🧵1/5 The developers behind Stealc have released Stealc v3, a major redesign that shifts the project beyond a traditional stealer. The most notable changes aren't new collection capabilities, they're improvements to deployment, scalability and operator experience. #ThreatIntel
marktsec
@marktsec.bsky.social
💫Threat Intel💫 Automation💫 Threat Analysis 💫OSINT💫 Testing 💫Network Security💫 https://github.com/marktsec
🧵1/ The Gentlemen RaaS operators have announced several updates for affiliates, but two additions stand out: Active Directory credential harvesting and an AI-assisted data analysis service designed to support ransom negotiations.#ThreatIntel #Ransomware #RaaS
🧵1/ A recently advertised phishing framework "AutoLogin Phishing kit" suggests phishing tooling is evolving beyond static login pages. The project is marketed as a browser automation platform using real Chrome instances to interact with legitimate login flows. #ThreatIntel
🧵1/ A custom ransomware project was recently advertised on cybercrime forum, and its feature list provides an interesting snapshot of what operators now market as a "premium" ransomware offering. #ThreatIntel #Ransomware
🧵1/ An underground vendor selling code-signing certificates has revised its offering following Microsoft's recent reputation changes. The update suggests certificate possession alone is no longer sufficient to reliably bypass SmartScreen. #ThreatIntel #infosec
🧵 1/ A newly advertised ransomware operation, SevyWare RaaS, is promoting an unusual addition to its affiliate offering: "Violence as a Service." #ThreatIntel #Ransomware
🧵1/ Since its public debut in early June, the emerging VOLTA MaaS stealer has maintained a rapid development cadence, with 6 public updates released in less than a month. Below is a timeline of its development 👇 #ThreatIntel #infosec
🧵1/ The developers behind the Stealc malware have announced the sale of the complete Stealc v2 source code ahead of the planned v3 release. According to the advertisement, only two copies of the source code will be sold for $60,000 each. #ThreatIntel #Malware #secops
🧵1/ A new update to the ErrTraffic ClickFix framework was recently advertised on a Russian-language cybercrime forum. The release focuses less on new delivery techniques and more on scaling affiliate operations. #ThreatIntel #ClickFix #infosec
When Three Threats Meet One Inbox Against Japan ransom-isac.com/blog/three-t...
When Three Threats Meet One Inbox Against Japan
Three unrelated Chinese-nexus operators — CoGUI email phishing, the Smishing Triad SMS/iMessage ecosystem, and MirrorFace espionage — converge on Japanese inboxes simultaneously, producing a single-ca...
ransom-isac.com
Someone's Hands Are on Your Keyboard Then Your Whole Network. Courtesy of ClickFix, Potemkin, RMMProject and EtherRAT www.huntress.com/blog/potemki...
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack | Huntress
A ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts.
huntress.com
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices www.bleepingcomputer.com/news/securit...
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.
bleepingcomputer.com
APT28, an evolution of tradecraft blog.sekoia.io/apt28-an-evo...
APT28, an evolution of tradecraft
Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years. The intrusion set, also known as Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm or Sednit and public...
blog.sekoia.io
My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli www.pillar.security/blog/my-agen...
My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli
pillar.security
Nightmare-Eclipse is back. RoguePlanet Windows Defender Vulnerability github.com/MSNightmare/...
GitHub - MSNightmare/RoguePlanet: RoguePlanet Windows Defender Vulnerability
RoguePlanet Windows Defender Vulnerability. Contribute to MSNightmare/RoguePlanet development by creating an account on GitHub.
github.com
TierOne forum has moved to a new onion domain. The old site now points users to the replacement address, but the new service is currently throwing an Internal Server Error. #OSINT #ThreatIntel #DarkWeb
The Gentlemen Leak Analysis (Part 2) — JA456 Follow-on ransom-isac.org/blog/the-gen...
The Gentlemen Leak Analysis (Part 2) — JA456 Follow-on
Analysis of JA456, a follow-on package to the original Gentlemen Leaks that exposes operator-side artifacts — MEGA session history, a Synology NAS shadow dump, and wipe-in-progress screenshots — yield...
ransom-isac.org
Weaponizing a signed lenovo kernel driver to terminate any process — including EDR/AV protected processes. github.com/redteamfortr...
GitHub - redteamfortress/PhantomKiller: Another BYOVD process killer. works on all EDR's. fully signed.
Another BYOVD process killer. works on all EDR's. fully signed. - redteamfortress/PhantomKiller
github.com
Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoad harfanglab.io/insidethelab...
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
Identifier: TRR260501. Summary Investigating Gamaredon’s abuse of CVE-2025-8088, we identified a dozen waves of spearphishing emails against Ukrainian state institutions in a campaign that is still ac...
harfanglab.io
The Gentlemen Ransomware Group — Leak Analysis ransom-isac.org/blog/the-gen...
The Gentlemen Ransomware Group — Leak Analysis
A 120-minute technical intelligence whitepaper analysing the leaked Rocket.Chat corpus of The Gentlemen RaaS — 3,366 messages, 66 confirmed victims, custom G-BOT C2, Fortinet exploitation, AI-assisted...
ransom-isac.org
🚨 Storm Stealer operators announced a major feature update focused on Google’s DBSC protections. The group claims to have developed a “DBSC cookie bypass” module targeting Chrome 147 on Windows. #ThreatIntel #Infostealer #CyberSecurity
This article walks through three authentication paths that impacket-net supports NTLM hash (Pass-the-Hash), Kerberos ticket, and AES key. www.hackingarticles.in/impacket-for...
Impacket for Pentester: Net
Master impacket-net to enumerate & manage Active Directory using NTLM hash, Kerberos ticket, or AES key auth.
hackingarticles.in
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks www.bleepingcomputer.com/news/securit...
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in "Sorry" ransomware attacks.
bleepingcomputer.com
The first publicly available decryption method for The Gentlemen ransomware. github.com/Bedrock-Safe...
GitHub - Bedrock-Safeguard/gentlemen-decryptor: First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35 file...
First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35 files decrypted. Research by Bedrock Safeguard In...
github.com
Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency www.seqrite.com/blog/operati...
Operation GhostMail: Russian APT Exploits Zimbra XSS to Target Ukraine Government
Operation GhostMail uncovers a Russian APT campaign exploiting a Zimbra XSS vulnerability (CVE-2025-66376) to target a Ukrainian government agency via phishing emails and browser-based data exfiltrati...
seqrite.com
RedSun: How Windows Defender's Remediation Became a SYSTEM File Write nefariousplan.com/posts/redsun...
RedSun: How Windows Defender's Remediation Became a SYSTEM File Write — nefariousplan.com
A technical teardown of the RedSun zero-day — the second Defender escalation in two weeks from the same researcher — grounded in the actual source code.
nefariousplan.com
You’re Driving Me Crazy: Analysing and Detecting BYOVD ransom-isac.com/blog/analysi...
You’re Driving Me Crazy: Analysing and Detecting BYOVD
A deep-dive technical reference for SOC teams and threat hunters covering BYOVD attack analysis and detection.
ransom-isac.com