⤷ Title: XorDDoS Evolves: Cisco Talos Uncovers “VIP” Controller Fueling Global DDoS Campaigns
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 19 Apr 2025 00:05:23 +0000
════════════════════════
⌗ Tags: #Cybercriminals #botnet #central controller #Cisco Talos #Cybercrime #DDoS malware #Linux Malware #threat intelligence #VIP version #XorDDoS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 19 Apr 2025 00:05:23 +0000
════════════════════════
⌗ Tags: #Cybercriminals #botnet #central controller #Cisco Talos #Cybercrime #DDoS malware #Linux Malware #threat intelligence #VIP version #XorDDoS
Daily CyberSecurity
XorDDoS Evolves: Cisco Talos Uncovers “VIP” Controller Fueling Global DDoS Campaigns
Cisco Talos reveals a new VIP version of XorDDoS with centralized control, enabling global DDoS attacks. U.S. targeted in over 70% of observed campaigns.
⤷ Title: Outlaw Botnet Exploits Weak SSH to Hijack Linux Systems for Crypto Mining
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 May 2025 00:15:17 +0000
════════════════════════
⌗ Tags: #Malware #crypto mining #Cybersecurity Threats #IRC botnet #kaspersky #Linux Malware #Outlaw botnet #Perl malware #SSH vulnerability #ssh_hardening #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 May 2025 00:15:17 +0000
════════════════════════
⌗ Tags: #Malware #crypto mining #Cybersecurity Threats #IRC botnet #kaspersky #Linux Malware #Outlaw botnet #Perl malware #SSH vulnerability #ssh_hardening #XMRig
Daily CyberSecurity
Outlaw Botnet Exploits Weak SSH to Hijack Linux Systems for Crypto Mining
Outlaw botnet targets Linux servers via weak SSH, using Perl scripts and XMRig miners for crypto mining and backdoor access, Kaspersky warns.
⤷ Title: Supply Chain Attack Alert: Malicious Go Modules and npm/PyPI Packages Deliver Devastating Linux…
════════════════════════
𐀪 Author: CyDhaal
════════════════════════
ⴵ Time: Sun, 04 May 2025 06:19:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #linux_malware #supply_chain_attack #cryptocurrency_security #open_source_security
════════════════════════
𐀪 Author: CyDhaal
════════════════════════
ⴵ Time: Sun, 04 May 2025 06:19:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #linux_malware #supply_chain_attack #cryptocurrency_security #open_source_security
Medium
Supply Chain Attack Alert: Malicious Go Modules and npm/PyPI Packages Deliver Devastating Linux…
In a shocking revelation, cybersecurity researchers have uncovered multiple malicious packages in Go, npm, and PyPI repositories, capable…
⤷ Title: APT36 Suspected in India Gov Spoofing Phishing with ClickFix Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 May 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT36 #ClickFix #cyberattack #Government #Hunt.io #India #Indian Ministry #Linux #Linux Malware #malware #phishing #social engineering #Threat Hunting #threat intelligence #Transparent Tribe #windows #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 May 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT36 #ClickFix #cyberattack #Government #Hunt.io #India #Indian Ministry #Linux #Linux Malware #malware #phishing #social engineering #Threat Hunting #threat intelligence #Transparent Tribe #windows #Windows malware
Daily CyberSecurity
APT36 Suspected in India Gov Spoofing Phishing with ClickFix Tactics
A sophisticated phishing campaign, possibly by APT36, spoofs Indian government sites and uses ClickFix tactics to target Windows and Linux users.
⤷ Title: Plague Backdoor: New Linux Malware Infiltrates Authentication Stack, Evading Detection for a Year
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 03:23:20 +0000
════════════════════════
⌗ Tags: #Linux #Malware #Authentication #Backdoor #cybersecurity #Evasion #Linux malware #PAM #Plague #ssh #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 03:23:20 +0000
════════════════════════
⌗ Tags: #Linux #Malware #Authentication #Backdoor #cybersecurity #Evasion #Linux malware #PAM #Plague #ssh #threat intelligence
Penetration Testing Tools
Plague Backdoor: New Linux Malware Infiltrates Authentication Stack, Evading Detection for a Year
A new backdoor, Plague, disguised as a Linux PAM component, evaded detection for over a year. It grants attackers persistent SSH access and leaves no forensic trail.
⤷ Title: The BOSS Breach: APT36 Pivots to Linux Espionage with “Silent” Shortcuts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 00:15:45 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT36 #BOSS OS #cyber_espionage #cybersecurity #Linux Malware #threat intelligence #Transparent Tribe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 00:15:45 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT36 #BOSS OS #cyber_espionage #cybersecurity #Linux Malware #threat intelligence #Transparent Tribe
Daily CyberSecurity
The BOSS Breach: APT36 Pivots to Linux Espionage with "Silent" Shortcuts
Transparent Tribe (APT36) evolves with new Linux malware targeting Indian government BOSS systems via weaponized shortcut files.
⤷ Title: The European Pivot: China-Linked UAT-7290 Targets Telecoms with SilentRaid
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 04:12:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_Nexus #Cisco Talos #Cyber Espionage #Linux malware #ORB #RushDrop #SilentRaid #South Asia #Southeastern Europe #Telecommunications #UAT_7290
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 04:12:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_Nexus #Cisco Talos #Cyber Espionage #Linux malware #ORB #RushDrop #SilentRaid #South Asia #Southeastern Europe #Telecommunications #UAT_7290
Information Security News
The European Pivot: China-Linked UAT-7290 Targets Telecoms with SilentRaid
The Cisco Talos intelligence unit has reported a significant geographical expansion in the activities of a threat actor utilizing sophisticated Linux malware to target telecommunication entities. …
⤷ Title: VoidLink: The “Cloud-First” Malware Hunting Your Linux Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 00:21:17 +0000
════════════════════════
⌗ Tags: #Malware #Check Point Research #Chinese Threat Actor #Cloud Security #Cobalt Strike #container security #DevOps Security #eBPF #Kubernetes Security #Linux Malware #supply chain attack #VoidLink #Zig Programming Language
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 00:21:17 +0000
════════════════════════
⌗ Tags: #Malware #Check Point Research #Chinese Threat Actor #Cloud Security #Cobalt Strike #container security #DevOps Security #eBPF #Kubernetes Security #Linux Malware #supply chain attack #VoidLink #Zig Programming Language
Daily CyberSecurity
VoidLink: The "Cloud-First" Malware Hunting Your Linux Servers
New "cloud-first" malware VoidLink targets Linux & containers with advanced stealth. Written in Zig, it mimics Cobalt Strike to evade EDR. Check your cloud.
⤷ Title: IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:46:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Asian Cyber Threat #BadIIS #Cisco Talos #cyber_espionage #GotoHTTP #IIS Security #Linux Malware #SEO Fraud #UAT_8099 #WEBJACK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:46:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Asian Cyber Threat #BadIIS #Cisco Talos #cyber_espionage #GotoHTTP #IIS Security #Linux Malware #SEO Fraud #UAT_8099 #WEBJACK
Daily CyberSecurity
IIS Under Siege: UAT-8099 Deploys Region-Locked "BadIIS" & Linux Variants
Cisco Talos warns of UAT-8099 targeting Asian IIS servers with region-locked BadIIS malware. New variants now attack Linux systems.
⤷ Title: Invisible Intruder: “ShadowHS” Malware Weaponizes Hackshell on Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
Daily CyberSecurity
Invisible Intruder: "ShadowHS" Malware Weaponizes Hackshell on Linux
Cyble uncovers "ShadowHS," a fileless Linux malware weaponizing hackshell. It uses GSocket tunneling to evade firewalls and kill rival bots.
⤷ Title: Shattering the Edge: Cisco Talos Unmasks “DKnife,” the 7-Module Framework Hijacking Your Router
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 04:19:48 +0000
════════════════════════
⌗ Tags: #Malware #AitM attack #China_nexus APT #Cisco Talos #DarkNimbus #DKnife #edge device security #Linux malware #network infrastructure #router malware #ShadowPad #Tech News 2026 #WizardNet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 04:19:48 +0000
════════════════════════
⌗ Tags: #Malware #AitM attack #China_nexus APT #Cisco Talos #DarkNimbus #DKnife #edge device security #Linux malware #network infrastructure #router malware #ShadowPad #Tech News 2026 #WizardNet
Penetration Testing Tools
Shattering the Edge: Cisco Talos Unmasks "DKnife," the 7-Module Framework Hijacking Your Router
Security analysts at Cisco Talos have unmasked a clandestine offensive platform that has operated surreptitiously within network infrastructure
⤷ Title: VoidLink Rising: New “AI-Ready” Malware Framework Targets Linux & IoT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:19:11 +0000
════════════════════════
⌗ Tags: #Malware #Cisco Talos #Cloud Security #Cyber Warfare #IoT security #Kubernetes Security #Linux Malware #Malware Analysis #Modular Framework #UAT_9921 #VoidLink
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 00:19:11 +0000
════════════════════════
⌗ Tags: #Malware #Cisco Talos #Cloud Security #Cyber Warfare #IoT security #Kubernetes Security #Linux Malware #Malware Analysis #Modular Framework #UAT_9921 #VoidLink
Daily CyberSecurity
VoidLink Rising: New "AI-Ready" Malware Framework Targets Linux & IoT
Cisco Talos reveals VoidLink, a modular Linux malware framework by UAT-9921. Features "compile-on-demand" tools to target IoT & cloud infrastructure.
⤷ Title: Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:02:53 +0000
════════════════════════
⌗ Tags: #Malware #Bincrypter #ClipXDaemon #Cryptocurrency Hijacker #cybersecurity #Cyble Research #infosec #Linux Malware #Process Masquerading #threat intelligence #X11 Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:02:53 +0000
════════════════════════
⌗ Tags: #Malware #Bincrypter #ClipXDaemon #Cryptocurrency Hijacker #cybersecurity #Cyble Research #infosec #Linux Malware #Process Masquerading #threat intelligence #X11 Security
Daily CyberSecurity
Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server
Cyble Research unmasks ClipXDaemon, a C2-less Linux malware that silently hijacks cryptocurrency wallet addresses in X11 clipboard environments.
⤷ Title: The Invisible Switch: How “ClipXDaemon” Hijacks Linux Clipboards to Steal Crypto
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:35:12 +0000
════════════════════════
⌗ Tags: #Malware #Bitcoin #Clipboard hijacker #ClipXDaemon #Cryptocurrency Theft #Cyber Security 2026 #Ethereum #Fileless Malware #Linux Desktop security #Linux malware #Monero #X11 security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:35:12 +0000
════════════════════════
⌗ Tags: #Malware #Bitcoin #Clipboard hijacker #ClipXDaemon #Cryptocurrency Theft #Cyber Security 2026 #Ethereum #Fileless Malware #Linux Desktop security #Linux malware #Monero #X11 security
Penetration Testing Tools
The Invisible Switch: How "ClipXDaemon" Hijacks Linux Clipboards to Steal Crypto
Cybersecurity researchers have unearthed a nascent Linux malware strain christened ClipXDaemon. This insidious program clandestinely intercepts the contents
⤷ Title: New Mirai Variant and “Monaco” Miner Targeting Linux Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 13:00:39 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CondiBot #Cryptojacking #cybersecurity #ddos #Eclypsium #infosec #IoT security #Linux Malware #Monaco Cryptominer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 13:00:39 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CondiBot #Cryptojacking #cybersecurity #ddos #Eclypsium #infosec #IoT security #Linux Malware #Monaco Cryptominer
Daily CyberSecurity
New Mirai Variant and "Monaco" Miner Targeting Linux Devices
Eclypsium uncovers two new Linux malware strains: a CondiBot DDoS variant and the Monaco SSH cryptominer targeting servers and IoT. Secure your network.
⤷ Title: APT41’s New “Zero-Detection” Backdoor Targets Linux Workloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba Cloud #APT41 #Breakglass Intelligence #Cloud Security #Credential Harvesting #cybersecurity #ELF Backdoor #infosec #Linux Malware #SMTP C2 #Winnti
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba Cloud #APT41 #Breakglass Intelligence #Cloud Security #Credential Harvesting #cybersecurity #ELF Backdoor #infosec #Linux Malware #SMTP C2 #Winnti
Daily CyberSecurity
APT41’s New "Zero-Detection" Backdoor Targets Linux Workloads
APT41's new zero-detection ELF backdoor uses SMTP (Port 25) to hijack Linux cloud workloads invisibly. Secure your credentials—audit your SMTP traffic today.
⤷ Title: Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:50:51 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Credential Harvester #DevSecOps #eBPF #GitHub Security #Kubernetes #Linux malware #malware analysis #QLNX #Quasar Linux #rootkit #supply chain attack #Trend Micro
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:50:51 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Credential Harvester #DevSecOps #eBPF #GitHub Security #Kubernetes #Linux malware #malware analysis #QLNX #Quasar Linux #rootkit #supply chain attack #Trend Micro
Penetration Testing Tools
Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain
The novel Linux implant, Quasar Linux, poses a formidable threat not merely to individual workstations but to the
⤷ Title: Security Alert: Cemu Emulator Linux Releases Compromised via GitHub Backdoor (May 2026)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 07:19:11 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cemu #Cemu_2.6_x86_64.AppImage #Cybersecurity 2026 #Emulation Security #GitHub Breach #infosec #Linux Malware #Malware Alert #Pro_Russian Hackers #Wii U Emulator
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 07:19:11 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cemu #Cemu_2.6_x86_64.AppImage #Cybersecurity 2026 #Emulation Security #GitHub Breach #infosec #Linux Malware #Malware Alert #Pro_Russian Hackers #Wii U Emulator
Daily CyberSecurity
Security Alert: Cemu Emulator Linux Releases Compromised via GitHub Backdoor (May 2026)
Critical: Cemu 2.6 Linux binaries were backdoored via a developer's stolen GitHub token. If you downloaded Cemu for Linux between May 6–12, audit your system now.
⤷ Title: Tengu Botnet Is a Modernized Mirai Variant That Fights to Stay on IoT Devices
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 07:14:59 +0000
════════════════════════
⌗ Tags: #Malware #ddos #IoT botnet #Linux Malware #Mirai #Mirai Variant #Nozomi Networks #Tengu
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 07:14:59 +0000
════════════════════════
⌗ Tags: #Malware #ddos #IoT botnet #Linux Malware #Mirai #Mirai Variant #Nozomi Networks #Tengu
Daily CyberSecurity
Tengu Botnet Is a Modernized Mirai Variant That Fights to Stay on IoT Devices
At a glance Malware family Tengu (Mirai-derived IoT botnet) Threat actor Unattributed; no operator named Target Internet-facing embedded Linux devices, such as routers, cameras, and DVRs Delivery …
⤷ Title: XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
Daily CyberSecurity
XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
At a glance Field Detail Malware family Modified XMRig 6.25.0 botnet implant (marked “PRIVATE VERSION FOR BOTNET”), cross-compiled with musl libc Threat actor Unidentified; campaign tr…