ClickFix lures deliver the ChainScript RAT, which uses a Polygon smart contract to locate active WebSocket ...
Im Zentrum des Angriffs steht der Kernel-Treiber Alinubx.sys. Um einer Entdeckung zu entgehen, tarnt sich die Datei als ...
Windows向け情報窃取マルウェア「Rapuncel」を配布するキャンペーンが確認された。攻撃では、Microsoftの認証を受けたカーネルドライバーを利用し、ウイルス対策ソフトやEDRに関連する145のプロセスを停止させたうえで、ブラウザーの認証情報や暗号資産ウォレットのデータなどを収集する。
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
ChainScript RAT arriva tramite ClickFix, usa Node.js e un contratto Polygon per risolvere dinamicamente il C2 e mantenere accesso remoto persistente.
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results