WebNews

Please enter a web search for web results.

NewsWeb

SOC Prime
socprime. com > active-threats > what-was-really-inside-the-shortcut-file-disguised-as-a-privacy-consent-form

Fake Privacy Consent LNK Files Deliver Fileless Malware

18+ hour, 48+ min ago  (195+ words) SOC Prime Bias: High Threat actors are distributing malicious LNK files disguised as privacy consent forms to deceive users into opening them. When executed, these shortcut files launch obfuscated Power Shell commands that retrieve and run additional payloads using fileless…...

SOC Prime
socprime. com > active-threats > operation-poisson-breaking-down-an-entire-cybercriminal-operation

Operation Poisson Exposes a Resilient Credential Theft Chain

2+ day, 13+ hour ago  (202+ words) SOC Prime Bias: High A low-skilled threat actor known as "Poisson" carried out a multi-stage credential theft campaign aimed at French individuals and a small business. The attacker used Havoc C2, a custom Python keylogger, and built resilient access through Open…...

SOC Prime
socprime. com > active-threats > shinyhunters-targets-education-sector-with-oracle-peoplesoft-exploit

Shiny Hunters Exploits Oracle People Soft in Education

3+ day, 12+ hour ago  (197+ words) SOC Prime Bias: Critical The threat actor UNC6240, also known as Shiny Hunters, is running an active compromise and extortion campaign against Oracle People Soft environments. The attackers abuse a zero-day remote code execution flaw in the Environment Management component to…...

Symbols: googl.o,orcl.n
SOC Prime
socprime. com > active-threats > onyxc2-a-new-stealer-targeting-210-applications

Onyx C2 Targets 210 Apps with Stealthy Data Theft

3+ day, 13+ hour ago  (246+ words) SOC Prime SOC Prime Bias: High Onyx C2: A New Stealer Targeting 210 Applications Onyx C2 is an emerging malware-as-a-service stealer designed to target credentials, two-factor authentication extensions, and cryptocurrency wallets across roughly 210 applications. The platform offers a full commercial-style toolkit, including a…...

SOC Prime
socprime. com > active-threats > analyzing-sheetcreep-the-malware-returns-with-new-config-obfuscation

SHEETCREEP Returns with New Google Sheets RAT Obfuscation

3+ day, 20+ hour ago  (210+ words) SOC Prime SOC Prime Bias: Critical Analyzing SHEET#CREEP: The Malware Returns with New Config Obfuscation An active espionage operation known as SHEETCREEP relies on a C# remote access trojan that uses the Google Sheets API for command and control....

Symbols: cert-ua
SOC Prime
socprime. com > active-threats > op-report-from-ssa-phish-to-adaptixc2-a-multi-rat-intrusion

SSA Phishing Leads to Adaptix C2, XWorm, and Screen Connect

4+ day, 20+ hour ago  (298+ words) SOC Prime SOC Prime Bias: High [Op Report] From SSA Phish to Adaptix C2: A Multi-RAT Intrusion A threat actor carried out a layered commodity intrusion beginning with a phishing email themed around the U. S. Social Security Administration. The operation relied on…...

SOC Prime
socprime. com > active-threats > from-crypto-wallets-to-a-100m-user-vpn-inside-an-active-stx-rat-supply-chain-campaign

STX RAT Supply Chain Attack Hits Wallets and X-VPN

1+ week, 3+ day ago  (433+ words) SOC Prime SOC Prime Bias: Critical From Crypto Wallets to a 100 M-User VPN: Inside an Active STX RAT Supply Chain Campaign Researchers uncovered an active supply chain campaign in which a threat actor abused DLL sideloading with a malicious CRYPTBASE....

SOC Prime
socprime. com > active-threats > from-fake-amazon-security-alert-to-harborwatch-agent-delivery

Fake Amazon Alert Delivers Harbor Watch Agent RAT

1+ week, 3+ day ago  (273+ words) SOC Prime Bias: Medium Cofense traced the campaign from the spoofed sender address through the malicious domains, the Power Shell downloader, and the final malware payload. Dynamic analysis of mysql. exe revealed outbound communication with a command-and-control server at 185. 193. 127. 44 and…...

Symbols: nasdaq:amzn,nasdaq:crwd
Google News
socprime. com > active-threats > seeking-counsel-ongoing-targeted-attacks-against-us-law-firms

UNC3753 Targets US Law Firms with Vishing and Extortion

1+ week, 3+ day ago  (129+ words) SOC Prime Bias: High Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected…...

Symbols: nasdaq:smci
Google News
socprime. com > active-threats > gammasteel-inside-gamaredons-unfolding-malware-chain

Gamma Steel Uses Registry-Stored Power Shell and Tebi

1+ week, 4+ day ago  (751+ words) SOC Prime SOC Prime Bias: Critical Gamma Steel: Inside Gamaredon's Unfolding Malware Chain The report describes Gamma Steel, a new Gamaredon ( UAC-0010 ) intrusion chain built around a fileless Power Shell stealer. The malware stores 71 encrypted functions in the HKCU\Printers…...

Symbols: btc-usd,cert-ua