OCRFix botnet hides C2 in BNB Smart Chain contracts
A three-stage VBSEdit botnet uses BSC testnet smart contracts to resolve C2 URLs at runtime. One blockchain transaction rotates every bot to a new domain.
FakeGit: LuaJIT malware distributed via GitHub at scale
A Vietnamese operator has run 600+ malicious ZIPs through 47+ GitHub accounts for 13 months. C2 resolves via Polygon smart contract. Final payload is StealC.
A TAG-124 fileless PowerShell RAT with 1/76 VT detection. We decoded the wire protocol, four DGA systems, persistence modes, and probed the live C2 server.
Analysis of Tranium, a Go wiper disguised as ransomware. AES-CBC encryption, MBR overwrite, 30+ system files destroyed, 10 persistence mechanisms, zero payment infrastructure.
Full static analysis of the Payload ransomware group: Curve25519 and ChaCha20 encryption, Windows and ESXi builds, Babuk-derived kill lists, and a leak site that has since run to 65 organisations.
InterLock: full tooling teardown of a ransomware operation
Static analysis of 15 InterLock samples: ScreenConnect delivery, NodeSnake implants in three languages, a shared crypter, and dual-platform ransomware.
Analysis of a Go binary that sends host telemetry to GPT-4 and only drops its Sliver C2 payload if the model says the environment is safe. We recovered the full system prompt.
Pay2Key encryptor: what a January 2026 build reveals
Crypto analysis of a Jan 2026 Pay2Key encryptor. ChaCha20 + Curve25519 via OpenSSL, null nonce, session.tmp on disk. Intermittent mode leaves 70-87% plaintext in large files.
Breaking Aura: five obfuscation layers & hates sandboxes
Five code obfuscation layers broken, transport encryption reversed, and the full server-pushed config decrypted from a live Aura Stealer C2. Heaven's Gate, CFF, FNV-1a hash tables, and AES-256-CBC.
SERPENTINE#CLOUD returns: ClickFix lure drops five RATs
Same operator, new delivery chain. ClickFix through Cloudflare tunnels drops five RAT families simultaneously - including Brute Ratel C4 wrapping PureHVNC.
Qilin: inside the Windows ransomware build behind 1,000+ victims
Teardown of the CheckQilin Windows build from 2025's top ransomware crew: BYOVD EDR killer, AES/ChaCha20 dispatch, RSA-OAEP footer, one-byte password bypass.
TryNodeUpdate turns GitHub and BSC into a TCP control lane
A PowerShell sample installs a GitHub-hosted Node controller, uses a BNB Smart Chain contract to resolve its backend, then hands elevated Windows hosts to a native rpc.exe helper.
Urelas is old, weird, and still watching Korean card games
A fresh Urelas cluster shows thousands of March-April 2026 samples, Korean ISP command-and-control hosts, a bit-flipped MSMP config, and JPEG capture records built for Korean card-game clients.
M3rx ransomware: inside a new leak-site actor and Go encryptor
M3rx surfaced with a small leak-site burst and a Go ransomware sample using gzip+gob config data, X25519, AES-CTR file encryption, AES-GCM key wrapping, and a 0x400-byte footer.
VECT ransomware: small files decrypt, large files lose their nonces
A VECT 2.0 Windows sample can recover small files with a static ChaCha20 key and saved 12-byte nonce, but its large-file path keeps only the final nonce and loses the rest.
Five-layer delivery chain from a RAR5 archive through a signed carrier DLL side-load, AES-CBC hidden in a fake zlib DLL, IExpress extraction, AutoIt process hollowing, and a .NET C2 beacon on WebSocket.
PoisonX WindowsTelemetry: BYOVD-Assisted RAT With a Plugin Loader
PoisonX WindowsTelemetry chain: VERSION.dll sideloading, BYOVD scheduler, 10FX RAT protocol, SOCKS relay, plugin loading, and C2 reuse across two archives.
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
Deep-dive analysis of a trojanized Roblox executor that functions as a highly convincing lure with live DeepSeek script generation, while silently staging a Python 3.12 variant of Glove Stealer that bypasses Google Chrome's App-Bound Encryption.
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor
Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.
Direttiva CER: la resilienza diventa una funzione strategica dell’impresa
La direttiva CER introduce un nuovo modello europeo di resilienza che coinvolge board, security, risk management e compliance. Per i soggetti critici non si tratta solo di nuovi adempimenti, ma di ripensare la governance aziendale per gestire rischi sempre più interconnessi