#Cyderes
After multiple security firms called out the 0APT ransomware group for listing fake victims on its dark web leak site, Cyderes has managed to get its hands on the group's actual ransomware, and it's apparently a legit encrypter

www.cyderes.com/howler-cell/...
February 17, 2026 at 2:41 AM
Researchers at cybersecurity vendor Cyderes are warning about a new strain of Windows-based malware, which has been hiding inside cracked games and modified game installers.

More at PCMag: bit.ly/46EIPMq
📸: janews via Shutterstock
February 9, 2026 at 10:10 PM
Security Consultant - CyberArk @ Cyderes Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity ...

Origin | Interest | Match
isecjobs.com will become foo🦍 - visit foorilla.com!
isecjobs.com will become foo🦍 - visit foorilla.com!
isecjobs.com
July 5, 2025 at 10:26 AM
Researchers at cybersecurity vendor Cyderes are warning about the threat, which has been hiding inside cracked games and modified game installers for franchises including Far Cry, Need for Speed, FIFA, and Assassin's Creed.
Malware Hidden in Pirated Games Infects 400,000 Devices
Researchers at cybersecurity vendor Cyderes are warning about the threat, which has been hiding inside cracked games and modified game installers for franchises including Far Cry, Need for Speed, FIFA, and Assassin’s Creed.
bit.ly
February 7, 2026 at 3:34 AM
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware

Cybersecurity researchers have disclosed details of a new campaign that has used cracked software distribution sites as a distribution vector for a new version of a modular and stealthy loader known as…
#hackernews #news
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware
Cybersecurity researchers have disclosed details of a new campaign that has used cracked software distribution sites as a distribution vector for a new version of a modular and stealthy loader known as CountLoader. The campaign "uses CountLoader as the initial tool in a multistage attack for access, evasion, and delivery of additional malware families," Cyderes Howler Cell Threat Intelligence
thehackernews.com
December 20, 2025 at 7:07 PM
⚠️ Cyderes is reporting a Incident since 18:51 UTC

"Azure Sentinel Service Degradation"

Affects: Microsoft Sentinel

Live timeline → https://pingoru.io/providers/cyderes/incidents/10986026

#Cyderes #CyderesDown
September 15, 2026 at 6:58 PM
🟢 Update: Cyderes marked this resolved at 23:03 UTC.

Duration: 4h 12m.
September 15, 2026 at 11:12 PM
📢 Cyderes is #hiring a Project Manager: CMMC Audit!

🌎 Worldwide

🔗 http://jbs.ink/Sju5lGFfnAts

#jobalert #jobsearch #remotejob #remotework #wfh
September 13, 2026 at 11:54 PM
📢 Cyderes is #hiring a Customer Success Manager: Bilingual!

🌎 Worldwide

🔗 http://jbs.ink/nv0eUdzcwalr

#jobalert #jobsearch #remotejob #remotework #wfh
September 13, 2026 at 11:51 PM
🟢 Update: Cyderes marked this resolved at 14:07 UTC.

Duration: 1d 23h.
September 2, 2026 at 2:16 PM
⚠️ Cyderes is reporting a Incident since 14:12 UTC

"Azure Sentinel Service Degradation"

Affects: Microsoft Sentinel

Live timeline → https://pingoru.io/providers/cyderes/incidents/9867700

#Cyderes #CyderesDown
August 31, 2026 at 2:19 PM
🟢 Update: Cyderes marked this resolved at 02:15 UTC.

Duration: 1d 4h.
August 30, 2026 at 2:22 AM
⚠️ Cyderes is reporting a Incident since 22:00 UTC

"Azure Sentinel Service Degradation"

Affects: Microsoft Sentinel

Live timeline → https://pingoru.io/providers/cyderes/incidents/9648111

#Cyderes #CyderesDown
August 28, 2026 at 10:06 PM
We would like to thank Proofpoint & Cyderes for being a Copper Sponsor for Wild West Hackin' Fest - Deadwood 2026! We are very grateful for your support! Be sure to check out all their services here: www.proofpoint.com/us and www.cyderes.com
August 11, 2026 at 4:39 PM
A little help from your search engine. [Research Saturday]

Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an …
#anthropic #claude #hackernews
A little help from your search engine. [Research Saturday]
Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command. The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised. The research and executive brief can be found here: Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer
thecyberwire.com
August 9, 2026 at 4:45 PM
Opening a fake Indian income-tax notice right now can install two remote-access trojans. Cyderes traced a China-linked campaign that abuses a signed Windows app to side-load malware, running a Gh0st RAT and a Quasar-family implant in memory, per The Hacker News.
July 9, 2026 at 7:10 PM
Cybercriminals exploit India’s tax filing season with a dual-malware campaign
Cybercriminals are exploiting India’s tax filing season with a new malware campaign that refuses to put all its eggs in one basket. Researchers at Cyderes have uncovered a sophisticated phishing operation that poses as the Indian Tax Department to deliver two remote access trojans (RATs) through a multi-stage infection chain, giving attackers persistent access to compromised systems. Indians receive fake tax assessment emails that pressure them into downloading what appears to be an official ITR utility. But the convincing government branding hides a carefully engineered infection sequence that abuses legitimate Windows binaries, DLL side-loading, in-memory execution, and process injection to gain persistent access. According to Cyderes, the operation deploys a Gh0st RAT derivative and a .NET-based implant related to the QuasarRAT/AsyncRAT family, each communicating with separate command-and-control (C2) servers. “The dual-implant design gives the attacker redundant access even if one channel is blocked or detected,” Cyderes researchers said in a blog post. ## A stealthy, multi-stage infection chain To avoid detection, the campaign layers its execution chain, rather than dropping malware immediately after initial access. Once the victims are lured into downloading and opening the archives posing as legitimate Income Tax Department utilities, trusted Windows executables are abused to load malicious DLLs. This allows the malware to borrow the legitimacy of signed binaries while sidestepping security controls. “The infection begins with ‘COU_ITR-1_to_4_AY2026-27.exe’, a legitimate and digitally signed binary that the attacker repurposes as a launcher,” the researchers said, adding that it is a known technique where an attacker “places a malicious library in a path the trusted binary will check first, giving the malware a clean entry point.” The campaign then runs its subsequent infection stages, which employ multiple defense-evasion techniques, including anti-analysis checks, AMSI patching, encrypted in-memory execution of .NET assemblies, and session-aware process injection into svchost.exe. The multiple attack stages include DLL sideloading, privilege checking to ensure the attack process is running with admin rights, and session-aware payload injection. ## Dual implants for operational resilience The campaign was particularly flagged for its deliberate use of two distinct RAT families rather than relying on a single backdoor. While one implant is based on the long-running Gh0st RAT lineage, the second belongs to the QuasarRAT/AsyncRAT ecosystem. Both provide remote administration capabilities, allowing attackers to execute commands, collect data, deploy additional payloads, and maintain long-term access to infected endpoints. Each of these RATs communicates with a dedicated command-and-control (c2) infrastructure, likely to survive detection and blocking of either during incident response. Cyderes recommended focusing on behavioral detections rather than relying solely on EDR signatures, as the campaign abuses trusted Windows components and in-memory execution. Key indicators include DLL sideloading, unexpected service creation, AMSI tampering, native processes hosting the .NET runtime, and process injection into svchost.exe. The disclosure also provided a detailed set of IOCs, including file hashes, malicious domains, C2 infrastructure, and host artifacts associated with both RAT families.
www.csoonline.com
July 8, 2026 at 5:47 PM
🟢 Update: Cyderes marked this resolved at 21:25 UTC.

Duration: 6h 6m.
July 6, 2026 at 9:29 PM
⚠️ Cyderes is reporting a Incident since 15:19 UTC

"Azure Sentinel Service Degradation"

Affects: Alerting Pipeline, Case Notification System

Live timeline → https://pingoru.io/providers/cyderes/incidents/5714243

#Cyderes #CyderesDown
July 6, 2026 at 3:25 PM
Golpe usa nome do Claude Code para roubar senhas de usuários
Pesquisadores da empresa de segurança Cyderes identificaram uma campanha ativa de roubo de credenciais que usa o nome do Claude Code, ferramenta de programação por inteligência artificial da Anthropic, para enganar usuários sem experiência técnica. O ataque começa com SEO poisoning, técnica que manipula resultados de busca para colocar um site falso no topo do Google quando alguém pesquisa como instalar o programa. A página imita o visual oficial da Anthropic e instrui a vítima a abrir a janela Executar do Windows e colar um comando malicioso, apresentado como etapa normal de instalação. Ao fazer isso, o computador baixa um arquivo disfarçado de MP3 que carrega um script oculto. A partir daí, o ataque desativa o verificador de scripts do Windows, baixa um segundo arquivo diretamente na memória do computador e instala um programa que rouba senhas salvas nos navegadores, enviando tudo para servidores em infraestrutura russa.
www.tecmundo.com.br
June 28, 2026 at 12:30 PM