⤷ Title: African Financial Institutions Targeted: “CL-CRI-1014” IAB Uses Open-Source Tools & Forged Signatures for Covert Access
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 07:22:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Africa #Chisel #CL_CRI_1014 #Classroom Spy #cyberattack #cybersecurity #Financial Institutions #IAB #Initial Access Broker #Palo Alto Networks #PoshC2 #Threat Actor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 07:22:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Africa #Chisel #CL_CRI_1014 #Classroom Spy #cyberattack #cybersecurity #Financial Institutions #IAB #Initial Access Broker #Palo Alto Networks #PoshC2 #Threat Actor
Penetration Testing Tools
African Financial Institutions Targeted: "CL-CRI-1014" IAB Uses Open-Source Tools & Forged Signatures for Covert Access
Palo Alto Networks exposes CL-CRI-1014, an IAB targeting African financial institutions. They use open-source tools like PoshC2 and Classroom Spy, disguised with forged signatures for covert network access.
⤷ Title: Gold Melody’s Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
Daily CyberSecurity
Gold Melody's Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
Unit 42 reveals "Gold Melody" uses leaked ASP.NET Machine Keys to achieve in-memory RCE via View State deserialization and privilege escalation via GodPotato, compromising web servers.
⤷ Title: The SocGholish Malware Economy: Stealthy “Fake Updates” Fuel a Global Cybercrime Ecosystem
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 00:10:49 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evil Corp #FakeUpdates #IAB #initial access broker #MaaS #Malware_as_a_Service #ransomware #SocGholish #TA569
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 00:10:49 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evil Corp #FakeUpdates #IAB #initial access broker #MaaS #Malware_as_a_Service #ransomware #SocGholish #TA569
Daily CyberSecurity
The SocGholish Malware Economy: Stealthy "Fake Updates" Fuel a Global Cybercrime Ecosystem
Silent Push exposes SocGholish as a MaaS platform for Initial Access Brokers. The malware, disguised as fake updates, fuels top-tier Russian ransomware groups like Evil Corp.
⤷ Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Daily CyberSecurity
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
Storm-0249 IAB abuses the SentinelOne EDR process via DLL sideloading to evade detection. The group uses LoLBin tools for fileless execution and sells access to ransomware groups like LockBit.
⤷ Title: Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
Daily CyberSecurity
Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
GreyNoise reveals a massive Japan-based holiday campaign: 2.5 million attacks targeting 767 CVEs to harvest access for ransomware gangs.
⤷ Title: Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
Daily CyberSecurity
Hidden in Plain Sight: TA584 Deploys "Tsundere Bot" & Invisible Registry Keys
TA584 triples activity with new "Tsundere Bot" malware. Attackers use invisible Registry keys to hide persistence. Read the Proofpoint analysis.