Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Virus Bulletin

@VirusBulletin@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security information portal, testing and certification body.
Organisers of the annual Virus Bulletin conference.

2657 Followers
57 Following
50 Posts
Joined November 25, 2022
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Zscaler ThreatLabz examines four GoGRPC variants from a likely initial access broker for ransomware that leverages vishing techniques through Microsoft Teams. C2 communication protocols & the additional malware tools observed are also analysed. https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
zscaler.com
1
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 3mo ago
Huntress reports a standardized 7-step playbook beginning with CitrixBleed 2 exploitation. Stolen NetScaler sessions made MFA irrelevant, while follow-on actions included AppMgmt-based privilege escalation, rogue local admins, ScreenConnect or Zoho Assist, and DragonForce ransomware. https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
huntress.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Huntress investigates 6-stage kill chain MacSync: a thin zsh loader, a server-side AppleScript stealer keeping logic behind an API-key gate, a native Mach-O RAT for hands-on access, a signed helper built to steal one TCC permission & a set of wallet-app trojans. https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering
huntress.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Ransom-ISAC examines Telegram's role in the malware ecosystem. Its Bot API gives malware authors a free, TLS-protected, globally reachable message bus, with no infrastructure to rent, no domain to burn, and no certificate to manage. https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
The Telegram Malware Ecosystem
Ransom-ISAC

The Telegram Malware Ecosystem

A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.

0
0
0
1
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Cisco Talos has discovered a new Rust-based RAT attributed to the Chaos ransomware group. msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution & covert tunnelling for C2 communications. https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
blog.talosintelligence.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Join Damien Schaeffer from ESET at VB2026 in Seville. Find out more about this talk 👉https://tinyurl.com/s38swkcx 🎟️ Early Bird tickets are now available. Get yours here 👉 https://tinyurl.com/kd8hbudw
tinyurl.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
eSentire's TRU looks into a malicious ClickFix-style command that installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150. https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
esentire.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Cisco Talos researchers Alex Karkins & Chetan Raghuprasad show how UAT-11795, a Russian-speaking, financially motivated adversary targeting users in the US & Europe, uses the novel Python-based Starland RAT and a C2 memory implant known as the WLDR agent. https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/
blog.talosintelligence.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Bitsight's Pedro Falé uncovers the “Fuyao Enterprise”, a highly modular ad-fraud botnet operating within Android TV boxes. Its operators openly advertise their network of over 120,000 “AI digital humans". https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
bitsight.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Microsoft details CaptiveCrunch, a Storm-2945 (Midnight Blizzard sub-cluster) campaign targeting captive portal traffic at hospitality venues, using doppelganger domains & Entra ID device-code AiTM phishing to deliver malware & steal traveller credentials. https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Microsoft Security Blog

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
SOCRadar STRU analyses the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency & Web3 professionals with fake job interviews, delivering the PylangGhost RAT on Windows & the GolangGhost RAT on macOS. https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/
socradar.io
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Insikt Group has identified a series of BlueDelta (APT28/Fancy Bear/Forest Blizzard) initial access campaigns targeting government & diplomatic organizations in Romania, Spain & Turkey. The campaigns deliver the HOOKEDGE backdoor using diplomatic-themed lures. https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge
recordedfuture.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Genians Security Center reports on indications that the Kimsuky group built & operated local LLM environments using Ollama, GPT4All & Msty. https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm?hsCtaAttrib=379684624063
genians.co.kr
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Zscaler ThreatLabz provides a technical analysis of Abyssos, a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
zscaler.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 3mo ago
Sygnia analyses a 72-hour AWS intrusion where AI appears to have accelerated familiar cloud attack techniques. No zero-days or novel malware, just fast, parallel abuse of identities, CI/CD, cloud permissions, and runtime services. https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/
How AI Supercharged a 72-Hour Cloud Attack: Inside the Investigation
Sygnia

How AI Supercharged a 72-Hour Cloud Attack: Inside the Investigation

Learn how attackers used AI to accelerate a cloud compromise from initial access to broad impact in just 72 hours, and the key lessons for defending against faster, AI-enabled threats.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Microsoft has published its Q2 2026 email threat landscape report - notable campaigns observed demonstrated how threat actors combine automation, trusted services, and multi-stage delivery chains to scale operations. https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog
Microsoft Security Blog

Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains.

0
1
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
KnowBe4's Prabhakaran Ravichandhiran & Jeewan Singh Jalal look inside an OS-aware phishing kit that profiles the victim device dynamically and silently routes it into a completely different attack depending on the answer. https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
blog.knowbe4.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Elastic researchers analyse wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). https://www.elastic.co/security-labs/wp2shell-wordpress-rce-detection-elastic-defend
elastic.co
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Microsoft researchers have observed increased ACR Stealer activity across customer environments. These campaigns are using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
ACR Stealer: Two observed intrusion chains amid increased threat activity | Microsoft Security Blog
Microsoft Security Blog

ACR Stealer: Two observed intrusion chains amid increased threat activity | Microsoft Security Blog

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Sophos analysts investigate a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems & facilitate ransomware deployment. https://www.sophos.com/en-gb/blog/chaos-in-teams-vishing
sophos.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Proofpoint looks at Cruciferra’s functionalities and observed real-world use. Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal threat clusters and delivers a wide range of remote access trojans and infostealers. https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service
Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Proofpoint US
Proofpoint

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Proofpoint US

Key Findings Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal threat clusters. It has been observed delivering a wide range of

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Infoblox's Darby Wise & Nick Sundvall look inside an adversary-in-the-middle phishing (AiTM) campaign targeting universities, enterprises, and multinational institutions, including European Union & United Nations agencies. https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/
Inside a Global Procurement-Themed AiTM Phishing Campaign
Infoblox Blog

Inside a Global Procurement-Themed AiTM Phishing Campaign

Researchers discover a phishing campaign targeting global enterprises and agencies using multiple AiTM phishing kits to bypass MFA and steal sessions.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2w ago
TraderTraitor (DPRK) is shifting beyond crypto, using fake job workflows and weaponised Terraform projects to target DevOps teams. SentinelOne breaks down the new FLATROOF and ROOFDECK macOS backdoors behind the campaign. https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/
Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
SentinelOne

Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Proofpoint

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US

Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
360 ​​Advanced Threat Research Institute discovered and captured a new attack campaign by the OceanLotus (APT-C-00) threat group, also known as APT32. The campaign utilizes CD-ROM image files with malicious payloads attached to emails as delivery carriers. https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508745&idx=1&sn=d2e8bf3bed50b91adf218cabe5be731c&poc_token=HB3CYWqjXTJh49hdeOD1SG6NbHJcwxj3Jnf7HhuI
mp.weixin.qq.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
⏰ Early Bird closes soon! Secure your place at VB2026 in Seville and save €200 on your ticket before the Early Bird rate ends on 7 August. Join 300+ cybersecurity professionals and 90+ speakers for three days of world-class talks, learning and networking. 🎟️ Don’t miss out. Book your ticket now 👉 https://tinyurl.com/2v3ywne7
tinyurl.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2w ago
ThreatDown​ ​researchers​ ​uncovered​ ​CARBONATO, which targets unauthenticated Docker daemons, then installs the legitimate Hermes Agent. A modified SOUL.md tells it to take Telegram tasks and prioritise AI API keys over credentials. https://www.threatdown.com/blog/carbonato/
​CARBONATO:​ ​a​ ​botnet​ ​built​ ​around an AI agent​ | ThreatDown
ThreatDown

​CARBONATO:​ ​a​ ​botnet​ ​built​ ​around an AI agent​ | ThreatDown

​ThreatDown​ ​researchers​ ​uncovered​ ​CARBONATO,​ ​a​ ​Docker​ ​botnet​ ​built​ ​around​ ​an​ ​AI​ ​agent​ ​that​ ​compromises​ ​exposed​ ​Docker​ ​daemons,​ ​spreads​ ​across​ ​reachable​ ​hosts,​ ​and​ ​gives​ ​operators​ ​a​ ​Telegram-controlled​ ​tool​​ for​ ​post-compromise activity.​

0
0
1
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1w ago
K7 researchers analyse a Python-based MaaS infostealer builder and an embedded infostealer payload. Operators are able to generate customized Windows executables using Nuitka or PyInstaller, with webhook configuration integrated into the build process. https://labs.k7computing.com/index.php/the-stealer-factory-unpacking-a-python-based-maas-infostealer-builder/
The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder - K7 Labs
K7 Labs

The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder - K7 Labs

The first layer of an archive rarely tells the complete story. Some archives hide behind familiar formats, requiring deeper analysis […]

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Seqrite's Prashil Moon looks into a multi-stage Phantom stealer malspam campaign disguised as different trusted entities including a global logistics provider and a government tax authority. https://www.seqrite.com/blog/abusing-trusted-business-workflows-a-multi-stage-phantom-stealer-campaign/
seqrite.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
proofpoint.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 3mo ago
LevelBlue Managed Threat Research investigates a multi-stage LNK attack where a malicious ZIP triggers hidden PowerShell, downloads a legitimate node.exe, and deploys a Node.js backdoor. The malware uses EtherHiding via the TON blockchain to retrieve its C2 address. https://www.levelblue.com/blogs/spiderlabs-blog/hiding-in-the-chain-multi-stage-lnk-attack-leveraging-ton-blockchain-to-deliver-node.js-backdoor
levelblue.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
IIJ-SECT's Bynaoki Takayam looks into three of the latest BlueShell variants observed in May 2026, primarily used in attacks by threat actors based in China. https://sect.iij.ad.jp/blog/2026/07/blueshell-variant-deployed-by-apt-group/
sect.iij.ad.jp
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Gen's Martin Chlumecký & Luis Corrons look into Phantom Deal, a fake acquisition fraud campaign. Attackers posed as executives, moved conversations to WhatsApp and personal email, and forged acquisition documents to set up international wire transfers. https://www.gendigital.com/blog/insights/research/phantom-deal
gendigital.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1w ago
Microsoft researchers delve into the attack techniques attributed to Storm-2570, a ransomware affiliate linked to multiple ransomware payloads like Qilin, DragonForce, Anubis, and BERT ransomware. https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments | Microsoft Security Blog
Microsoft Security Blog

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments | Microsoft Security Blog

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Point Wild's LAT61 team analysed Vanta Stealer, a Python-based cross-platform infostealer targeting many apps & digital assets. A notable characteristic is its use of multiple PyArmor protection layers, combined with a PyInstaller-packaged executable. https://www.pointwild.com/threat-intelligence/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware/
pointwild.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Fortinet's Yurren Wan writes about a global campaign in which threat actors use disguised .ttf files and low-detection Lua loaders to deliver RATs and infostealers. https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader
fortinet.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Through ongoing tracking of the TAG-195 MaaS ecosystem, Recorded Future Insikt Group identified four new TAG-195 (Golden Chickens, Venom Spider) malware families: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator. https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
recordedfuture.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Trend Micro researcher Takehiro Iwai uncovered a tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. https://www.trendmicro.com/en_us/research/26/g/tech-support-scams-targeting-japan.html
trendmicro.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
In collaboration with ANY.RUN, Mauro Eldritch from BCA LTD & Heiner García from NorthScan created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/
any.run
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
JUMPSEC analysed source code from an active BlueNoroff phishing kit used to impersonate Zoom & Microsoft Teams meetings. Operators mistakenly exposed JS source maps on live infrastructure, giving researchers source-level insight into how the operation works. https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
jumpsec.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Huntress analyst Michael Tigges looks into a malvertising campaign that led to a malicious Claude artifact and to the download of SectopRAT. https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat
huntress.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2w ago
The VB2026 programme has just been updated with this year’s last-minute papers, adding even more timely research to the line-up. Join us in Seville this October for three days of expert-led talks, fresh technical insight and the latest developments in cybersecurity research. 🔍 View the full programme: https://vb2026.virusbulletin.com/ 🎟️ Get your ticket: https://vb2026.virusbulletin.com/#tickets #VB2026 #CyberSecurity #VBConference #SecurityResearch #Seville
vb2026.virusbulletin.com
0
0
1
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Gen has published its H1 2026 Threat Report: Attackers spent the first half of 2026 abusing trust that already exists - hotel workflows, messaging sessions, browser data, developer tools, AI agents, payment habits and identity signals. https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026
gendigital.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
🔥 Gone in record time! Super Early Bird tickets are officially sold out, but Early Bird tickets are still up for grabs. 🎟️ Don’t wait too long. Get yours before they’re gone too 👉https://tinyurl.com/4ft265m2 #vb2026 #vbconference #cybersecurity #seville
tinyurl.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Acronis Threat Research Unit (TRU) has identified an active Lampion malware campaign targeting Portuguese users through phishing emails masquerading as financial and administrative communications. https://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/
Lampion's Portugal-focused phishing campaign delivers multistage malware
Acronis

Lampion's Portugal-focused phishing campaign delivers multistage malware

Acronis Threat Research Unit (TRU) has identified an active Lampion malware campaign targeting Portuguese users through phishing emails masquerading as financial and administrative communications.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Securonix researchers analyse SMOKE#SCREEN, a multi-wave campaign where attackers use rotating social engineering lures - fake Zoom updates, document reviews, and system maintenance tools - to deliver silent ScreenConnect RMM agent installations. https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
securonix.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
VMRay Labs identified a campaign conducted by a Russian-speaking threat group, tracked as Operation STANDOFF, which combines two layers: a mass-access with a pay-per-install loader & a multi-operator console for human-operated hands-on-keyboard intrusion. https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/
vmray.com
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Google GTIG shows that UNC6671 actively conducts compromises leading to data theft extortion. Telemetry and infrastructure analysis reveal that UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix & Falcon. https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | Google Cloud Blog
Google Cloud Blog

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | Google Cloud Blog

UNC6671 has rebranded from BlackFile to REDACT while diversifying its extortion operations across multiple brands, including FALCON, HELIX, and PINK.

0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Elastic Security Labs found a new Contagious Interview campaign hiding malware inside SVG image files using steganography. Campaigns involve coding challenges & take-home assignments with benign-looking projects containing malicious backdoored code. https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography
elastic.co
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Proofpoint reports that Indirect Prompt Injection (IDPI) is increasingly being discussed by malicious actors on closed, underground forums. Tools & services designed to leverage IDPI within attack chains are actively being developed, refined, and advertised for sale. https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection
Notes from Underground: Adversarial Prompt Injection | Proofpoint US
Proofpoint

Notes from Underground: Adversarial Prompt Injection | Proofpoint US

Key Takeaways Indirect Prompt Injection (IDPI) is increasingly being discussed by malicious actors on closed, underground forums. Tools and services designed to leverage IDPI

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:53:37 UTC