#MalwareDelivery
Void Dokkaebi exploits fake job interview repos to spread malware via obfuscated JavaScript and VS Code tasks, rewriting git history and delivering DEV#POPPER variants targeting developers and firms like DataStax. #VoidDokkaebi #MalwareDelivery
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
Void Dokkaebi has turned infected developer repositories into self-propagating malware delivery channels by abusing VS Code workspace tasks and injecting obfuscated JavaScript that rewrites git history. The campaign uses blockchain-staged loaders to fetch payloads and has delivered variants such as DEV#POPPER, enabling compromise of individual developers and amplification into organizations like...
www.hendryadrian.com
April 21, 2026 at 12:15 PM
The China-linked potatocrime group Cruciferra uses the BYOVD crypter to deliver its malware, raising global threat concerns. #China #PotatoCrime #Cruciferra #BYOVD #MalwareDelivery https://themashernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html
July 28, 2026 at 4:46 PM
The China-linked cybercrime group Cruciferra uses the BYOVD crypter to deliver its malware, raising global threat concerns. #China #CyberCrime #Cruciferra #BYOVD #MalwareDelivery https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra uses BYOVD, API unhooking, and Process Ghosting to hide RAT and stealer payloads delivered through phishing campaigns
thehackernews.com
July 28, 2026 at 4:46 PM
Threat actor UNC6692 uses Microsoft Teams helpdesk impersonation and email bombing to deploy “Snow” malware—combining a Chrome extension, tunneler, and Python backdoor for deep network compromise and credential theft. #UNC6692 #MalwareDelivery
Threat actor uses Microsoft Teams to deploy new “Snow” malware
UNC6692 uses social engineering and Microsoft Teams helpdesk impersonation to deploy a custom malware suite called "Snow," which combines a Chrome extension, a tunneler, and a Python backdoor to establish covert persistence and relay commands. The group conducts deep network compromise—dumping LSASS, using pass-the-hash, and exfiltrating Active Directory data (via FTK Imager and LimeWire) to steal credentials and take over domains. #Snow #UNC6692
www.hendryadrian.com
April 26, 2026 at 12:45 PM
Cloudflare Workers and Tunnels are being exploited to host AiTM phishing pages and deliver malware like Xeno RAT and XWorm RAT, leveraging trusted domains to evade defenses and detection. #CredentialTheft #CloudAbuse #MalwareDelivery
The Unintentional Enabler: How Cloudflare Services are Abused for Credential Theft and Malware Distribution
Cloudflare services — particularly Workers and Tunnels — are being abused by threat actors to host convincing AiTM phishing pages and to stage covert connections that deliver malware, including Xeno RAT and XWorm RAT. These attacks leverage trusted Cloudflare domains and free tiers (e.g., *.workers[.]dev, *.trycloudflare[.]com, *.pages[.]dev, *.r2[.]dev) to bypass email and network defenses and evade detection. #XenoRAT #XWormRAT
www.hendryadrian.com
March 27, 2026 at 2:20 AM
January 13, 2026 at 7:00 PM
January 2, 2026 at 3:00 PM
The JDownloader site was hacked to replace installers with Python RAT malware - trusted download channels can become perfect delivery systems. Verify hashes, not just brands. 🐍⚠️ #SupplyChainAttack #MalwareDelivery
JDownloader site hacked to replace installers with Python RAT malware
The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Windows payload found deploying a…
buff.ly
May 11, 2026 at 6:39 AM