🚨 New #JavaStealer “MaksStealer” uncovered!
Fully in-memory, FUD, DES–Blowfish runtime decryption, WebSockets on 4025/4028/6662.
Author “Max, 17yo” left his signature in the payload 🤯
Full report & IoCs 👉 https://t.co/HHuNMn5FPL
#infosec#malware#ThreatIntel@malwrhunterteam
🇮🇹 Nuova campagna di phishing a tema "rimborso fiscale" ai danni di #AdE
🎯 Il vero obbiettivo dei criminali è impossessarsi dei dati della carte di credito o debito.
ℹ️ Info e #IoC (via Telegram)👇
🔗https://t.co/G3Ffd6nHCe
⚠️ALERT⚠️
#AgentTesla spreading in Italy
📧Purchase Order #10045
📡hxxp://185.29.10[.]77/VbnpIdAHD29.bin
⛔ftp[.]holzbrenzii[.]com
⛔[email protected]
Bazaar: https://t.co/fsahBvCoSO
@anyrun_app: https://t.co/CSWH16lDxD
Thanks @JAMESWT_WT for the other samples
🚨ALERT🚨
There is a #DarkCloud#malspam campaign started in novembre 2025 and still active
"Quotation - Labmate Scientific USA"
eml > rar > DarkCloud (UPX packed)
📡C2: mail[.]mokasco[.]com (turkish company)
Sender IP: 31[.]57[.]184[.]57 🇮🇷🦁
bazaar: https://t.co/dm2bS09HmX
Threat actors are abusing branded PDFs to deliver phishing via malicious QR codes.
📩"Employee Pay Raise and Bonus Allocation"
The QR code redirects users outside the corporate perimeter to a credential harvesting page.
🎣hxxps://crioralo[.]ru