mastodon.gamedev.place is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server focused on game development and related topics.

Server stats:

5.1K
active users

#trojan

2 posts2 participants0 posts today
Center of the Universe<p>Free event in one week - Pumpegris is playing live as well! <a href="https://mastodon.social/tags/folkmusic" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>folkmusic</span></a> <a href="https://mastodon.social/tags/norway" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>norway</span></a> <a href="https://mastodon.social/tags/trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojan</span></a></p>
OTX Bot<p>Weaponized Words: Uyghur Language Software Hijacked to Deliver Malware</p><p>This analysis details a spearphishing campaign targeting senior members of the World Uyghur Congress (WUC) in March 2025. The attackers used a trojanized version of a legitimate Uyghur language text editor to deliver Windows-based malware for remote surveillance. While not technically advanced, the malware delivery was well-customized to reach the Uyghur community. This incident is part of a broader pattern of digital transnational repression against Uyghur diaspora by actors likely aligned with the Chinese government. The malware profiled systems, sent information to remote servers, and could load additional malicious plugins. The campaign demonstrates the ongoing digital threats facing exiled Uyghur communities and the exploitation of software meant to support marginalized cultures.</p><p>Pulse ID: 680f07377e6aaa99a9dafcc4<br>Pulse Link: <a href="https://otx.alienvault.com/pulse/680f07377e6aaa99a9dafcc4" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">otx.alienvault.com/pulse/680f0</span><span class="invisible">7377e6aaa99a9dafcc4</span></a> <br>Pulse Author: AlienVault<br>Created: 2025-04-28 04:42:31</p><p>Be advised, this data is unverified and should be considered preliminary. Always do further verification.</p><p><a href="https://social.raytec.co/tags/Chinese" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Chinese</span></a> <a href="https://social.raytec.co/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://social.raytec.co/tags/Government" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Government</span></a> <a href="https://social.raytec.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://social.raytec.co/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.raytec.co/tags/OTX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OTX</span></a> <a href="https://social.raytec.co/tags/OpenThreatExchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenThreatExchange</span></a> <a href="https://social.raytec.co/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> <a href="https://social.raytec.co/tags/RAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RAT</span></a> <a href="https://social.raytec.co/tags/SpearPhishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SpearPhishing</span></a> <a href="https://social.raytec.co/tags/TextEditor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TextEditor</span></a> <a href="https://social.raytec.co/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> <a href="https://social.raytec.co/tags/Windows" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Windows</span></a> <a href="https://social.raytec.co/tags/Word" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Word</span></a> <a href="https://social.raytec.co/tags/bot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bot</span></a> <a href="https://social.raytec.co/tags/AlienVault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlienVault</span></a></p>
PrivacyDigest<p>New <a href="https://mas.to/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://mas.to/tags/spyware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>spyware</span></a> is targeting <a href="https://mas.to/tags/Russian" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Russian</span></a> <a href="https://mas.to/tags/military" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>military</span></a> personnel on the front lines - Ars Technica</p><p><a href="https://mas.to/tags/Trojanized" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojanized</span></a> <a href="https://mas.to/tags/mapping" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mapping</span></a> app steals users' <a href="https://mas.to/tags/locations" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>locations</span></a> , <a href="https://mas.to/tags/contacts" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>contacts</span></a> , and more.<br><a href="https://mas.to/tags/trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojan</span></a> <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mas.to/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://mas.to/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> <a href="https://mas.to/tags/russia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>russia</span></a> </p><p><a href="https://arstechnica.com/security/2025/04/russian-military-personnel-on-the-front-lines-targeted-with-new-android-spyware/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/security/2025/</span><span class="invisible">04/russian-military-personnel-on-the-front-lines-targeted-with-new-android-spyware/</span></a></p>
Antinous the Gay God<p>🪷 On 24 April 1184 BC Greeks sacked <a href="https://social.anoxinon.de/tags/Troy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Troy</span></a> by sneaking through the gates inside the <a href="https://social.anoxinon.de/tags/TrojanHorse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TrojanHorse</span></a>. <a href="https://social.anoxinon.de/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> warrior by gay illustrator J.C. <a href="https://social.anoxinon.de/tags/Leyendecker" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Leyendecker</span></a>, saint of <a href="https://social.anoxinon.de/tags/Antinous" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Antinous</span></a>. 🪷</p>
OTX Bot<p>Newly Registered Domains Distributing SpyNote Malware</p><p>Cybercriminals are employing deceptive websites on newly registered domains to distribute AndroidOS SpyNote malware. These sites imitate the Google Chrome install page on the Google Play Store, tricking users into downloading SpyNote, a powerful Android remote access trojan. SpyNote is used for surveillance, data exfiltration, and remote control of infected devices. The investigation uncovered multiple domains, IP addresses, and APK files associated with this campaign. The malware utilizes various C2 endpoints for communication and data exfiltration, with functions designed to retrieve and manipulate device information, contacts, SMS, and applications.</p><p>Pulse ID: 67feb504b76dd387be73309b<br>Pulse Link: <a href="https://otx.alienvault.com/pulse/67feb504b76dd387be73309b" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">otx.alienvault.com/pulse/67feb</span><span class="invisible">504b76dd387be73309b</span></a> <br>Pulse Author: AlienVault<br>Created: 2025-04-15 19:35:32</p><p>Be advised, this data is unverified and should be considered preliminary. Always do further verification.</p><p><a href="https://social.raytec.co/tags/APK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APK</span></a> <a href="https://social.raytec.co/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://social.raytec.co/tags/Chrome" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Chrome</span></a> <a href="https://social.raytec.co/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://social.raytec.co/tags/DoS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DoS</span></a> <a href="https://social.raytec.co/tags/Endpoint" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Endpoint</span></a> <a href="https://social.raytec.co/tags/Google" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Google</span></a> <a href="https://social.raytec.co/tags/GooglePlay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GooglePlay</span></a> <a href="https://social.raytec.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://social.raytec.co/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.raytec.co/tags/OTX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OTX</span></a> <a href="https://social.raytec.co/tags/OpenThreatExchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenThreatExchange</span></a> <a href="https://social.raytec.co/tags/RAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RAT</span></a> <a href="https://social.raytec.co/tags/RemoteAccessTrojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RemoteAccessTrojan</span></a> <a href="https://social.raytec.co/tags/SMS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SMS</span></a> <a href="https://social.raytec.co/tags/SpyNote" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SpyNote</span></a> <a href="https://social.raytec.co/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> <a href="https://social.raytec.co/tags/bot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bot</span></a> <a href="https://social.raytec.co/tags/AlienVault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlienVault</span></a></p>
World Concert Hall<p>Right now, <a href="https://mastodon.world/tags/Mozart" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mozart</span></a> <a href="https://mastodon.world/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> with Sidorova, de Hartmann and <a href="https://mastodon.world/tags/Tchaikovsky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tchaikovsky</span></a> from <a href="https://mastodon.world/tags/Poole" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Poole</span></a> <a href="https://www.worldconcerthall.com/en/schedule/mozart_trojan_with_sidorova_de_hartmann_and_tchaikovsky_from_poole/86872/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">worldconcerthall.com/en/schedu</span><span class="invisible">le/mozart_trojan_with_sidorova_de_hartmann_and_tchaikovsky_from_poole/86872/</span></a> <a href="https://mastodon.world/tags/wch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wch</span></a></p>
World Concert Hall<p>In 15 minutes, <a href="https://mastodon.world/tags/Mozart" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mozart</span></a> <a href="https://mastodon.world/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> with Sidorova, de Hartmann and <a href="https://mastodon.world/tags/Tchaikovsky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tchaikovsky</span></a> from <a href="https://mastodon.world/tags/Poole" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Poole</span></a> <a href="https://www.worldconcerthall.com/en/schedule/mozart_trojan_with_sidorova_de_hartmann_and_tchaikovsky_from_poole/86872/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">worldconcerthall.com/en/schedu</span><span class="invisible">le/mozart_trojan_with_sidorova_de_hartmann_and_tchaikovsky_from_poole/86872/</span></a> <a href="https://mastodon.world/tags/wch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wch</span></a></p>
Oliver BleesV I N Y L O V E<br> <a href="https://pixelfed.social/discover/tags/buyvinyls?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#buyvinyls</a> <a href="https://pixelfed.social/discover/tags/vinyl?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#vinyl</a> <a href="https://pixelfed.social/discover/tags/vinylgram?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#vinylgram</a> <a href="https://pixelfed.social/discover/tags/reggae?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#reggae</a> <a href="https://pixelfed.social/discover/tags/trojan?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#trojan</a> <a href="https://pixelfed.social/discover/tags/rocksteady?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#rocksteady</a> <a href="https://pixelfed.social/discover/tags/bluebeat?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#bluebeat</a> <a href="https://pixelfed.social/discover/tags/mrnrnw?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#mrnrnw</a> <a href="https://pixelfed.social/discover/tags/makerockandrollnotwar?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#makerockandrollnotwar</a> <a href="https://pixelfed.social/discover/tags/makeskaandsoulnotwar?src=hash" class="u-url hashtag" rel="nofollow noopener noreferrer" target="_blank">#makeskaandsoulnotwar</a>
World Concert Hall<p>Today, <a href="https://mastodon.world/tags/Mozart" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mozart</span></a> <a href="https://mastodon.world/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> with Sidorova, de Hartmann and <a href="https://mastodon.world/tags/Tchaikovsky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tchaikovsky</span></a> from <a href="https://mastodon.world/tags/Poole" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Poole</span></a> <a href="https://www.worldconcerthall.com/en/schedule/mozart_trojan_with_sidorova_de_hartmann_and_tchaikovsky_from_poole/86872/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">worldconcerthall.com/en/schedu</span><span class="invisible">le/mozart_trojan_with_sidorova_de_hartmann_and_tchaikovsky_from_poole/86872/</span></a> <a href="https://mastodon.world/tags/wch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wch</span></a></p>
OTX Bot<p>Newly Registered Domains Distributing SpyNote Malware</p><p>Deceptive websites hosted on newly registered domains are being used to deliver AndroidOS SpyNote malware, mimicking the Google Chrome install page on the Google Play Store. The campaign utilizes a mix of English and Chinese-language delivery sites, with Chinese-language comments in the code. The malware is distributed through a two-stage installation process, using an APK dropper to deploy the core SpyNote RAT. SpyNote is a potent Android remote access trojan capable of extensive surveillance, data exfiltration, and remote control. It aggressively requests numerous intrusive permissions, allowing for theft of sensitive data and significant remote access capabilities. The malware's keylogging functionality and ability to manipulate calls, activate cameras and microphones, and remotely wipe data make it a formidable tool for espionage and cybercrime.</p><p>Pulse ID: 67f80a4aa4c9d5d796071af6<br>Pulse Link: <a href="https://otx.alienvault.com/pulse/67f80a4aa4c9d5d796071af6" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">otx.alienvault.com/pulse/67f80</span><span class="invisible">a4aa4c9d5d796071af6</span></a> <br>Pulse Author: AlienVault<br>Created: 2025-04-10 18:13:30</p><p>Be advised, this data is unverified and should be considered preliminary. Always do further verification.</p><p><a href="https://social.raytec.co/tags/APK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APK</span></a> <a href="https://social.raytec.co/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://social.raytec.co/tags/Chinese" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Chinese</span></a> <a href="https://social.raytec.co/tags/Chrome" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Chrome</span></a> <a href="https://social.raytec.co/tags/CyberCrime" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberCrime</span></a> <a href="https://social.raytec.co/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://social.raytec.co/tags/DoS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DoS</span></a> <a href="https://social.raytec.co/tags/Espionage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Espionage</span></a> <a href="https://social.raytec.co/tags/Google" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Google</span></a> <a href="https://social.raytec.co/tags/GooglePlay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GooglePlay</span></a> <a href="https://social.raytec.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://social.raytec.co/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.raytec.co/tags/Mimic" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mimic</span></a> <a href="https://social.raytec.co/tags/OTX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OTX</span></a> <a href="https://social.raytec.co/tags/OpenThreatExchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenThreatExchange</span></a> <a href="https://social.raytec.co/tags/RAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RAT</span></a> <a href="https://social.raytec.co/tags/RemoteAccessTrojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RemoteAccessTrojan</span></a> <a href="https://social.raytec.co/tags/SpyNote" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SpyNote</span></a> <a href="https://social.raytec.co/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> <a href="https://social.raytec.co/tags/bot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bot</span></a> <a href="https://social.raytec.co/tags/AlienVault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlienVault</span></a></p>
Muffin<p><a href="https://yiff.life/tags/corruption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>corruption</span></a> <a href="https://yiff.life/tags/tf" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tf</span></a> <a href="https://yiff.life/tags/transformation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>transformation</span></a> <a href="https://yiff.life/tags/furryNSFW" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>furryNSFW</span></a> <a href="https://yiff.life/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> <a href="https://yiff.life/tags/virus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>virus</span></a> <a href="https://yiff.life/tags/trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojan</span></a> <a href="https://yiff.life/tags/mobile" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mobile</span></a> <a href="https://yiff.life/tags/phone" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phone</span></a></p>
Pyrzout :vm:<p>Grandoreiro Strikes Again: Geofenced Phishing Attacks Target LATAM <a href="https://hackread.com/grandoreiro-strikes-geofenced-phishing-attacks-latam/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hackread.com/grandoreiro-strik</span><span class="invisible">es-geofenced-phishing-attacks-latam/</span></a> <a href="https://social.skynetcloud.site/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/PhishingScam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhishingScam</span></a> <a href="https://social.skynetcloud.site/tags/CyberAttack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAttack</span></a> <a href="https://social.skynetcloud.site/tags/Grandoreiro" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Grandoreiro</span></a> <a href="https://social.skynetcloud.site/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.skynetcloud.site/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> <a href="https://social.skynetcloud.site/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://social.skynetcloud.site/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.skynetcloud.site/tags/TROJAN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TROJAN</span></a> <a href="https://social.skynetcloud.site/tags/LATAM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LATAM</span></a> <a href="https://social.skynetcloud.site/tags/Scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scam</span></a></p>
OTX Bot<p>Deobfuscating APT28's HTA Trojan: A Deep Dive into VBE Techniques &amp; Multi-Layer Obfuscation</p><p>This analysis delves into APT28's cyber espionage campaign targeting Central Asia and Kazakhstan diplomatic relations, focusing on their HTA Trojan. The malware employs advanced obfuscation techniques, including VBE (VBScript Encoded) and multi-layer obfuscation. The investigation uses x32dbg debugging to decode the obfuscated code, revealing a custom map algorithm for character deobfuscation. The process involves decoding strings using embedded characters from Windows vbscript.dll. The analysis identifies the use of Microsoft's Windows Script Encoder (screnc.exe) to create VBE files. By employing various deobfuscation techniques, including a Python script, the final malware sample is extracted and analyzed, showcasing APT28's evolving tactics in cyber espionage.</p><p>Pulse ID: 67efc6e712b49d46c1423ca9<br>Pulse Link: <a href="https://otx.alienvault.com/pulse/67efc6e712b49d46c1423ca9" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">otx.alienvault.com/pulse/67efc</span><span class="invisible">6e712b49d46c1423ca9</span></a> <br>Pulse Author: AlienVault<br>Created: 2025-04-04 11:47:51</p><p>Be advised, this data is unverified and should be considered preliminary. Always do further verification.</p><p><a href="https://social.raytec.co/tags/APT28" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APT28</span></a> <a href="https://social.raytec.co/tags/Asia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Asia</span></a> <a href="https://social.raytec.co/tags/CentralAsia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CentralAsia</span></a> <a href="https://social.raytec.co/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://social.raytec.co/tags/Espionage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Espionage</span></a> <a href="https://social.raytec.co/tags/ICS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ICS</span></a> <a href="https://social.raytec.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://social.raytec.co/tags/Kazakhstan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kazakhstan</span></a> <a href="https://social.raytec.co/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.raytec.co/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> <a href="https://social.raytec.co/tags/OTX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OTX</span></a> <a href="https://social.raytec.co/tags/OpenThreatExchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenThreatExchange</span></a> <a href="https://social.raytec.co/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> <a href="https://social.raytec.co/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> <a href="https://social.raytec.co/tags/VBS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VBS</span></a> <a href="https://social.raytec.co/tags/Windows" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Windows</span></a> <a href="https://social.raytec.co/tags/bot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bot</span></a> <a href="https://social.raytec.co/tags/AlienVault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlienVault</span></a></p>
securityaffairs<p>Experts warn of the new sophisticate <a href="https://infosec.exchange/tags/Crocodilus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Crocodilus</span></a> <a href="https://infosec.exchange/tags/mobile" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mobile</span></a> <a href="https://infosec.exchange/tags/banking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>banking</span></a> <a href="https://infosec.exchange/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a><br><a href="https://securityaffairs.com/175976/malware/new-sophisticate-crocodilus-mobile-banking-trojan.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">securityaffairs.com/175976/mal</span><span class="invisible">ware/new-sophisticate-crocodilus-mobile-banking-trojan.html</span></a><br><a href="https://infosec.exchange/tags/securityaffairs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securityaffairs</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a></p>
securityaffairs<p>Crooks are reviving the <a href="https://infosec.exchange/tags/Grandoreiro" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Grandoreiro</span></a> <a href="https://infosec.exchange/tags/banking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>banking</span></a> <a href="https://infosec.exchange/tags/trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojan</span></a><br><a href="https://securityaffairs.com/175964/malware/crooks-are-reviving-the-grandoreiro-banking-trojan.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">securityaffairs.com/175964/mal</span><span class="invisible">ware/crooks-are-reviving-the-grandoreiro-banking-trojan.html</span></a><br><a href="https://infosec.exchange/tags/securityaffairs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securityaffairs</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a></p>
Cybernews<p>Russians are once again ramping up their efforts to snoop on Ukrainian soldiers.</p><p><a href="https://infosec.exchange/tags/trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojan</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/Ukraine" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ukraine</span></a> <a href="https://infosec.exchange/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a> <a href="https://infosec.exchange/tags/Russia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Russia</span></a> </p><p><a href="https://cnews.link/dark-crystal-trojan-ukrainians-signal-1/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">cnews.link/dark-crystal-trojan</span><span class="invisible">-ukrainians-signal-1/</span></a></p>
OTX Bot<p>File Hashes Analysis with Power BI from Data Stored in DShield SIEM</p><p>This analysis showcases the use of Power BI to examine file hash data from a DShield SIEM over a 60-day period. The process involved exporting data from Elastic Discover, importing it into Power BI, and creating visualizations for analysis. Key findings include the identification of an IP address (87.120.113.231) associated with RedTail malware, uploading six different files with multiple hashes. The analysis also revealed the reappearance of a previously identified Linux Trojan (Xorddos) from new IP addresses within the same subnet. Additionally, two strange filenames were discovered and investigated, with one identified as an IRCBot through VirusTotal. This method of large dataset analysis proves valuable in uncovering potentially overlooked or lost data through retrospective examination.</p><p>Pulse ID: 67d2a955c677b493cb1eaa8f<br>Pulse Link: <a href="https://otx.alienvault.com/pulse/67d2a955c677b493cb1eaa8f" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">otx.alienvault.com/pulse/67d2a</span><span class="invisible">955c677b493cb1eaa8f</span></a> <br>Pulse Author: AlienVault<br>Created: 2025-03-13 09:45:57</p><p>Be advised, this data is unverified and should be considered preliminary. Always do further verification.</p><p><a href="https://social.raytec.co/tags/0Day" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>0Day</span></a> <a href="https://social.raytec.co/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://social.raytec.co/tags/DDoS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DDoS</span></a> <a href="https://social.raytec.co/tags/DShield" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DShield</span></a> <a href="https://social.raytec.co/tags/DoS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DoS</span></a> <a href="https://social.raytec.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://social.raytec.co/tags/LUA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LUA</span></a> <a href="https://social.raytec.co/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://social.raytec.co/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.raytec.co/tags/OTX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OTX</span></a> <a href="https://social.raytec.co/tags/OpenThreatExchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenThreatExchange</span></a> <a href="https://social.raytec.co/tags/Rust" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Rust</span></a> <a href="https://social.raytec.co/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> <a href="https://social.raytec.co/tags/VirusTotal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VirusTotal</span></a> <a href="https://social.raytec.co/tags/bot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bot</span></a> <a href="https://social.raytec.co/tags/AlienVault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlienVault</span></a></p>
OTX Bot<p>Targeting of freelance developers</p><p>North Korea-aligned cybercriminals are targeting freelance software developers through fake job offers and coding challenges containing malware. The campaign, dubbed DeceptiveDevelopment, uses two main malware families - BeaverTail and InvisibleFerret - to steal cryptocurrency wallets and login credentials. Attackers pose as recruiters on platforms like LinkedIn and GitHub, providing trojanized projects as part of fake interview processes. The malware steals browser data, cryptocurrency wallets, and system information, and can deploy remote access tools. Hundreds of victims globally have been observed across Windows, Linux and macOS systems. The operation shows increasing sophistication and is expected to continue evolving its tactics to target cryptocurrency users.</p><p>Pulse ID: 67b81609424eb59f7dd64a0b<br>Pulse Link: <a href="https://otx.alienvault.com/pulse/67b81609424eb59f7dd64a0b" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">otx.alienvault.com/pulse/67b81</span><span class="invisible">609424eb59f7dd64a0b</span></a> <br>Pulse Author: AlienVault<br>Created: 2025-02-21 05:58:33</p><p>Be advised, this data is unverified and should be considered preliminary. Always do further verification.</p><p><a href="https://social.raytec.co/tags/Browser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Browser</span></a> <a href="https://social.raytec.co/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://social.raytec.co/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> <a href="https://social.raytec.co/tags/ICS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ICS</span></a> <a href="https://social.raytec.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://social.raytec.co/tags/Korea" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Korea</span></a> <a href="https://social.raytec.co/tags/LinkedIn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LinkedIn</span></a> <a href="https://social.raytec.co/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://social.raytec.co/tags/Mac" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mac</span></a> <a href="https://social.raytec.co/tags/MacOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MacOS</span></a> <a href="https://social.raytec.co/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.raytec.co/tags/NorthKorea" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NorthKorea</span></a> <a href="https://social.raytec.co/tags/OTX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OTX</span></a> <a href="https://social.raytec.co/tags/OpenThreatExchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenThreatExchange</span></a> <a href="https://social.raytec.co/tags/RAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RAT</span></a> <a href="https://social.raytec.co/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> <a href="https://social.raytec.co/tags/Windows" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Windows</span></a> <a href="https://social.raytec.co/tags/bot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bot</span></a> <a href="https://social.raytec.co/tags/cryptocurrency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cryptocurrency</span></a> <a href="https://social.raytec.co/tags/developers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>developers</span></a> <a href="https://social.raytec.co/tags/AlienVault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlienVault</span></a></p>
Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:<p>A large-scale malware campaign dubbed "StaryDobry" has been targeting gamers worldwide with trojanized versions of cracked games such as Garry's Mod, BeamNG.drive, and Dyson Sphere Program. <a href="https://kolektiva.social/tags/MalwareAttacks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MalwareAttacks</span></a> <a href="https://kolektiva.social/tags/Trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trojan</span></a> <a href="https://kolektiva.social/tags/Gamers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gamers</span></a> <a href="https://www.bleepingcomputer.com/news/security/cracked-garrys-mod-beamngdrive-games-infect-gamers-with-miners/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/cracked-garrys-mod-beamngdrive-games-infect-gamers-with-miners/</span></a></p>
Lady Miss Penelope<p><a href="https://mastodon.social/tags/turningtoday" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>turningtoday</span></a> <a href="https://mastodon.social/tags/trojan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojan</span></a> <a href="https://mastodon.social/tags/trojanrecords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojanrecords</span></a> <a href="https://mastodon.social/tags/trojanqueens" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trojanqueens</span></a> <a href="https://mastodon.social/tags/loveisallibring" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>loveisallibring</span></a> <a href="https://mastodon.social/tags/reggaeonvinyl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reggaeonvinyl</span></a> <a href="https://mastodon.social/tags/vinyl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vinyl</span></a> <a href="https://mastodon.social/tags/vinylonly" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vinylonly</span></a> <a href="https://mastodon.social/tags/queens" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>queens</span></a></p>