A reported intrusion chain tied to APT28 combines Office lures, COM hijacking, PNG steganography, and reflective loading to keep payloads out of sight and traffic inside trusted services.
A malware chain built around ScreenConnect abuse and fake installers shows how attackers can turn everyday remote-management habits into a quiet path to AsyncRAT.
A path-traversal flaw in WinRAR’s Windows build has been tied to archive extraction that can plant a Startup shortcut, then use PowerShell staging and in-memory loading to make detection harder.