#Gamaredon
This report analyses over a decade of malware families and establishes a unified naming taxonomy to cut through the fragmented nomenclature.
1:
https://t.co/pjywWtlIkQ
2:
https://t.co/fKcZ0hSaEf
3:
https://t.co/vcMDWqD47S
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.io.
Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.
TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys.
Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
Here's a cool #YARA rule I wrote to only match zip files containing specific extensions:
https://t.co/mEEJvlNCUr
You can easily add desired extensions, it automagically works. I was surprised it was possible to do it like this, YARA is great.