Cyfirma

APT36 Phishing Campaign Targets Indian Defense Using Credential-Stealing Malware

APT36 is conducting a targeted phishing campaign against Indian defense personnel. The campaign uses spear-phishing emails with malicious PDF attachments that mimic official government documents to deliver credential-stealing malware.

Understanding CyberEYE RAT Builder: Capabilities and Implications

CyberEye, also referred to as TelegramRAT, is a newly discovered RAT that utilizes Telegram’s Bot API for C2 operations. It is gaining popularity among cybercriminals due to its powerful surveillance features and ease of deployment.

GhostSpy Android Malware Grants Full Device Control and Evades Detection

GhostSpy is a newly identified Android malware that poses a severe threat to mobile security by granting attackers full control over infected devices. It employs advanced evasion, persistence, and surveillance techniques.

Technical Malware Analysis Report: Python-based RAT Malware

A newly discovered Python-based Remote Access Trojan (RAT) leverages Discord as its command-and-control (C2) platform, transforming the popular communication tool into a hub for malicious operations.

HANNIBAL Stealer: A Rebranded Threat Born from Sharp and TX Lineage - CYFIRMA

Hannibal Stealer is a newly surfaced malware, identified as a cracked and rebranded variant of the Sharp and TX stealers, promoted by the reverse engineering group ‘llcppc_reverse.’

SCAMONOMICS THE DARK SIDE OF STOCK & CRYPTO INVESTMENTS IN INDIA

A coordinated fraud campaign is targeting investors using fake investment platforms, impersonation tactics, and compromised legitimate websites. These schemes aim to steal financial data and defraud victims through social engineering.

Python-based RAT Abuses Discord API to Execute Data Theft Attacks

The Python-based Discord Remote Access Trojan (RAT) leverages Discord’s API as a C2 server to execute arbitrary system commands, steal sensitive information, capture screenshots, and manipulate both local machines and Discord servers.

Flesh Stealer Snoops on Web Browsers and Cryptocurrency Wallets

Flesh Stealer has been actively promoted on Discord, Telegram channels, and underground forums like Pyrex Guru. Employing Base64 obfuscation techniques to conceal its functions and strings, the stealer first emerged in August 2024.

NonEuclid RAT Combines Advanced Stealth, Anti-Detection, and Ransomware Capabilities

Developed in C# for the .NET Framework 4.8, NonEuclid is built to evade detection and offers a suite of advanced capabilities, including ransomware encryption, privilege escalation, and anti-detection mechanisms.

New FireScam Information Stealer Comes with Spyware Capabilities

FireScam monitors device activities such as screen state changes, e-commerce transactions, clipboard activity, and user engagement to gather valuable information covertly.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags