Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
ClickFix lures deliver the ChainScript RAT, which uses a Polygon smart contract to locate active WebSocket ...
PowerShell malware hides XMRig payloads in the Registry, PNGs, and WAV files, enabling stealthy cryptomining and memory-only ...
When running PowerShell from automation tools or agents, operations requiring administrator privileges will fail silently. Sometimes no error is produced. You might think it succeeded, but in reality, ...
ConclusionEven if the syntax is correct, it is safer not to execute PowerShell scripts created by AI directly on production ...
Transparent Tribe uses four newly identified malware families in attacks on government and defense entities in India and Afghanistan.
Pakistan-linked threat actor APT36 has launched a new cyber campaign targeting government and defense organizations in India and Afghanistan.
IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the ...
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.
Apart from email and files, the script also pulls numbers such as my bank balance from Standard Chartered Bank through an API ...
Researchers have uncovered an exposed attacker-controlled staging server containing evidence of a wide-ranging intrusion ...