Derp | Security Research
Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.
Security News
CIA Cyber Intelligence Enabled Capture of Venezuela's Nicolás Maduroopens in a new tab
malware.news
Russian Developer Extradited Over $14.6 Million Bank Account-Takeover Schemeopens in a new tab
Cyberscoop
Microsoft Fixes 973 Flaws Including Two Exploited Windows Privilege Escalation Zero-Daysopens in a new tab
malware.news
Compromised Flutter Package Carries XCSSET Malware in Example Projectopens in a new tab
Aikido Dev
ChatGPT Sandbox Flaw Enabled Cross-Account Gmail Data Exfiltrationopens in a new tab
Cryptika
WeWorm Zero-Click WeChat Calls Could Hijack Accounts Across iOS and Androidopens in a new tab
Help Net Security
Social-Engineering Ring Accused of Stealing $240 Million in Bitcoinopens in a new tab
SecurityWeek
UTA-2026-024 Disables Endpoint Protection and Seizes Windows Domain Controlopens in a new tab
Cyber Security
ClickFix Campaigns Abuse Browser Scripts to Steal Cryptocurrency and Credentialsopens in a new tab
malware.news
Critical FreeIPA Flaw Chain Lets Anonymous LDAP Clients Gain Administrator Accessopens in a new tab
The Hacker News
N-able N-central Flaws Let Unauthenticated Attackers Create System Administratorsopens in a new tab
Rapid7
Qubes OS qvm-copy-to-vm Flaw Enabled Command Execution in Dom0opens in a new tab
Opennet
MacSync macOS Stealer Uses ClickFix Lures to Exfiltrate Credentialsopens in a new tab
malware.news
Panzer RaaS Targets Italian Firms With VMware ESXi Encryption Capabilityopens in a new tab
Cyber Security
ShinyHunters Breach Exposes 6.39 Million Odido and Ben Customer Recordsopens in a new tab
Cyber Security
AD RMS SLC Key Compromise Can Expose All Protected Documentsopens in a new tab
Huntress
Microsoft Fixes AD CS Flaw Allowing Local SYSTEM Privilege Escalationopens in a new tab
Msrc Microsoft
BigBear 2.0 AiTM Service Stole Microsoft 365 Credentials and MFA Sessionsopens in a new tab
malware.news
Bimbo Bakeries Employee Data Stolen Through Oracle EBS Zero-Dayopens in a new tab
Cyber Security
Mathspace Reporting-System Breach Exposes Data of 1.08 Million Usersopens in a new tab
Cyber Security
ConnectWise Warns of ScreenConnect File-Transfer Security Flawopens in a new tab
Cyber Security
BYOTC Hijacks Trusted Windows Clients to Abuse Privileged Driversopens in a new tab
Cyber Security
DPRK Cyber Program Split Into Six Lazarus-Linked Operational Clustersopens in a new tab
Infosecurity Magazine
Fake Minecraft Lithium Mod Delivers Myth Stealer RATopens in a new tab
Cyber Security
OpenVPN 2.7.7 Patches Remote DoS and Six Windows Security Flawsopens in a new tab
Cyber Security
N-able Patches Pre-Authentication RCE in N-centralopens in a new tab
Mkd Cirt
UK Cyber Bill Faces Calls for Executive Liability and AI Shutdown Powersopens in a new tab
Register Security
Russian GRU-Linked HOOKEDGE Backdoor Targets European Government and Defense Bodiesopens in a new tab
Cyber Security
vlt 1.0 Launches npm-Compatible Registry With Malware Blockingopens in a new tab
Infoq
Kimsuky Evolves GitHub PAT-Based LNK Campaign With AI-Generated Decoysopens in a new tab
Lazarusholic Bluesky
Critical Frontend Admin WordPress Plugin Flaw Enables Administrator Takeoveropens in a new tab
ThreatAft
StyleSmuggler Zero-Day Enables Unauthenticated RCE in Magento Storesopens in a new tab
Cyber Security
Windows PE TLS Callbacks Execute Code Before the Program Entry Pointopens in a new tab
malware.news
OpenAI-Identified Agents Used German Wiki to Coordinate Sandbox Evasionopens in a new tab
Register Security
US and UK Coordinate Takedowns of Southeast Asian Scam Centersopens in a new tab
The Record Media
PostGREShell Flaw Lets Replication Users Take Over PostgreSQL Serversopens in a new tab
The Hacker News
DPRK-Linked Actors Deploy HAProxy Backdoor and CurlRAT Against South Korean Firmsopens in a new tab
The Hacker News
Empty SMTP Envelope Sender Bypasses Microsoft 365 Direct Send Blockingopens in a new tab
SC World
DaVita Pays $15 Million to Settle Ransomware Data-Breach Lawsuitopens in a new tab
malware.news
TP-Link Archer AX55 Flaws Enable LAN Code Execution and Admin Password Decryptionopens in a new tab
Cyber Security
Microsoft Teams Will Obscure QR Codes in External Messages to Thwart Phishingopens in a new tab
Cyber Security
Botnet Takedowns Shrink DDoS Fleets as Attack Intensity Reaches 2.3 Tbit/sopens in a new tab
Itpro
Toy Ghouls Deploys HiveMQ and Matrix-Based Windows Backdoorsopens in a new tab
malware.news
PEEP Browser RAT Masquerades as Smart Bookmarks Chrome Extensionopens in a new tab
SOCRadar
Attackers Abuse Radmin and UltraVNC to Turn Korean Hosts Into Proxy Serversopens in a new tab
malware.news
ShinyHunters Vishing Attack Hits Jack Henry Internal Systemsopens in a new tab
Cyberveille
SSRF Exploitation of EC2 IMDSv1 Credentials Led to Unauthorized Amazon Bedrock Useopens in a new tab
Aws Security
Exposed Robobox Infrastructure Links AI-Assisted Malware Toolkit to Coruna iOS C2opens in a new tab
Netaskari Substack
CrySyS Lab Introduces EMBeD Benchmark for IoT Malware Detectionopens in a new tab
malware.news
Leaked AWS IAM Key Used to Steal and Resell Paid Bedrock AI Accessopens in a new tab
Cyber Security
DPRK-Linked Contagious Interview Uses Trojanized macOS Installers to Deploy OtterCookieopens in a new tab
Lazarusholic Bluesky
Signed Shift Browser Adware Fingerprints Hosts Before Installing Browser Payloadopens in a new tab
Heimdalsecurity Com Threat Center
MECCHA CHAMELEON Steam Workshop Maps Enabled Two-Click RCEopens in a new tab
Aikido Dev
Wyden Urges NSA Warning That Single-Hop VPNs Enable Traffic Correlationopens in a new tab
malware.news
Goja TypedArray Memory Corruption Enables RCE in Zendesk and Nucleiopens in a new tab
Slcyber
Path Traversal and Upload Path Tampering in Telerik UI for ASP.NET AJAXopens in a new tab
malware.news
Russian National Extradited Over Freelancer Platform Malware Campaignopens in a new tab
Infosecurity Magazine
TukTuk Framework Enables Credential Theft and EDR Evasion for Gentlemen Ransomwareopens in a new tab
Cyber Security
Gambling Goblin Hijacks Brazilian Websites for Gambling SEO Fraudopens in a new tab
Infosecurity Magazine
Public Exploit Targets Cleo Harmony JWT Authentication Bypassopens in a new tab
Cyber Security
Knight Office AiTM Kit Steals Microsoft 365 Sessions and Establishes Entra Persistenceopens in a new tab
IT Security Guru
Kimsuky Uses Seafood Purchase Lure to Deploy Backblaze B2-Backed Malwareopens in a new tab
Lazarusholic Bluesky
AI-Assisted Ransomware Attack Compromised Enterprise via Public APIopens in a new tab
Unit 42
ExfilSquad Extorts UK Institutions With Stolen Cloud and CRM Dataopens in a new tab
malware.news
International Operation Sinkholes Sality Botnet and Seizes Payload Domainsopens in a new tab
Help Net Security
SafePay Ransomware Abuses OneDrive for Stealthy Data Exfiltrationopens in a new tab
malware.news
Microsoft to Enable Memory Integrity by Default on Eligible Windows 11 PCsopens in a new tab
Windowslatest
Trackers
Distribution
- 15,937
- unique hosts seen in 7 days
- 205
- families in the feed
Malware C2
- 3,869
- unique C2 hosts seen in 7 days
- 252
- families in the feed
PhaaS
- 16,015
- domains under tracking
- +1,250
- added in the last 7 days
ClickFix
- 22,971
- domains under tracking
- +3,731
- added in the last 7 days
Ransomware
- 186
- victims named in 7 days
- 83
- groups active in 30 days
npm
- 85
- releases flagged in 7 days
- 85
- confirmed malicious
Latest Research
8 min read
ClickFix via Cloudflare Zaraz and the BW Panel
A malicious Cloudflare Zaraz action on edgeupstudio[.]com loaded an ErrTraffic BW Panel bootstrap that looked up its panel address in a Polygon contract.
11 min read
1,509 WordPress sites feed an active SocGholish chain
One integrated WordPress-to-GhoLoader operation mapped to Proofpoint's TA2726 and TA569/SocGholish labels, followed by ClickFix on shared hosts.
15 min read
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.
23 min read
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor
Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.