Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host.
This TerminalFix campaign uses fake CAPTCHA verification prompts to facilitate user-executed PowerShell commands. Beyond the initial lure, this campaign uses DLL sideloading through LockScreenContentServer.exe, steganographic payload delivery, and persistence mechanisms. It then performs extensive reconnaissance to identify reachable systems and key infrastructure.
Organizations should investigate devices where users interacted with suspicious CAPTCHA verification prompts and look for unusual execution of LockScreenContentServer.exe, hidden ProgramData folders, and outbound connections associated with the activity.
Additional guidance and technical analysis will be published soon by Microsoft Security Research.
We're making Whisper models free for all users.
Starting today, you no longer need a Superwhisper Pro subscription to use them.
We’ve also reset Pro usage for everyone.
If you’d already reached your limit, you now have 3,000 words to try the latest Pro features.
Local, private, and fast voice-to-text. Free for everyone.
INTEL DROP
Remote-management tools are the access layer for a lot of live intrusions. Right now we're tracking 1,123 malicious IPs running RMM software (AnyDesk, ScreenConnect, MeshCentral, RustDesk) across 307 ASNs, most of it in the US, the Netherlands, and Germany, with India and Russia rounding out the top five.
RMM staging malware:
185.187.84.31 screen-connect + malware-hosting
91.92.240.17 screen-connect + malware-hosting
91.92.34.123 screen-connect + malware-hosting
RMM co-located with C2:
102.165.14.23 anydesk + screen-connect + purerat
108.171.194.80 anydesk + venomrat
117.18.127.179 anydesk + xworm
91.92.42.118 meshcentral + cobaltstrike
RMM with an open directory exposing malware or C2 config:
103.68.109.59 anydesk + open-dir + malware-hosting
129.80.196.225 meshcentral + open-dir + malware-hosting
51.79.134.41 anydesk + open-dir + xworm + malware-config
115.159.33.118 rustdesk + open-dir + cyberstrikeai + proxy:nps
Bulletproof hosting + brute-force:
91.220.163.50 anydesk + bph
149.104.30.78 rustdesk + proxy:frp
68.64.183.125 komari + proxy:frp
210.212.136.3 anydesk + scanner:brute-force
#TotalInsights #ThreatIntel #RMM #C2
https://t.co/nDqrsELahM
Vercel Connect is now generally available.
Give your apps and agents secure access to @slackhq, @linear, @github & 100+ other services.
• Short-lived, scoped access tokens
• Token and trigger observability
• RBAC and audit trails
https://t.co/3JUlBz3ddo
The ransomware attack dubbed “JADEPUFFER”, one of the first documented cases of a threat actor using large language model (LLM) to conduct an end-to-end attack, offers a glimpse into how AI could shape future ransomware campaigns. https://t.co/FX87ickKFt
While the attack relied on familiar techniques, it demonstrated how AI can rapidly iterate, adapt to failures, and continue progressing toward an objective.
In this episode of the Microsoft Threat Intelligence Podcast, Elliot Volkman speaks with Michael Clark and Crystal Morin of Sysdig about the AI-driven activity, including its ability to generate and modify code, reason through errors, and work through technical obstacles that might slow a human operator.
Despite its use of AI, JADEPUFFER relied on familiar weaknesses, including exposed services, unpatched vulnerabilities, and poor credential hygiene, highlighting the continued importance of exposure management and foundational security practices.