Category: Research
MacSync macOS Stealer Now Hides Commands in Public iCloud Calendars
A new MacSync variant abuses public iCloud calendar event descriptions to smuggle shell commands and fetch next-stage payloads, while a new Finder-spoofing…
New Process Parameter-Poisoning Trick Lets Malware Slip Past EDR
Researchers detail a process injection technique that tampers with initialization structures instead of calling the Windows APIs most EDR products monitor, letting…
TrustSink Attack Lets Rogue Entra MFA Providers Steal Passwords Post-Compromise
Varonis Threat Labs details TrustSink, a technique where attackers with privileged Entra access register a rogue external MFA provider to harvest passwords…
New ChainScript RAT Spreads via ClickFix Lures, Uses Polygon for C2
Researchers have identified a previously undocumented RAT called ChainScript that abuses ClickFix-style social engineering and rotates command-and-control infrastructure through the Polygon blockchain.
Malicious npm Packages Dodge Install-Script Defenses by Hiding in Runtime Code
A campaign centered on the fake 'indexed-btree' package shows attackers bypassing npm's new lifecycle-script protections by embedding malware inside a library's normal…
North Korean WaterPlum Hackers Hit 30,000 Devices, Stole $10.7M in Crypto
A joint advisory from US, Japanese, Australian, and German authorities details how the Contagious Interview campaign used fake job offers and malicious…
CISA Issues Guidance on Using Cyber Decoys to Catch Attackers Early
The agency's new playbook shows critical infrastructure operators how to deploy honeypots, honeytokens, and other decoy systems to detect intruders using legitimate…
FamousSparrow’s New SparroWocky Backdoor Hits Latin American Governments
ESET researchers tracked the China-linked espionage group deploying a heavily obfuscated new backdoor against government targets across Latin America for over a…
BambooToken Malware Abuses MQTT Protocol to Control Windows and Linux Hosts
A cross-platform malware family active since 2023 is using the IoT messaging protocol MQTT for stealthy command-and-control, hitting mobile app backends, law…
Five Alleged Black Axe Leaders Extradited to US on Fraud Charges
US prosecutors say the men ran a decade-long romance scam and advance fee fraud operation from Cape Town, part of the notorious…
DDRop Attack Defeats Intel TDX and AMD SEV-SNP Memory Encryption
A newly disclosed hardware attack called DDRop can silently drop memory writes in confidential computing environments, tricking processors into trusting stale encrypted…
UK Man, 68, Jailed Over $1.3M Illegal IPTV Streaming Operation
A City of London Police investigation found Milan Ibrahim ran an 80-server pirate IPTV service that pulled in nearly £1 million by…