Sunday 26 July 2026 09:41:36 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Scheduled task


TrickBot Quietly Rewired the Oldest Trick in the Book: DNS as a Remote Control Line

Published: 23 July 2026 14:40Category: Malware & BotnetsAuthor: IRONQUERY

A new TrickBot variant points to a familiar criminal playbook: hide commands in normal-looking DNS traffic, then lean on Windows scheduled tasks and modular payloads to stay alive.

TrickBot Hides in a Wireshark-Themed Update While DNS Carries the Noise

Published: 23 July 2026 10:12Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A familiar Windows malware family is being linked to a persistence trick that blends into routine admin work, while its control traffic shifts into DNS and away from the more obvious web channels.

When the Chat Becomes a Worker: ChatGPT Work and the New Security Problem

Published: 13 July 2026 12:40Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

ChatGPT Work is framed as a shift from quick replies to persistent, supervised tasks, but that same shift pushes permissions, data handling, and human approval to the center of AI security.

One Drive, One Task, One Wiper: How a Destructive Implant Hides in Plain Sight

Published: 10 July 2026 10:32Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A Golang-based malware family is reported to use a OneDrive-themed scheduled task for persistence, showing how ordinary Windows maintenance patterns can be repurposed for destructive operations.

BusySnake’s Quiet Path Into Sensitive Networks

Published: 04 July 2026 12:02Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A phishing-led intrusion chain tied to the Armored Likho label shows how a stealer, scheduled-task persistence, and covert tunneling can turn one inbox click into a durable access problem.

TinyRCT and the Quiet Web-Shell Campaign Hidden in Southeast Asia’s Critical Networks

Published: 26 June 2026 16:09Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A Unit 42-tracked intrusion cluster blended open-source tooling with a custom .NET backdoor, raising the stakes for governments and energy operators that depend on exposed web applications.

SharkLoader Turns Trusted Windows Paths into a Quiet Launchpad

Published: 25 June 2026 11:04Category: Malware & BotnetsGeo: Asia / IndonesiaAuthor: SIGNALMONK

A newly named loader linked to the StrikeShark cluster shows how public-facing application exposure, DLL side-loading, and in-memory staging can turn a routine foothold into a much harder problem.

Claimed Ransom Note Targets APH as The Gentlemen Steps Into View

Published: 04 June 2026 18:09Category: Ransomware & ExtortionGeo: Middle East / Saudi ArabiaAuthor: LOGICFALCON

A public ransomware claim names a Saudi holding company and its web domain, but the real story is the uncertainty between an extortion post and a verified compromise.

A Short Lure, a Long Shadow: How a Finance Ministry Became a Phishing Test Case

Published: 30 May 2026 08:36Category: Cyber Warfare & Nation-State OperationsGeo: Asia / AfghanistanAuthor: AGONY

A targeted Windows intrusion chain tied to SideCopy-style tradecraft shows how localized phishing, trusted system tools, and recycled RAT code can still threaten government finance operations.

When a Windows Scheduler Becomes an Intruder’s Hideout

Published: 15 May 2026 10:45Category: Cyber Warfare & Nation-State OperationsGeo: Europe / BelarusAuthor: AGONY

A Belarusian-aligned cluster tracked under multiple names is drawing attention for one of the oldest stealth tricks in Windows: scheduled tasks that keep access alive after the initial break-in fades from view.

Windows Tasks, Quiet Hands: The Persistence Trick Behind a New Spyware Pattern

Published: 15 May 2026 08:06Category: Cyber Warfare & Nation-State OperationsGeo: Europe / UkraineAuthor: AGONY

Reported activity against Ukrainian government organizations uses scheduled tasks for stealthy persistence, with a separate validation step that may help operators keep noisy executions out of sight.