#Gryxa
Gryxa malware fights back when you try to remove it, using AI-built persistence and credential theft. #AI #Malware #Cybersecurity #Gryxa #ThreatIntel #EndpointSecurity https://thedailytechfeed.com/gryxa-malware-uses-ai-to-restore-itself-and-spy-on-cleanup-efforts/
August 31, 2026 at 10:08 AM
-Artifactory bug exploited in the wild
-Sangoma Switchvox exploitation
-New Langflow attacks
-Major new GeoNetwork vulnerabilities
-Secure disk bugs impact ATMs
-Palo Alto Networks has acquired Console
-OpenClaw 2.0 is out
-New malware: BraZetsu, Gryxa, RevStealer
September 2, 2026 at 7:40 AM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Ac…
#claude #hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted Infrastructure       Gryxa: The AI-Built Toolkit That Watches How You Remove It ValleyRAT masquerading as adware   […]
securityaffairs.com
September 7, 2026 at 7:26 AM
Nieuwe malware 'Gryxa' imiteert legitieme software en blijft persistent na verwi

Een nieuwe Windows malware toolkit, genaamd Gryxa, is geïdentificeerd. Deze toolkit biedt cybercriminelen op afstand toegang tot systemen en blijft actief na gedeeltelijke verwijdering. Gryxa richt zich op wach...
Nieuwe malware 'Gryxa' imiteert legitieme software en blijft persistent na verwijderingspogingen
Een nieuwe Windows malware toolkit, genaamd Gryxa, is geïdentificeerd. Deze toolkit biedt cybercriminelen op afstand toegang tot systemen en blijft actief na gedeeltelijke verwijdering. Gryxa richt zich op wachtwoorden die zijn opgeslagen in op Chromium gebaseerde browsers en kan detecteren wanneer beveiligingsanalisten proberen deze te verwijderen. De malware wordt vermoedelijk verspreid via een phishingbericht dat een 19 MB zelfuitpakkend uitvoerbaar bestand bevat, vermomd als een factuur met de naam invoice_.exe. Na uitvoering haalt de installer componenten binnen via HTTPS. Gryxa maakt gebruik van legitieme remote monitoring and management (RMM) software als verborgen control...
newsfacts.info
August 31, 2026 at 10:00 AM
新たなツールキット「Gryxa」、AIが構築した永続化機構でセキュリティチームに対抗

金銭目的の脅威アクターが、Windows向けの新たなツールキット「Gryxa」を使用していることがわかりました。このツールキットは、リモート監視・管理(RMM)ツールの悪用、AI支援による開発、ブラウザ認証情報の窃取、そして不完全な駆除処理を乗り越えるよう設計された強力な永続化機構を組み合わせたものです。 このツール...
新たなツールキット「Gryxa」、AIが構築した永続化機構でセキュリティチームに対抗
金銭目的の脅威アクターが、Windows向けの新たなツールキット「Gryxa」を使用していることがわかりました。このツールキットは、リモート監視・管理(RMM)ツールの悪用、AI支援による開発、ブラウザ認証情報の窃取、そして不完全な駆除処理を乗り越えるよう設計された強力な永続化機構を組み合わせたものです。 このツール
blackhatnews.tokyo
August 31, 2026 at 7:50 AM
Gryxaツールキット、防御側の駆除手口を学ぶためWindowsログを収集

このツールキットは正規のリモート監視管理(RMM)ソフトウェアを悪用して密かにアクセスを維持し、複数の復旧メカニズムを備え、ブラウザに保存された認証情報を窃取するほか、エンドポイントセキュリティツールを無効化して報復することもできます。 最も特異な機能は、防御側が可視化されたRMMインプラントを除去した後に発動します...
Gryxaツールキット、防御側の駆除手口を学ぶためWindowsログを収集
このツールキットは正規のリモート監視管理(RMM)ソフトウェアを悪用して密かにアクセスを維持し、複数の復旧メカニズムを備え、ブラウザに保存された認証情報を窃取するほか、エンドポイントセキュリティツールを無効化して報復することもできます。 最も特異な機能は、防御側が可視化されたRMMインプラントを除去した後に発動します
blackhatnews.tokyo
August 31, 2026 at 6:40 AM
📢 Gryxa : un toolkit malveillant développé par IA ciblant 324 hôtes avec persistance avancée

Le 28 août 2026, l'équipe de recherche sur les menaces de ReliaQuest a publié une analyse technique détaillée d'un nouveau toolkit…

🟡 vérification factuelle moyenne
#Gryxa #AIAssistedMalware #Cyberveille
Gryxa : un toolkit malveillant développé par IA ciblant 324 hôtes avec persistance avancée
Le 28 août 2026, l'équipe de recherche sur les menaces de ReliaQuest a publié une analyse technique détaillée d'un nouveau toolkit malveillant baptisé Gryxa, utilisé par un acteur financièrement motivé non nommé. Le toolkit a été identifié sur 324 hôtes compromis, dont 69 actifs au moment de l'analyse.
cyberveille.ch
August 29, 2026 at 2:30 PM
ReliaQuest details Gryxa, a financially driven toolkit on 324 hosts that uses RMM abuse, persistence, and credential theft, then gathers Windows logs after removal attempts. #Gryxa #ReliaQuest #MicrosoftDefender
Gryxa: The AI-Built Toolkit That Watches How You Remove It
ReliaQuest reports Gryxa, a new toolkit used by a financially motivated threat actor to maintain access across 324 listed hosts, and assesses that much of it was built with a commercial AI coding agent. The toolkit uses RMM abuse, layered persistence, credential theft, and response-aware countermeasures, while collecting Windows logs and host artifacts after defenders try to remove it. #Gryxa #ReliaQuest #Chromium #MicrosoftDefender #Telegram
www.hendryadrian.com
August 28, 2026 at 7:00 PM