Samedi 05 Septembre 2026 03:31:26 GMT+02:00

Netcrook

AccueilManifeste
Actualités
Techcrook
Geocrook
WikicrookÉquipeAppContact
EnglishItaliano

SIGNALMONK
Auteur Netcrook

SIGNALMONK

Expert en sécurité sans fil et RFID

CHMOD 433Malware & Botnetsfr

Profil professionnel

SignalMonk dirige des opérations de sécurité sur Wi‑Fi, BLE, RFID et l’IoT sans fil.

Compétences clés

Capture de trafic sans fil; exploitation BLE; détection de clonage RFID; communication IoT sécurisée; forensique radio

Réalisations majeures

Mise au jour d’un vol d’entreprise via des badges clonés.

Articles de SIGNALMONK

The Proxy Trap: How a Hidden Linux Implant Turned HAProxy Into a Traffic Filter

Published: 04 September 2026 18:09Category: Malware & BotnetsGeo: Asia / South KoreaAuthor: SIGNALMONK

A trojanized edge proxy can sit in the middle of web sessions, making the compromise of one server matter far beyond that single machine.

Toy Ghouls Backdoors Use HiveMQ and Element as Control Channels

Published: 04 September 2026 16:07Category: Malware & BotnetsAuthor: SIGNALMONK

A financially motivated crew is linked to Windows backdoors that route command traffic through public MQTT and Matrix-based messaging infrastructure.

When Help Turns Hostile: Windows Remote-Access Tools Used as a Persistence Route

Published: 03 September 2026 12:04Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A late-August cluster of intrusions shows how trusted support software can be repurposed into a quiet backdoor path on Windows endpoints.

JSCeal Hides in V8 Bytecode, Blurring the Line Between Script and Stealer

Published: 02 September 2026 21:17Category: Malware & BotnetsAuthor: SIGNALMONK

A cryptocurrency-focused information stealer reportedly ships as compiled V8 bytecode in a .jsc file, a format that can make JavaScript malware harder to inspect while it hunts for browser credentials and HTTPS traffic.

When a Theme Package Turns into a Trap for iPhones and Wallet Owners

Published: 02 September 2026 20:59Category: Malware & BotnetsAuthor: SIGNALMONK

Thirteen malicious Composer packages allegedly bent trusted web pages into a delivery path for ad fraud, redirects, and a spyware campaign aimed at unpatched iOS devices.

When a Botnet Loses Its Backbone: Why the Sality Seizure Matters

Published: 02 September 2026 19:39Category: Malware & BotnetsAuthor: SIGNALMONK

A coordinated cyber disruption targeted Sality’s malware infrastructure, showing how defenders can still hit a long-running peer-to-peer botnet where it hurts most - its control plane.

The Job Test That Might Not Be a Test

Published: 01 September 2026 14:09Category: Malware & BotnetsGeo: Middle East / IranAuthor: SIGNALMONK

Fake coding exercises are being used as a malware lure against developers, with researchers attributing the campaign with high confidence to Mirage Kitten.

When a Dependency Becomes the Trapdoor: Packagist Themes and the iPhone Browser Risk

Published: 01 September 2026 12:22Category: Malware & BotnetsGeo: Europe / GermanyAuthor: SIGNALMONK

A reported package-chain abuse on Composer's ecosystem shows how a single injected script can turn ordinary mobile page views into a credential-harvesting event.

npm’s Quiet Trapdoor: How a Trusted Codegen Package Became a Supply-Chain Hazard

Published: 01 September 2026 12:12Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A widely used npm package was pushed through multiple malicious releases, and researchers say the episode fits a broader pattern of install-time abuse that can turn developer tools into credential targets.

Fake AI Desktop Tools Are Becoming a New Stealer Trap

Published: 01 September 2026 12:10Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A Windows malware campaign used a fake Claude-branded desktop app to pull passwords and crypto wallet data into a familiar-looking download path.

Fake AI Desktop App Turns a Trusted Brand Into a Password Trap

Published: 01 September 2026 10:04Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A trojanized Electron installer impersonating Claude Opus 5 shows how believable software branding can be repurposed into a Windows infostealer delivery path.

The npm Package That Became a Worm Carrier

Published: 31 August 2026 12:43Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A developer tool with heavy weekly usage was turned into a supply-chain infection path, showing how install-time behavior can matter as much as runtime code.

How a Browser Add-on Became the Front Door for Wallet and Credential Theft

Published: 31 August 2026 12:38Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A cluster of malicious Chrome and Edge extensions shows how ordinary browser permissions can turn trusted add-ons into a quiet risk for logins and crypto activity.

When a CAPTCHA Becomes a Shell: The TerminalFix Playbook for Turning Trust Into Access

Published: 31 August 2026 10:15Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A fake verification page can do more than annoy users - in ClickFix-style campaigns, it can become the first step in a multi-stage intrusion chain that ends with a reverse-tunnel foothold.

When a Build Tool Turns Hostile: The npm Package That Put Developer Trust on the Line

Published: 29 August 2026 12:05Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A popular OpenAPI-to-TanStack Query generator was linked to a burst of malicious releases, raising a familiar but uncomfortable question: what happens when the tool chain itself becomes the threat surface?

Ten Minutes, Ten Bad Releases: How a Build Tool Became the Weakest Link

Published: 29 August 2026 10:09Category: Malware & BotnetsAuthor: SIGNALMONK

A reported malicious npm release campaign against a popular OpenAPI-to-TanStack Query code generator highlights how build-time developer tools can become high-value supply-chain targets.

Tax Lures, Modular Malware, and the Quiet Return of Packaged Access

Published: 29 August 2026 10:05Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A phishing chain tied to the cluster tracked as TA4922 shows how tax-themed email can be turned into a delivery path for a modular RAT, staged loaders, and follow-on access tooling.

When a CAPTCHA Becomes a Trap Door: Fake Verification Pages and the PowerShell Pivot

Published: 29 August 2026 10:03Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A disguised human-check page can push a browser session into terminal execution, turning ordinary Windows endpoints into reverse-tunnel footholds for attackers.

Tax Notices, Telegram Sales, and a Modular RAT: The Quiet Machinery Behind a Phishing Run

Published: 29 August 2026 08:04Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A tax-themed lure linked to TA4922 shows how localized phishing and commodity malware can be fused into a repeatable access playbook without proving full compromise.

The Resume Trap That Can Turn Research Inboxes Into Malware Runways

Published: 28 August 2026 10:25Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A credential-flavored archive can look ordinary for one second and hostile the next, especially when it hides a disguised executable linked to the SNOWLIGHT and VShell malware stack.