Cisco Talos’ 2025 Year in Review is available to view now! Read the full report here for key trends and defense tips — no annoying forms, just helpful analysis: https://t.co/bkwvt9iDvO
DPRK alligned Famous Chollima keeps their operational tempo high and although not the most sophisticated actors, they have been consistently adding new features to their tools.
https://t.co/obObpNrwfV
Although these malware families have historically been associated with campaigns attributed to Naikon or BackdoorDiplomacy, our analysis indicates a connection.
https://t.co/kKNsxo6Qqu
Cisco Talos has observed an ongoing malware campaign that seeks to infect victims with a multi-stage malware framework, implemented in PowerShell and C#, which we are referring to as “PS1Bot.”
https://t.co/g3TfwDbA8O
Cisco Talos Incident Response (Talos IR) recently observed attacks by Chaos, a relatively new ransomware-as-a-service (RaaS) group conducting big-game hunting and double extortion attacks.
https://t.co/fYkgdfkuRD
We published our findings about a Python variant of a Golang RAT used by Famous Chollima (aka Wagemole). This has been recently used with limited success.
https://t.co/CWLeowvuUm
This started as an investigation into a maldoc with obfuscated VBA code and some unused legit functions lead to discovery of other maldocs generated by MacroPack.
https://t.co/h6B28Q1rmZ