Virus Bulletin
VirusBulletin@infosec.exchange
<p>Security information portal, testing and certification body.<br />Organisers of the annual Virus Bulletin conference.</p>
Posts
-
Post #4556343
Insikt Group has identified a series of BlueDelta (APT28/Fancy Bear/Forest Blizzard) initial access campaigns targeting government & diplomatic organizations in Romania, Spain & Turkey. The campaigns deliver the HOOKEDGE backdoor using diplomatic-themed lures. https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge
-
Post #4493384
Zscaler ThreatLabz provides a technical analysis of Abyssos, a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
-
Post #4493274
In collaboration with ANY.RUN, Mauro Eldritch from BCA LTD & Heiner García from NorthScan created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/
-
Post #4483530
Google GTIG shows that UNC6671 actively conducts compromises leading to data theft extortion. Telemetry and infrastructure analysis reveal that UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix & Falcon. https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/
-
Post #4483505
Genians Security Center reports on indications that the Kimsuky group built & operated local LLM environments using Ollama, GPT4All & Msty. https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm?hsCtaAttrib=379684624063
-
Post #4410736
Point Wild's LAT61 team analysed Vanta Stealer, a Python-based cross-platform infostealer targeting many apps & digital assets. A notable characteristic is its use of multiple PyArmor protection layers, combined with a PyInstaller-packaged executable. https://www.pointwild.com/threat-intelligence/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware/
-
Post #4391703
Securonix researchers analyse SMOKE#SCREEN, a multi-wave campaign where attackers use rotating social engineering lures - fake Zoom updates, document reviews, and system maintenance tools - to deliver silent ScreenConnect RMM agent installations. https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
-
Post #4362214
📣 The VB2026 programme is live! Three days. Many voices. One Seville. Explore the sessions, speakers and ideas shaping this year’s event, and start planning your VB2026 experience. 📍 Seville, Spain 📅 14–16 October 2026 View the full programme 👉 https://www.virusbulletin.com/conference/vb2026/programme/ #VB2026 #VirusBulletin #vbconference #Seville
-
Post #4350896
Microsoft details CaptiveCrunch, a Storm-2945 (Midnight Blizzard sub-cluster) campaign targeting captive portal traffic at hospitality venues, using doppelganger domains & Entra ID device-code AiTM phishing to deliver malware & steal traveller credentials. https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
-
Post #4273677
Huntress investigates 6-stage kill chain MacSync: a thin zsh loader, a server-side AppleScript stealer keeping logic behind an API-key gate, a native Mach-O RAT for hands-on access, a signed helper built to steal one TCC permission & a set of wallet-app trojans. https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering
-
Post #4273439
Bitsight's Pedro Falé uncovers the “Fuyao Enterprise”, a highly modular ad-fraud botnet operating within Android TV boxes. Its operators openly advertise their network of over 120,000 “AI digital humans". https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
-
Post #4273397
KnowBe4's Prabhakaran Ravichandhiran & Jeewan Singh Jalal look inside an OS-aware phishing kit that profiles the victim device dynamically and silently routes it into a completely different attack depending on the answer. https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
-
Post #4234680
IIJ-SECT's Bynaoki Takayam looks into three of the latest BlueShell variants observed in May 2026, primarily used in attacks by threat actors based in China. https://sect.iij.ad.jp/blog/2026/07/blueshell-variant-deployed-by-apt-group/
-
Post #4234523
Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
-
Post #4234385
Sophos analysts investigate a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems & facilitate ransomware deployment. https://www.sophos.com/en-gb/blog/chaos-in-teams-vishing
-
Post #4198892
⏰ Early Bird closes soon! Secure your place at VB2026 in Seville and save €200 on your ticket before the Early Bird rate ends on 7 August. Join 300+ cybersecurity professionals and 90+ speakers for three days of world-class talks, learning and networking. 🎟️ Don’t miss out. Book your ticket now 👉 https://tinyurl.com/2v3ywne7
-
Post #4190010
Zscaler ThreatLabz examines four GoGRPC variants from a likely initial access broker for ransomware that leverages vishing techniques through Microsoft Teams. C2 communication protocols & the additional malware tools observed are also analysed. https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
-
Post #4189726
Proofpoint reports that Indirect Prompt Injection (IDPI) is increasingly being discussed by malicious actors on closed, underground forums. Tools & services designed to leverage IDPI within attack chains are actively being developed, refined, and advertised for sale. https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection
-
Post #4160314
Ransom-ISAC examines Telegram's role in the malware ecosystem. Its Bot API gives malware authors a free, TLS-protected, globally reachable message bus, with no infrastructure to rent, no domain to burn, and no certificate to manage. https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
-
Post #4133095
JUMPSEC analysed source code from an active BlueNoroff phishing kit used to impersonate Zoom & Microsoft Teams meetings. Operators mistakenly exposed JS source maps on live infrastructure, giving researchers source-level insight into how the operation works. https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
-
Post #4133071
Gen has published its H1 2026 Threat Report: Attackers spent the first half of 2026 abusing trust that already exists - hotel workflows, messaging sessions, browser data, developer tools, AI agents, payment habits and identity signals. https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026
-
Post #4133024
Huntress analyst Michael Tigges looks into a malvertising campaign that led to a malicious Claude artifact and to the download of SectopRAT. https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat
-
Post #4132961
Through ongoing tracking of the TAG-195 MaaS ecosystem, Recorded Future Insikt Group identified four new TAG-195 (Golden Chickens, Venom Spider) malware families: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator. https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
-
Post #4132862
Trend Micro researcher Takehiro Iwai uncovered a tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. https://www.trendmicro.com/en_us/research/26/g/tech-support-scams-targeting-japan.html
-
Post #4059369
Microsoft has published its Q2 2026 email threat landscape report - notable campaigns observed demonstrated how threat actors combine automation, trusted services, and multi-stage delivery chains to scale operations. https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
-
Post #4059302
Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
-
Post #4058899
Cisco Talos has discovered a new Rust-based RAT attributed to the Chaos ransomware group. msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution & covert tunnelling for C2 communications. https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
-
Post #4058835
Seqrite's Prashil Moon looks into a multi-stage Phantom stealer malspam campaign disguised as different trusted entities including a global logistics provider and a government tax authority. https://www.seqrite.com/blog/abusing-trusted-business-workflows-a-multi-stage-phantom-stealer-campaign/
-
Post #4032724
Acronis Threat Research Unit (TRU) has identified an active Lampion malware campaign targeting Portuguese users through phishing emails masquerading as financial and administrative communications. https://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/
-
Post #4032674
Elastic researchers analyse wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). https://www.elastic.co/security-labs/wp2shell-wordpress-rce-detection-elastic-defend