الأحد 26 يوليو 2026 09:43:43 GMT+02:00

Netcrook

الرئيسيةالبيان
الأخبار
Techcrook
Geocrook
WikicrookالفريقAppاتصالتسجيل الدخول
EnglishItaliano

يوليو 2026

09 يوليو 2026


When Ransomware Borrows the Admin Desk: PsExec, Password Stores, and the Quiet Road to Encryption

Published: 09 July 2026 18:58Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A GodDamn ransomware incident highlights a familiar but dangerous pattern: legitimate Windows tooling, credential harvesting, and rapid internal spread.

PowerShell Under a Prompt Engine: The AD Recon Report That Changes the Defensive Lens

Published: 09 July 2026 18:45Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A June 3 incident tied to Huntress shows how AI-generated PowerShell can be used for Active Directory enumeration without introducing a new exploit chain.

Go Malware, Faster Bots, and the Quiet Threat Spilling Toward OT

Published: 09 July 2026 15:56Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Nozomi Networks Labs identified Apex2 and c2c/meow, two Golang-based malware families linked to faster IoT botnet attacks and a higher risk profile for OT environments.

RedHook Returns With a Stranger Trick: Android Debugging Turned Into Malware Control

Published: 09 July 2026 15:53Category: Malware & BotnetsGeo: Asia / VietnamAuthor: NEXUSGUARDIAN

A fresh look at RedHook suggests the threat is moving beyond ordinary permission abuse and into a more dangerous trust zone inside Android.

Android Malware Turns a Safety Feature into a Shell-Access Path

Published: 09 July 2026 14:31Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

RedHook is being linked to a control-chain abuse pattern that uses Accessibility, Developer Options, and wireless debugging to reach Android shell-level privileges.

Fake VPN Lures Are Turning Trust Into a Malware Delivery Channel

Published: 09 July 2026 11:31Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.

Everest Sample Hides Its Tracks in .NET, Then Adds Wake-on-LAN to the Mix

Published: 09 July 2026 11:22Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A legacy .NET ransomware binary protected with ConfuserEx and featuring Wake-on-LAN capability highlights how modern malware can combine obfuscation with reach-related design choices.

Inside SNOW: A Phishing Chain That Hides in Chat, Browsers, and Web Traffic

Published: 09 July 2026 10:31Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A multi-stage intrusion pattern tied to SNOW shows how attackers can braid together collaboration abuse, browser persistence, and WebSocket tunneling to make a single intrusion look like ordinary office noise.

Fake SDKs, Real Risk: The Package Trap Lurking in Developer Workflows

Published: 09 July 2026 10:24Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A cluster of malicious packages in npm and PyPI shows how public registries can be turned into a delivery channel for software-supply-chain abuse.

The Fake 7-Zip Trap That Turns a Download Into a Proxy Network

Published: 09 July 2026 08:33Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

A familiar utility brand, a lookalike domain, and a silent installer chain can be enough to turn a consumer PC into part of someone else’s network abuse.

يوليو 2026