Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion.
Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Posts
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
🚨 Investigation & Collaboration Request
We are currently investigating malicious activity associated with the following LNK file:
1b3089a761da4a9b7a1bfb485cc857969346ce61 — Employment_Verification_Details.lnk
We observed command-and-control communications with:
🌐 work[.]officialm[.]com — VT Score: 0/91
🌐 31[.]192[.]107[.]162:443 — VT Score: 0/91
If you have observed related activity and/or possess additional intelligence, and would like to collaborate, please reach out!
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator's day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. Logs indicated more than 900 confirmed compromises...
Read the full report: https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/
Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |
We’re seeing a “Missing Font” ClickFix chain in the wild.
Flow:
1️⃣ Fake “Missing Font” prompt
2️⃣ Leads to a BSOD-style recovery screen
3️⃣ Prompts users to open Terminal/PowerShell directly (skipping the Run dialog) and execute commands
This variant leans into a more convincing multi-step user flow compared to typical ClickFix lures.
Curious if others are seeing similar activity?