Virus Bulletin
@virusbtn
Security information portal, testing and certification body. Organisers of the annual Virus Bulletin conference.
Rapid7's Anna Širokova & Jan Recinsky look inside an exposed WebDAV malware delivery lab containing over 1000 artifacts. The infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. www.rapid7.com/blog/post/tr...
ENKI researchers look into a recent Kimsuky campaign that targeted South Korean groupware vendors from 2025 through to early 2026. They identified two new malware strains based on Gomir/HttpTroy, tracked as BirdTroy & DriveTroy. www.enki.co.kr/en/media-cen...
VMRay Labs identified a campaign conducted by a Russian-speaking threat group, tracked as Operation STANDOFF, which combines two layers: a mass-access with a pay-per-install loader & a multi-operator console for human-operated hands-on-keyboard intrusion. www.vmray.com/execution-le...
Join Damien Schaeffer from @esetofficial.bsky.social at #VB2026 in Seville. Find out more about this talk 👉 tinyurl.com/s38swkcx 🎟️ Early Bird tickets are now available. Get yours here 👉 tinyurl.com/3654rk29 #VirusBulletin #vbconference #cybersecurity
SOCRadar STRU analyses the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency & Web3 professionals with fake job interviews, delivering the PylangGhost RAT on Windows & the GolangGhost RAT on macOS. socradar.io/blog/dprk-cl...
Microsoft researchers have observed increased ACR Stealer activity across customer environments. These campaigns are using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. www.microsoft.com/en-us/securi...
Proofpoint looks at Cruciferra’s functionalities and observed real-world use. Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal threat clusters and delivers a wide range of remote access trojans and infostealers. www.proofpoint.com/us/blog/thre...
Zscaler ThreatLabz explores the technical details of the multi-stage attack chain targeting government entities in the Middle East, focusing on TELESHIM, MIXEDKEY, and the post-compromise activity observed during the campaign. www.zscaler.com/blogs/securi...
Fortinet's Yurren Wan writes about a global campaign in which threat actors use disguised .ttf files and low-detection Lua loaders to deliver RATs and infostealers. www.fortinet.com/blog/threat-...
Cisco Talos researchers Alex Karkins & Chetan Raghuprasad show how UAT-11795, a Russian-speaking, financially motivated adversary targeting users in the US & Europe, uses the novel Python-based Starland RAT and a C2 memory implant known as the WLDR agent. blog.talosintelligence.com/uat-11795-de...
Elastic Security Labs found a new Contagious Interview campaign hiding malware inside SVG image files using steganography. Campaigns involve coding challenges & take-home assignments with benign-looking projects containing malicious backdoored code. www.elastic.co/security-lab...
eSentire's TRU looks into a malicious ClickFix-style command that installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150. www.esentire.com/blog/dindoor...
Join Asher Davila, Chris Navarrete & Doel Santos from Palo Alto Networks at #VB2026 in Seville. Find out more about this talk 👉 tinyurl.com/3kc7ttzh 🎟️ Early Bird tickets are now available. Get yours here 👉 tinyurl.com/t7j9hwcn #VirusBulletin #vbconference #cybersecurity
🔥 Gone in record time! Super Early Bird tickets are officially sold out, but Early Bird tickets are still up for grabs. 🎟️ Don’t wait too long. Get yours before they’re gone too 👉https://tinyurl.com/2w2z8fr2 #vb2026 #vbconference #cybersecurity #seville
🎟️ The Super Early Bird has officially landed in Seville! 📅 When: 14-16 October 2026 📍 Where: Barceló Sevilla Renacimiento, Seville Secure your ticket now and get the best price before they're gone. 👉🏻 tinyurl.com/ynphph23 #vb2026 #vbconference #cybersecurity #seville
Symantec Threat Hunter Team reports GodDamn as the latest rebrand of Beast ransomware, itself a rebrand of Monster from the Hyadina developers. Operators used AnyDesk, NirSoft credential tools, and the Microsoft-signed PoisonX driver to disable endpoint defences. www.security.com/threat-intel...
Hybrid Analysis reports fake cryptocurrency wallets distributed as oversized Advanced Installer packages. The campaign impersonates wallets (Anchor, Zec, Iota, Onto, Dark, Stellar) using search-ranked attacker domains & valid code-signing certificates hybrid-analysis.blogspot.com/2026/07/susp...
Huntress reports a 7-step playbook beginning with CitrixBleed 2 exploitation. Stolen NetScaler sessions made MFA irrelevant; follow-on actions included AppMgmt-based privilege escalation, rogue local admins, ScreenConnect or Zoho Assist, & DragonForce ransomware. www.huntress.com/blog/citrixb...
LevelBlue Managed Threat Research investigates a multi-stage LNK attack where a malicious ZIP triggers hidden PowerShell, downloads a legitimate node.exe, and deploys a Node.js backdoor. The malware uses EtherHiding via the TON blockchain to retrieve its C2 address. www.levelblue.com/blogs/spider...
Huntress analyses an incident in which a threat actor used a vibe-coded PowerShell script for Active Directory enumeration. The script looked for the Domain Controller, mapped users, computers & domains, exported the results, and generated an AD_Report.html summary. www.huntress.com/blog/ai-code...
Sygnia analyses a 72-hour AWS intrusion where AI appears to have accelerated familiar cloud attack techniques. No zero-days or novel malware, just fast, parallel abuse of identities, CI/CD, cloud permissions, and runtime services. www.sygnia.co/blog/inside-...
Join Guillaume Couchard and Erwan Chevalier from Sekoia at VB2026 in Seville to explore a previously unseen approach to detection engineering, using Landlock’s logging capabilities beyond its original role as a Linux sandboxing mechanism. Find out more about this talk 👉 tinyurl.com/52jvwh3m
Unit 42 reports a financially motivated campaign delivering Vidar stealer & XMRig to consumers & SMBs worldwide. Victims are lured through malvertising to fake cracked-software downloads, where the loader drops credential theft & Monero mining payloads. unit42.paloaltonetworks.com/vidar-steale...
Elastic Security Labs analyses REF6045, a Mexican banking-fraud operation that adapts ClickFix delivery into operator-assisted fraud. The SCMBANKER PowerShell toolkit monitors banking sessions, captures screenshots, manipulates clipboards & can install Remote Utilities www.elastic.co/security-lab...
Proofpoint Threat Research Team tracks UNK_MassTraction, a suspected China-aligned cluster exploiting Roundcube mailservers at N. American university physics & engineering departments. The chain steals credentials then installs a webshell or loads VShell in memory. www.proofpoint.com/us/blog/thre...
Zimperium zLabs uncovers RedWing, a new Android spyware offered as MaaS through Telegram and distributed via mobile phishing sites, supporting SMS, contact, call log & file theft, VNC screen streaming, remote screen locking, banking & crypto overlays & DDoS capability. zimperium.com/blog/redwing...
Qianxin Threat Intelligence Center analyses MODBEACON, a highly modular Rust trojan delivered by a Ghost distributor to selected targets across technology, education, and state-owned enterprises. ti.qianxin.com/blog/article...
LevelBlue SpiderLabs uncovers a CrySome RAT campaign that started with a spear-phishing email posing as a logistics rate confirmation document. The attack relied on familiar business workflows to persuade the victim to trigger the first stage of the infection chain. www.levelblue.com/blogs/spider...
The Seqrite Threat Research Team uncover a spear-phishing campaign targeting Russian aerospace organizations with a fake invoice lure. The chain uses a password-protected archive to deploy additional payloads & configure AnyDesk for unattended remote access. www.seqrite.com/blog/from-in...
K7's Azhagan KMS looks at a technique known as a boss scam - a modern variation of business email compromise (BEC) or CEO fraud. Researchers analysed boss scam campaigns that target and compromise WhatsApp Web sessions belonging to business leaders. labs.k7computing.com/index.php/bo...