PavokwiLoader buries its logic in an 80,000-instruction function and uses custom API hashing to slow analysis. Malbear Labs links the loader to an intrusion chain that also deployed RMMCRAT. https://t.co/5rnWVDdUXt
We are super stoked to publish this collab with @ThruntingLabs: four payloads from one intrusion, all built to waste an analyst's time.
@ThruntingLabs traced the intrusion and turned it into a hands-on lab. Big thanks to @SecurityAura again for the threat intel context on the SEO poisoning and the samples 🐼
Our teardown: https://t.co/8ldpXYPAq6
THL Lab:
https://t.co/ERHeubcZVM
THL Intrusion report:
https://t.co/0J4cQBDvZl
We’re really excited to publish this one alongside @malbearlabs 🥳
For the first time at Threat Hunting Labs, we’re releasing a real intrusion as both a public investigation report and a hands-on lab:
*️⃣ From SEO Poisoning to Custom RMM and Cobalt Strike
Read exactly what happened in this real intrusion, then open the lab and investigate the same evidence yourself.
It started with an administrator searching for RVTools and executing two malicious downloads on the same workstation. The activity then split into separate paths involving browser process injection, Level RMM, another custom RMM-style service, and eventually a Python-hosted Cobalt Strike Beacon.
What stood out to us was the amount of remote-access tooling involved. Instead of relying on one method, the attackers ended up with multiple access paths using legitimate RMM software, custom tooling, and Cobalt Strike.
You can investigate the evidence across Threat Hunting, Incident Response, Detection Engineering, and Malware Analysis.
🎥 When you finish, every lab includes a recorded walkthrough where we explain how we investigated the activity and arrived at the answers.
MalBear Labs went much deeper into the recovered payloads and malware, complementing our intrusion analysis with their own companion report.
And a big thank you to @securityaura for helping us with the threat intelligence context around the SEO poisoning and malicious samples.
Lab:
https://t.co/6zGJ9En7zo
Intrusion report:
https://t.co/HIwTgP1gxn
MalBear Labs:
https://t.co/uRczAOpoZH
New @MalbearLabs collab with @ThruntingLabs and this one is a GOOD one: four payloads from one intrusion, all built to waste an analyst's time.
PavokwiLoader was the spicy one - WinMain is a single function with over 80,000 instructions and over 2,000 MBA clusters in that one function.
Also in there: RMMCRAT, a custom C++ payload wearing an RMM agent's clothes, a fake RMM service, and a Python loader that brute-forces its own decryption key instead of storing it.
@ThruntingLabs traced the intrusion and turned it into a hands-on lab. Big thanks to @SecurityAura for the threat intel context on the SEO poisoning and the samples 🐼
MalbearLabs teardown: https://t.co/e5vVPFS3rK
Medium was never home but now we have one 🐻
https://t.co/UEj59r4gfc is LIVE!
We reverse the threat, then hand you the notes. Make sure to sub and new drops land in your inbox ❤️
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.
Compromised packages (confirmed malicious) include:
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- qlik/[email protected]
- cacheable/memory, /utils, /net
- 17+ servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.)
In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js.
The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases.
Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens.
Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”
‼️ WARNING - A new critical cPanel flaw could let shared hosting customers run SQL as database root, bypassing database privilege boundaries.
CVE-2026-58048 (CVSS 9.4) affects supported cPanel & WHM versions and WP Squared. In some configurations, impact may extend to OS-level compromise.
Details: https://t.co/7RyYdMlKII