Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malwa...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
17 articles found
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malwa...
CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-...
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 s...
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-a...
Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code o...
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back wit...
VulnCheck CTO Jacob Baines claims that Zbtlink routers are intentionally designed to communicate with command and control servers, a feature he calls a "phon...
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP add...
SparkKitty is a cross‑platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrati...
This TrickBot variant, detailed in research by Fortinet's FortiGuard Labs, utilizes a modular architecture but features a redesigned transport layer.
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealt...
Command and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders
During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and ...
Elastic Security Labs researchers identified a new malware family written in C++ that we refer to as SOMNIRECORD. This malware functions as a backdoor and co...