⤷ Title: The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT group #cyber_espionage #HoneyMyte #kaspersky #Kernel_Mode #Microsoft Defender Bypass #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Southeast Asia #Thailand #ToneShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT group #cyber_espionage #HoneyMyte #kaspersky #Kernel_Mode #Microsoft Defender Bypass #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Southeast Asia #Thailand #ToneShell
Daily CyberSecurity
The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
The notorious cyber-espionage group HoneyMyte (also known as Mustang Panda or Bronze President) has dramatically upgraded its arsenal, deploying a sophisticated kernel-mode rootkit to entrench its…
⤷ Title: The Forensic Backfire: How Hackers Weaponized a Legacy EnCase Driver to Decapitate Modern EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 02:41:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cyberattack 2026 #driver blocklist #EDR killer #EnCase driver #Huntress #HVCI #kernel_mode #MFA Bypass #process termination #SonicWall #SSL VPN
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 02:41:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cyberattack 2026 #driver blocklist #EDR killer #EnCase driver #Huntress #HVCI #kernel_mode #MFA Bypass #process termination #SonicWall #SSL VPN
Penetration Testing Tools
The Forensic Backfire: How Hackers Weaponized a Legacy EnCase Driver to Decapitate Modern EDR
Adversaries are increasingly inaugurating their offensives not with conventional malware, but by subverting legitimate remote access credentials. A
⤷ Title: Shadows Vanish: The “Global Man” Exit Scam Leaves Malware Operators in the Dark
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 02:34:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #code_signing certificates #cybercrime forums #digital certificates #EV Certificates #Exit Scam #Global Man #kernel_mode drivers #malware obfuscation #security breach 2026 #Shadow Economy #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 02:34:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #code_signing certificates #cybercrime forums #digital certificates #EV Certificates #Exit Scam #Global Man #kernel_mode drivers #malware obfuscation #security breach 2026 #Shadow Economy #threat intelligence
Penetration Testing Tools
Shadows Vanish: The "Global Man" Exit Scam Leaves Malware Operators in the Dark
In the clandestine digital underworld, a prominent purveyor of code-signing certificates has executed a high-profile disappearance. The Global
⤷ Title: Ghost in the Browser: Hijacking Authenticated Sessions via NTLM Relay with ghostsurf
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:49:11 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cyber Security 2026 #ghostsurf #IIS Security #Kernel_Mode Auth #NTLM Auth #NTLM Relay #Penetration Testing #red teaming #Session Hijacking #SOCKS5 Proxy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:49:11 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cyber Security 2026 #ghostsurf #IIS Security #Kernel_Mode Auth #NTLM Auth #NTLM Relay #Penetration Testing #red teaming #Session Hijacking #SOCKS5 Proxy
Penetration Testing Tools
Ghost in the Browser: Hijacking Authenticated Sessions via NTLM Relay with ghostsurf
Master NTLM relay with ghostsurf. Use a SOCKS5 proxy to hijack browser sessions, bypass kernel-mode auth, and impersonate users on IIS and HTTPS targets.