Topic: defense evasion

  • New Spirals ransomware encrypts networks in under 24 hours

    New Spirals ransomware encrypts networks in under 24 hours

    A new ransomware strain called "Spirals" completed a full corporate intrusion cycle in under 24 hours, targeting an IT services company in South Asia by compromising a publicly exposed IIS server. The attacker bypassed UAC, enabled Remote Desktop, dumped credentials, disabled Microsoft Defender...

    Read More »
  • New Ransomware Uses Malicious Driver to Disable Security Tools

    New Ransomware Uses Malicious Driver to Disable Security Tools

    A new ransomware variant called "GodDamn", an evolution of the Beast/Monster (Hyadina) ransomware first seen in 2022, uses a "Microsoft-signed malicious driver (PoisonX)" to disable endpoint security tools, making detection much harder. Attackers gain initial access, often through account com...

    Read More »
  • What Attackers Do After a Break-In

    What Attackers Do After a Break-In

    A Huntress investigation revealed a post-breach attack where the intruder gained entry via SQL injection, then methodically established persistence by enabling RDP, creating an admin account, and disabling Windows Defender. The attacker weaponized the compromised server by installing BadIIS web m...

    Read More »
  • Gentlemen Ransomware Grows Rapidly With New Affiliates

    Gentlemen Ransomware Grows Rapidly With New Affiliates

    A new ransomware-as-a-service group called "The Gentlemen" has rapidly emerged as a major threat, claiming over 320 victims with a surge in early 2026 and targeting corporate networks with a sophisticated, cross-platform toolkit. The operation provides affiliates with powerful, Go-based ransomw...

    Read More »
  • Inside the PureRAT Attack: From Info Stealer to Full Control

    Inside the PureRAT Attack: From Info Stealer to Full Control

    A sophisticated cyberattack begins with phishing emails using sideloading techniques to deploy malware, escalating from credential theft to deploying the full-featured PureRAT remote access trojan for complete system control. The campaign employs multiple layers of obfuscation, including custom c...

    Read More »
  • Ransomware Insider Exposes 'The Gentlemen' Gang's Secrets

    Ransomware Insider Exposes 'The Gentlemen' Gang's Secrets

    An emerging ransomware group called The Gentlemen, operating on a ransomware-as-a-service model, was exposed by a disgruntled affiliate, revealing its sophisticated and cross-platform attack methods. The group employs dual-extortion tactics, systematically exploits vulnerabilities like FortiGate ...

    Read More »
  • HR and Recruiters Hit by Year-Long Malware Attack

    HR and Recruiters Hit by Year-Long Malware Attack

    A long-running malware campaign is specifically targeting HR and recruitment professionals to steal sensitive organizational data using sophisticated, stealthy techniques. The attack begins with a deceptive resume-themed file that triggers a multi-stage infection, employing tactics like DLL sidel...

    Read More »
  • Australian Cyber Security Centre Warns of ClickFix Cyber Attacks

    Australian Cyber Security Centre Warns of ClickFix Cyber Attacks

    The Australian Cyber Security Centre warns that a malicious campaign is using ClickFix social engineering tactics, including fake CAPTCHA prompts, to deliver Vidar Stealer malware to critical infrastructure and organizations. Vidar Stealer targets Windows users to harvest sensitive data like cred...

    Read More »
  • MaaS Attack Chain Merges ClickFix, ErrTraffic, Cruciferra

    MaaS Attack Chain Merges ClickFix, ErrTraffic, Cruciferra

    A new malware-as-a-service campaign combines ClickFix social engineering, the ErrTraffic delivery service, and the Cruciferra loader to push malware while disabling endpoint defenses, as detailed by eSentire's Threat Response Unit. The attack chain starts on hijacked WordPress sites, uses Ethereu...

    Read More »
  • New AI Worm Poses a Potentially Unstoppable Cyber Threat

    New AI Worm Poses a Potentially Unstoppable Cyber Threat

    Researchers have introduced an AI-powered computer worm that autonomously spreads and adapts in real time, representing a "fundamentally new threat" to cybersecurity. Unlike traditional malware, this worm uses generative AI to rewrite its attack strategies, evade detection, and craft convincing p...

    Read More »