Zscaler researchers look into Shai-Hulud campaign evolution: changes over the last 6 months include expanding beyond npm into the PyPI, a shift from maintainer-focused compromise to CI/CD abuse, & use of prompt injection to evade AI-based security scanners https://t.co/845S4DPURR
FortiGuard Labs recently observed a campaign delivering malicious files as AI-related documents. The attack chain uses several staged scripts to hide activity before deploying AutoHotkey-based loaders that reflectively inject in memory a .NET RAT & AsynRAT https://t.co/5FOlD8xxeU
🚨 Qilin Activity Spike Detected
Qilin has published a wave of 10+ new victims in a short period of time.
A clear pattern is emerging: most victims belong to the legal sector, with the majority based in the United States. The activity may indicate a potential supply chain-related incident affecting multiple organizations.
Qilin remains one of the most active ransomware groups, with more than 1,500 victims claimed overall.
🔎 Track Qilin activity with us:
https://t.co/1TFlJ1IuL7
#Qilin #Ransomware #CyberSecurity #ThreatIntel #LegalSector #DataBreach
Notable threat activity ⚠️
Proofpoint @threatinsight has observed a significant increase in device code phishing attacks driven by new criminal toolkits that have emerged on Telegram and in criminal forums.
Read the research. 👉 https://t.co/rInsunNgpb
ClickFix just leveled up.
One user-pasted command now drops scheduled task persistence + PySoxy (a 10-year-old open-source Python SOCKS5 proxy) for encrypted backup access.
Blocking the first C2? Doesn’t stop it — the task keeps retrying for hours.
Read: https://t.co/YYKwKrR2Qz
Join us next Friday, May 8th at 11AM with Elias Bachaalany (@allthingsida) for the next @offby1security stream on, "Automated Reverse Engineering with LibGhidra, GhidraSQL, and AI Agents!
https://t.co/tLrD3qUvEk
🚨PHISHING ALERT: AI-Powered "Vibe Coding" Phish via Evernote 🚨
KnowBe4 ThreatLabs is tracking an active campaign exploiting Evernote’s legitimate infrastructure to deliver high-fidelity Microsoft credential harvesters. This attack highlights a shifting landscape: threat actors are now leveraging Base44, an AI "vibe coding" platform, to build sophisticated phishing pages without writing a single line of code.
The Attack Flow:
The Hook: Users receive a "Note shared with you" email featuring high-pressure financial lures—payment approvals, contracts, or finance reports.
The Bypass: Sent from no-reply[@]mail[.]evernote[.]com, these emails sail past SPF/DKIM/DMARC authentication.
The Bridge: Links lead to real share.evernote[.]com notes containing a "View Document" CTA.
The AI Twist: The CTA lands on a phishing page built with Base44 AI an AI "vibe coding" platform. These pages are protected by Cloudflare bot-checks to evade sandbox detection.
The Sting: A pixel-perfect M365 login screen designed to harvest credentials in real-time.
Why It Works:
✓ Reputation Hijacking: Sender and initial host are legitimate Evernote domains.
✓ AI-Speed: Base44 allows attackers to spin up unique, professional-grade pages instantly.
✓ Sandbox Evasion: Multi-stage redirects hide the final payload from automated scanners.
Indicators of Compromise (IOCs)
ashrafreda[.]com
atomicurl[.]com
voice0356[.]us
techformulagrayfellowshipinvestments[.]tvwpotalsources[.]vu
easywaytech[.]co[.]ke
enthusiastic-secure-link-go[.]base44[.]app
freight-sync-link[.]base44[.]app
login[.]yum[.]homes
office[.]cotiviti[.]top
hticybernetics[.]com[.]sharepoint[.]com/s/finance/Eba1
berenzweiglaw[.]com[.]sharepoint[.]com/:f:/s/finance/Eba1
serviceamericanreprographicscompany[.]golkppdmansachs[.]vu/
#CyberSecurity #Phishing #M365 #OAuth #KnowBe4 #ThreatIntel #HumanRisk #Evernote #AI
Mahadev Joshi at LevelBlue SpiderLabs analyses a multi-stage loader chain that began with MicrosoftToolkit.exe & ended in Vidar-linked C2 communication. The infection used file extension masquerading, extract32.exe, & an AutoIt loader to stage the payload. https://t.co/cQjvLharcV
The detection rule that catches most BEC persistence (most still miss this one):
OfficeActivity
| where TimeGenerated > ago(1h)
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules", "Set-Mailbox")
| extend Parsed = parse_json(Parameters)
| mv-expand Parsed
| extend ParamName = tostring(https://t.co/NoT29gDyYJ), ParamValue = tostring(Parsed.Value)
| where ParamName in ("ForwardTo", "RedirectTo", "ForwardAsAttachmentTo", "ForwardingSmtpAddress", "DeleteMessage", "MarkAsRead", "MoveToFolder", "Name")
| summarize
RuleActions = make_set(ParamName),
ForwardDest = make_set(iff(ParamName in ("ForwardTo", " RedirectTo", "ForwardAsAttachmentTo", "ForwardingSmtpAddress"), ParamValue, "")),
RuleName = max( iff(ParamName == "Name", ParamValue, "") ),
ClientIP = max(ClientIP)
by TimeGenerated, UserId, Operation
| where RuleActions has_any ("ForwardTo", "RedirectTo", "ForwardAsAttachmentTo", "ForwardingSmtpAddress")
and (RuleActions has_any ("DeleteMessage", "MarkAsRead", "MoveToFolder") or array_length(ForwardDest) > 0)
// Optional: add your internal domains filter here to eliminate noise
// | where not(ForwardDest has_any ("@example.com", "@yourdomain.com", ...))
| project TimeGenerated, UserId, Operation, RuleName, ForwardDest, RuleActions, ClientIP
| order by TimeGenerated desc
Deploy this as a Sentinel analytics rule.
Run every 15 minutes. Alert on every hit.
This catches end-user inbox rules that forward to external addresses + hide/delete messages — the #1 BEC persistence trick.
(Pro tip: add your internal domains to kill false positives.)
This single rule would have caught the persistence mechanism in the majority of BEC cases we investigated last year.
There are other ways to address this, but the focus is on detection
One Regex to catch them all - EvilToken@Cloudflare 🎯
| where ActionType == "ConnectionSuccess"
| where RemoteUrl matches regex "(?i)^[a-z0-9]{3,}-[a-z0-9]{3,}-[a-z0-9]{3,}\\..*\\.workers\\.dev$"
Go search and detect! 🫡
#Cybersecurity#EvilToken#CloudFlare#DefenderXDR
New Mimikatz
Researchers took an old version of Mimikatz and taught it how to dump credentials from the latest operating systems!
The research: https://t.co/JxZwg135Mr
The repo:
https://t.co/Lpsu09AMng
#redteam#pentesting
You clicked what you thought was an event invitation.
That's all it took.
Elastic Security Labs breaks down SILENTCONNECT, a newly documented loader that hides behind a Cloudflare CAPTCHA page, downloads a children's story VBScript, and silently installs ScreenConnect on your machine.
Key findings:
• Attack starts with a fake invitation link redirecting to a Cloudflare Turnstile page
• VBScript disguised with a children's story decoy pulls C# payload from Google Drive
• Compiled and executed entirely in memory via PowerShell
• PEB masquerading makes it look like winhlp32.exe to fool EDRs
• Active since March 2025, largely undetected until now
Full analysis + YARA rules + detections: https://t.co/bJLL6fwpgx
🚨 𝗺𝗮𝗰𝗢𝗦-𝗦𝗽𝗲𝗰𝗶𝗳𝗶𝗰 #𝗖𝗹𝗶𝗰𝗸𝗙𝗶𝘅 𝗖𝗮𝗺𝗽𝗮𝗶��𝗻 𝗧𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴 𝗖𝗹𝗮𝘂𝗱𝗲 𝗖𝗼𝗱𝗲 𝗨𝘀𝗲𝗿𝘀: 𝗗𝗲𝘁𝗲𝗰𝘁 𝗜𝘁 𝗘𝗮𝗿𝗹𝘆
⚠️ We identified a campaign targeting users of AI platforms such as Claude Code, Grok, n8n, NotebookLM, Gemini CLI, OpenClaw, and Cursor with AMOS Stealer.️ As macOS adoption grows in enterprise environments, these attacks exploit gaps in visibility and make early-stage detection harder.
🎯 In this case, attackers use a redirect from Google ads to a fake Claude Code documentation page and a ClickFix flow to deliver a payload. A terminal command downloads an encoded script, which installs AMOS Stealer, collects browser data, credentials, Keychain contents, and sensitive files, then deploys a backdoor.
The backdoor module (~/.mainhelper) was first described by Moonlock Lab in July 2025. Our analysis shows that it has since evolved. While the original version supported only a limited set of commands via periodic HTTP polling, the updated variant significantly expands functionality and introduces a 𝗳𝘂𝗹𝗹𝘆 𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝘃𝗲 𝗿𝗲𝘃𝗲𝗿𝘀𝗲 𝘀𝗵𝗲𝗹𝗹 𝗼𝘃𝗲𝗿 𝗪𝗲𝗯𝗦𝗼𝗰𝗸𝗲𝘁 𝘄𝗶𝘁𝗵 𝗣𝗧𝗬 𝘀𝘂𝗽𝗽𝗼𝗿𝘁.
❗️ This turns the infection from data theft into 𝗽𝗲𝗿𝘀𝗶𝘀𝘁𝗲𝗻𝘁, 𝗵𝗮𝗻𝗱𝘀-𝗼𝗻 𝗮𝗰𝗰𝗲𝘀𝘀 𝘁𝗼 𝘁𝗵𝗲 𝗶𝗻𝗳𝗲𝗰𝘁��𝗱 𝗠𝗮𝗰, giving the attacker real-time control over the system.
Multi-stage delivery, obfuscated scripts, and abuse of legitimate macOS components break visibility into fragmented signals. Triage slows down, and escalation decisions take longer, leading to credential theft and data exfiltration.
⚡️ #ANYRUN Sandbox lets security teams analyze macOS, Windows, Linux, and Android threats with full visibility into execution, attacker behavior, and artifacts, helping detect threats early, attribute activity, and build stronger detection logic, while reducing MTTD and MTTR.
See sample execution in a live analysis session: https://t.co/B0ZxggjGFW
💬 𝗙𝗶𝗻𝗱 #𝗜𝗢𝗖𝘀 𝗶𝗻 𝘁𝗵𝗲 𝗰𝗼𝗺𝗺𝗲𝗻𝘁𝘀 𝗮𝗻𝗱 𝘃𝗮𝗹𝗶𝗱𝗮𝘁𝗲 𝘆𝗼𝘂𝗿 𝗱𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 𝗰𝗼𝘃𝗲𝗿𝗮𝗴𝗲. We’ve broken down the attack chain in detail — let us know if you’d like to see the full analysis!
👨💻️ Expand your SOC’s cross-platform threat visibility. Learn how to boost performance and business security with #ANYRUN: https://t.co/3PitGGdnpe
#ExploreWithANYRUN
Here’s wishing you and your families a joyful, peaceful and blessed Eid. Love and light to one and all, may we get all that we pray for and more… Eid Mubarak!!
#ESETresearch analyzed more than 80 EDR killers, seen across real-world intrusions, and used ESET telemetry to document how these tools operate, who uses them, and how they evolve beyond simple driver abuse. https://t.co/fHOclYAGGn 1/6