⤷ Title: Kimsuky’s PebbleDash Campaign: PowerShell Attacks & RDP Bypass Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Apr 2025 00:12:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AhnLab #APT #backdoor #cybersecurity #Kimsuky #malware #PebbleDash #powershell #RDP exploit #spear_phishing #termsrv.dll
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Apr 2025 00:12:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AhnLab #APT #backdoor #cybersecurity #Kimsuky #malware #PebbleDash #powershell #RDP exploit #spear_phishing #termsrv.dll
Daily CyberSecurity
Kimsuky's PebbleDash Campaign: PowerShell Attacks & RDP Bypass Tactics
Kimsuky revives PebbleDash malware using spear-phishing and patched RDP DLLs for stealthy access and control, warns new ASEC March 2025 report.
⤷ Title: SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
Daily CyberSecurity
SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
AhnLab uncovers SVF Bot, a Python-based DDoS botnet abusing Discord as its C&C channel to target misconfigured Linux servers and launch HTTP/UDP floods.
⤷ Title: AmateraStealer (ACRStealer) Evolves: New Version Uses Low-Level NTAPIs & Heaven’s Gate for Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 00:06:26 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #AmateraStealer #C2 Communication #cybersecurity #evasion #Heaven's Gate #Infostealer #malware #NTAPIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 00:06:26 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #AmateraStealer #C2 Communication #cybersecurity #evasion #Heaven's Gate #Infostealer #malware #NTAPIs
Daily CyberSecurity
AmateraStealer (ACRStealer) Evolves: New Version Uses Low-Level NTAPIs & Heaven's Gate for Evasion
AmateraStealer (formerly ACRStealer) has significantly evolved, using low-level NTAPIs, Heaven's Gate, and multi-layered encryption to evade detection and steal sensitive data.
⤷ Title: ACRStealer’s Stealthy Evolution: New Variants Use Heaven’s Gate & Low-Level NTAPIs to Evade Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:45:56 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #cybersecurity #Data Exfiltration #Evasion #Heaven's Gate #Infostealer #malware #NTAPI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:45:56 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #cybersecurity #Data Exfiltration #Evasion #Heaven's Gate #Infostealer #malware #NTAPI
Penetration Testing Tools
ACRStealer's Stealthy Evolution: New Variants Use Heaven's Gate & Low-Level NTAPIs to Evade Detection
ACRStealer (AmateraStealer) has evolved, now using Heaven's Gate and direct NTAPI calls to AFD driver to evade detection and steal sensitive data with heightened stealth.
⤷ Title: SVF Botnet Strikes: New Linux DDoS Threat Leverages Discord for Covert Command and Control
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:19:18 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BOTNET #C2 #Command and Control #cybersecurity #DDoS #Discord #Linux #python #SVF Botnet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:19:18 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BOTNET #C2 #Command and Control #cybersecurity #DDoS #Discord #Linux #python #SVF Botnet
Penetration Testing Tools
SVF Botnet Strikes: New Linux DDoS Threat Leverages Discord for Covert Command and Control
AhnLab uncovers SVF Botnet, a Python-based DDoS threat exploiting weak SSH credentials on Linux servers and using Discord as a stealthy command-and-control channel.
⤷ Title: GitHub Malware Campaign: SmartLoader Poses as Game Cheats to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 00:23:56 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #cybersecurity #github #Infostealer #Lumma Stealer #malware #phishing #RedLine #Rhadamanthys #SmartLoader #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 00:23:56 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #cybersecurity #github #Infostealer #Lumma Stealer #malware #phishing #RedLine #Rhadamanthys #SmartLoader #social engineering
Daily CyberSecurity
GitHub Malware Campaign: SmartLoader Poses as Game Cheats to Steal Data
A new large-scale malware campaign is using GitHub repositories disguised as game cheats and software cracks to distribute SmartLoader and steal user data.
⤷ Title: Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
Daily CyberSecurity
Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
A new report from AhnLab reveals the Interlock ransomware group is actively attacking businesses and critical infrastructure in North America and Europe with a sophisticated encryption model.
⤷ Title: DireWolf: The New Ransomware Group Targeting Global Businesses
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 00:01:31 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Cybercrime #cybersecurity #DireWolf #Double Extortion #malware #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 00:01:31 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Cybercrime #cybersecurity #DireWolf #Double Extortion #malware #ransomware
Daily CyberSecurity
DireWolf: The New Ransomware Group Targeting Global Businesses
A new ransomware group, DireWolf, has rapidly emerged to target global businesses with a powerful new strain of malware and a double extortion model.
⤷ Title: CyberVolk Ransomware’s Decryption Flaw Makes Data Recovery Impossible
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 03:59:10 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Critical Infrastructure #Cybercrime #CyberVolk #Geopolitical #pro_Russia #ransomware #unrecoverable encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 03:59:10 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Critical Infrastructure #Cybercrime #CyberVolk #Geopolitical #pro_Russia #ransomware #unrecoverable encryption
Daily CyberSecurity
CyberVolk Ransomware’s Decryption Flaw Makes Data Recovery Impossible
A new report reveals CyberVolk ransomware, a pro-Russian strain that encrypts data with an unrecoverable flaw. Its decryption key is useless, making recovery impossible.
⤷ Title: BlackNevas Ransomware: A Persistent Global Threat With Impossible-to-Decrypt Payloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:10:44 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BlackNevas #Critical Infrastructure #Cybercrime #cybersecurity #Geopolitical #pro_Russia #ransomware group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:10:44 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BlackNevas #Critical Infrastructure #Cybercrime #cybersecurity #Geopolitical #pro_Russia #ransomware group
Daily CyberSecurity
BlackNevas Ransomware: A Persistent Global Threat With Impossible-to-Decrypt Payloads
AhnLab has uncovered BlackNevas, a new ransomware group with strong encryption. The group is attacking businesses and critical infrastructure across the globe.
⤷ Title: BlackLock Ransomware: A New Cross-Platform Threat Spreading Rapidly
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:25:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #BlackLock #Cross_Platform #Cybercrime #go #Linux #ransomware #VMware ESXi #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:25:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #BlackLock #Cross_Platform #Cybercrime #go #Linux #ransomware #VMware ESXi #windows
Daily CyberSecurity
BlackLock Ransomware: A New Cross-Platform Threat Spreading Rapidly
AhnLab has uncovered BlackLock, a Go-based ransomware targeting Windows, Linux, and VMware ESXi. The malware uses advanced crypto and covert backup deletion.
⤷ Title: Kawa4096: A New Ransomware Group with Akira-Style Branding and Qilin-Like Notes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 00:16:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #Cross_Platform #Cybercrime #go #KAWA4096 #Linux #ransomware #VMware ESXi #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 00:16:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #Cross_Platform #Cybercrime #go #KAWA4096 #Linux #ransomware #VMware ESXi #windows
Daily CyberSecurity
Kawa4096: A New Ransomware Group with Akira-Style Branding and Qilin-Like Notes
AhnLab has uncovered Kawa4096, a Go-based ransomware targeting Windows, Linux, and VMware ESXi. The malware uses advanced crypto and covert backup deletion.
⤷ Title: LNK Stomping: Attackers Bypass Windows Security by Stripping the ‘Mark of the Web’
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
Daily CyberSecurity
LNK Stomping: Attackers Bypass Windows Security by Stripping the 'Mark of the Web'
A vulnerability dubbed "LNK Stomping" (CVE-2024-38217) is actively used to strip the 'Mark of the Web' from LNK files, bypassing Windows security policies.
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
Daily CyberSecurity
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
Threat actors are actively exploiting a new WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM shells and deploy the dangerous ShadowPad backdoor. Patch immediately!
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
Penetration Testing Tools
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
Threat actors are actively exploiting the critical WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM access and deploy the powerful, Chinese-linked ShadowPad espionage backdoor.
⤷ Title: Lazarus Group Stole $1.4B in Crypto; Will Use AI & Deepfakes for 2026 Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:24:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #AI Attacks #Bybit #Cryptocurrency Theft #cybercrime #Deepfake #Lazarus Group #North Korea APT #Spear Phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:24:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #AI Attacks #Bybit #Cryptocurrency Theft #cybercrime #Deepfake #Lazarus Group #North Korea APT #Spear Phishing
Penetration Testing Tools
Lazarus Group Stole $1.4B in Crypto; Will Use AI & Deepfakes for 2026 Attacks
North Korea’s Lazarus hacking collective is intensifying its targeted phishing campaigns against cryptocurrency platforms and individual investors, amassing