threat-intel JavaScript obfuscation: From party trick to phishing kit This article from Cisco Talos explores the techniques used to obfuscate JavaScript code, primarily for malicious purposes like phishing and malware delivery. The author details various methods of hiding code, including string manipulation, identifier renaming, runtime decoding, and control-flow flattening. They emphasi… Cisco Talos · 3d ago High obfuscationjavascriptmalware
threat-intel A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th) This article details a sophisticated phishing page that employs a polymorphic obfuscation technique to evade detection. The page initially presents as broken, causing a 30-second delay and high CPU usage, due to a global… SANS Internet Storm Center · 3d ago Medium phishingobfuscationpolymorphism
threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and con… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate The U.S. Department of Justice and FBI have taken down Chinese hacking tools – QScan and QTRouter – used by China’s Ministry of State Security and People’s Liberation Army to target U.S. agencies, including the Federal R… The Record · 4d ago High CHchinaiotcyberattack
threat-intel Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th) Attackers are increasingly using hostname-based IP address obfuscation, specifically leveraging services like 1u.ms to bypass security measures. This tactic is used to exploit vulnerabilities like Server Side Request For… SANS Internet Storm Center · 5d ago Medium ssrfdnsobfuscation
threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel Brazilian Banking Trojan Actively Spreading in Portugal A long-standing Brazilian banking Trojan, Lampion, is actively targeting Portuguese organizations, leveraging the shared language and cultural connection between Brazilian hackers and Portuguese businesses. The malware,… Dark Reading · Jul 23, 2026 High BRPTESbanking trojanphishinggeofencing
threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
threat-intel Linux Process Name Masquerading, (Wed, Jun 24th) This SANS Internet Storm Center diary details a technique used by attackers, specifically the Velvet Ant Chinese group, to mask process names in Linux systems. Attackers modify the ‘comm’ and ‘cmdline’ entries in the /pr… SANS Internet Storm Center · Jun 24, 2026 Medium CHprocess_namemasqueradinglinux
malware New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer A new malware loader, dubbed OXLOADER, is being used to distribute the CastleStealer information stealer through malicious Google Ads. The campaign, codenamed REF8372, leverages deceptive advertising and PowerShell execu… The Hacker News · Jun 22, 2026 Medium RUUAgoogle adsmalware loadercastlestealer
ransomware From a VHDX File to a Remcos RAT, (Tue, Jun 16th) A malicious ZIP archive, containing a VHDX file, was discovered utilizing a multi-stage attack chain to deploy the Remcos RAT. The initial delivery involves a JavaScript payload that leverages WMI and PowerShell to execu… SANS Internet Storm Center · Jun 16, 2026 High DEratpowershellwmi
malware Evil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th) This report details the analysis of the "Evil MSI Background" file, a suspicious JPEG containing a hidden payload. The analysis, conducted by Didier Stevens, utilized tools like `byte-stats.py` and `base64dump.py` to unc… SANS Internet Storm Center · Jun 15, 2026 Medium base64reverse engineeringobfuscation
malware The Evil MSI Background is Back!, (Fri, Jun 5th) This report details a recent cyberattack utilizing a classic MSI-branded JPEG payload, a technique previously documented by the SANS Internet Storm Center. The attack began with a phishing email containing a WeTransfer l… SANS Internet Storm Center · Jun 5, 2026 High USphishingmalwarepowershell
malware An Example of Stack String in High Level Language, (Sat, May 23rd) This article discusses a malware obfuscation technique called "stack strings," where strings are dynamically constructed on the stack at runtime rather than being stored as contiguous data in the binary. The example demo… SANS Internet Storm Center · May 23, 2026 Medium obfuscationstackassembly
malware Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files This report details the evolving tactics of the Gremlin stealer malware, specifically a recent variant employing sophisticated obfuscation techniques to evade detection. The malware, which targets sensitive data like pay… Palo Alto Unit 42 · May 15, 2026 High USobfuscationanti-analysisresource section