⤷ Title: Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:00:11 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Delphi RAT #lateral movement #LogMeIn Resolve #PatoRAT #PDQ Connect #Remote Access Trojan #RMM Abuse
Daily CyberSecurity
Delphi PatoRAT Backdoor Hijacks LogMeIn Resolve and PDQ Connect RMM Tools for Full System Takeover
ASEC exposed PatoRAT, a Delphi RAT that hijacks LogMeIn Resolve and PDQ Connect RMM tools. Attackers use maliciously configured installers disguised as 7-Zip/Notepad++ to gain full system control.
⤷ Title: Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and Access Resale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
Daily CyberSecurity
Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and…
Broadcom exposed a group deploying multiple RMM tools (ScreenConnect, LogMeIn, Naverisk) weeks apart to achieve redundant persistence. The likely Initial Access Broker (IAB) prepares systems for resale.
⤷ Title: The Admin’s Shadow: How Hackers Turned the Nezha Monitoring Tool into a Stealth RAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:38:40 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #Evasion #Nezha #NT AUTHORITY\SYSTEM #Ontinue #open source #post_exploitation #Qualys #RAT #RMM Abuse #Root Access
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:38:40 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #Evasion #Nezha #NT AUTHORITY\SYSTEM #Ontinue #open source #post_exploitation #Qualys #RAT #RMM Abuse #Root Access
Information Security News
The Admin’s Shadow: How Hackers Turned the Nezha Monitoring Tool into a Stealth RAT
Threat actors have begun repurposing a legitimate server monitoring tool as a ready-made platform for remotely controlling systems that have already been compromised. According to the Ontinue Cybe…
⤷ Title: New “Eternl Desktop” Phishing Lure Drops LogMeIn to Hijack Cardano Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 00:00:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ADA #Anurag #Blockchain security #Cardano #crypto security #Eternl Wallet #LogMeIn Resolve #malware #Phishing Campaign #RMM Abuse #Staking Scams #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 00:00:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ADA #Anurag #Blockchain security #Cardano #crypto security #Eternl Wallet #LogMeIn Resolve #malware #Phishing Campaign #RMM Abuse #Staking Scams #supply chain attack
Daily CyberSecurity
New “Eternl Desktop” Phishing Lure Drops LogMeIn to Hijack Cardano Wallets
The Cardano community is currently in the crosshairs of a highly sophisticated “wolf in sheep’s clothing” campaign. Threat researcher Anurag has issued a critical warning regardi…
⤷ Title: Attackers Weaponize Legitimate RMM Tools via Fake PDFs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 02:12:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyber attacks #living_off_the_land #Malware Analysis #NinjaOne #NSIS #PDF Malware #phishing #RMM Abuse #ScreenConnect #SuperOps #Syncro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 02:12:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #cyber attacks #living_off_the_land #Malware Analysis #NinjaOne #NSIS #PDF Malware #phishing #RMM Abuse #ScreenConnect #SuperOps #Syncro
Daily CyberSecurity
Attackers Weaponize Legitimate RMM Tools via Fake PDFs
In a new report, the AhnLab Security Intelligence Center (ASEC) warns of a rising trend where threat actors are hijacking powerful Remote Monitoring and Management (RMM) software to infiltrate vic…
⤷ Title: The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
Penetration Testing Tools
The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
Security analysts at ReliaQuest have unmasked a sophisticated phishing campaign wherein adversaries secrete remote access mechanisms within an
⤷ Title: Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 03:58:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #BeyondTrust #CISA KEV #CVE_2026_1731 #lateral movement #Patch Alert #Privileged Remote Access #Remote Support #RMM #SimpleHelp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 03:58:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #BeyondTrust #CISA KEV #CVE_2026_1731 #lateral movement #Patch Alert #Privileged Remote Access #Remote Support #RMM #SimpleHelp
Daily CyberSecurity
Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover
Arctic Wolf warns of CVE-2026-1731, a critical BeyondTrust flaw exploited in the wild. Attackers use it to deploy backdoors. Patch self-hosted instances now.
⤷ Title: The Fake IT Threat: “TrustConnect” Malware-as-a-Service Masquerades as Legitimate RMM Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:11:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Malware #Cyber Security #DocConnect #infosec #MaaS #Malware_as_a_Service #Proofpoint #Redline stealer #RMM Abuse #TrustConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:11:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Malware #Cyber Security #DocConnect #infosec #MaaS #Malware_as_a_Service #Proofpoint #Redline stealer #RMM Abuse #TrustConnect
Daily CyberSecurity
The Fake IT Threat: "TrustConnect" Malware-as-a-Service Masquerades as Legitimate RMM Software
Proofpoint exposes TrustConnect, a new Malware-as-a-Service masquerading as an IT tool. The AI-assisted fake RMM software replaces dismantled threats.
⤷ Title: Stealth & Persistence: MuddyWater’s New Rust-Based Payload Mimics Cloudflare and Reddit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 00:06:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Genians Report #infosec #Macro_based Attacks #MuddyWater APT #Operation Olalampo #RMM tool abuse #Rust malware #State_Sponsored Espionage #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 00:06:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Genians Report #infosec #Macro_based Attacks #MuddyWater APT #Operation Olalampo #RMM tool abuse #Rust malware #State_Sponsored Espionage #threat intelligence
Daily CyberSecurity
Stealth & Persistence: MuddyWater’s New Rust-Based Payload Mimics Cloudflare and Reddit
Genians report reveals MuddyWater APT's shift to Rust-based malware and RMM tool abuse for long-term espionage across government and critical infrastructure.
⤷ Title: Signed Malware Masquerading as Workplace Apps Deploys Persistent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:13:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #EV Certificate Phishing #infosec #malware #MeshAgent #Microsoft Defender #RMM Backdoors #ScreenConnect #Tactical RMM #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:13:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #EV Certificate Phishing #infosec #malware #MeshAgent #Microsoft Defender #RMM Backdoors #ScreenConnect #Tactical RMM #threat intelligence
Daily CyberSecurity
Signed Malware Masquerading as Workplace Apps Deploys Persistent Backdoors
Microsoft Defender exposes a new phishing campaign using EV certificates and fake Teams invites to silently deploy RMM backdoors on corporate networks.