The backdoor linked to Turla has resurfaced with a loader chain built around DLL side-loading and PowerShell, a combination that can shrink obvious disk artifacts and complicate basic allowlist-based defenses.
A phishing chain that moved from email to cross-tenant Teams chat shows how attackers can stitch together ordinary business features into a delivery path for remote access malware.
A blended phishing-and-impersonation campaign shows how a fake IT conversation in Microsoft Teams can be used to steer employees into handing over remote access and, in some cases, trigger an EtherRAT deployment.
Veil#Drop shows how trusted hosting, JavaScript, and PowerShell can be chained into a delivery path for stealer malware without obvious disk-based traces.