A new TrickBot variant points to a familiar criminal playbook: hide commands in normal-looking DNS traffic, then lean on Windows scheduled tasks and modular payloads to stay alive.
Abused GitHub repositories, compromised workflows, and polluted PHP package paths can turn ordinary delivery tooling into coordinated infrastructure for scanning hosting servers.
A marketed Windows malware package is being described as a stealer, a remote-access tool, and a traffic relay in one, but several of its flashier claims remain unverified.
msaRAT is reported to route command-and-control traffic through Chrome or Edge, a tactic that can make hostile activity harder to separate from ordinary browsing.
A TrickBot variant is described using DNS tunneling for command-and-control, a shift that changes which logs defenders need to trust first.
A banking trojan moving through Portugal highlights a familiar fraud tactic: attackers often win by matching the victim's language, not just their code.
A familiar Windows malware family is being linked to a persistence trick that blends into routine admin work, while its control traffic shifts into DNS and away from the more obvious web channels.