https://
pure8s.ddnsfree.com and 52.241.248.38.
Uses .NET evasion techniques (DisableNativeImageLoad),…
— from @ipurple (https://x.com/ipurple/status/2102336812282675637)
https://
pure8s.ddnsfree.com and 52.241.248.38.
Uses .NET evasion techniques (DisableNativeImageLoad),…
— from @ipurple (https://x.com/ipurple/status/2102336812282675637)
Cybersecurity firm Sekoia reports a widespread fraud where criminals compromise hotel systems (Booking.com, Expedia and others) with PureRAT malware, then use stolen reservation data to phish and defraud gues…
#hackernews #news
Cybersecurity firm Sekoia reports a widespread fraud where criminals compromise hotel systems (Booking.com, Expedia and others) with PureRAT malware, then use stolen reservation data to phish and defraud gues…
#hackernews #news
Greedy Sponge hackers are pushing a weaponized Chrome proxy zip that drops AllaKore RAT—now upgraded to exfiltrate credentials and act as a SOCKS5 proxy.
💰 Financial fraud is the goal. And it’s working. #CyberSecurity #cybercrime
Greedy Sponge hackers are pushing a weaponized Chrome proxy zip that drops AllaKore RAT—now upgraded to exfiltrate credentials and act as a SOCKS5 proxy.
💰 Financial fraud is the goal. And it’s working. #CyberSecurity #cybercrime
⛳️ C2 port is often 56001, 56002 or 56003
🔢 Bot sends 04 00 00 00, then TLS handshake
🔑 Client and server run TLS 1.0
🖊️ X.509 cert is self signed
📅 X.509 cert expires 9999-12-31
netresec.com?b=2589522
⛳️ C2 port is often 56001, 56002 or 56003
🔢 Bot sends 04 00 00 00, then TLS handshake
🔑 Client and server run TLS 1.0
🖊️ X.509 cert is self signed
📅 X.509 cert expires 9999-12-31
netresec.com?b=2589522
The reason for the conclusion? Emojis throughout the code, likely from social media posts the AI has ripped content from... 👀
www.infosecurity-magazine.com/news/emojis-...
The reason for the conclusion? Emojis throughout the code, likely from social media posts the AI has ripped content from... 👀
www.infosecurity-magazine.com/news/emojis-...
-Unpatched Foscam bugs
-Go crypto has a security audit
-New SCC cyber industry group
-New ENISA NIS2 handbook
-OffensiveCon 2025 videos
-Malware reports on ELPACO-team ransomware, 3AM ransomware, PureRAT, Hannibal Stealer
-Unpatched Foscam bugs
-Go crypto has a security audit
-New SCC cyber industry group
-New ENISA NIS2 handbook
-OffensiveCon 2025 videos
-Malware reports on ELPACO-team ransomware, 3AM ransomware, PureRAT, Hannibal Stealer
Insure the safe return of more money
For analysis
All other considerations are secondary
Teammates expendable" #nufc #PureRat #IsakEarth #fuckinstagram
Insure the safe return of more money
For analysis
All other considerations are secondary
Teammates expendable" #nufc #PureRat #IsakEarth #fuckinstagram
netresec.com?b=267e877
netresec.com?b=267e877
Read 🔗 hackread.com/i-paid-twice...
#Cybersecurity #Malware #Phishing #ClickFix
Read 🔗 hackread.com/i-paid-twice...
#Cybersecurity #Malware #Phishing #ClickFix
Introduction A new phishing campaign linked to a Vietnamese threat actor is showing how artificial intelligence is reshaping cybercrime at street level. By abusing AI tools to generate polished scripts, detailed…
Introduction A new phishing campaign linked to a Vietnamese threat actor is showing how artificial intelligence is reshaping cybercrime at street level. By abusing AI tools to generate polished scripts, detailed…
An Alarming Example of Malware Innovation and Social Engineering A new and highly coordinated cyberattack has been uncovered by eSentire’s Threat Response Unit (TRU), targeting a U.S.-based certified public accounting…
An Alarming Example of Malware Innovation and Social Engineering A new and highly coordinated cyberattack has been uncovered by eSentire’s Threat Response Unit (TRU), targeting a U.S.-based certified public accounting…
We also detailed the fraud scheme targeting hotel customers.
We also detailed the fraud scheme targeting hotel customers.
So, NEVER do that! Better yet, switch to a Linux OS.
So, NEVER do that! Better yet, switch to a Linux OS.
The two `zgRAT` IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/]. The reason for the `Unknown` tag is […]
The two `zgRAT` IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/]. The reason for the `Unknown` tag is […]
The two `zgRAT` IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/]. The reason for the `Unknown` tag is […]
The two `zgRAT` IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/]. The reason for the `Unknown` tag is […]