'PROPERTY LEASING AGENCY AGREEMENT.exe' seen from Cambodia @abuse_ch
8a72afcb3bdd892ae106b2e6c7bd3df4e4be98f151342509603e31d7efd555f3
https://t.co/sbJBkRZzVL
FUD Domain: zhugel5(.)com
FUD IP: 206.119.81(.)53
'AdobeFix_WRQ4CT0J.vbs' seen from Brazil @abuse_ch
e78621a003939efda0a6eab548c07a25167275be9fd70da1d4c2b8833fbff104
https://t.co/I7oJgD2DWr
Next stage:
hxxps://storage.googleapis(.)com/protesto-att/agent.msi
21e5d1db878d6830f1830e8f6675250cac209c9d8453617436ce8d1f09c1d9ae
https://t.co/jWINi0gbFR
Sample is now on VT!
🚩Hash: 3878dd5c8eba1e5b53ab2e07e7b5482e95a3fd3e98268bcd7861318bc9902376
🎯Actor name: UAT7810
🔹Comment: Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025.
🌐URL: https://t.co/gL2LTSKJ5Y
🔎OnVT: https://t.co/JnpVvn4pcC
Sample is now on VT!
🚩Hash: ed2c4429cf27e19aa6881d86bc5b42c21470525564fc53be688b9b26c83db766
🎯Actor name: RUDEPANDA
🔹Comment: compromises of IIS servers with a previously undocumented malicious module which we call “HijackServer”. The associated infection chain involved the use of previously exposed ASP .NET machine keys and a ready-made toolset which notably includes a cus
🌐URL: https://t.co/0wvrt9xENa
🔎OnVT: https://t.co/2pauGK28FG
The cat’s finally out of the bag! 🐈
Proud to announce that my book, The (Un)Natural History of Malware, is now available on the @nostarch website! 📖
https://t.co/AO7XL0jPBI
✍️ Technical Analysis Published: Telegram Account Compromised, Wallet Swapped: How Does macOS Malware Break Through Your Defenses?
Our latest investigation reconstructs how a single malware sample chains together Telegram session theft, wallet database exfiltration, offline decryption and fake wallet applications into a complete account takeover workflow.
Our analysis shows:
1️⃣Stolen Telegram Desktop and Telegram for macOS session files can be restored on another Mac without re-entering a phone number, verification code or 2FA password
2️⃣For Telegram for macOS, even after server-side security mechanisms respond, cached chat history may remain accessible instead of being cleared by a forced logout
3️⃣Wallet databases can be paired with passwords collected from Keychain, browsers and Apple Notes for offline decryption, without interacting with the victim's device
4️⃣Fake Ledger and Trezor desktop apps are actually WKWebView-based loaders that replace trusted wallet interfaces with attacker-controlled phishing pages
The malware doesn't rely on a single technique—it combines authenticated sessions, encrypted wallet data and credential material into one attack chain.
💡 Defense tip: Protect your local Telegram session by enabling a Telegram Passcode and using a strong, unique password.
Full analysis and practical mitigation guidance👇
https://t.co/TCLrelsGd3
Fake Windows Update page delivering a multi-stage malware loader.
The site microsoft[.]updata[.]net[.]cn instructs users to run a PowerShell command that downloads kB2025072926.exe from a Cloudflare R2 bucket.
Dynamic analysis shows kB2025072926.exe first deploys a copy of the legitimate open-source TrafficMonitor application under %AppData%\Roaming\TrafficMonitor\ (including its FAQ shortcut pointing to the official GitHub project).
It then drops a second stage under C:\ProgramData\SystemTools\,
including:
- xaweg.exe
- pnMpWI32.dll
- comsdk.dll
- Cache.pmt
xaweg.exe loads pnMpWI32.dll, which reads Cache.pmt and appears to decrypt and/or decompress it before executing shellcode in memory.
Interestingly, a @urlscanio scan from 2025 on the same fake update site shows it previously delivered WindowsUpdata.exe (SHA256: a71455506d7048f1dbbcdd48100860a8cd2088cbe4a0b3881cc8a179ce494e99), which the community associated with Amadey and Black Basta. The current sample follows a different infection chain, so further analysis is required before attributing it to the same malware family.
IOCs:
microsoft[.]updata[.]net[.]cn
pub-620def1d93ef431dbdf24616a9b11c77[.]r2[.]dev/kB2025072926.exe
%AppData%\Roaming\TrafficMonitor\
C:\ProgramData\SystemTools\xaweg.exe
C:\ProgramData\SystemTools\pnMpWI32.dll
C:\ProgramData\SystemTools\Cache.pmt
Hash:
Filename: xaweg.exe
35ae900295477f1c47edc229cd08c049fa50c1c14fab9f308868027134db778d
Filename: pnMpWI32.dll
7bb5f352f582407330bba12d2ddd15e70a3c5002fe96b7366980e644bec8a565
Filename: Cache.pmt
5a514fb0caceb37000a716df626163f5f8856bc7703adfa2bc3c1b59103c4ff4
Filename: kB2025072926.exe
b127701d2be865e3dc9417f6e0975e73b55b44906f166dc7147c9b392d008a00
#Malware #Fakeupdate #Clickfix #Threathunting @malwrhunterteam@500mk500@skocherhan@JAMESWT_WT@James_inthe_box
Some findings:
- The C2: 54.39.43[.]117 (WIN-6HTEEE5UVML)
- The TA's Firebase project: my-first-metamask-39906
- Firestore collection: wallet_Information
- Previous repo they had but was removed: hxxps://github[.]com/centrelocuslabs/Jackpot-v1/
- Victims across Italy, Belgium, and the US - all within 24 hours.
Lessons learned from here:
- Do not ever connect your crypto wallets on sketchy sites
- Take-homes and "collab repos" from any recruiter, real or fake, run in a VM. No wallets, no creds, no .env, no route back to your home network.
- The profile picture looks AI generated - do your basic OSINT and if that fails - use AI image detectors e.g. wasitai[.]com
'ការផ្លាស់ប្តូរថ្មីចំពោះលេខកូដ QR របស់ ABA.rar' seen from Cambodia @abuse_ch
ad6b7658635192bbbb428c0b8b78db842c7d4f3501a4998cd69def8a1fa84b20
https://t.co/qMmQShPmO3
FUD Domain: xieerbi2(.)com
UEFITool / UEFIExtract / UEFIFind NE A75
- more bugfixes for various issues here and there
- further improved Insyde FlashDeviceMap parser
- search for text in information sections
- AMD parser is still not re-enabled, work in progress
https://t.co/rhOheILg8s
'AGGT-N012141 zip' seen from China, Taiwan and Hungary @abuse_ch
File with VHDX extension in it.
36676e250845e80680378907fc59be007fabf6eb8967994cbd5c16fbf69893d6
https://t.co/0yYlkN6CBX
'zadost O Cenovou Nabidku Unitex Intex Service Prague, Czech Republic 07092026.gz' seen from Czech Republic @abuse_ch
4003ca6885cba04a837e4cd8954289aa19a8c9b857889c422bdc9ccaf66e0533
https://t.co/iMYmxBqnEl
IP: 94.198.96(.)164