Skip to content
Threat Feed

Severity

rumour 9 briefs RSS
rumour rumour

HEAVYGRAM Telegram-based Surveillance Backdoor

HEAVYGRAM is a Windows-based surveillance backdoor used by Handala Hack that utilizes the Telegram API for command-and-control communication to facilitate remote information theft and system monitoring.

Handala Hack backdoor surveillance c2 telegram
1t
rumour rumour

SparroWock Backdoor Analysis

SparroWock is a backdoor malware that utilizes custom command-and-control communication mechanisms to execute arbitrary commands on compromised Windows systems, establishing persistence to maintain long-term access.

malware backdoor persistence command-and-control
2t
rumour rumour

SilkParasite Campaign Infrastructure Analysis

Analysis of the SilkParasite campaign reveals a 13-server command-and-control cluster facilitating the deployment of SpiceRAT against targets in Central Asia.

spicerat silkparasite command-and-control central-asia network-security threat-intelligence
1t
rumour rumour

Linux Local Privilege Escalation Detection Framework

This brief summarizes a detection engineering framework from Elastic Security Labs for identifying post-exploitation activity and system misconfigurations associated with Linux local privilege escalation.

linux detection-engineering privilege-escalation informational
1t
rumour rumour

Monitoring Malicious Use of SCCM Application Execution

This brief documents the execution mechanics of Microsoft System Center Configuration Manager (SCCM), identifying risks where adversary-controlled software or scripts are deployed through the SCCM client infrastructure.

System Center Configuration Manager execution enterprise-management windows monitoring
1t
rumour rumour

Abuse of Faronics Deploy for Remote Execution and Persistence

Threat actors are exploiting compromised Faronics Deploy management consoles to push malicious scripts and binaries, enabling unauthorized remote code execution and persistence across managed enterprise endpoints.

Faronics Deploy persistence remote-access execution privilege-escalation
1r 1t updated
rumour rumour

NachoMDM Vulnerability in Windows MDM Enrollment

NachoMDM is a vulnerability within the Windows Mobile Device Management (MDM) enrollment process that allows an attacker to achieve UAC bypass and execute arbitrary code with SYSTEM privileges.

Windows Mobile Device Management privilege-escalation windows mdm
2t
rumour rumour

Infrastructure Tracking of Chinese Malware Delivery Operations

This report catalogs domain infrastructure identified in ongoing malware delivery and command-and-control operations linked to Chinese-based threat actors, facilitating improved network-level detection and defensive blocking.

malware-delivery command-and-control threat-intelligence infrastructure-tracking
1t
rumour rumour

Lightweight Backdoor Uses desktop.ini Whitespace for C2 Configuration

A 12 KB Windows backdoor evades traditional detection by storing its command-and-control infrastructure within hidden whitespace characters inside standard desktop.ini configuration files.

backdoor obfuscation windows command-and-control
1t