Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

OTX Bot

@techbot@social.raytec.co
mastodon 4.7.3
  • Open on social.raytec.co

Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike@social.raytec.co.

Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts:

-cyberhunter_nl
-tr2222200
-tr1sa111
-bluenumberone
-dekarituraj
-feisty-swim1410

If they become overwhelming or repetitive I will gladly accept suggestions to remove any.

A little bot maintained by @mike@social.raytec.co to post the latest pulses from Open Threat Exchange.

Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted.

Unaffiliated with OTX or AlienVault

WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it.

#OTX #AlienVault

408 Followers
1 Following
45 Posts
Joined October 10, 2023
Written in:
Python
Written by:
Raymond Tec
Maintainer:
@mike
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix

Threat actors exploited ChatGPT's Custom GPT feature to impersonate legitimate ChatGPT models, directing victims through sponsored Google ads to malicious Custom GPTs titled 'Plus 5.6'. These instances served fake service availability notices, redirecting users to Google Sites pages hosting ClickFix lures disguised as CloudFlare CAPTCHA checks. Victims were tricked into executing PowerShell commands that downloaded malicious MSI installers. The attack chain employed DLL sideloading through legitimate Canon-signed and later Stardock-signed executables, establishing dual persistence mechanisms via registry Run keys and scheduled tasks. The multi-stage infection involved obfuscated scripts, encrypted payloads hidden in WAV files and NuGet packages, and ultimately deployed a feature-rich remote access trojan with capabilities including remote desktop, browser hijacking, credential theft, and follow-on payload delivery. Huntress investigated approximately 40 incidents linked to this campaign, with confirmed Cus...

Pulse ID: 6ac12c993806593609d1c30c
Pulse Link: https://otx.alienvault.com/pulse/6ac12c993806593609d1c30c
Pulse Author: AlienVault
Created: 2026-10-03 16:26:01

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#ChatGPT #Clickfix #RAT #CAPTCHA #OTX #AlienVault

otx.alienvault.com
1
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and... Pulse ID: 6a9ef40735b49c55dc7166c9 Pulse Link: https://otx.alienvault.com/pulse/6a9ef40735b49c55dc7166c9 Pulse Author: AlienVault Created: 2026-09-07 17:27:35 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CredentialHarvesting #CyberSecurity #DNS #DoubleClick #Email #Google #Government #ICS #InfoSec #Manufacturing #OTX #OpenThreatExchange #Phishing #Proxy #RAT #Rust #ScreenConnect #Telegram #bot #AlienVault
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

2
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Malicious Chrome Extension Can Steal Login Sessions and Turn PCs Into Remote Backdoors Indicators extracted from public reporting. Source: https://socradar.io/blog/peep-browser-rat-chrome-extension/ Pulse ID: 6a9e7c2ce1129dcc5ae37c04 Pulse Link: https://otx.alienvault.com/pulse/6a9e7c2ce1129dcc5ae37c04 Pulse Author: CyberHunter_NL Created: 2026-09-07 08:56:12 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #BackDoor #Browser #Chrome #ChromeExtension #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL
socradar.io
1
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 2mo ago
Contagious Interview malware in SVG images: DPRK campaign A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers. Pulse ID: 6a5a8ba0229db5a5b2686baa Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa Pulse Author: AlienVault Created: 2026-07-17 20:08:00 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

1
0
1
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon Pulse ID: 6aa8d28c00a1fa0064105d5e Pulse Link: https://otx.alienvault.com/pulse/6aa8d28c00a1fa0064105d5e Pulse Author: Tr1sa111 Created: 2026-09-15 05:07:24 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Chinese #Government #OTX #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Pulse ID: 6aa8d48bb9571ef6455a21c6 Pulse Link: https://otx.alienvault.com/pulse/6aa8d48bb9571ef6455a21c6 Pulse Author: Tr1sa111 Created: 2026-09-15 05:15:55 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Phishing #Browser #OTX #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service. The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries. The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek […] The post Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices appeared first on Cyber Security News .

Pulse ID: 6ac35805e1df7ad5ed81fdf1
Pulse Link: https://otx.alienvault.com/pulse/6ac35805e1df7ad5ed81fdf1
Pulse Author: CyberHunter_NL
Created: 2026-10-05 07:55:49

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Google #IoT #botnet #Malware #OTX #CyberHunter_NL

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack Pulse ID: 6aa8f78f28a8d7073b557898 Pulse Link: https://otx.alienvault.com/pulse/6aa8f78f28a8d7073b557898 Pulse Author: Tr1sa111 Created: 2026-09-15 07:45:19 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #0Day #Adobe #Magento #RCE #OTX #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

SMTP is the key: BPFDoor and AVERAT hitting the network edge

A sophisticated multi-component campaign targeting telecommunications and network-edge appliances has been discovered, featuring BPFDoor variants and a newly identified implant designated AVERAT. The operation leverages SMTP traffic on port 25 to blend command-and-control communications with legitimate mail relay activity, exploiting the trust environments of targeted systems. Attackers deploy a dropper that stages payloads into memory-only execution, leaving no on-disk artifacts for forensic analysis. BPFDoor variants impersonate legitimate processes such as SpamSniper components on South Korean systems, while AVERAT samples target Taiwanese appliances using regionalized disguises. The infrastructure relies on compromised consumer devices including NAS units, CCTV systems, and DVRs as operational relays, consistent with China-nexus covert network patterns. Each component demonstrates advanced operational security through process spoofing, encrypted configurations, and deliberate evasion of network monitor...

Pulse ID: 6abfb61b65922c3229d35cf8
Pulse Link: https://otx.alienvault.com/pulse/6abfb61b65922c3229d35cf8
Pulse Author: AlienVault
Created: 2026-10-02 13:48:11

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Edge #Deploy #China #OTX #AlienVault

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 2mo ago
Security Update – August 2, 2026 Pulse ID: 6a740db739f5ddf6e048bf0a Pulse Link: https://otx.alienvault.com/pulse/6a740db739f5ddf6e048bf0a Pulse Author: Tr1sa111 Created: 2026-08-06 04:29:43 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
PIVOTPIPE: A New .NET-based Unofficial Beacon Payload Pulse ID: 6aab7c429cbc2675255fd261 Pulse Link: https://otx.alienvault.com/pulse/6aab7c429cbc2675255fd261 Pulse Author: Tr1sa111 Created: 2026-09-17 05:36:02 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #NET #OTX #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
Financially Motivated Threat Actor BREEZE COMET Targets Brazil Pulse ID: 6aa8d24632573b2a3c81b5f6 Pulse Link: https://otx.alienvault.com/pulse/6aa8d24632573b2a3c81b5f6 Pulse Author: Tr1sa111 Created: 2026-09-15 05:06:14 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Brazil #OTX #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia Pulse ID: 6a9f95581dc4c6de1b0540b2 Pulse Link: https://otx.alienvault.com/pulse/6a9f95581dc4c6de1b0540b2 Pulse Author: Tr1sa111 Created: 2026-09-08 04:55:52 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Asia #Chinese #CyberSecurity #Education #Government #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

Pulse ID: 6ac3ac6e93930b4d37dbe1fa
Pulse Link: https://otx.alienvault.com/pulse/6ac3ac6e93930b4d37dbe1fa
Pulse Author: CyberHunter_NL
Created: 2026-10-05 13:55:58

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#botnet #Deploy #OTX #CyberHunter_NL

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

CVE-2026-104286: Critical FortiMail Zero-Day Exploited for Unauthenticated File Writes

Fortinet has disclosed a critical FortiMail zero-day vulnerability that attackers are already exploiting in the wild. Tracked as CVE-2026-104286 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated remote attacker to write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests. The vulnerability poses a significant risk […] The post CVE-2026-104286: Critical FortiMail Zero-Day Exploited for Unauthenticated File Writes appeared first on SOC Prime .

Pulse ID: 6ac3e4c60b5f3d6ef7c5140a
Pulse Link: https://otx.alienvault.com/pulse/6ac3e4c60b5f3d6ef7c5140a
Pulse Author: CyberHunter_NL
Created: 2026-10-05 17:56:22

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CVE2026104286 #ZeroDay #HTTP #HTTPS #OTX #CyberHunter_NL

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 2w ago
Beware the SparroWock: The backdoor that bites, the commands that catch Indicators extracted from public reporting. Source: https://www.eset.com/int/business/services/threat-intelligence/?utm_source=welivesecurity.com&utm_medium=referral&utm_campaign=wls-research&utm_content=beware-sparrowock-backdoor-bites-commands-catch&sfdccampaignid=7011n0000017htTAAQ Pulse ID: 6aad0a9f11a363a15814494b Pulse Link: https://otx.alienvault.com/pulse/6aad0a9f11a363a15814494b Pulse Author: CyberHunter_NL Created: 2026-09-18 09:55:43 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #BackDoor #OTX #CyberHunter_NL
eset.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

Pulse ID: 6ac33890e1bfafb65406440a
Pulse Link: https://otx.alienvault.com/pulse/6ac33890e1bfafb65406440a
Pulse Author: Tr1sa111
Created: 2026-10-05 05:41:36

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CVE202688771 #Citrix #NetScaler #OTX #Tr1sa111

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Caught in 4K: The Gentlemen Files

A Russian-speaking affiliate of the Gentlemen ransomware group, identifying as Azazel, compromised over two dozen organizations across six countries while simultaneously betraying the RaaS operator. The threat actor deployed independent leak site LEAKNED, keeping all extortion proceeds. Attack chains primarily exploited CI/CD secrets from GitLab instances, with one deep compromise involving an AI platform through SSRF, credential decryption, and continuous object storage exfiltration. Azazel operationalized MCP (Model Context Protocol) as a command-and-control channel, marking the first documented criminal use of AI assistant tooling for attack execution. Infrastructure consisted of three nodes totaling over 50TB storage capacity, with approximately 6TB of actively transferring victim data discovered during investigation. Victims spanned logistics, insurance, pharmaceutical, AI, medical devices, and government-adjacent sectors.

Pulse ID: 6ac3a6d89aeb3e3d383d6d06
Pulse Link: https://otx.alienvault.com/pulse/6ac3a6d89aeb3e3d383d6d06
Pulse Author: AlienVault
Created: 2026-10-05 13:32:08

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#RaaS #Credential #OTX #AlienVault

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Indicators extracted from public reporting. Source: https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/ Pulse ID: 6aa835ee9dc88a53daa3efde Pulse Link: https://otx.alienvault.com/pulse/6aa835ee9dc88a53daa3efde Pulse Author: CyberHunter_NL Created: 2026-09-14 17:59:10 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #SSL #VPN #Vulnerability #OTX #CyberHunter_NL
cybersecuritynews.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Hackers Actively Exploiting PaperCut Servers Command Execution Vulnerabilities Indicators extracted from public reporting. Source: https://cybersecuritynews.com/papercut-command-execution-flaws-exploited/ Pulse ID: 6a9e6e1a6891a0ac0d93faec Pulse Link: https://otx.alienvault.com/pulse/6a9e6e1a6891a0ac0d93faec Pulse Author: CyberHunter_NL Created: 2026-09-07 07:56:10 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #AWS #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
cybersecuritynews.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
The banana stand: brokering and managing infections across Asia using MQTT Pulse ID: 6aab7c49da521a5fde002948 Pulse Link: https://otx.alienvault.com/pulse/6aab7c49da521a5fde002948 Pulse Author: Tr1sa111 Created: 2026-09-17 05:36:09 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Asia #MQTT #OTX #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

A STUNning Disguise: Cling Malware Masquerades as Google

A sophisticated IoT botnet dubbed Cling has been discovered exploiting vulnerable internet-exposed devices through CVE-2021-35394 and other command-injection flaws. The malware distinguishes itself by abusing STUN protocol traffic and public STUN infrastructure for command-and-control communications, making malicious activity appear as legitimate NAT-traversal behavior. Cling propagates through multiple CVE exploits targeting routers, DVRs and embedded appliances, establishes persistence via init scripts and wget binary replacement, then communicates with operators through STUN-like exchanges with public servers. The botnet operator uses IP spoofing to make commands appear as if originating from Google's STUN infrastructure. Capabilities include propagation scanning, DDoS flooding, TCP tunneling and proxy relay functions. The malware supports various attack commands hidden within STUN transaction ID fields while maintaining a low detection profile by blending into legitimate application traffic from collab...

Pulse ID: 6ac368846173b592a85473db
Pulse Link: https://otx.alienvault.com/pulse/6ac368846173b592a85473db
Pulse Author: AlienVault
Created: 2026-10-05 09:06:12

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Cling #Google #botnet #CVE202135394 #OTX #AlienVault

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

XWorm Malware: Worming Its Way From Entry to Exploitation

XWorm is a versatile modular malware that poses a multifaceted threat through remote access, data theft, ransomware delivery, and botnet creation. Associated with the DDGroup cybercrime group, it rapidly gained notoriety for using advanced techniques. The malware employs diverse delivery methods including phishing emails with malicious attachments, drive-by downloads, exploit kits targeting browser vulnerabilities, USB drives, and Remote Desktop Protocol exploitation. Once established, XWorm steals sensitive data like passwords and credit card information, deploys additional malware strains including ransomware and spyware, and causes system crashes and denial-of-service attacks. Its modular nature and varied attack vectors make it a persistent threat requiring robust cybersecurity measures and continuous vigilance.

Pulse ID: 6ac34ecea12957741eb7ac1b
Pulse Link: https://otx.alienvault.com/pulse/6ac34ecea12957741eb7ac1b
Pulse Author: AlienVault
Created: 2026-10-05 07:16:30

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#XWorm #botnet #Malware #CreditCard #OTX #AlienVault

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Hackers Use Ethereum Blockchain to Steal Credit Card Data From Online Shoppers Indicators extracted from public reporting. Source: https://blog.confiant.com/p/skimming-on-the-blockchain-a-magecart Pulse ID: 6a956bcebf30addf06a8d0a2 Pulse Link: https://otx.alienvault.com/pulse/6a956bcebf30addf06a8d0a2 Pulse Author: CyberHunter_NL Created: 2026-08-31 11:55:58 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #BlockChain #CreditCard #CyberSecurity #HTTP #HTTPS #InfoSec #Magecart #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning
blog.confiant.com

Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning

One attacker wallet, 144 smart contracts, and 40+ compromised e-commerce checkouts quietly stealing shoppers' card data.

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 2w ago
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Indicators extracted from public reporting. Source: https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html Pulse ID: 6aacb63e160b1f1ab8d3a1fd Pulse Link: https://otx.alienvault.com/pulse/6aacb63e160b1f1ab8d3a1fd Pulse Author: CyberHunter_NL Created: 2026-09-18 03:55:42 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #OTX #CyberHunter_NL
thehackernews.com

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Anatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystem

BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware. Unlike standard infostealers, it functions as a comprehensive toolkit for Initial Access Brokers, converting compromised systems into high-value commercial assets. The framework employs modular architecture, advanced evasion techniques, and AI-enhanced reconnaissance capabilities to target corporate, financial, industrial, and law enforcement environments across Iberia and Latin America. It specifically harvests financial transaction files in Brazilian CNAB format, detailed browsing histories, and digital certificates. BraZetsu powers the 'Infected Marketplace' where Exilware commercializes initial access to compromised systems, enabling criminal clients to remotely execute additional malicious payloads. The malware demonstrates rapid technical evolution since February 2026, progressing from basic remote access to an AI-enhanced intelligence collection platform.

Pulse ID: 6abfae3085404615c3cf7a32
Pulse Link: https://otx.alienvault.com/pulse/6abfae3085404615c3cf7a32
Pulse Author: AlienVault
Created: 2026-10-02 13:14:24

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Underground #LatinAmerica #LawEnforcement #Python #OTX #AlienVault

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/ Pulse ID: 6a913f0e09f2b3ab49915028 Pulse Link: https://otx.alienvault.com/pulse/6a913f0e09f2b3ab49915028 Pulse Author: CyberHunter_NL Created: 2026-08-28 07:55:58 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
Dark Caracal Reloaded: New Malware, Same Hunting Grounds - Arctic Wolf
Arctic Wolf

Dark Caracal Reloaded: New Malware, Same Hunting Grounds - Arctic Wolf

During a targeted intrusion investigation, Arctic Wolf uncovered GoCaracal, a previously undocumented, modular framework written in Go. Its long-term development offers new insight into the evolution of Dark Caracal's capabilities, operations, and tradecraft.

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX

Socket identified a malicious cluster of Visual Studio Code extensions spanning both VS Code Marketplace and Open VSX registries. Two confirmed malicious themes were discovered: Aurora Nocturne Night Theme, which downloaded and executed threat actor-controlled batch files, and Cosmic Nebula Themes, containing a staged loader that decrypts embedded JavaScript, performs Russian-language gating, and uses Solana blockchain transaction memos to dynamically resolve payload infrastructure. The cluster includes at least ten extensions across both platforms, with over 8,000 Visual Studio Marketplace installs and tens of thousands of Open VSX downloads. Git history, Russian-language source code comments, and distinctive execution patterns connect these extensions to the broader GlassWorm supply chain campaign. Several extensions remain unweaponized but retain executable capabilities that pose significant risk. The operation employs brandjacking tactics and demonstrates sophisticated infrastructure rotation technique...

Pulse ID: 6ac07308bd5cef8481adcf61
Pulse Link: https://otx.alienvault.com/pulse/6ac07308bd5cef8481adcf61
Pulse Author: AlienVault
Created: 2026-10-03 03:14:16

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BlockChain #JavaScript #SupplyChain #OTX #AlienVault

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Warlock Ransomware Attackers Hit Water and Telecom Operators

Pulse ID: 6ac338a9cf325c4919d1b050
Pulse Link: https://otx.alienvault.com/pulse/6ac338a9cf325c4919d1b050
Pulse Author: Tr1sa111
Created: 2026-10-05 05:42:01

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Telecom #Warlock #RansomWare #OTX #Tr1sa111

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing

Hackers are using a legitimate ScreenConnect client to turn a payment notification into a route for remote access. Instead of delivering custom malware, the phishing attempt directs recipients to software already designed to let someone else connect to their computer. The email claims that a payment of $5745.65 has been received and invites the recipient […] The post Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing appeared first on Cyber Security News .

Pulse ID: 6ac39071863fe3f8d9c2d228
Pulse Link: https://otx.alienvault.com/pulse/6ac39071863fe3f8d9c2d228
Pulse Author: CyberHunter_NL
Created: 2026-10-05 11:56:33

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#ScreenConnect #Phishing #Email #OTX #CyberHunter_NL

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3w ago
The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Pulse ID: 6aab7c54a7d3b34045501163 Pulse Link: https://otx.alienvault.com/pulse/6aab7c54a7d3b34045501163 Pulse Author: Tr1sa111 Created: 2026-09-17 05:36:20 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Chrome #OTX #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Popular npm Package With 150K+ Weekly Downloads Hit by Credential-Stealing Supply-Chain Worm Indicators extracted from public reporting. Source: https://research.jfrog.com/post/shai-hulud-trinitite/ Pulse ID: 6a956bc92f739d8a0e243dd2 Pulse Link: https://otx.alienvault.com/pulse/6a956bc92f739d8a0e243dd2 Pulse Author: CyberHunter_NL Created: 2026-08-31 11:55:53 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
research.jfrog.com

Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegen - JFrog Security Research

JFrog Security Research analyzed a new Mini Shai-Hulud wave on @7nohe/openapi-react-query-codegen. Ten npm versions drop a Trinitite-labeled worm through preinstall and an obfuscated binding.gyp command.

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Response Overview and Colonel Clustered – Grouping Burp Responses by Content

Two Burp Suite extensions that group responses by content: Response Overview, a BApp with a threshold you set, and Colonel Clustered, which picks its own.

Pulse ID: 6ac39e746ceb2124f3eb1e3d
Pulse Link: https://otx.alienvault.com/pulse/6ac39e746ceb2124f3eb1e3d
Pulse Author: CyberHunter_NL
Created: 2026-10-05 12:56:20

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#OTX #CyberHunter_NL

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

The Psychedelic Stealer: When the CAPTCHA Is the Installer

Between September 9 and September 14, 2026, an unattributed Russian-speaking operator compromised at least six legitimate Ukrainian small-business websites to deliver a fake Cloudflare verification page. The ClickFix chain convinced victims to manually execute msiexec.exe commands via the Windows Run dialog, achieving a 14 percent completion rate (79 infections from 426 clicks). The payload, internally named Psychedelic, combines credential theft with persistent agent capabilities, installing browser extensions with native-messaging bridges, establishing scheduled tasks, and polling a REST API for arbitrary executable tasking. Targeting focused overwhelmingly on Ukraine with clear financial motivation, collecting browser credentials, session tokens, and cryptocurrency wallet data from MetaMask, Trust Wallet, Exodus, Atomic Wallet, and others. The technique deliberately avoids encoded PowerShell, using signed Microsoft binaries to bypass common ClickFix detections.

Pulse ID: 6abfb63a870eec5021127b09
Pulse Link: https://otx.alienvault.com/pulse/6abfb63a870eec5021127b09
Pulse Author: AlienVault
Created: 2026-10-02 13:48:42

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Psychedelic #CAPTCHA #Atomic #Clickfix #OTX #AlienVault

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

TIKTOUK: Tracing a WordPress Credential Collection Toolkit

Pulse ID: 6ac338b90015d38c899398ec
Pulse Link: https://otx.alienvault.com/pulse/6ac338b90015d38c899398ec
Pulse Author: Tr1sa111
Created: 2026-10-05 05:42:17

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Credential #TIKTOUK #Wordpress #OTX #Tr1sa111

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
ASCII smuggling crosses over from AI prompt injection to phishing evasion Pulse ID: 6a9f94de75e1687221b3fb6f Pulse Link: https://otx.alienvault.com/pulse/6a9f94de75e1687221b3fb6f Pulse Author: Tr1sa111 Created: 2026-09-08 04:53:50 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #bot #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

Pulse ID: 6ac3389ecc4d8f2f8b8a0c6f
Pulse Link: https://otx.alienvault.com/pulse/6ac3389ecc4d8f2f8b8a0c6f
Pulse Author: Tr1sa111
Created: 2026-10-05 05:41:50

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#TA419 #China #OTX #Tr1sa111

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
Contagious Interview steps outside the developer workflow Pulse ID: 6a9f9497e3279459528af385 Pulse Link: https://otx.alienvault.com/pulse/6a9f9497e3279459528af385 Pulse Author: Tr1sa111 Created: 2026-09-08 04:52:39 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 2mo ago
Analysis of BlueShell Variants Used by APT Groups BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities. Pulse ID: 6a69c06b441d532a963887ee Pulse Link: https://otx.alienvault.com/pulse/6a69c06b441d532a963887ee Pulse Author: AlienVault Created: 2026-07-29 08:57:15 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

Pulse ID: 6ac338b11e9a6f20af31a928
Pulse Link: https://otx.alienvault.com/pulse/6ac338b11e9a6f20af31a928
Pulse Author: Tr1sa111
Created: 2026-10-05 05:42:09

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#OTX #Tr1sa111

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache

A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter. The instruction looks simple, but it makes the victim run the attacker’s command. The […] The post ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache appeared first on Cyber Security News .

Pulse ID: 6ac3ac68f9c76cd14a4824e4
Pulse Link: https://otx.alienvault.com/pulse/6ac3ac68f9c76cd14a4824e4
Pulse Author: CyberHunter_NL
Created: 2026-10-05 13:55:52

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CAPTCHA #Clickfix #Browser #Malware #OTX #CyberHunter_NL

otx.alienvault.com
0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3mo ago
Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088 A campaign exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 has been actively targeting Ukraine since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden PowerShell stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes. Pulse ID: 6a34c6344468a941c924c02c Pulse Link: https://otx.alienvault.com/pulse/6a34c6344468a941c924c02c Pulse Author: AlienVault Created: 2026-06-19 04:31:48 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #Gamaredon #InfoSec #LNK #Military #OTX #OpenThreatExchange #PowerShell #RAT #SocialEngineering #UK #Ukr #Ukraine #Ukrainian #Vulnerability #WinRAR #Windows #bot #AlienVault
LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
1
1
0
Open post
OTX Bot @techbot@social.raytec.co
· 5mo ago

Abusing OAuth Device Code Flow

In early 2026, phishing attacks remain a top threat vector in security operations. This analysis covers a novel attack method exploiting Microsoft's OAuth 2.0 Device Authorization Grant (Device Code Flow) to compromise user accounts. Attackers use phishing emails containing Mailchimp's Mandrill service links to bypass security controls, leading victims to fake Adobe-themed websites. The sites abuse legitimate Microsoft authentication mechanisms to obtain access and refresh tokens, granting persistent delegated access to critical resources like Graph API, Teams, Outlook, and SharePoint. The technique leverages shared client IDs across tenants and family of client IDs (FOCI) for lateral movement. Two variants exist: one using external phishing infrastructure with dynamic code generation, and another relying solely on fake meeting invitations containing pre-generated device codes. The attack is particularly effective as it uses legitimate Microsoft services, making detection challenging.

Pulse ID: 69e68ccac96ab3f866763f12
Pulse Link: https://otx.alienvault.com/pulse/69e68ccac96ab3f866763f12
Pulse Author: AlienVault
Created: 2026-04-20 20:30:02

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Adobe #CyberSecurity #Email #InfoSec #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #RCE #SMS #bot #AlienVault

LevelBlue Open Threat Exchange

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today

0
0
1
0
Open post
OTX Bot @techbot@social.raytec.co
· 1mo ago
BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update Indicators extracted from public reporting. Source: https://www.virtualizor.com/blog/security-incident-bgp-hijacking/ Pulse ID: 6a965ad3c05038d75e980a31 Pulse Link: https://otx.alienvault.com/pulse/6a965ad3c05038d75e980a31 Pulse Author: CyberHunter_NL Created: 2026-09-01 04:55:46 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
virtualizor.com

Security Incident – BGP Hijacking – Virtualizor

0
0
0
0
Open post
OTX Bot @techbot@social.raytec.co
· 3d ago

GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware

GlassWorm is turning developer tools into malware delivery channels, this time through extensions advertised as attractive VS Code themes. The investigated cluster spans Visual Studio Marketplace and Open VSX, showing how appearance changes can provide cover for code that runs on developer machines. The campaign first surfaced in October 2025 and has since expanded across […] The post GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware appeared first on Cyber Security News .

Pulse ID: 6ac39e5ee608657a5f263a97
Pulse Link: https://otx.alienvault.com/pulse/6ac39e5ee608657a5f263a97
Pulse Author: CyberHunter_NL
Created: 2026-10-05 12:55:58

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#SupplyChain #Malware #OTX #CyberHunter_NL

otx.alienvault.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:02:09 UTC