TASK#STOMP deploys a PowerShell backdoor that steals documents and Wi-Fi passwords, monitors files, and executes remote commands.
The TASK#STOMP backdoor steals office documents on Windows PCs, grabs new files as they're saved, and can rebuild itself if partly removed.
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
ClickFix lures deliver the ChainScript RAT, which uses a Polygon smart contract to locate active WebSocket ...
PowerShell malware hides XMRig payloads in the Registry, PNGs, and WAV files, enabling stealthy cryptomining and memory-only ...