⤷ Title: Outdated and Unblocked: Legacy Driver Vulnerability Exploited in Widespread Attack
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 27 Feb 2025 01:43:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #Gh0st RAT #Truesight.sys driver #windows
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 27 Feb 2025 01:43:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #Gh0st RAT #Truesight.sys driver #windows
Daily CyberSecurity
Outdated and Unblocked: Legacy Driver Vulnerability Exploited in Widespread Attack
Uncover the threat of Legacy Driver Vulnerability in cyberattacks. Learn how attackers exploit outdated drivers to bypass security.
⤷ Title: Sophisticated IIS Malware Targets South Korean Web Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 May 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 May 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #china #cyberattack #Gh0st RAT #HijackDriverManager #IIS #malware #south korea #web server #Web Shell #Winkbj.sys
Daily CyberSecurity
Sophisticated IIS Malware Targets South Korean Web Servers
A sophisticated campaign deployed malicious IIS modules on South Korean web servers, enabling traffic control and backdoor access. Suspected Chinese actor.
⤷ Title: Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
Daily CyberSecurity
Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
A sophisticated malware campaign targets Korean Internet cafés with Gh0st RAT and CoinMiner, hijacking systems for crypto mining. ASEC urges immediate action.
⤷ Title: Silver Fox APT: Chinese Threat Actor Deploys Trojanized Medical Software in Stealth Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 00:19:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #cyber_espionage #cybersecurity #DICOM Viewer #Gh0st RAT #healthcare #Japan #malware #Silver Fox #state_sponsored #Taiwan #Trojanized Software #ValleyRAT #Winos 4.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 00:19:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #cyber_espionage #cybersecurity #DICOM Viewer #Gh0st RAT #healthcare #Japan #malware #Silver Fox #state_sponsored #Taiwan #Trojanized Software #ValleyRAT #Winos 4.0
Daily CyberSecurity
Silver Fox APT: Chinese Threat Actor Deploys Trojanized Medical Software in Stealth Espionage Campaign
A newly surfaced report from Picus has shed light on Silver Fox (a.k.a. Void Arachne or The Great Thief of Valley), a sophisticated China-based advanced persistent threat (APT) group responsible f…
⤷ Title: Silver Fox Unleashes Sainbox RAT & Hidden Rootkit Via Fake Software Installers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 03:52:30 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #Gh0st RAT #Hidden Rootkit #malware #Netskope #phishing #Sainbox RAT #Silver Fox #Typosquatting #Void Arachne
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 03:52:30 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #Gh0st RAT #Hidden Rootkit #malware #Netskope #phishing #Sainbox RAT #Silver Fox #Typosquatting #Void Arachne
Penetration Testing Tools
Silver Fox Unleashes Sainbox RAT & Hidden Rootkit Via Fake Software Installers
Chinese hacker group Silver Fox is using fake software installers to deploy Sainbox RAT and a Hidden rootkit, targeting Chinese speakers with stealthy, cost-effective spyware.
⤷ Title: Spies in Your Skype: GodRAT Malware Uses Steganography to Target Financial Firms
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 00:33:07 +0000
════════════════════════
⌗ Tags: #Malware #cyber_espionage #cybersecurity #Financial Sector #Gh0st RAT #GodRAT #kaspersky #malware #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 00:33:07 +0000
════════════════════════
⌗ Tags: #Malware #cyber_espionage #cybersecurity #Financial Sector #Gh0st RAT #GodRAT #kaspersky #malware #steganography
Daily CyberSecurity
Spies in Your Skype: GodRAT Malware Uses Steganography to Target Financial Firms
Kaspersky Labs has identified a sophisticated cyber-espionage campaign targeting financial institutions, particularly trading and brokerage firms, through the deployment of a new remote access tro…
⤷ Title: The Silent Threat: How SEO Poisoning Spreads Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 08:27:11 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fortinet #Gh0st RAT #hacking #malware #SEO Poisoning #Silver Fox #trojan #Winos
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 08:27:11 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fortinet #Gh0st RAT #hacking #malware #SEO Poisoning #Silver Fox #trojan #Winos
Penetration Testing Tools
The Silent Threat: How SEO Poisoning Spreads Malware
A new SEO poisoning campaign is tricking users into downloading malware through fake websites for popular apps, deploying Gh0st RAT and Winos.
⤷ Title: China-Linked Hackers Weaponize Nezha Monitoring Tool and Log Poisoning to Deploy Gh0st RAT on 100+ Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:27:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #China_Nexus #Compromise #Gh0st RAT #Huntress #Log Poisoning #Nezha #phpMyAdmin #Web Shell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:27:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #China_Nexus #Compromise #Gh0st RAT #Huntress #Log Poisoning #Nezha #phpMyAdmin #Web Shell
Penetration Testing Tools
China-Linked Hackers Weaponize Nezha Monitoring Tool and Log Poisoning to Deploy Gh0st RAT on 100+ Systems
Huntress exposed a China-linked campaign using log poisoning on vulnerable phpMyAdmin to deploy a web shell and the Nezha monitoring tool for delivering Gh0st RAT to over 100 victims.
⤷ Title: Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
Daily CyberSecurity
Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
Researchers at Palo Alto Networks Unit 42 have uncovered two expansive and interconnected malware campaigns active throughout 2025, both designed to mass-distribute Gh0st RAT variants to Chinese-s…
⤷ Title: Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
Daily CyberSecurity
Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
Elastic exposed Dragon Breath APT's new RoningLoader malware. It uses PPL abuse and a signed kernel driver (ollama.sys) to disable Windows Defender and inject a modified gh0st RAT for espionage.