark
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 09:40:07 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #signed_messages_thm #signed_messages_tryhackme #bug_bounty
════════════════════════
𐀪 Author: Nolan Stark
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 09:40:07 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #signed_messages_thm #signed_messages_tryhackme #bug_bounty
Medium
Signed Messages — TryHackMe
To complete this Room The Only thing we need is a Message and a Python Script You can Type `Hello` as Message Content And Here’s the Script
⤷ Title: Signed Messages — LoveNote THM Writeup
════════════════════════
𐀪 Author: spirit
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 17:42:30 GMT
════════════════════════
⌗ Tags: #signed_messages #tryhackme #thm_writeup #ctf_writeup
════════════════════════
𐀪 Author: spirit
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 17:42:30 GMT
════════════════════════
⌗ Tags: #signed_messages #tryhackme #thm_writeup #ctf_writeup
Medium
Signed Messages — LoveNote THM Writeup
Overview