Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Virus Bulletin

@VirusBulletin@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security information portal, testing and certification body.
Organisers of the annual Virus Bulletin conference.

0 Followers
0 Following
50 Posts
Joined November 25, 2022
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Zscaler ThreatLabz examines four GoGRPC variants from a likely initial access broker for ransomware that leverages vishing techniques through Microsoft Teams. C2 communication protocols & the additional malware tools observed are also analysed. https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
1
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Ransom-ISAC examines Telegram's role in the malware ecosystem. Its Bot API gives malware authors a free, TLS-protected, globally reachable message bus, with no infrastructure to rent, no domain to burn, and no certificate to manage. https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
0
0
0
1
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
eSentire's TRU looks into a malicious ClickFix-style command that installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150. https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
LevelBlue SpiderLabs uncovers a CrySome RAT campaign that started with a spear-phishing email posing as a logistics rate confirmation document. The attack relied on familiar business workflows to persuade the victim to trigger the first stage of the infection chain. https://www.levelblue.com/blogs/spiderlabs-blog/from-phishing-to-persistence-a-crysome-rat-infection-chain-analysis
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2w ago
Gen's Martin Chlumecký & Luis Corrons look into Phantom Deal, a fake acquisition fraud campaign. Attackers posed as executives, moved conversations to WhatsApp and personal email, and forged acquisition documents to set up international wire transfers. https://www.gendigital.com/blog/insights/research/phantom-deal
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Elastic Security Labs found a new Contagious Interview campaign hiding malware inside SVG image files using steganography. Campaigns involve coding challenges & take-home assignments with benign-looking projects containing malicious backdoored code. https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Fortinet's Yurren Wan writes about a global campaign in which threat actors use disguised .ttf files and low-detection Lua loaders to deliver RATs and infostealers. https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Zscaler ThreatLabz provides a technical analysis of Abyssos, a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Google GTIG shows that UNC6671 actively conducts compromises leading to data theft extortion. Telemetry and infrastructure analysis reveal that UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix & Falcon. https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Through ongoing tracking of the TAG-195 MaaS ecosystem, Recorded Future Insikt Group identified four new TAG-195 (Golden Chickens, Venom Spider) malware families: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator. https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Bitsight's Pedro Falé uncovers the “Fuyao Enterprise”, a highly modular ad-fraud botnet operating within Android TV boxes. Its operators openly advertise their network of over 120,000 “AI digital humans". https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Cisco Talos has discovered a new Rust-based RAT attributed to the Chaos ransomware group. msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution & covert tunnelling for C2 communications. https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
In collaboration with ANY.RUN, Mauro Eldritch from BCA LTD & Heiner García from NorthScan created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
The Seqrite Threat Research Team uncover a spear-phishing campaign targeting Russian aerospace organizations with a fake invoice lure. The chain uses a password-protected archive to deploy additional payloads & configure AnyDesk for unattended remote access. https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
IIJ-SECT's Bynaoki Takayam looks into three of the latest BlueShell variants observed in May 2026, primarily used in attacks by threat actors based in China. https://sect.iij.ad.jp/blog/2026/07/blueshell-variant-deployed-by-apt-group/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Proofpoint reports that Indirect Prompt Injection (IDPI) is increasingly being discussed by malicious actors on closed, underground forums. Tools & services designed to leverage IDPI within attack chains are actively being developed, refined, and advertised for sale. https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Securonix researchers analyse SMOKE#SCREEN, a multi-wave campaign where attackers use rotating social engineering lures - fake Zoom updates, document reviews, and system maintenance tools - to deliver silent ScreenConnect RMM agent installations. https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Genians Security Center reports on indications that the Kimsuky group built & operated local LLM environments using Ollama, GPT4All & Msty. https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm?hsCtaAttrib=379684624063
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Cisco Talos researchers Alex Karkins & Chetan Raghuprasad show how UAT-11795, a Russian-speaking, financially motivated adversary targeting users in the US & Europe, uses the novel Python-based Starland RAT and a C2 memory implant known as the WLDR agent. https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
KnowBe4's Prabhakaran Ravichandhiran & Jeewan Singh Jalal look inside an OS-aware phishing kit that profiles the victim device dynamically and silently routes it into a completely different attack depending on the answer. https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
🔥 Gone in record time! Super Early Bird tickets are officially sold out, but Early Bird tickets are still up for grabs. 🎟️ Don’t wait too long. Get yours before they’re gone too 👉https://tinyurl.com/4ft265m2 #vb2026 #vbconference #cybersecurity #seville
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Microsoft researchers have observed increased ACR Stealer activity across customer environments. These campaigns are using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
360 ​​Advanced Threat Research Institute discovered and captured a new attack campaign by the OceanLotus (APT-C-00) threat group, also known as APT32. The campaign utilizes CD-ROM image files with malicious payloads attached to emails as delivery carriers. https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508745&idx=1&sn=d2e8bf3bed50b91adf218cabe5be731c&poc_token=HB3CYWqjXTJh49hdeOD1SG6NbHJcwxj3Jnf7HhuI
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Gen has published its H1 2026 Threat Report: Attackers spent the first half of 2026 abusing trust that already exists - hotel workflows, messaging sessions, browser data, developer tools, AI agents, payment habits and identity signals. https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Microsoft details CaptiveCrunch, a Storm-2945 (Midnight Blizzard sub-cluster) campaign targeting captive portal traffic at hospitality venues, using doppelganger domains & Entra ID device-code AiTM phishing to deliver malware & steal traveller credentials. https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Huntress reports a standardized 7-step playbook beginning with CitrixBleed 2 exploitation. Stolen NetScaler sessions made MFA irrelevant, while follow-on actions included AppMgmt-based privilege escalation, rogue local admins, ScreenConnect or Zoho Assist, and DragonForce ransomware. https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Huntress analyst Michael Tigges looks into a malvertising campaign that led to a malicious Claude artifact and to the download of SectopRAT. https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Sygnia analyses a 72-hour AWS intrusion where AI appears to have accelerated familiar cloud attack techniques. No zero-days or novel malware, just fast, parallel abuse of identities, CI/CD, cloud permissions, and runtime services. https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Point Wild's LAT61 team analysed Vanta Stealer, a Python-based cross-platform infostealer targeting many apps & digital assets. A notable characteristic is its use of multiple PyArmor protection layers, combined with a PyInstaller-packaged executable. https://www.pointwild.com/threat-intelligence/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Join Damien Schaeffer from ESET at VB2026 in Seville. Find out more about this talk 👉https://tinyurl.com/s38swkcx 🎟️ Early Bird tickets are now available. Get yours here 👉 https://tinyurl.com/kd8hbudw
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
WatchGuard's Euler Neto & Cristóbal Tárraga look into a campaign associated with TimbreStealer, which is known to target companies based in Mexico. https://www.watchguard.com/wgrd-security-hub/secplicity-blog/timbrestealer-malware-targets-mexico-companies-advanced-evasion
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Acronis Threat Research Unit (TRU) has identified an active Lampion malware campaign targeting Portuguese users through phishing emails masquerading as financial and administrative communications. https://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Leveraging Landlock telemetry for Linux detection engineering Join Guillaume Couchard and Erwan Chevalier from Sekoia at VB2026 in Seville to explore a previously unseen approach to detection engineering, using Landlock’s logging capabilities beyond its original role as a Linux sandboxing mechanism. 📅 Oct 15 | 09:30-10:00 | Green Room Find out more about this talk 👉 https://tinyurl.com/52jvwh3m
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
JUMPSEC analysed source code from an active BlueNoroff phishing kit used to impersonate Zoom & Microsoft Teams meetings. Operators mistakenly exposed JS source maps on live infrastructure, giving researchers source-level insight into how the operation works. https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Unit 42 reports a financially motivated campaign delivering Vidar stealer and XMRig to consumers and SMBs worldwide. Victims are lured through malvertising to fake cracked-software downloads, where the loader drops both credential theft and Monero mining payloads. https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
Proofpoint looks at Cruciferra’s functionalities and observed real-world use. Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal threat clusters and delivers a wide range of remote access trojans and infostealers. https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 3w ago
Insikt Group has identified a series of BlueDelta (APT28/Fancy Bear/Forest Blizzard) initial access campaigns targeting government & diplomatic organizations in Romania, Spain & Turkey. The campaigns deliver the HOOKEDGE backdoor using diplomatic-themed lures. https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
SOCRadar STRU analyses the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency & Web3 professionals with fake job interviews, delivering the PylangGhost RAT on Windows & the GolangGhost RAT on macOS. https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Trend Micro researcher Takehiro Iwai uncovered a tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. https://www.trendmicro.com/en_us/research/26/g/tech-support-scams-targeting-japan.html
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Sophos analysts investigate a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems & facilitate ransomware deployment. https://www.sophos.com/en-gb/blog/chaos-in-teams-vishing
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
VMRay Labs identified a campaign conducted by a Russian-speaking threat group, tracked as Operation STANDOFF, which combines two layers: a mass-access with a pay-per-install loader & a multi-operator console for human-operated hands-on-keyboard intrusion. https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Seqrite's Prashil Moon looks into a multi-stage Phantom stealer malspam campaign disguised as different trusted entities including a global logistics provider and a government tax authority. https://www.seqrite.com/blog/abusing-trusted-business-workflows-a-multi-stage-phantom-stealer-campaign/
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Elastic researchers analyse wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). https://www.elastic.co/security-labs/wp2shell-wordpress-rce-detection-elastic-defend
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 2mo ago
LevelBlue Managed Threat Research investigates a multi-stage LNK attack where a malicious ZIP triggers hidden PowerShell, downloads a legitimate node.exe, and deploys a Node.js backdoor. The malware uses EtherHiding via the TON blockchain to retrieve its C2 address. https://www.levelblue.com/blogs/spiderlabs-blog/hiding-in-the-chain-multi-stage-lnk-attack-leveraging-ton-blockchain-to-deliver-node.js-backdoor
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Huntress investigates 6-stage kill chain MacSync: a thin zsh loader, a server-side AppleScript stealer keeping logic behind an API-key gate, a native Mach-O RAT for hands-on access, a signed helper built to steal one TCC permission & a set of wallet-app trojans. https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Microsoft has published its Q2 2026 email threat landscape report - notable campaigns observed demonstrated how threat actors combine automation, trusted services, and multi-stage delivery chains to scale operations. https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
0
1
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
⏰ Early Bird closes soon! Secure your place at VB2026 in Seville and save €200 on your ticket before the Early Bird rate ends on 7 August. Join 300+ cybersecurity professionals and 90+ speakers for three days of world-class talks, learning and networking. 🎟️ Don’t miss out. Book your ticket now 👉 https://tinyurl.com/2v3ywne7
0
0
0
0
Open post
Virus Bulletin @VirusBulletin@infosec.exchange
· 1mo ago
Infoblox's Darby Wise & Nick Sundvall look inside an adversary-in-the-middle phishing (AiTM) campaign targeting universities, enterprises, and multinational institutions, including European Union & United Nations agencies. https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 15:48:54 UTC