Dimanche 26 Juillet 2026 09:54:30 GMT+02:00

Netcrook

AccueilManifeste
Actualités
Techcrook
Geocrook
WikicrookÉquipeAppContactLogin
EnglishItaliano

Malware & Botnets / Asia


Image Files as Bait: How Interview Lures Are Being Used to Slip Malware Past Developer Trust

Published: 20 July 2026 08:07Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: NEXUSGUARDIAN

A resurfaced recruitment-themed campaign is using SVG files as a delivery container, while a separate Ruby ecosystem intrusion underlines how quickly software trust can be turned against developers.

Two Trust Boundaries, One Trap: Active Images and Package Registries Turned Against Developers

Published: 20 July 2026 08:03Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: IRONQUERY

A malware campaign linked to SVG files and a separate RubyGems supply-chain incident show how developers can be targeted through the tools they use most.

Inside the Job-Test Trap: How SVG Files Became a Malware Delivery Layer

Published: 17 July 2026 18:38Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: IRONQUERY

A developer hiring exercise can look routine on the surface, yet the technical path underneath may hide staged malware, credential theft, and file harvesting.

Daxin Returns on a Taiwan Manufacturing Host, and a Second Backdoor Raises the Stakes

Published: 16 July 2026 17:52Category: Malware & BotnetsGeo: Asia / TaiwanAuthor: SIGNALMONK

A kernel-level implant and a pre-login Windows backdoor were found together, but their exact relationship and full impact remain unconfirmed.

Old Rootkit, New Shadow: Daxin’s Return Shows How Windows Intrusions Hide in Plain Traffic

Published: 16 July 2026 10:36Category: Malware & BotnetsGeo: Asia / TaiwanAuthor: IRONQUERY

A resurfaced backdoor and a separate DLL implant found on the same Windows host highlight how attackers can combine low-level network manipulation with logon-time persistence.

Rust, Search Poisoning, and a Quiet C2 Channel: The MODBEACON Problem

Published: 10 July 2026 16:32Category: Malware & BotnetsGeo: Asia / ChinaAuthor: NEXUSGUARDIAN

A reported Chinese-linked RAT pairs fake software downloads with gRPC-based command traffic, showing how modern delivery and transport choices can make old malware tradecraft harder to spot.

RedHook Returns With a Stranger Trick: Android Debugging Turned Into Malware Control

Published: 09 July 2026 15:53Category: Malware & BotnetsGeo: Asia / VietnamAuthor: NEXUSGUARDIAN

A fresh look at RedHook suggests the threat is moving beyond ordinary permission abuse and into a more dangerous trust zone inside Android.

Fake VPN Lures Are Turning Trust Into a Malware Delivery Channel

Published: 09 July 2026 11:31Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.

Tax Lures, Signed Files, and a Malware Chain Built on Trust

Published: 08 July 2026 10:11Category: Malware & BotnetsGeo: Asia / IndiaAuthor: NEXUSGUARDIAN

A compliance-themed phishing wave aimed at Indian taxpayers shows how official-looking pressure and a signed Windows executable can work together to move remote-access malware onto a victim machine.

Eight Stages, One Hidden Driver: Why This Windows Campaign Demands Extra Scrutiny

Published: 06 July 2026 14:53Category: Malware & BotnetsGeo: Asia / ChinaAuthor: IRONQUERY

A reported SilverFox operation pairs ValleyRAT with a long infection chain and a kernel-rootkit claim, a combination that raises the stakes for detection and cleanup.

When a RAT Moves Into the Kernel, Cleanup Gets Much Harder

Published: 06 July 2026 14:34Category: Malware & BotnetsGeo: Asia / ChinaAuthor: NEXUSGUARDIAN

A reported ValleyRAT upgrade into an eight-stage chain ending in kernel-mode stealth shows why defenders treat driver-level malware as a different class of problem.

When a Stealer Log Becomes a Fraud Lead: The RedLine Trail Into Maritime BEC

Published: 06 July 2026 10:05Category: Malware & BotnetsGeo: Asia / South KoreaAuthor: NEXUSGUARDIAN

A credential-theft clue can be more than malware noise, especially when investigators use it to map a possible email-fraud path around a named maritime company.

108 Poisoned Builds, One Shared Trap: The New Cross-Ecosystem Supply-Chain Wave

Published: 04 July 2026 14:07Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: IRONQUERY

A campaign tied to PolinRider has put malicious packages and browser extensions into npm, Packagist, Go, and Google Chrome, showing how one delivery pattern can travel across very different trust systems.

ValleyRAT’s Quiet Upgrade: Encryption, Shellcode, and a Trusted Windows Host

Published: 02 July 2026 12:17Category: Malware & BotnetsGeo: Asia / ChinaAuthor: IRONQUERY

The latest ValleyRAT activity shows a layered Windows tradecraft chain built to stay in memory, reduce disk artifacts, and make routine detection harder for defenders.

When Guest Complaints Become Malware Cover: The Hotel Phishing Campaign Built on TON

Published: 30 June 2026 10:06Category: Malware & BotnetsGeo: Asia / JapanAuthor: IRONQUERY

A targeted lure against Japan’s hotel sector shows how complaint-themed emails and blockchain-backed infrastructure can be paired to make malware harder to disrupt.

SharkLoader Turns Trusted Windows Paths into a Quiet Launchpad

Published: 25 June 2026 11:04Category: Malware & BotnetsGeo: Asia / IndonesiaAuthor: SIGNALMONK

A newly named loader linked to the StrikeShark cluster shows how public-facing application exposure, DLL side-loading, and in-memory staging can turn a routine foothold into a much harder problem.

SharkLoader Turns a Diplomatic Intrusion Into a Broader Beacon Problem

Published: 25 June 2026 08:13Category: Malware & BotnetsGeo: Asia / IndonesiaAuthor: SIGNALMONK

A newly named loader family linked to StrikeShark shows how a small foothold can become a wider intrusion chain when the real goal is to stage Cobalt Strike Beacon.

Forgotten Edge Devices, New Operator Tricks: AryStinger’s Quiet Relay Game

Published: 22 June 2026 15:05Category: Malware & BotnetsGeo: Asia / ChinaAuthor: IRONQUERY

A newly analyzed botnet turns aging routers and NAS appliances into scanning and tunneling nodes, showing how small edge devices can become useful infrastructure for hiding attacker origin and widening reach.

Forgotten Routers, Fresh Crimeware: AryStinger Turns Old D-Link Gear Into Hidden Transit

Published: 21 June 2026 18:02Category: Malware & BotnetsGeo: Asia / TaiwanAuthor: NEXUSGUARDIAN

A previously undocumented botnet has been tied to thousands of outdated routers, showing how edge devices can be repurposed into quiet infrastructure for malicious traffic.

Dropping Elephant’s Quiet Pivot: A China-Themed Loader, GitLab Pages, and a Memory-Resident RAT

Published: 18 June 2026 15:26Category: Malware & BotnetsGeo: Asia / IndiaAuthor: NEXUSGUARDIAN

A seven-week campaign tied to Dropping Elephant mixed trusted web services with fast-changing infrastructure, showing how attackers can turn ordinary publishing and chat-link features into malware delivery paths.