Dexphot Polymorphic Malware Attacking Windows Computer to Mine Cryptocurrency and Monitor Services

A new malware strain dubbed Dexphot attacking windows computers to mine cryptocurrency, monitoring services, and scheduled tasks to rerun the infection if windows defender removed it. The malware uses filess techniques it gets malicious codes executed directly in memory and also it hijacks the legitimate process to hide the malicious activity. Microsoft closely tracked the […]

Glances – An Eye On Your System. A Top/Htop Alternative For GNU/Linux, BSD, Mac OS And Windows Operating Systems

Glances is a cross-platform monitoring tool which aims to present a large amount of monitoring information through a curses or Web based interface. The information dynamically adapts depending on the size of the user interface.It can also work in client/server mode. Remote monitoring could be done via terminal, Web interface or API (XML-RPC and RESTful). […]

Cyborg ransomware posing as Windows update hits PCs

If you’ve updated your Windows today like me, this article may just end up scaring you a bit. In the latest, it has been discovered that a malicious campaign has been installing ransomware under the pretext of updating your operating system. Named as Cyborg ransomware; the attackers try to lure users by sending emails prompting […]

A Review Of Yodot Recovery Software For Windows And Mac

While SD cards provide a wonderful means to store photos, videos, and other data, they need careful handling since they are prone to damage and consequent data loss. However, with Yodot Recovery Software, there is a lifeline. Whether you accidentally delete any files, your memory card becomes corrupted, you can potentially recover your files. Quick […]

“Fake” Windows 10 Update Installs “Cyborg” Ransomware

The latest Windows 10 November 2019 Update has begun rolling out for users. But some evil minds didn’t spend much time in taking advantage of the situation and deliver infected and fake Windows Update to the users. A new ransomware campaign has been discovered by the security researchers at SpiderLabs (via TechRadar). The fake Windows […]

Fake Windows Updater Bypass Email Gateways To Launch Cyborg Ransomware On Windows PC

New malspam email campaign discovered with fake windows updater and its Builder, through which hackers launching Cyborg Ransomware to encrypt the compromised systems files. A spam email claims to be from Microsoft and email body urges the victims to Install the Latest “Microsoft Windows Update” by opening the attached file. Fake update attachment appears with […]

WinPwn – Automation For Internal Windows Penetrationtest / AD-Security

In many past internal penetration tests I often had problems with the existing Powershell Recon / Exploitation scripts due to missing proxy support. I often ran the same scripts one after the other to get information about the current system and/or the domain. To automate as many internal penetrationtest processes (reconnaissance as well as exploitation) […]

Meet ACbackdoor malware targeting Linux and Windows devices

Recently, a malware by the name of ACbackdoor has been discovered which infects both Windows and Linux based systems. With little to no documentation of its origin, it has capabilities for pretty complex operations which include arbitrary execution of shell commands, updating, arbitrary binary execution, and persistence. Although both of the variants have different backdoor […]

Multi-Platform Malware “ACBackdoor” Attack Both Windows & Linux Users PC by Executing Arbitrary Code

Researchers discovered a previously undetected multi-platform malware called ACbackdoor that has both Linux and Windows Variant to infect the respective users and steal sensitive information. Dubbed ACbackdoor Linux variant has a completely no detection rate while the Windows variant has a higher detection rate than the Linux variant. Researchers believe that the ACbackdoor variant is […]

Microsoft’s Algorithm Will Fix “High Disk Usage” Due To Windows Search

With the release of Windows Insider Build 19025 (20H1), Microsoft has introduced an algorithm to better fix the shortcomings of the Search indexer in Windows 10. Back in 2018, some Insiders turned off the Windows Search indexer on their machines. When Microsoft asked why, the user feedback revealed that high disk usage, high CPU usage, […]

New Malware Attack Drops Double Remote Access Trojan in Windows to Steal Chrome, Firefox Browsers Data

Researchers discovered a new malware campaign that drops two different Remote Access Trojan(RAT) on targeted Windows systems and steal sensitive information from popular browsers such as Chrome and Firefox. The samples that uncovered by Fortinet researchers drop the RevengeRAT and WSHRAT malware and it has various obfuscation functionalities that use the various stage to maintain […]

PureLocker Ransomware Attack Enterprise Production Servers and Encrypt Files in Windows, Linux, & macOS

Researchers discovered a new PureLocker Ransomware that capable of encrypting files in Windows, Linux, and macOS. The ransomware used by threat actors to perform a targeted attack against production servers of the enterprise networks. Code reuse analysis against Purelocker reveals that the ransomware related to the “more_eggs”,  a backdoor malware often used by Cobalt Gang, FIN6 […]

RaaS – Hackers Selling Buran Ransomware in Russian Forum That Encrypt All Version of Windows OS & Windows Server

Researchers uncovered a new ransomware family named “Buran” ransomware that works as a Ransomware-as-a-Service(RaaS) model and actively selling in a well-known Russian forum. Ransomware authors advertising in well known Russian underground forums and the Buran Ransomware compatible with all versions of the Windows OS and Windows server. Unlike other RaaS based ransomware such as GandCrab that earned […]

Titanium APT Hackers Inject New Hidden Backdoor on Windows Using Fileless Technique

A new wave of malware attack strikes again from the Titanium APT group that infects windows with hidden backdoor by mimicking common legitimate software and fileless technique. Titanium APT is one of the technologically advanced hacking group, they are using the various sophisticated technique to attack the target, and their method of attack makes very […]

This Hacker Managed To Run Windows 10 IoT Core On A Calculator

We have already seen Windows XP booting on Nintendo Switch and Windows 10 running on OnePlus 6T. This time a developer has managed to run Windows 10 on a calculator (via Windowslatest). The calculator, in this case, isn’t a basic or scientific calculator that we see commonly. The pictures posted by the developer shows an […]

Donut – Generates X86, X64, Or AMD64+x86 Position-Independent Shellcode That Loads .NET Assemblies, PE Files, And Other Windows Payloads From Memory

Donut generates x86 or x64 shellcode from VBScript, JScript, EXE, DLL (including .NET Assemblies) files. This shellcode can be injected into an arbitrary Windows processes for in-memory execution. Given a supported file type, parameters and an entry point where applicable (such as Program.Main), it produces position-independent shellcode that loads and runs entirely from memory. A […]