A deep dive into the privacy black boxes of three AI programming assistants: one hides a backdoor, while the other two are completely innocent.
cn:https://t.co/itCeXxFBAH
en:https://t.co/BcUHiNb6De
Surveillance Backdoor: A Deep Dive into the "China-Specific" Surveillance Backdoor Hidden in Claude Code
cn:https://t.co/VvYq5XRtDP
en:https://t.co/S1k7dOxFMU
#ICYMI: SquirrelWaffle has been known to deliver #CobaltStrike and #Qbot. We looked into its initial access techniques and the exploit of Exchange server flaws #ProxyShell and #ProxyLogon.
Read: https://t.co/I6FGZKSBUE
Today our researchers have found sample which belongs to #Donot#APT group
ITW:67abe8b04f62eb55b6b880668fb8a634
filename:ගුවන් හමුදාව - එක්සත් ජාතීන්ගේ බහුමාන ඒකාබද්ධ ස්ථායීකරණ මෙහෙයුම.doc
C2:
hxxp://wordfile.live/BXRi3EE06i5IES2k/rns63jefark0bRQf.php
Telecommunications and #IT share common characteristics in the back end. This also means that they share common threats and areas of concern. #TheSmartScene
Read our report to find out what they are and how to prevent them: https://t.co/wtDe9sA09E
This is a list of victim organizations that #REvil ransomware gang has posted on its leaked blog on the #DarkWeb.
A total of 273 victims they claim are posted on their darkweb leak blog site.
Today our reseachers have found new activities about #Lazarus (#DangerousPassword) #APT target at China
ITW:60214745027c7efa7cc920d43d9c254a
filename:安全状态检查.zip
ITW:9A06CE2B0B038DE9147F93BBB3B3C56C
filename:安全状态检查指南_signed.pdf.lnk
C2:hxxps://dev.sslsharecloud.net/
#Donot#APT
A batch of old C2 samples appeared on VirusTotal in April. Through its Name, it was found that the relevant samples were captured by relevant researchers in 2019.
C&C:help[.]domainoutlet[.]site
MD5:a96f9bd6dbeb92194add81eb89b31eeb etc.
Today our reseachers have found RTF sample which belongs to #Donot#APT group
ITW:d8f19b4b3b74cf6f4cb2482c4dc88d37
filename:Brief Report on International Boarder l 301-2(6.doc
C2:
hxxp://firm.tplinkupdates.space/
#APT#Donot maldoc.
It is exploiting equation editor vulnerability to create a scheduled task to execute its payload.
The payload is a downloader that downloads an additional payload, removes its scheduled task and creates two new tasks to execute downloaded payloads.
#APT It is suspected that #APT28 is the latest mobile attack, but its C2 has been reported by @darienhuss in 2016, mainly stealing information related to Russian interests.
C2:69[.]90.132.215
Md5:835c1ac1cba1b66715a42d4576b41b7d
https://t.co/Xcu7H6h38V
#Donot#APT New samples and new frameworks, @malwrhunterteam has found out, I also analyzed it briefly!
C2:transp[.]link
hash: 0decc4035570eac528c8af28453e3686
https://t.co/09oKNOLxho
#Fin7#APT#DiceLoader (dcdefb772a0e82dbf6432b7de652edda) -> Unpacked and Unmapped #CobaltStrike ReflectiveLoader (0754e14cca0907d6dda96047b6a1e8b9) w/ C2 185[.]205[.]209[.]3. More analysis for the @morphisec whitepaper https://t.co/l3PBH22kgt. 😅