⤷ Title: NightshadeC2: A New Botnet Is Using “UAC Prompt Bombing” to Bypass Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Malware #botnet #ClickFix #cybersecurity #malware #NightshadeC2 #Trojanized Software #UAC Prompt Bombing #Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Malware #botnet #ClickFix #cybersecurity #malware #NightshadeC2 #Trojanized Software #UAC Prompt Bombing #Windows Defender
Daily CyberSecurity
NightshadeC2: A New Botnet Is Using "UAC Prompt Bombing" to Bypass Windows Defender
A new botnet, NightshadeC2, is using a technique called "UAC Prompt Bombing" to bypass sandboxes and Windows Defender by relentlessly looping UAC prompts.
⤷ Title: NightshadeC2 Botnet Is Using “UAC Prompt Bombing” to Bypass Defenses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:09:34 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #eSentire #hacking #malware #NightshadeC2 #uac
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:09:34 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #eSentire #hacking #malware #NightshadeC2 #uac
Penetration Testing Tools
NightshadeC2 Botnet Is Using "UAC Prompt Bombing" to Bypass Defenses
A new botnet called NightshadeC2 uses "UAC Prompt Bombing" to force users to approve malicious actions, bypassing Windows Defender and analysis sandboxes.
⤷ Title: CERT-UA Warns: New Espionage Campaign Distributes CABINETRAT Backdoor via Signal Messenger XLL Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:56:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anti_Analysis #Backdoor #CABINETRAT #CERT_UA #Cyber Espionage #Signal #UAC_0245 #Ukraine #XLL
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:56:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anti_Analysis #Backdoor #CABINETRAT #CERT_UA #Cyber Espionage #Signal #UAC_0245 #Ukraine #XLL
Penetration Testing Tools
CERT-UA Warns: New Espionage Campaign Distributes CABINETRAT Backdoor via Signal Messenger XLL Files
CERT-UA uncovered a campaign (UAC-0245) using Signal to deliver malicious XLL files and inject the full-featured CABINETRAT backdoor. The malware evades sandboxes by checking system specs.
⤷ Title: UAC Bypass: Memory Injection (Metasploit)
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 17:17:54 GMT
════════════════════════
⌗ Tags: #uac_bypass #uac #user_account_control #ejpt #penetration_testing
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 17:17:54 GMT
════════════════════════
⌗ Tags: #uac_bypass #uac #user_account_control #ejpt #penetration_testing
Medium
UAC Bypass: Memory Injection (Metasploit)
⤷ Title: HTB_Academy: Extracting Passwords from Windows Systems Part 3:Attacking Windows Credential Manager
════════════════════════
𐀪 Author: Babatunde Ojo
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 14:12:14 GMT
════════════════════════
⌗ Tags: #htb_writeup #passwords #hacking #windows #uac_bypass
════════════════════════
𐀪 Author: Babatunde Ojo
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 14:12:14 GMT
════════════════════════
⌗ Tags: #htb_writeup #passwords #hacking #windows #uac_bypass
Medium
HTB_Academy: Extracting Passwords from Windows Systems Part 3:Attacking Windows Credential Manager
Enumerating credentials with cmdkey
⤷ Title: Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:10:46 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #Clipboard Hijacking #rat #rc4 #Remote Access Trojan #Screen Capture #Steam C2 #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:10:46 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #Clipboard Hijacking #rat #rc4 #Remote Access Trojan #Screen Capture #Steam C2 #UAC bypass
Daily CyberSecurity
Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage
A new C-compiled RAT, CastleRAT, uses Steam Community pages to hide its C2. The malware deploys advanced features like UAC Bypass, screen capture, and clipboard hijacking for espionage.
⤷ Title: “Purchase Order” Deception: Sophisticated Loader Targets Manufacturing Giants in Italy, Finland, and Saudi Arabia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:32:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyble #Government Cyberattacks #Malware_as_a_Service #Manufacturing Security #PureLog Stealer #Remcos RAT #steganography #TaskScheduler #UAC bypass #Unified Commodity Loader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:32:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyble #Government Cyberattacks #Malware_as_a_Service #Manufacturing Security #PureLog Stealer #Remcos RAT #steganography #TaskScheduler #UAC bypass #Unified Commodity Loader
Daily CyberSecurity
“Purchase Order” Deception: Sophisticated Loader Targets Manufacturing Giants in Italy, Finland, and Saudi Arabia
A highly sophisticated cyber-espionage campaign is indiscriminately targeting the manufacturing and government sectors across Europe and the Middle East, using a “Swiss Army Knife” sty…
⤷ Title: The Silence of the Scans: New NtKiller Utility Disables Antivirus at the Root
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:23:58 +0000
════════════════════════
⌗ Tags: #Malware #AlphaGhoul #Early Boot Persistence #EDR Bypass #endpoint security #HVCI #KrakenLabs #Malware 2025 #Microsoft Defender #NtKiller #rootkit #UAC bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:23:58 +0000
════════════════════════
⌗ Tags: #Malware #AlphaGhoul #Early Boot Persistence #EDR Bypass #endpoint security #HVCI #KrakenLabs #Malware 2025 #Microsoft Defender #NtKiller #rootkit #UAC bypass
Penetration Testing Tools
The Silence of the Scans: New NtKiller Utility Disables Antivirus at the Root
A new commodity has surfaced on underground forums for those seeking to operate more quietly—and for longer. An
⤷ Title: The Installer Trap: New SetupHijack Tool Bypasses Windows UAC via Race Conditions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 04:16:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Authenticode #Cybersecurity 2026 #MSBuild #MSI Exploitation #privilege escalation #Race Condition #red teaming #SetupHijack #UAC bypass #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 04:16:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Authenticode #Cybersecurity 2026 #MSBuild #MSI Exploitation #privilege escalation #Race Condition #red teaming #SetupHijack #UAC bypass #Windows Security
Information Security News
The Installer Trap: New SetupHijack Tool Bypasses Windows UAC via Race Conditions
SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows installer and update processes. It targets scenarios where privileged installers or upda…
⤷ Title: Weaponizing Grief: Hive0156 Exploits Military Families in High-Stakes Phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 08:39:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security 2026 #DLL Sideloading #Espionage #HijackLoader #Hive0156 #phishing #Remcos RAT #UAC_0184 #Ukraine #Verkhovna Rada #Viber
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 08:39:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security 2026 #DLL Sideloading #Espionage #HijackLoader #Hive0156 #phishing #Remcos RAT #UAC_0184 #Ukraine #Verkhovna Rada #Viber
Information Security News
Weaponizing Grief: Hive0156 Exploits Military Families in High-Stakes Phishing
Military and governmental institutions have once again found themselves in the crosshairs of a sophisticated spear-phishing campaign, where adversaries exploit the most poignant societal anxieties…