SERPENTINE#CLOUD returns: ClickFix lure drops five RATs
Same operator, new delivery chain. ClickFix through Cloudflare tunnels drops five RAT families simultaneously - including Brute Ratel C4 wrapping PureHVNC.
Qilin: inside the Windows ransomware build behind 1,000+ victims
Teardown of the CheckQilin Windows build from 2025's top ransomware crew: BYOVD EDR killer, AES/ChaCha20 dispatch, RSA-OAEP footer, one-byte password bypass.
TryNodeUpdate turns GitHub and BSC into a TCP control lane
A PowerShell sample installs a GitHub-hosted Node controller, uses a BNB Smart Chain contract to resolve its backend, then hands elevated Windows hosts to a native rpc.exe helper.
Urelas is old, weird, and still watching Korean card games
A fresh Urelas cluster shows thousands of March-April 2026 samples, Korean ISP command-and-control hosts, a bit-flipped MSMP config, and JPEG capture records built for Korean card-game clients.
M3rx ransomware: inside a new leak-site actor and Go encryptor
M3rx surfaced with a small leak-site burst and a Go ransomware sample using gzip+gob config data, X25519, AES-CTR file encryption, AES-GCM key wrapping, and a 0x400-byte footer.
VECT ransomware: small files decrypt, large files lose their nonces
A VECT 2.0 Windows sample can recover small files with a static ChaCha20 key and saved 12-byte nonce, but its large-file path keeps only the final nonce and loses the rest.
Five-layer delivery chain from a RAR5 archive through a signed carrier DLL side-load, AES-CBC hidden in a fake zlib DLL, IExpress extraction, AutoIt process hollowing, and a .NET C2 beacon on WebSocket.
PoisonX WindowsTelemetry: BYOVD-Assisted RAT With a Plugin Loader
PoisonX WindowsTelemetry chain: VERSION.dll sideloading, BYOVD scheduler, 10FX RAT protocol, SOCKS relay, plugin loading, and C2 reuse across two archives.
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
Deep-dive analysis of a trojanized Roblox executor that functions as a highly convincing lure with live DeepSeek script generation, while silently staging a Python 3.12 variant of Glove Stealer that bypasses Google Chrome's App-Bound Encryption.
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor
Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.
Direttiva CER: la resilienza diventa una funzione strategica dell’impresa
La direttiva CER introduce un nuovo modello europeo di resilienza che coinvolge board, security, risk management e compliance. Per i soggetti critici non si tratta solo di nuovi adempimenti, ma di ripensare la governance aziendale per gestire rischi sempre più interconnessi
This is a blog post about firmware updates, and I was inspired to write it by the news that NASA’s Curiosity rover on Mars has got an OTA update. The firmware image was about 21MB and took 11 days to send it over-the-air (or in this case, over-the-vacuum: Mars is currently 242 million kilometres from Earth).
The latest update of the open source can2 protocol decoder is able to automatically infer the sender of a CAN frame. It uses the method of deterministic distortion of CAN signals that result in frames from a given node on the bus having consistently shortened or lengthened recessive pulses. The differences can be quite small - just 10 or 15 nanoseconds - but they can be picked up by a suitably accurate logic analyzer.
No Room For Compromise: How Business Email Protection Predicts BEC Before It Starts
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
TrickBot ora usa il DNS tunneling per nascondersi: come mitigare il rischio
Una variante dello storico malware TrickBot adotta nuove tecniche di evasione e il DNS tunneling come metodo di comunicazione con il server di comando e controllo, per consentire agli attaccanti di nascondere lo scambio di dati all’interno del normale traffico DNS. Ecco tutti i dettagli e i consigli per mitigare il rischio