⤷ Title: Raven Stealer: New MaaS Infostealer Plunders Data via Reflective Process Hollowing & Telegram Exfil
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Malware #C++ #cybersecurity #data exfiltration #Delphi #Infostealer #MaaS #Malware_as_a_Service #Process Hollowing #Raven Stealer #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Malware #C++ #cybersecurity #data exfiltration #Delphi #Infostealer #MaaS #Malware_as_a_Service #Process Hollowing #Raven Stealer #Telegram
Daily CyberSecurity
Raven Stealer: New MaaS Infostealer Plunders Data via Reflective Process Hollowing & Telegram Exfil
A recent in-depth analysis from Cyfirma has shed light on the alarming capabilities of Raven Stealer, a lightweight yet powerful information-stealing malware rapidly gaining traction across the cy…
⤷ Title: Raven Stealer Unmasked: New MaaS Infostealer Plunders Data via Reflective Process Hollowing & Telegram Exfil
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 00:19:59 +0000
════════════════════════
⌗ Tags: #Malware #C++ #cybersecurity #Data Exfiltration #Delphi #Infostealer #MaaS #Malware_as_a_Service #Process Hollowing #Raven Stealer #Telegram
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 00:19:59 +0000
════════════════════════
⌗ Tags: #Malware #C++ #cybersecurity #Data Exfiltration #Delphi #Infostealer #MaaS #Malware_as_a_Service #Process Hollowing #Raven Stealer #Telegram
Penetration Testing Tools
Raven Stealer Unmasked: New MaaS Infostealer Plunders Data via Reflective Process Hollowing & Telegram Exfil
Cyfirma reveals Raven Stealer, a new, lightweight MaaS infostealer built in Delphi/C++, using reflective process hollowing and Telegram bots for stealthy data exfiltration from browsers.
⤷ Title: The OverRide Chronicles: When Your Calculator Becomes a Spy (And Why That’s Hilariously Terrifying)
════════════════════════
𐀪 Author: Lazyown Redteam
════════════════════════
ⴵ Time: Sun, 10 Aug 2025 06:13:28 GMT
════════════════════════
⌗ Tags: #process_hollowing #hacking #process_overwriting #shadownlink #override
════════════════════════
𐀪 Author: Lazyown Redteam
════════════════════════
ⴵ Time: Sun, 10 Aug 2025 06:13:28 GMT
════════════════════════
⌗ Tags: #process_hollowing #hacking #process_overwriting #shadownlink #override
Medium
The OverRide Chronicles: When Your Calculator Becomes a Spy (And Why That’s Hilariously Terrifying)
> By: grisun0, White Hat Blogger & Professional Overthinker of Suspiciously Suspended Processes
⤷ Title: DarkCloud Rises: New Fileless Stealer Uses PowerShell & Process Hollowing to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:01:00 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DarkCloud #evasion #fileless #Fortinet #Infostealer #malware #powershell #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:01:00 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DarkCloud #evasion #fileless #Fortinet #Infostealer #malware #powershell #Process Hollowing
Daily CyberSecurity
DarkCloud Rises: New Fileless Stealer Uses PowerShell & Process Hollowing to Evade Detection
Researchers from Fortinet’s FortiGuard Labs detected a new DarkCloud campaign deploying a stealthy, fileless payload through a sophisticated phishing and PowerShell-based attack chain. DarkCloud —…
⤷ Title: Malware Development with NIM — Process Hollowing (or the Art of Soul Transplant)
════════════════════════
𐀪 Author: Edgar Huemac Sanchez Hernandez
════════════════════════
ⴵ Time: Tue, 16 Sep 2025 00:51:43 GMT
════════════════════════
⌗ Tags: #programming #process_hollowing #cybersecurity #malware #infosec
════════════════════════
𐀪 Author: Edgar Huemac Sanchez Hernandez
════════════════════════
ⴵ Time: Tue, 16 Sep 2025 00:51:43 GMT
════════════════════════
⌗ Tags: #programming #process_hollowing #cybersecurity #malware #infosec
Medium
Malware Development with NIM — Process Hollowing (or the Art of Soul Transplant)
Hello back! I hope you’re doing just fine. Today’s topic is going to be a fun evasion technique (after all, that is in great part what…
⤷ Title: MissionEvasion: The New Windows Tool That Evades Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 02:57:43 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #malware #MissionEvasion #Process Hollowing #Process injection #Red Team #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 02:57:43 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #malware #MissionEvasion #Process Hollowing #Process injection #Red Team #windows
Penetration Testing Tools
MissionEvasion: The New Windows Tool That Evades Detection
MissionEvasion is a powerful new tool for Windows that uses advanced process hollowing and overwriting techniques to bypass defenses and inject code.
⤷ Title: Stealth Stealer: PhantomVAI Loader Uses Steganography in Images to Inject Katz Stealer and Evade Sandboxes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 02:27:02 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #C++ #Katz Stealer #Malware_as_a_Service #PhantomVAI Loader #phishing #Process Hollowing #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 02:27:02 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #C++ #Katz Stealer #Malware_as_a_Service #PhantomVAI Loader #phishing #Process Hollowing #steganography
Daily CyberSecurity
Stealth Stealer: PhantomVAI Loader Uses Steganography in Images to Inject Katz Stealer and Evade Sandboxes
Unit 42 exposed PhantomVAI Loader, a stealthy MaaS tool that uses steganography (hiding DLL in images) and VM detection to deploy Katz Stealer in MSBuild.exe and exfiltrate crypto credentials globally.
⤷ Title: Lumma Infostealer MaaS Campaign Uses NSIS/AutoIt and MEGA Cloud to Steal Credentials via Pirated Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:14 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt #Credential Theft #Cybercrime #Lumma Infostealer #MaaS #MEGA Cloud #NSIS Installer #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:14 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt #Credential Theft #Cybercrime #Lumma Infostealer #MaaS #MEGA Cloud #NSIS Installer #Process Hollowing
Daily CyberSecurity
Lumma Infostealer MaaS Campaign Uses NSIS/AutoIt and MEGA Cloud to Steal Credentials via Pirated Software
A sophisticated Lumma Infostealer MaaS campaign targets users with pirated software installers. It uses NSIS/AutoIt scripts, Process Hollowing, and MEGA cloud to steal credentials from browsers and crypto wallets.
⤷ Title: “Silver Fox” Unmasked: Chinese APT Group Impersonates Indian Tax Officials in Targeted Cyber Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 00:12:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Attribution Accuracy #China_linked #CloudSEK #cyber_espionage #DLL hijacking #Income Tax Phishing #India #Process Hollowing #Silver Fox APT #threat intelligence #Valley RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 00:12:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Attribution Accuracy #China_linked #CloudSEK #cyber_espionage #DLL hijacking #Income Tax Phishing #India #Process Hollowing #Silver Fox APT #threat intelligence #Valley RAT
Daily CyberSecurity
“Silver Fox” Unmasked: Chinese APT Group Impersonates Indian Tax Officials in Targeted Cyber Campaign
As tax season approaches, a sophisticated cyber-espionage campaign is targeting Indian organizations with highly convincing phishing lures. While initially mistaken for a familiar adversary, a new…
⤷ Title: Invisible Intruder: Fileless Remcos RAT Hides in Shipping Emails
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2017_11882 #Cyber Security #Fileless Malware #FortiGuard Labs #Malware Analysis #phishing #Process Hollowing #Remcos RAT #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2017_11882 #Cyber Security #Fileless Malware #FortiGuard Labs #Malware Analysis #phishing #Process Hollowing #Remcos RAT #steganography
Daily CyberSecurity
Invisible Intruder: Fileless Remcos RAT Hides in Shipping Emails
A sophisticated new phishing campaign has been detected in the wild, leveraging a fileless variant of the notorious Remcos RAT (Remote Access Trojan) to evade detection and seize control of victim…
⤷ Title: Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
Daily CyberSecurity
Signed & Stolen: "Phantom Stealer" Hijacks Java App via Fake DHL Invoice
Attackers use fake DHL invoices to sideload Phantom Stealer v3.5.0 via a signed Java utility. Malware hides in AddInProcess32.exe. Watch out.
⤷ Title: Digital Ghost: “PhantomVAI” Malware Revives Decade-Old RunPE Tricks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
Daily CyberSecurity
Digital Ghost: "PhantomVAI" Malware Revives Decade-Old RunPE Tricks
New "PhantomVAI" malware recycles old Hackforums "RunPE" code to bypass modern EDR. Campaigns use task scheduler masquerading to deliver infostealers.
⤷ Title: The “Phantom” Resurrection: How Intrinsec Unmasked the Mandark-Powered Malware Loader Evading Global Defense
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:48:37 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #cybersecurity news #DarkCloud #Intrinsec #IoCs 2026 #Mandark utility #PhantomVAI #Process Hollowing #Remcos #RunPE framework #Threat Hunting #XWorm #YARA rules
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:48:37 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #cybersecurity news #DarkCloud #Intrinsec #IoCs 2026 #Mandark utility #PhantomVAI #Process Hollowing #Remcos #RunPE framework #Threat Hunting #XWorm #YARA rules
Penetration Testing Tools
The "Phantom" Resurrection: How Intrinsec Unmasked the Mandark-Powered Malware Loader Evading Global Defense
Analysts at Intrinsec have documented a surge in offensives leveraging the PhantomVAI loader, a utility architected upon the
⤷ Title: Excel Trap: New Phishing Campaign Deploys Fileless XWorm RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:13:12 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2018_0802 #cybersecurity #Excel Malware #Fileless Malware #FortiGuard Labs #phishing #powershell #Process Hollowing #rat #steganography #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:13:12 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2018_0802 #cybersecurity #Excel Malware #Fileless Malware #FortiGuard Labs #phishing #powershell #Process Hollowing #rat #steganography #XWorm
Daily CyberSecurity
Excel Trap: New Phishing Campaign Deploys Fileless XWorm RAT
Phishing emails use malicious Excel files to deploy XWorm RAT. The fileless attack exploits CVE-2018-0802 to steal data & control systems.