North Korean Hackers Hide ‘Ted’ Backdoor Inside Trojanized HAProxy to Spy on South Korean Firms
Rapid7 researchers have uncovered a DPRK-linked Linux intrusion toolkit — built around a modified HAProxy binary dubbed Ted and a companion remote access tool called CurlRAT — that...
Fake ‘Lithium’ Minecraft Optimization Mod Hides Myth Stealer RAT Behind 12 Working Features
A trojanized Minecraft performance mod posing as the popular Lithium optimization project is quietly installing Myth Stealer, an information-stealing remote access tool that harvests browser credentials, session cookies,...
North Korea-Linked Hackers Hide OtterCookie Malware Inside 14 Fake Mac Apps
Researchers have identified fourteen trojanized macOS installers impersonating popular utilities like The Unarchiver and Sketch, all delivering the OtterCookie credential-stealing malware. The campaign, tied to North Korea's long-running...
Over 14,000 Dahua Cameras Compromised With Backdoors That Survive Factory Resets
Researchers at Hunt.io say a 35-day campaign compromised more than 14,000 internet-connected Dahua cameras, planting hidden administrator accounts and abusing cloud recovery codes that persist even through password...
Toy Ghouls Hide New Windows Backdoors Behind MQTT and Matrix Traffic
The Toy Ghouls group has deployed two custom Windows backdoors that use MQTT and Matrix-based services for command traffic. The malware adds durable remote control to compromises previously...
Rogue ScreenConnect Clients Turn Remote Support Sessions Into a Worm-Like Infection Chain
Attackers are abusing unauthorized ScreenConnect installations to push staged malware into newly connected Windows systems. The campaign begins with social engineering, then uses trusted remote-support functions for persistence,...
Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign
A Silver Fox-linked campaign is distributing counterfeit installers for brands like Razer, Microsoft Edge, and Kaspersky that use SYSTEM-level scheduled tasks to strip Microsoft Defender protections and delete...
ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor
A ValleyRAT campaign is disguising its infection chain as adware and familiar software installers, with most observed victims in China and India. The backdoor uses DLL sideloading and...