⤷ Title: Lumma Stealer: Advanced Obfuscation and Evasion Techniques Analysis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Apr 2025 00:16:52 +0000
════════════════════════
⌗ Tags: #Malware #anti_sandbox #API hashing #data exfiltration #Heaven's Gate #Infostealer #Lumma Stealer #MaaS #Malware Analysis #Obfuscation #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Apr 2025 00:16:52 +0000
════════════════════════
⌗ Tags: #Malware #anti_sandbox #API hashing #data exfiltration #Heaven's Gate #Infostealer #Lumma Stealer #MaaS #Malware Analysis #Obfuscation #Trellix
Daily CyberSecurity
Lumma Stealer: Advanced Obfuscation and Evasion Techniques Analysis
Trellix analysis reveals Lumma Stealer's latest tactics: code obfuscation, API hashing, ETW evasion, anti-VM. Learn how this InfoStealer avoids detection.
⤷ Title: “OneClik” APT Unmasked: China-Linked Campaign Abuses Microsoft ClickOnce & AWS Cloud to Target Energy Sector
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 27 Jun 2025 07:36:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #AWS #cloud security #Cyberespionage #cybersecurity #Energy Sector #Go Language #malware #Microsoft ClickOnce #Oil and Gas #OneClik #RunnerBeacon #Trellix
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 27 Jun 2025 07:36:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #AWS #cloud security #Cyberespionage #cybersecurity #Energy Sector #Go Language #malware #Microsoft ClickOnce #Oil and Gas #OneClik #RunnerBeacon #Trellix
Penetration Testing Tools
"OneClik" APT Unmasked: China-Linked Campaign Abuses Microsoft ClickOnce & AWS Cloud to Target Energy Sector
Trellix uncovers "OneClik," a sophisticated APT campaign abusing Microsoft ClickOnce and AWS cloud services to deploy Go-language backdoors, targeting energy, oil, and gas sectors.
⤷ Title: DoNot APT Expands to Europe: Targets Foreign Ministry with LoptikMod Malware via Google Drive Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:11:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT_C_35 #Cyberespionage #cybersecurity #DONOT APT #Europe #Foreign Affairs #Google Drive #LoptikMod #malware #Mint Tempest #Origami Elephant #phishing #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:11:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT_C_35 #Cyberespionage #cybersecurity #DONOT APT #Europe #Foreign Affairs #Google Drive #LoptikMod #malware #Mint Tempest #Origami Elephant #phishing #Trellix
Daily CyberSecurity
DoNot APT Expands to Europe: Targets Foreign Ministry with LoptikMod Malware via Google Drive Phishing
DoNot APT (APT-C-35) expands its cyber-espionage to a European foreign affairs ministry, using spear-phishing with Google Drive links to deliver the LoptikMod backdoor.
⤷ Title: Stealthy SquidLoader Malware Targets Hong Kong Financial Firms with Evasive Cobalt Strike Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 00:28:19 +0000
════════════════════════
⌗ Tags: #Malware #Cobalt Strike #cyberattack #cybersecurity #Financial services #Hong Kong #malware #SquidLoader #threat intelligence #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 00:28:19 +0000
════════════════════════
⌗ Tags: #Malware #Cobalt Strike #cyberattack #cybersecurity #Financial services #Hong Kong #malware #SquidLoader #threat intelligence #Trellix
Daily CyberSecurity
Stealthy SquidLoader Malware Targets Hong Kong Financial Firms with Evasive Cobalt Strike Attacks
Trellix has uncovered SquidLoader, a highly obfuscated malware targeting Hong Kong financial institutions to deploy Cobalt Strike beacons for persistent control.
⤷ Title: SquidLoader Malware Campaign Hits Hong Kong Financial Firms
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 20 Jul 2025 15:53:39 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Cybersecurity #Hong Kong #SquidLoader #Trellix #VirusTotal
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 20 Jul 2025 15:53:39 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Cybersecurity #Hong Kong #SquidLoader #Trellix #VirusTotal
Hackread
SquidLoader Malware Campaign Hits Hong Kong Financial Firms
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: 0bj3ctivityStealer: Stealthy Info-Stealer Uses Steganography & PowerShell to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:18:04 +0000
════════════════════════
⌗ Tags: #Malware #0bj3ctivityStealer #cybersecurity #data exfiltration #evasion #Infostealer #malware #phishing #powershell #steganography #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:18:04 +0000
════════════════════════
⌗ Tags: #Malware #0bj3ctivityStealer #cybersecurity #data exfiltration #evasion #Infostealer #malware #phishing #powershell #steganography #Trellix
Daily CyberSecurity
0bj3ctivityStealer: Stealthy Info-Stealer Uses Steganography & PowerShell to Evade Detection
Trellix uncovers 0bj3ctivityStealer, a sophisticated info-stealer using phishing, custom PowerShell, and steganography to evade detection and exfiltrate sensitive data.
⤷ Title: Spies in Plain Sight: How North Korean Hackers Used GitHub to Attack Embassies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 00:22:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyberespionage #Diplomatic Attacks #github #Kimsuky #North Korea #spear_phishing #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 00:22:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyberespionage #Diplomatic Attacks #github #Kimsuky #North Korea #spear_phishing #Trellix
Daily CyberSecurity
Spies in Plain Sight: How North Korean Hackers Used GitHub to Attack Embassies
A new report reveals a North Korean espionage campaign targeting embassies with spear phishing and a sophisticated C2 channel hidden on GitHub.
⤷ Title: Inside Kimsuky’s GitHub-Powered Cyber-Espionage Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 04:28:53 +0000
════════════════════════
⌗ Tags: #Malware #C2 #Cyber Espionage #cybersecurity #Github #Kimsuky #North Korea #Spear Phishing #Trellix
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 04:28:53 +0000
════════════════════════
⌗ Tags: #Malware #C2 #Cyber Espionage #cybersecurity #Github #Kimsuky #North Korea #Spear Phishing #Trellix
Penetration Testing Tools
Inside Kimsuky's GitHub-Powered Cyber-Espionage Campaign
A new report from Trellix reveals how the Kimsuky group used GitHub and sophisticated spear phishing to conduct a cyber-espionage campaign against diplomatic missions.
⤷ Title: A New Linux Malware Hides in Plain Sight by Weaponizing File Names
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 00:30:12 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 00:30:12 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
Daily CyberSecurity
A New Linux Malware Hides in Plain Sight by Weaponizing File Names
A new report reveals a dangerous Linux malware campaign that uses malicious filenames to execute a stealthy, fileless attack without the victim's knowledge.
⤷ Title: Weaponizing Filenames: Trellix Uncovers Stealthy Linux Malware Delivering VShell Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 02:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 02:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Bash #cyber attack #cybersecurity #Fileless Malware #filenames #Linux #malware #Trellix #VShell
Penetration Testing Tools
Weaponizing Filenames: Trellix Uncovers Stealthy Linux Malware Delivering VShell Backdoor
A new report reveals a dangerous Linux malware campaign that uses malicious filenames to execute a stealthy, fileless attack without the victim's knowledge.
⤷ Title: Beyond Simple Scripts: A New XWorm Campaign Uses Multi-Stage Stealth
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 00:05:39 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Cybercrime #cybersecurity #LNK File #malware #phishing #Trellix #windows #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 00:05:39 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Cybercrime #cybersecurity #LNK File #malware #phishing #Trellix #windows #XWorm
Daily CyberSecurity
Beyond Simple Scripts: A New XWorm Campaign Uses Multi-Stage Stealth
A new report reveals a sophisticated XWorm backdoor campaign that uses .lnk files and a multi-stage infection chain to gain stealthy and persistent control of Windows systems.
⤷ Title: XWorm V6.0 Resurfaces: Modular RAT Returns with Ransomware Plugin and Advanced Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Oct 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #ransomware #rat #Remote Access Trojan #Trellix #windows #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Oct 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #ransomware #rat #Remote Access Trojan #Trellix #windows #XWorm
Daily CyberSecurity
XWorm V6.0 Resurfaces: Modular RAT Returns with Ransomware Plugin and Advanced Evasion
XWorm V6.0 has resurfaced with 35+ plugins, including ransomware functionality. The modular RAT uses stealth injection and obfuscated PowerShell to bypass AMSI.
⤷ Title: CrazyHunter: The “Ruthless” Ransomware Stalking Healthcare
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:17:34 +0000
════════════════════════
⌗ Tags: #Malware #Active Directory Security #BYOVD (Bring Your Own Vulnerable Driver) #CrazyHunter #healthcare security #Malware Analysis #ransomware #SharpGPOAbuse #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:17:34 +0000
════════════════════════
⌗ Tags: #Malware #Active Directory Security #BYOVD (Bring Your Own Vulnerable Driver) #CrazyHunter #healthcare security #Malware Analysis #ransomware #SharpGPOAbuse #Trellix
Daily CyberSecurity
CrazyHunter: The “Ruthless” Ransomware Stalking Healthcare
A new, highly aggressive ransomware strain is cutting a swath through the healthcare sector, leaving hospitals and critical organizations scrambling to protect their data. Security researchers at …
⤷ Title: The Ghost Window: Trellix Warns of “Perfect” Facebook Phishing Traps
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 03:18:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BitB #Browser In The Browser #Credential Theft #Cybersecurity 2026 #facebook #Meta #Netlify #phishing #Social Engineering #Trellix #Vercel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 03:18:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BitB #Browser In The Browser #Credential Theft #Cybersecurity 2026 #facebook #Meta #Netlify #phishing #Social Engineering #Trellix #Vercel
Penetration Testing Tools
The Ghost Window: Trellix Warns of "Perfect" Facebook Phishing Traps
Adversaries have intensified their offensives against Facebook users by deploying one of the most inconspicuous and treacherous phishing
⤷ Title: “Browser-in-the-Browser” Attack Escalates: Trellix Reports Surge in Sophisticated Facebook Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 00:18:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BitB #Browser In The Browser #Credential Harvesting #Cyber Security #Facebook Security #Netlify #phishing #social engineering #Trellix #Vercel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 00:18:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BitB #Browser In The Browser #Credential Harvesting #Cyber Security #Facebook Security #Netlify #phishing #social engineering #Trellix #Vercel
Daily CyberSecurity
"Browser-in-the-Browser" Attack Escalates: Trellix Reports Surge in Sophisticated Facebook Phishing
Trellix warns: "Browser-in-the-Browser" phishing creates perfect fake Facebook login pop-ups. Learn how this invisible trap steals credentials.
⤷ Title: Trusted Tool Turned Traitor: Signed ‘ahost.exe’ Weaponized to Sideload Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 00:12:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #AgentTesla #ahost.exe #c_ares #DLL Sideloading #GitKraken #infosec #living_off_the_land #Malware Analysis #Remcos #supply chain attack #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 00:12:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #AgentTesla #ahost.exe #c_ares #DLL Sideloading #GitKraken #infosec #living_off_the_land #Malware Analysis #Remcos #supply chain attack #Trellix
Daily CyberSecurity
Trusted Tool Turned Traitor: Signed ‘ahost.exe’ Weaponized to Sideload Malware
A routine utility often bundled with developer tools has been weaponized by cybercriminals to bypass security scanners and deliver a payload of devastating malware. The Trellix Advanced Research C…
⤷ Title: APT28 Weaponizes Office Flaw to Spy on NATO & Military
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:06:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT28 #BeardShell #CVE_2026_21509 #Fancy Bear #Filen.io #Military Espionage #NATO Targets #NotDoor #Trellix #WebDAV Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:06:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT28 #BeardShell #CVE_2026_21509 #Fancy Bear #Filen.io #Military Espionage #NATO Targets #NotDoor #Trellix #WebDAV Exploit
Daily CyberSecurity
APT28 Weaponizes Office Flaw to Spy on NATO & Military
APT28 (Fancy Bear) weaponized CVE-2026-21509 in 24 hours to target NATO. New "BeardShell" and "NotDoor" malware steals emails. Patch Office now.
⤷ Title: The End of the Static Era: Trellix Uncovers Fully Fileless Remcos RAT Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 06:03:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #Remcos RAT #Remote Access Trojan #threat intelligence #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 06:03:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #Remcos RAT #Remote Access Trojan #threat intelligence #Trellix
Daily CyberSecurity
The End of the Static Era: Trellix Uncovers Fully Fileless Remcos RAT Campaign
Trellix uncovers a stealthy, fileless Remcos RAT campaign utilizing process hollowing to execute entirely in memory and evade traditional security.
⤷ Title: Inside the Masjesu IoT Botnet’s 3-Year Stealth Reign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 07:05:05 +0000
════════════════════════
⌗ Tags: #Malware #C2 Infrastructure #D_Link #DDoS_for_hire #GPON #IoT security #Malware Analysis #Masjesu Botnet #Netgear #Trellix ARC #XOR encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 07:05:05 +0000
════════════════════════
⌗ Tags: #Malware #C2 Infrastructure #D_Link #DDoS_for_hire #GPON #IoT security #Malware Analysis #Masjesu Botnet #Netgear #Trellix ARC #XOR encryption
Daily CyberSecurity
Inside the Masjesu IoT Botnet’s 3-Year Stealth Reign
Trellix ARC reveals Masjesu, a stealthy, professional IoT botnet operational since 2023. Targeted DDoS-for-hire with a low-profile strategy. Patch now!
⤷ Title: PureRAT Unmasked: The Stealthy, Multi-Stage “Dynamic Loader” Targeting Windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
Daily CyberSecurity
PureRAT Unmasked: The Stealthy, Multi-Stage "Dynamic Loader" Targeting Windows
Trellix uncovers PureRAT, a modular Trojan hiding malware in PNG images. Learn how it uses steganography and fileless delivery to bypass Windows security.