Tag
Zbtlink Router Firmware Contains Embedded ENDLESSDOORS Implant
3 TTPs 1 CVEZbtlink router firmware ships with the ENDLESSDOORS remote-control implant, which runs as root, masquerades as a kernel process, and enables unauthenticated remote command execution.
CastleLoader Malware Loader and ClearFake Activity in July 2026
3 rules 7 TTPs 7 IOCsRed Canary reports heightened activity of the CastleLoader malware loader, which uses paste-and-run techniques and legitimate tools to deliver infostealers and RATs, alongside continued prevalence of the ClearFake activity cluster in June 2026.
Unpacking 'Cruciferra': Analysis of a Sophisticated Crypter Service
1 rule 10 TTPs 11 IOCsCruciferra is a sophisticated crypter-as-a-service, written in Mono, actively developed and sold to multiple cybercriminal threat actors who use it to deliver a wide range of remote access trojans and infostealers, employing extensive defense evasion techniques like BYOVD-based EDR tampering, Process Ghosting, and unique cryptographic obfuscation via email-based phishing campaigns.
Detection of Malicious Remote Access Tools by Antivirus
1 rule 1 TTPThis brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.