EtherRAT brought blockchain-backed C2 into this intrusion.
A malicious MSI masquerading as Sysinternals RAMMap deployed EtherRAT, which used EtherHiding to retrieve Ethereum-hosted C2 config updates before pivoting to TryCloudflare infrastructure.
Full report: https://t.co/QZoH3FXfTp
#DFIR #ThreatIntel #DigitalForensics
Threat actors are increasingly exploiting legitimate cloud services like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to evade detection and streamline the deployment of the scam infrastructure.
We analyze the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud and share detailed statistics on the platforms and domains phishers abuse most frequently 👉 https://t.co/50VSnAwNoF
Zscaler ThreatLabz presents the second part of a technical analysis of new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. This part looks into a new modular stage 3 backdoor: BINDCLOAK, a variant of OctLurk https://t.co/2iESHSiRMx
H96 #AndroidTV boxes are doing far more than streaming. Researchers found devices that rotate between ad fraud and residential proxy abuse, turning home networks into malware infrastructure.
Listen/Read: https://t.co/gxiSV1JoOH
#CyberSecurity#Android#Malware#AdFraud#IoT
Sample is now on VT!
🚩Hash: 8e6c07f38ef920b5154fd081ba252b9295e8184d
🎯Actor name: APT28
🔹Comment: This blogpost introduces an operation that we named RoundPress, targeting high-value webmail servers with XSS vulnerabilities, and that we assess with medium confidence is run by the Sednit cyberespionage group. The ultimate goal of this operation is to
🌐URL: https://t.co/TGLS5pw6YG
🔎OnVT: https://t.co/TjjIIjyJJS
We uncovered #DOUBLECUP, a ClickFix loader using steganography & IP-based environmental keying to deliver #CountLoader and #DeviceManager. DeviceManager is a novel RAT using #EtherHiding & DNS tunneling for covert C2.
https://t.co/W9jOhVCIfi
📦 ThreatLabz has identified a malicious PyPI package named jsonschema-viewer. The package name was designed to impersonate the legitimate jsonschema package, one of the most widely used Python libraries with over 100 million weekly downloads.
The malicious PyPI package executes a multi-stage attack chain using curl to pull a shell script from the C2 server, which then downloads an architecture-specific ELF loader. The loader decrypts and executes the final payload in memory using a single byte XOR key (0x99), delivering VShell, a Go-based remote access tool and backdoor.
The package has since been removed from PyPI.
IOCs for this campaign are the following:
C2: 49[.]232[.]169[.]67[:]8084
Shell script MD5: 21f5c39665ad9fcbaa173084ed1ce966
Linux_amd64 (loader) MD5: 37a6bfa17f600445df6abb9f26bc29ed
Linux_arm MD5: a976f5be086cf15cae1614f188be1502
Linux_arm64 MD5: d0f38b97b43049adfd37088dbeaa69b9
Linux_i386 MD5: 28057c3e5fb92492801b91bd97ae8625
VShell payload MD5: b1acca2399b7289b684daee915d53efb
A full-scale municipal data breach and active Sliver C2 operation have been uncovered. The attacker used multiple implants communicating over mTLS with 43.157.204[.]73:8888 and c2.ashveil[.]org:8888, leveraging ECC certificates with codenames like OBJECTIVE_CHANNEL, SPIRITUAL_WOMEN, COMMERCIAL_CONVERSATION. On a compromised Windows host, Mimikatz extracted NTLM hashes for Administrator and several other accounts. TeamViewer 15.80.4 was fully backdoored via exfiltration of PermanentPassword, CertificateKey, PK/SK blobs, and SRP identifier while Always_Online was set to 1. AnyDesk device-id cache, stored RDP credentials, and router panels (TP-Link, ZTE) were also harvested. Internal scanning of the 10.160.197[.]0/24 range identified an Oracle database server at 10.160.197[.]88:1521 (SID newdhmos) accessed with hardcoded credentials lucence:otsdba. The full database was dumped, exposing 103,892 associate records containing full names, IBANs, AMKA social security numbers, tax IDs, monthly salaries, addresses, and contact details. Additionally, 1,390 employee records and 13,667 payroll entries were exfiltrated. Live API keys for the Greek transparency portal Diavgeia (6212_4 / 17DD357783BED4EF01A6CB) and the GSIS tax authority service manage_afe (L00011242L01450HKTWHXZNW87SH7P7H3FE / 0BD72E7B87FCDCEF0ED6, running on 10.160.197[.]88:7575) were stored in plaintext. Financial data shows 137,064 e-payment transactions totaling €341,748.13, with 92 payments already processed in 2025.
The operator's OPSEC is critically broken. The entire Sliver database is backed up via a shell script to github[.]com/serverops-admin/sliver using a hardcoded personal access token: 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. The repo ballooned from 365 MB to 634 MB in one day, indicating continuous exfiltration. Git config reveals the email feiyue@hermes[.]local and alias "绯月 FeiYue", granting full access to the attacker's GitHub account and a rare attribution window.
#ThreatIntel #Sliver #C2 #DataBreach #Oracle #Greece #OpSecFail #Infosec
Zscaler ThreatLabz has published Part 2 of our technical analysis of a targeted campaign against government entities in the Middle East. Part 1 covered a multi-stage infection chain that begins with an ISO file delivering previously undocumented tooling: TELESHIM and MIXEDKEY. In Part 2, we analyze BINDCLOAK and highlight code overlaps and shared C2 infrastructure with OctLurk.
Read our full analysis here: https://t.co/LUm7NvQElT
Microsoft details CaptiveCrunch, a Storm-2945 (Midnight Blizzard sub-cluster) campaign targeting captive portal traffic at hospitality venues, using doppelganger domains & Entra ID device-code AiTM phishing to deliver malware & steal traveller credentials. https://t.co/OMaJurdGah
Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰).
Jul 28, 2026
https://t.co/SFtP6wJM40
Sample is now on VT!
🚩Hash: 162e436f18fe6099c57855c8d63fd747493624e87702dc749b242eb9a6b758ca
🎯Actor name: UAT11795
🔹Comment: UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. The actor targets victims' credentials and cryptocurrency wallet assets, establishing a persistent connection to the victims' machines from the C2 server, with the potential to deliver and execute further payloads
🌐URL: https://t.co/Qu02gQURl8
🔎OnVT: https://t.co/NpGxV2HuLP
A new RAT variant has been discovered named AtlasRAT, masquerading as a Flash Player installer. Discovered by researchers at ASEC, AtlasRAT obfuscates itself and disguises as a legitimate Flash Player installer using ChaCha20 encryption over TLS, employing self-signed certificates spoofed to resemble Microsoft update infrastructure.
The RAT once fully deployed contains a variety of capabilities including offline keylogging, gathering system information and identifying installed security products, exfiltrating data over encrypted channels, and injecting DLLs into applications like WeChat, potentially allowing the attacker to hide malware activity or connectivity.
Based on historical data, the researchers suspect that AtlasRAT is a reusable framework or commercial offering rather than a one-off tool used by a single group.
#ThreatIntel #cyber #CyberSecurity
https://t.co/87aPiTu9Sw
This kernel rootkit takes its C2 commands through the Windows registry.
It registers a CmRegisterCallbackEx routine, then the user-mode agent writes commands into a benign key using nothing but standard registry APIs. Every write gets checked for the magic value 0x2625B7146B and the command is unpacked from it.
No IOCTL. No DeviceIoControl. No named pipe. Nothing on the user-mode side that looks like it is talking to a driver at all.
The command set behind it is a full kernel toolkit: arbitrary physical memory read and write by building a custom page table and injecting it into a free PML4 slot, PFN database reads, KVA shadow bypass, kernel APC DLL injection, ETW and CKCL and syscall table hooks, HvlGetQpcBias and GetCpuClock patched for timing.
Then the HWID spoofing shows up. Disk, Nvidia GPU, SMBIOS, plus forged mouhid and i8042prt input packets.
This started life as a game cheat driver. The cheat scene has been shipping production grade kernel capability for a decade and it keeps getting laundered into malware.
Author: @xeroxsec
Full analysis, IOCs and a YARA rule by 0xSec:
https://t.co/T4GX6pKFqN
The C2 infrastructure was still live and unflagged on VirusTotal at time of writing.
IIJ-SECT's Bynaoki Takayam looks into three of the latest BlueShell variants observed in May 2026, primarily used in attacks by threat actors based in China. https://t.co/efc2LpU6rY