Threat Actors Exploit Government Website Vulnerabilities For Phishing Attacks post, januari 30, 2025februari 24, 2025 A recent report by Cofense Intelligence shows that how attackers are weaponizing .gov top-level domains (TLDs) across multiple countries for malicious purposes, including credential phishing, malware delivery, and command-and-control (C2) operations. Continue Reading
ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms post, december 11, 2024februari 24, 2025 Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after resurfacing a year ago. “Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and… Continue Reading
Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town post, september 23, 2024februari 24, 2025 Attackers are using Splinter, a new post-exploitation tool, to wreak havoc in victims’ IT environments after initial infiltration, utilizing capabilities such as executing Windows commands, stealing files, collecting cloud service account info, and downloading additional malware onto victims’ systems. Then the malicious code self-deletes, according to Palo Alto Networks’ Unit… Continue Reading
Aanvallers tonen inventiviteit in DuneQuixote post, mei 2, 2024februari 24, 2025 De afgelopen maand ontdekte DuneQuixote malware campaign laat eens te meer zien hoe inventief aanvallers zijn. DuneQuixote maakt gebruik van twee verschillende ‘droppers’ en twee verschillende ‘payloads’. De dropper wordt gebruik voor de initiele toegang en zet de communicatie met de command&control infrastructuur op. De aanvallers gebruiken delen van Spaanse… Continue Reading