⤷ Title: Booking.com Impersonated in Phishing Campaign Delivering Credential-Stealing Malware
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Sun, 16 Mar 2025 01:45:37 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #Booking #Booking phishing campaign #ClickFix #DanaBot #Lumma Stealer #NetSupport RAT #Phishing Campaign #Storm_1865 #VenomRAT #XWorm
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Sun, 16 Mar 2025 01:45:37 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #Booking #Booking phishing campaign #ClickFix #DanaBot #Lumma Stealer #NetSupport RAT #Phishing Campaign #Storm_1865 #VenomRAT #XWorm
Daily CyberSecurity
Booking.com Impersonated in Phishing Campaign Delivering Credential-Stealing Malware
Stay informed about Booking Phishing schemes. Discover how attackers use social engineering to steal credentials in this campaign.
⤷ Title: Bulletproof Hosting Fuels Russia-Linked Intrusion Sets’ Global Cyber Campaign
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 00:11:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Black Basta #Cactus #LiteManager #Lockbit ransomware #NetSupport Manager #RansomHub #Remcos #sLoad #UAC_0006 #UAC_0050 #Zservers
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 00:11:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Black Basta #Cactus #LiteManager #Lockbit ransomware #NetSupport Manager #RansomHub #Remcos #sLoad #UAC_0006 #UAC_0050 #Zservers
Daily CyberSecurity
Bulletproof Hosting Fuels Russia-Linked Intrusion Sets' Global Cyber Campaign
Learn how UAC-0006 Espionage is linked to Russian cyber operations targeting Ukraine through financial and psychological warfare.
⤷ Title: Alert: Fake DocuSign & Gitcodes Pages Install NetSupport RAT Malware!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 00:25:35 +0000
════════════════════════
⌗ Tags: #Malware #cyberattack #cybersecurity #Docusign #DomainTools #Gitcodes #malware #NetSupport RAT #phishing #powershell #Remote Access Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 00:25:35 +0000
════════════════════════
⌗ Tags: #Malware #cyberattack #cybersecurity #Docusign #DomainTools #Gitcodes #malware #NetSupport RAT #phishing #powershell #Remote Access Trojan
Daily CyberSecurity
Alert: Fake DocuSign & Gitcodes Pages Install NetSupport RAT Malware!
A new campaign uses fake DocuSign & Gitcodes pages to trick users into manually installing NetSupport RAT, gaining remote control.
⤷ Title: GrayAlpha’s Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:02:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:02:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
Daily CyberSecurity
GrayAlpha’s Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
GrayAlpha, linked to FIN7, escalates tactics with fake browser/7-Zip updates and TAG-124 TDS, spreading NetSupport RAT in a multi-pronged infection campaign.
⤷ Title: NetSupport RAT Returns: Weaponized via WordPress & “ClickFix” for Remote Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:44:44 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Cybereason #cybersecurity #malware #NetSupport Manager #phishing #rat #Remote Access Trojan #social engineering #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:44:44 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Cybereason #cybersecurity #malware #NetSupport Manager #phishing #rat #Remote Access Trojan #social engineering #wordpress
Daily CyberSecurity
NetSupport RAT Returns: Weaponized via WordPress & "ClickFix" for Remote Access
Cybereason exposes a deceptive malware campaign using compromised WordPress sites and the "ClickFix" technique to deliver weaponized NetSupport Manager RAT clients for remote access.
⤷ Title: CastleBot: The New MaaS Framework Fueling Info-Stealer & Ransomware Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:25:51 +0000
════════════════════════
⌗ Tags: #Malware #CastleBot #cybersecurity #Infostealer #MaaS #Malware_as_a_Service #NetSupport #ransomware #Trojan #WarmCookie
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:25:51 +0000
════════════════════════
⌗ Tags: #Malware #CastleBot #cybersecurity #Infostealer #MaaS #Malware_as_a_Service #NetSupport #ransomware #Trojan #WarmCookie
Daily CyberSecurity
CastleBot: The New MaaS Framework Fueling Info-Stealer & Ransomware Attacks
IBM X-Force has unveiled an in-depth analysis of CastleBot, a newly emerging Malware-as-a-Service (MaaS) framework that is quickly becoming a potent weapon in the cybercrime ecosystem. Designed fo…
⤷ Title: NetSupport RAT Campaign Abuses ClickFix to Infect Hosts; 3 Threat Clusters Use RMM for Covert Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EVALUSION #Multi_Cluster #NetSupport RAT #powershell #Remote Access Trojan #RMM Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EVALUSION #Multi_Cluster #NetSupport RAT #powershell #Remote Access Trojan #RMM Abuse
Daily CyberSecurity
NetSupport RAT Campaign Abuses ClickFix to Infect Hosts; 3 Threat Clusters Use RMM for Covert Access
eSentire exposed a surge in NetSupport RAT campaigns using the ClickFix social engineering tactic. Three threat clusters leverage a PowerShell loader to bypass AV and gain full remote access via the RMM tool.
⤷ Title: Amatera Stealer Campaign Uses ClickFix to Deploy Malware, Bypassing EDR by Patching AMSI in Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Stealer #AMSI Bypass #ClickFix #Credential Theft #NetSupport RAT #powershell #Pure Crypter #WoW64 syscalls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Stealer #AMSI Bypass #ClickFix #Credential Theft #NetSupport RAT #powershell #Pure Crypter #WoW64 syscalls
Daily CyberSecurity
Amatera Stealer Campaign Uses ClickFix to Deploy Malware, Bypassing EDR by Patching AMSI in Memory
eSentire’s Threat Response Unit (TRU) has uncovered a widespread malware operation leveraging a deceptive social-engineering technique known as ClickFix to deliver a newly rebranded version of the…
⤷ Title: Bloody Wolf Hackers Impersonate Government Agencies to Deploy NetSupport RAT in Central Asia
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 02:43:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bloody Wolf #Central Asia #Cyber Espionage #Government Impersonation #Group_IB #Kyrgyzstan #NetSupport RAT #phishing #Uzbekistan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 02:43:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bloody Wolf #Central Asia #Cyber Espionage #Government Impersonation #Group_IB #Kyrgyzstan #NetSupport RAT #phishing #Uzbekistan
Penetration Testing Tools
Bloody Wolf Hackers Impersonate Government Agencies to Deploy NetSupport RAT in Central Asia
The “Bloody Wolf” group is expanding its targeted campaign across Central Asia, deploying NetSupport RAT and impersonating government
⤷ Title: Bloody Wolf APT Expands to Central Asia, Deploys NetSupport RAT via Custom Java Droppers and Geo-Fencing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:00:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Bloody Wolf #Central Asia #Espionage #Java Dropper #NetSupport RAT #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:00:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Bloody Wolf #Central Asia #Espionage #Java Dropper #NetSupport RAT #spear_phishing
Daily CyberSecurity
Bloody Wolf APT Expands to Central Asia, Deploys NetSupport RAT via Custom Java Droppers and Geo-Fencing
Bloody Wolf APT is targeting Central Asia using custom Java droppers to deploy the NetSupport RAT. The group uses geo-fencing and fake Ministry of Justice lures to achieve stealthy, persistent access for espionage.
⤷ Title: New JS#SMUGGLER Campaign Drops NetSupport RAT Through Infected Sites
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 18:16:40 +0000
════════════════════════
⌗ Tags: #Malware #Security #Cyber Attack #Cybersecurity #JS#SMUGGLER #NetSupport Manager #PowerShell #RAT #Securonix
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 18:16:40 +0000
════════════════════════
⌗ Tags: #Malware #Security #Cyber Attack #Cybersecurity #JS#SMUGGLER #NetSupport Manager #PowerShell #RAT #Securonix
Hackread
New JS#SMUGGLER Campaign Drops NetSupport RAT Through Infected Sites
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: JS#SMUGGLER Malware Evades EDR Using “Junk Code” JavaScript and Fileless PowerShell to Deploy NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:14:50 +0000
════════════════════════
⌗ Tags: #Malware #fileless #HTA #JS#SMUGGLER #Junk Code Obfuscation #LOLBins #NetSupport RAT #powershell #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:14:50 +0000
════════════════════════
⌗ Tags: #Malware #fileless #HTA #JS#SMUGGLER #Junk Code Obfuscation #LOLBins #NetSupport RAT #powershell #Supply Chain
Daily CyberSecurity
JS#SMUGGLER Malware Evades EDR Using "Junk Code" JavaScript and Fileless PowerShell to Deploy NetSupport RAT
The JS#SMUGGLER campaign uses "Junk Code" JavaScript and fileless PowerShell executed via mshta.exe to bypass EDR. This multi-stage attack silently installs the NetSupport RAT.
⤷ Title: Fileless Evasion: Multi-Stage Campaign Deploys NetSupport RAT via Obfuscated HTA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:36:59 +0000
════════════════════════
⌗ Tags: #Malware #Corporate Attack #cybersecurity #Fileless Malware #HTA #JavaScript #NetSupport RAT #PowerShell #Remote Access Trojan #Securonix
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:36:59 +0000
════════════════════════
⌗ Tags: #Malware #Corporate Attack #cybersecurity #Fileless Malware #HTA #JavaScript #NetSupport RAT #PowerShell #Remote Access Trojan #Securonix
Penetration Testing Tools
Fileless Evasion: Multi-Stage Campaign Deploys NetSupport RAT via Obfuscated HTA
Researchers at Securonix have uncovered a multi-layered malware campaign designed to surreptitiously deploy the NetSupport RAT remote access
⤷ Title: “ClickFix” Trap: Fake Human Verification Leads to Qilin Ransomware Infection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
Daily CyberSecurity
"ClickFix" Trap: Fake Human Verification Leads to Qilin Ransomware Infection
Sophos CTU reveals how the ClickFix tactic led to a Qilin ransomware attack via NetSupport RAT and StealC V2 using stolen VPN credentials.
⤷ Title: The “IClickFix” Trap: 3,800+ WordPress Sites Poisoned by Fake CAPTCHAs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 01:49:29 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #fake CAPTCHA #IClickFix #malware #NetSupport RAT #powershell #Sekoia TDR #social engineering #watering hole attack #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 01:49:29 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #fake CAPTCHA #IClickFix #malware #NetSupport RAT #powershell #Sekoia TDR #social engineering #watering hole attack #wordpress security
Daily CyberSecurity
The "IClickFix" Trap: 3,800+ WordPress Sites Poisoned by Fake CAPTCHAs
IClickFix malware hijacks 3,800+ WordPress sites with fake Cloudflare CAPTCHAs. This watering hole attack tricks users into running malicious PowerShell.
⤷ Title: Stan Ghouls Target Uzbekistan and Russia with NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:27:34 +0000
════════════════════════
⌗ Tags: #Malware #Bloody Wolf #cyber_espionage #Java Loader #kaspersky #Mirai botnet #NetSupport RAT #phishing #rat #social engineering #Stan Ghouls #Uzbekistan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:27:34 +0000
════════════════════════
⌗ Tags: #Malware #Bloody Wolf #cyber_espionage #Java Loader #kaspersky #Mirai botnet #NetSupport RAT #phishing #rat #social engineering #Stan Ghouls #Uzbekistan
Daily CyberSecurity
Stan Ghouls Target Uzbekistan and Russia with NetSupport RAT
Stan Ghouls group targets Uzbekistan via fake court emails and malicious Java loaders. Learn how they deploy NetSupport RAT to spy on victims.
⤷ Title: The ‘ClickFix’ Trap: GrayCharlie Hijacks US Law Firms to Deploy NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:22:38 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Cyber Security #Fake Browser Update #GrayCharlie #infosec #Insikt Group #NetSupport RAT #StealC #supply chain attack #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:22:38 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Cyber Security #Fake Browser Update #GrayCharlie #infosec #Insikt Group #NetSupport RAT #StealC #supply chain attack #wordpress security
Daily CyberSecurity
The 'ClickFix' Trap: GrayCharlie Hijacks US Law Firms to Deploy NetSupport RAT
Insikt Group exposes GrayCharlie compromising WordPress sites & US law firms. Attackers use "ClickFix" fake CAPTCHAs to deploy the NetSupport RAT.
⤷ Title: The “ClickFix” Trap: GrayCharlie Syndicate Hijacks U.S. Law Firm Sites in Sophisticated Supply-Chain Strike
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:24:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #fake browser updates #GrayCharlie #Insikt Group #legal sector cyberattack #NetSupport RAT #SMB Team #Stealc infostealer #supply chain attack #Tech News 2026 #WordPress Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:24:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #fake browser updates #GrayCharlie #Insikt Group #legal sector cyberattack #NetSupport RAT #SMB Team #Stealc infostealer #supply chain attack #Tech News 2026 #WordPress Security
Penetration Testing Tools
The "ClickFix" Trap: GrayCharlie Syndicate Hijacks U.S. Law Firm Sites in Sophisticated Supply-Chain Strike
Experts from the Insikt Group division have promulgated the inaugural comprehensive dossier regarding GrayCharlie, a threat syndicate that,
⤷ Title: Clubfoot Wolf Hits Russian Firms With NetSupport Manager
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 13:16:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BI.ZONE #Clubfoot Wolf #LNK malware #NetSupport Manager #phishing #Remote Access Tool #Russian companies
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 13:16:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BI.ZONE #Clubfoot Wolf #LNK malware #NetSupport Manager #phishing #Remote Access Tool #Russian companies
Daily CyberSecurity
Clubfoot Wolf Hits Russian Firms With NetSupport Manager
At a glance Actor / group Clubfoot Wolf (cluster tracked by BI.ZONE) Activity type Phishing that deploys NetSupport Manager for remote access Targets / victims Russian firms across eight sectors; …
⤷ Title: CastleLoader Malware Now Delivers NeedleStealer Wallet and Browser Spoofers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:11:48 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #CastleLoader #CASTLESTEALER #ClickFix #crypto wallet spoofer #Infostealer #malware loader #NeedleStealer #NetSupport RAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:11:48 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #CastleLoader #CASTLESTEALER #ClickFix #crypto wallet spoofer #Infostealer #malware loader #NeedleStealer #NetSupport RAT
Daily CyberSecurity
CastleLoader Malware Now Delivers NeedleStealer Wallet and Browser Spoofers
At a glance Malware family CastleLoader (loader); payloads include CastleStealer, NetSupport RAT, Lobshot, and NeedleStealer Threat actor Not named in this report; the loader is publicly tied to a…