Unit 42 measured a large share of C2-active malware that connected straight to IP addresses, sidestepping DNS and the visibility layer many security teams still depend on.
Threat researchers traced a targeted campaign to three newly named malware families, showing how a familiar messaging platform can be repurposed as covert command infrastructure.
A Golang-based malware family is reported to use a OneDrive-themed scheduled task for persistence, showing how ordinary Windows maintenance patterns can be repurposed for destructive operations.
PHANTOMPULSE shows how a trusted plugin ecosystem, a UAC bypass, and blockchain-based tasking can combine into a stealthy Windows intrusion path.