ChainScript RAT arriva tramite ClickFix, usa Node.js e un contratto Polygon per risolvere dinamicamente il C2 e mantenere accesso remoto persistente.
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
ClickFix lures deliver the ChainScript RAT, which uses a Polygon smart contract to locate active WebSocket ...
Windows向け情報窃取マルウェア「Rapuncel」を配布するキャンペーンが確認された。攻撃では、Microsoftの認証を受けたカーネルドライバーを利用し、ウイルス対策ソフトやEDRに関連する145のプロセスを停止させたうえで、ブラウザーの認証情報や暗号資産ウォレットのデータなどを収集する。
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
Rapuncel infostealer campaign stole browser passwords and crypto wallet data from Windows users after a Microsoft-signed kernel driver killed 145 antivirus and EDR tools -- the same driver that scored ...
Welcome to the swamp of programming languagesAbout the authorA kemomimi (animal ears) enthusiast who mainly inhabits VRChat ...
เตือนภัย มัลแวร์ ClickFix ปลอมเป็น CAPTCHA หลอกเหยื่อกด Win+R รันคำสั่งผ่าน PowerShell แอบขโมยรหัสผ่านและคุกกี้ไปแบบไม่รู้ตัว ...
2026年9月第三週的資安新聞熱點,聚焦歐盟CRA通報義務上路、AI安全爭議升溫與個資保護監管強化;針對網路、應用程式與端點的漏洞利用攻擊持續頻傳,國內外亦接連傳出企業遭駭,特別是義大利醫療機構遭勒索軟體攻擊造成多項醫療服務中斷近兩週,商周集團網站復 ...