Your browser is a C2 agent waiting to happen.
@KingOfTheNOPs shows how to silently sideload a Chromium extension, no prompts or GUI, and turn Chrome/Edge into a persistent implant with SOCKS, cookie theft, and OS access.
Read more 👇 https://t.co/kh0W1ObkeQ
Introduction to Windows shellcode development series
Part 1:- https://t.co/EMdEvLUaud
Part 2:- https://t.co/UwLvzr9NUl
Part 3:- https://t.co/Oyj2AkRSZA
#redteam#exploit#shellcode
The latest LoremIpsumLoader is JS instead of an MSI file.
They still use the same dead drop technique. They decode text from
https[:]//www[.]letsdiskuss[.]com/user/stevenseagal4596
C2: https[:]//loginrestforest[.]com/api/init/bf428ad4-cb18-44b1-87f7-7047da02c592
https[:]//grapesinlife[.]com/api/cl/b6bac461-9d5d-49b8-958a-5bf9ce07f667
https://t.co/laN51EN2GP
https://t.co/E5wvFchQuA
The DFIR Report recently observed MEOWBACKCONN again in the wild:
➡️ Initial Access: Malicious Microsoft Teams MSI Installer
➡️ Execution: Encrypted PowerShell backdoor
➡️ Discovery: PowerShell Cmdlets, WMI, and whoami
➡️ Credential Access: SAM Registry Dump
➡️ Exfil: Curl to temp[.]sh
➡️ Lateral Movement: SOCKS proxy dropped to enable RDP
🐱 MEOWBACKCONN dropped on domain controllers
The last time we observed this malware was from a GOOTLOADER case in Nov 2025.
AhnLabs reports seeing evidence of the campaign going back as far as October 2025.
Thanks to folk who upload such files to MalwareBazaar, VT, and help report the certificates.
Thanks @AhnLab_SecuInfo for publishing the analysis:
https://t.co/rUKnUByjt2
2/2