Prinz Eugen Ransomware Uses RemotePC RMM and PowerShell Stagers to Evade Detection
A new ransomware group is deploying the Go-based Prinz Eugen ransomware by abusing legitimate remote management software (RemotePC) and PowerShell stagers. The campaign has already hit major financial...
SmartApeSG Campaign Exploits ClickFix Fake Verification Pages to Deliver NetSupport RAT
The SmartApeSG campaign is using ClickFix scripts disguised as fake browser verification pages to deploy a two-stage infection chain, culminating in a persistent NetSupport Manager RAT installation on...
ClickFix Evolves: Attackers Combine Social Engineering With Decade-Old PySoxy SOCKS5 Proxy for Persistent Access
A new ClickFix campaign observed by ReliaQuest pairs the social engineering technique with PySoxy, a 10-year-old Python SOCKS5 proxy, creating a two-channel persistent access chain that continues operating...
Operation SilentCanvas: Hackers Hide PowerShell Malware in Fake JPEG to Deploy Trojanized ScreenConnect Backdoor
Operation SilentCanvas is a new Windows attack campaign that hides a PowerShell script inside a fake JPEG file to deploy a trojanized ScreenConnect backdoor. The multi-stage infection chain...
Qilin Ransomware Adopts Stealthy RDP History Enumeration to Map Victim Networks
The Qilin ransomware group, responsible for over 700 attacks in 2025, has been observed using a stealthy PowerShell technique to enumerate RDP authentication history on compromised servers —...
BlueNoroff Deploys AI Deepfake Zoom Lures and Fileless PowerShell to Drain Crypto Wallets Across 20+ Countries
North Korea's BlueNoroff subgroup has launched a sophisticated global campaign targeting cryptocurrency and Web3 executives, using AI-generated deepfake Zoom meetings, ClickFix clipboard injection, and fileless PowerShell implants that...
ToddyCat’s new tricks: email hacking evolves with the cloud
The age-old adage “if it ain’t broke, don’t fix it” doesn’t always hold true in cybersecurity. As attackers are increasingly leveraging cloud services to protect sensitive data, their...
Increasing phishing threats targeting Microsoft OneDrive users
In an emerging and sophisticated phishing campaign identified by the Trellix Advanced Research Center, Microsoft OneDrive users are facing a new wave of cyber threats. This campaign employs...