⤷ Title: Kimsuky’s PebbleDash Campaign: PowerShell Attacks & RDP Bypass Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Apr 2025 00:12:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AhnLab #APT #backdoor #cybersecurity #Kimsuky #malware #PebbleDash #powershell #RDP exploit #spear_phishing #termsrv.dll
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Apr 2025 00:12:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AhnLab #APT #backdoor #cybersecurity #Kimsuky #malware #PebbleDash #powershell #RDP exploit #spear_phishing #termsrv.dll
Daily CyberSecurity
Kimsuky's PebbleDash Campaign: PowerShell Attacks & RDP Bypass Tactics
Kimsuky revives PebbleDash malware using spear-phishing and patched RDP DLLs for stealthy access and control, warns new ASEC March 2025 report.
⤷ Title: SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
Daily CyberSecurity
SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
AhnLab uncovers SVF Bot, a Python-based DDoS botnet abusing Discord as its C&C channel to target misconfigured Linux servers and launch HTTP/UDP floods.
⤷ Title: AmateraStealer (ACRStealer) Evolves: New Version Uses Low-Level NTAPIs & Heaven’s Gate for Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 00:06:26 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #AmateraStealer #C2 Communication #cybersecurity #evasion #Heaven's Gate #Infostealer #malware #NTAPIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 00:06:26 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #AmateraStealer #C2 Communication #cybersecurity #evasion #Heaven's Gate #Infostealer #malware #NTAPIs
Daily CyberSecurity
AmateraStealer (ACRStealer) Evolves: New Version Uses Low-Level NTAPIs & Heaven's Gate for Evasion
AmateraStealer (formerly ACRStealer) has significantly evolved, using low-level NTAPIs, Heaven's Gate, and multi-layered encryption to evade detection and steal sensitive data.
⤷ Title: ACRStealer’s Stealthy Evolution: New Variants Use Heaven’s Gate & Low-Level NTAPIs to Evade Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:45:56 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #cybersecurity #Data Exfiltration #Evasion #Heaven's Gate #Infostealer #malware #NTAPI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:45:56 +0000
════════════════════════
⌗ Tags: #Malware #ACRStealer #AhnLab ASEC #cybersecurity #Data Exfiltration #Evasion #Heaven's Gate #Infostealer #malware #NTAPI
Penetration Testing Tools
ACRStealer's Stealthy Evolution: New Variants Use Heaven's Gate & Low-Level NTAPIs to Evade Detection
ACRStealer (AmateraStealer) has evolved, now using Heaven's Gate and direct NTAPI calls to AFD driver to evade detection and steal sensitive data with heightened stealth.
⤷ Title: SVF Botnet Strikes: New Linux DDoS Threat Leverages Discord for Covert Command and Control
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:19:18 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BOTNET #C2 #Command and Control #cybersecurity #DDoS #Discord #Linux #python #SVF Botnet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 23:19:18 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BOTNET #C2 #Command and Control #cybersecurity #DDoS #Discord #Linux #python #SVF Botnet
Penetration Testing Tools
SVF Botnet Strikes: New Linux DDoS Threat Leverages Discord for Covert Command and Control
AhnLab uncovers SVF Botnet, a Python-based DDoS threat exploiting weak SSH credentials on Linux servers and using Discord as a stealthy command-and-control channel.
⤷ Title: GitHub Malware Campaign: SmartLoader Poses as Game Cheats to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 00:23:56 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #cybersecurity #github #Infostealer #Lumma Stealer #malware #phishing #RedLine #Rhadamanthys #SmartLoader #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 00:23:56 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #cybersecurity #github #Infostealer #Lumma Stealer #malware #phishing #RedLine #Rhadamanthys #SmartLoader #social engineering
Daily CyberSecurity
GitHub Malware Campaign: SmartLoader Poses as Game Cheats to Steal Data
A new large-scale malware campaign is using GitHub repositories disguised as game cheats and software cracks to distribute SmartLoader and steal user data.
⤷ Title: Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
Daily CyberSecurity
Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
A new report from AhnLab reveals the Interlock ransomware group is actively attacking businesses and critical infrastructure in North America and Europe with a sophisticated encryption model.
⤷ Title: DireWolf: The New Ransomware Group Targeting Global Businesses
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 00:01:31 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Cybercrime #cybersecurity #DireWolf #Double Extortion #malware #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 00:01:31 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Cybercrime #cybersecurity #DireWolf #Double Extortion #malware #ransomware
Daily CyberSecurity
DireWolf: The New Ransomware Group Targeting Global Businesses
A new ransomware group, DireWolf, has rapidly emerged to target global businesses with a powerful new strain of malware and a double extortion model.
⤷ Title: CyberVolk Ransomware’s Decryption Flaw Makes Data Recovery Impossible
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 03:59:10 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Critical Infrastructure #Cybercrime #CyberVolk #Geopolitical #pro_Russia #ransomware #unrecoverable encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 03:59:10 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #Critical Infrastructure #Cybercrime #CyberVolk #Geopolitical #pro_Russia #ransomware #unrecoverable encryption
Daily CyberSecurity
CyberVolk Ransomware’s Decryption Flaw Makes Data Recovery Impossible
A new report reveals CyberVolk ransomware, a pro-Russian strain that encrypts data with an unrecoverable flaw. Its decryption key is useless, making recovery impossible.
⤷ Title: BlackNevas Ransomware: A Persistent Global Threat With Impossible-to-Decrypt Payloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:10:44 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BlackNevas #Critical Infrastructure #Cybercrime #cybersecurity #Geopolitical #pro_Russia #ransomware group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:10:44 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #BlackNevas #Critical Infrastructure #Cybercrime #cybersecurity #Geopolitical #pro_Russia #ransomware group
Daily CyberSecurity
BlackNevas Ransomware: A Persistent Global Threat With Impossible-to-Decrypt Payloads
AhnLab has uncovered BlackNevas, a new ransomware group with strong encryption. The group is attacking businesses and critical infrastructure across the globe.
⤷ Title: BlackLock Ransomware: A New Cross-Platform Threat Spreading Rapidly
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:25:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #BlackLock #Cross_Platform #Cybercrime #go #Linux #ransomware #VMware ESXi #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:25:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #BlackLock #Cross_Platform #Cybercrime #go #Linux #ransomware #VMware ESXi #windows
Daily CyberSecurity
BlackLock Ransomware: A New Cross-Platform Threat Spreading Rapidly
AhnLab has uncovered BlackLock, a Go-based ransomware targeting Windows, Linux, and VMware ESXi. The malware uses advanced crypto and covert backup deletion.
⤷ Title: Kawa4096: A New Ransomware Group with Akira-Style Branding and Qilin-Like Notes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 00:16:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #Cross_Platform #Cybercrime #go #KAWA4096 #Linux #ransomware #VMware ESXi #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 00:16:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #Cross_Platform #Cybercrime #go #KAWA4096 #Linux #ransomware #VMware ESXi #windows
Daily CyberSecurity
Kawa4096: A New Ransomware Group with Akira-Style Branding and Qilin-Like Notes
AhnLab has uncovered Kawa4096, a Go-based ransomware targeting Windows, Linux, and VMware ESXi. The malware uses advanced crypto and covert backup deletion.
⤷ Title: LNK Stomping: Attackers Bypass Windows Security by Stripping the ‘Mark of the Web’
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
Daily CyberSecurity
LNK Stomping: Attackers Bypass Windows Security by Stripping the 'Mark of the Web'
A vulnerability dubbed "LNK Stomping" (CVE-2024-38217) is actively used to strip the 'Mark of the Web' from LNK files, bypassing Windows security policies.
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
Daily CyberSecurity
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
Threat actors are actively exploiting a new WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM shells and deploy the dangerous ShadowPad backdoor. Patch immediately!
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
Penetration Testing Tools
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
Threat actors are actively exploiting the critical WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM access and deploy the powerful, Chinese-linked ShadowPad espionage backdoor.
⤷ Title: Lazarus Group Stole $1.4B in Crypto; Will Use AI & Deepfakes for 2026 Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:24:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #AI Attacks #Bybit #Cryptocurrency Theft #cybercrime #Deepfake #Lazarus Group #North Korea APT #Spear Phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:24:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #AI Attacks #Bybit #Cryptocurrency Theft #cybercrime #Deepfake #Lazarus Group #North Korea APT #Spear Phishing
Penetration Testing Tools
Lazarus Group Stole $1.4B in Crypto; Will Use AI & Deepfakes for 2026 Attacks
North Korea’s Lazarus hacking collective is intensifying its targeted phishing campaigns against cryptocurrency platforms and individual investors, amassing
⤷ Title: Emerging Gentlemen Ransomware Hits 17 Countries with Double Extortion & BYOVD Evasion Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:19:29 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Threats #AhnLab #BYOVD #Cybercrime #Double Extortion #Gentlemen #GPO Manipulation #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:19:29 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Threats #AhnLab #BYOVD #Cybercrime #Double Extortion #Gentlemen #GPO Manipulation #ransomware
Daily CyberSecurity
Emerging Gentlemen Ransomware Hits 17 Countries with Double Extortion & BYOVD Evasion Tactics
The Gentlemen ransomware group rapidly emerged, targeting 17 countries with double extortion. It uses BYOVD and GPO manipulation to bypass security and hit manufacturing, healthcare, and insurance sectors.