Zscaler

December 23, 2025

Zscaler Threat Hunting Catches Evasive SideWinder APT Campaign

A sophisticated espionage campaign by the SideWinder APT group targets Indian entities by impersonating the Income Tax Department of India. The campaign uses advanced techniques such as DLL side-loading with legitimate Microsoft Defender binaries.

BlindEagle Deploys Caminho and DCRAT

BlindEagle, a threat actor operating in South America, has launched a sophisticated spear phishing campaign targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism (MCIT).

SEO Poisoning Targets Ivanti VPN: Credential Theft Alert

A new SEO poisoning campaign is targeting users searching for Ivanti Pulse Secure VPN software, redirecting them to attacker-controlled sites hosting a trojanized installer. The malware steals VPN credentials and exfiltrates them to a C2 server.

YiBackdoor: Linked to IcedID and Latrodectus

A new malware family named YiBackdoor has been identified, exhibiting strong code overlaps with IcedID and Latrodectus. YiBackdoor can execute arbitrary commands, collecting system information, capturing screenshots, and deploying encrypted plugins.

Black Hat SEO Poisoning Search Engine Results For AI

Threat actors are exploiting the popularity of AI tools by using Black Hat SEO to poison search engine results and Vidar Stealer, Lumma Stealer, and Legion Loader through complex redirection chains and obfuscated JavaScript.

TransferLoader Malware Loader Deploys Morpheus Ransomware Using Obfuscated Backdoor and IPFS-Based C2

TransferLoader is a newly identified malware loader active since at least February 2025. It comprises three main components—a downloader, a backdoor loader, and a backdoor—each employing advanced anti-analysis and obfuscation techniques.
April 16, 2025

Mustang Panda: PAKLOG, CorKLOG, and SplatCloak

Mustang Panda, a China-linked APT group, has expanded its malware arsenal with PAKLOG and CorKLOG and an EDR evasion driver named SplatCloak. The malware is delivered via RAR archives containing legitimate signed binaries and malicious DLLs.

Technical Analysis of Xloader Versions 6 and 7

Xloader is known for its ability to steal sensitive information from web browsers, email clients, and FTP applications, as well as deploy second-stage payloads on infected systems.

Technical Analysis of RiseLoader Reveals Similarities with RisePro’s Communication Protocol

RiseLoader is a new malware loader family that was first observed in October 2024. The malware implements a custom TCP-based binary network protocol that is similar to RisePro.

NodeLoader Malware Found Evading Detection on Windows Systems

NodeLoader uses a module called sudo-prompt, a publicly available tool on GitHub and NPM, for privilege escalation. The malware delivered by NodeLoader includes cryptocurrency miners and information stealers.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags