A GodDamn ransomware incident highlights a familiar but dangerous pattern: legitimate Windows tooling, credential harvesting, and rapid internal spread.
A June 3 incident tied to Huntress shows how AI-generated PowerShell can be used for Active Directory enumeration without introducing a new exploit chain.
Nozomi Networks Labs identified Apex2 and c2c/meow, two Golang-based malware families linked to faster IoT botnet attacks and a higher risk profile for OT environments.
A fresh look at RedHook suggests the threat is moving beyond ordinary permission abuse and into a more dangerous trust zone inside Android.
RedHook is being linked to a control-chain abuse pattern that uses Accessibility, Developer Options, and wireless debugging to reach Android shell-level privileges.
A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.
A legacy .NET ransomware binary protected with ConfuserEx and featuring Wake-on-LAN capability highlights how modern malware can combine obfuscation with reach-related design choices.
A multi-stage intrusion pattern tied to SNOW shows how attackers can braid together collaboration abuse, browser persistence, and WebSocket tunneling to make a single intrusion look like ordinary office noise.
A cluster of malicious packages in npm and PyPI shows how public registries can be turned into a delivery channel for software-supply-chain abuse.
A familiar utility brand, a lookalike domain, and a silent installer chain can be enough to turn a consumer PC into part of someone else’s network abuse.