Derp | Security Research
Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.
Security News
Path Traversal and Upload Path Tampering in Telerik UI for ASP.NET AJAXopens in a new tab
malware.news
Russian National Extradited Over Freelancer Platform Malware Campaignopens in a new tab
Infosecurity Magazine
TukTuk Framework Enables Credential Theft and EDR Evasion for Gentlemen Ransomwareopens in a new tab
Cyber Security
Gambling Goblin Hijacks Brazilian Websites for Gambling SEO Fraudopens in a new tab
Infosecurity Magazine
Public Exploit Targets Cleo Harmony JWT Authentication Bypassopens in a new tab
Cyber Security
Knight Office AiTM Kit Steals Microsoft 365 Sessions and Establishes Entra Persistenceopens in a new tab
IT Security Guru
Kimsuky Uses Seafood Purchase Lure to Deploy Backblaze B2-Backed Malwareopens in a new tab
Lazarusholic Bluesky
AI-Assisted Ransomware Attack Compromised Enterprise via Public APIopens in a new tab
Unit 42
ExfilSquad Extorts UK Institutions With Stolen Cloud and CRM Dataopens in a new tab
malware.news
International Operation Sinkholes Sality Botnet and Seizes Payload Domainsopens in a new tab
Help Net Security
SafePay Ransomware Abuses OneDrive for Stealthy Data Exfiltrationopens in a new tab
malware.news
Microsoft to Enable Memory Integrity by Default on Eligible Windows 11 PCsopens in a new tab
Windowslatest
Actively Exploited SonicWall SMA1000 Flaws Enable SSRF and Command Executionopens in a new tab
BleepingComputer
Counterfeit Software Installers Deliver Silver Fox-Like Malware Campaignopens in a new tab
malware.news
Nexus Dark-Web Service Sells 153 Million Driver’s License Scansopens in a new tab
malware.news
Ransomware Groups Recruit Insiders for Corporate Network Accessopens in a new tab
Dark Reading
Phishing Campaign Abuses Faronics Deploy to Install ScreenConnectopens in a new tab
BleepingComputer
Leaked Bauman Records Expose Russian Military Cyber Recruitment Pipelineopens in a new tab
Gbhackers
Critical JFrog Artifactory Authentication Bypass Exploited for Admin Tokensopens in a new tab
Decipher Sc
Malicious npm Dependency Chain Delivers Cross-Platform Remote-Access Trojanopens in a new tab
Lazarusholic Bluesky
Chameleon SEO Poisoning Drives Banking Phishing Pages Above Search Resultsopens in a new tab
Knowbe4
ClickFix Campaign Abuses ChatGPT Links to Deploy NetSupport Remote-Access Malwareopens in a new tab
Cyber Security
Active Exploitation of Sangoma Switchvox SQL Injection Enables RCEopens in a new tab
Reddit Netsec
Attackers Exploit Critical Langflow RCE to Harvest Cloud and SSH Credentialsopens in a new tab
SecurityWeek
Indian Data Broker Sells Unauthorized KYC Records via Telegram and APIopens in a new tab
malware.news
Chrome Web Store Permanently Removes Manifest V2 Extensionsopens in a new tab
Thecybersecguru
BREEZE COMET Targets Brazilian Financial Networks for Fraudulent Transfersopens in a new tab
Mandiant
Trojanized Exodus Wallet Installer Deploys Modular Memory-Resident RATopens in a new tab
Huntress
OEMPocalypse Exploit Chains Achieve Kernel Compromise on Major Android OEMsopens in a new tab
malware.news
Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attemptopens in a new tab
The Record Media
Rogue Free LLM Endpoint Captures Coding-Agent Context and Tool Accessopens in a new tab
malware.news
White House Launches Texas Water-System Cybersecurity Pilotopens in a new tab
Cyberscoop
Manic Android Trojan Relays Stolen Banking Data Through Nearby Devicesopens in a new tab
Kaspersky
Dependency Cooldowns Limit Exposure to Malicious Package Releasesopens in a new tab
The New Stack
Trojanized Packagist Themes Use FUNNULL-Hosted iPhone Spyware Chainopens in a new tab
Socket
Orova Claims Theft of 150,000 Cardiology Associates Patient Recordsopens in a new tab
malware.news
Global Ransomware Activity Reaches 2026 High With 894 July Victimsopens in a new tab
Zdnet
OpenClaw 2.0 Adds Credential, Plugin and AI-Agent Security Controlsopens in a new tab
Cyber Security
ValleyRAT Backdoor Delivered Through Trojanized QN Wallpaper Adwareopens in a new tab
malware.news
Spring Ring Uses Microsoft Teams Vishing to Pursue Domain Compromiseopens in a new tab
Unit 42
Nigerian Sextortion Suspects Extradited to Face Charges Linked to Teen Deathsopens in a new tab
BleepingComputer
China-Linked Fire Ant Abuses Trusted Infrastructure for Espionageopens in a new tab
The Hacker News
Fraudulent School Websites Target Students, Parents and Educatorsopens in a new tab
malware.news
Automated Bots Consume Nearly All git.kernel.org Trafficopens in a new tab
Opennet
TerminalFix ClickFix Campaign Establishes Reverse-Tunnel Access Through Compromised Hostsopens in a new tab
malware.news
McKesson Investigates Data Theft Claim After Third-Party Application Breachopens in a new tab
malware.news
OpenAPI React Query Codegen npm Releases Deliver Credential-Stealing Supply-Chain Malwareopens in a new tab
StepSecurity
Magecart Skimmers Abuse Stripe APIs and Ethereum Contracts for Payload Deliveryopens in a new tab
Confiant
KubeCap Identifies Excess Linux Capabilities in Kubernetes Workloadsopens in a new tab
Linuxsecurity
X Dismantles Suspected China-Linked Bot Farm Targeting AI Data-Center Debateopens in a new tab
Foxbusiness
CISA Flags Actively Exploited ownCloud, Linux Kernel and JFrog Artifactory Flawsopens in a new tab
Security Affairs
Root Backdoors Found in Globally Rebranded ZBT Router Firmwareopens in a new tab
Heise
Critical cPanel Flaw Lets Hosting Users Escalate to Root Server Controlopens in a new tab
The Hacker News
Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNsopens in a new tab
Csirt Italia
CISA Finds Known Internet-Exposed Flaws Drive Most Damaging Compromisesopens in a new tab
Security Online Info
Log4Shell RCE in Apache Log4j Exposes Java Applicationsopens in a new tab
Tenable Nessus Plugins
Agentic AI Enables Rapid Enterprise Attacks and Expands Threat Actor Capabilityopens in a new tab
Cyberscoop
Dark-Web Marketplaces Sell Corporate Executive SSNs for $0.25opens in a new tab
Cyber Security
PaperCut NG/MF Zero-Day Exploited on Internet-Exposed Serversopens in a new tab
BleepingComputer
Manchester Airports Group Customer Data Stolen in Cybersecurity Incidentopens in a new tab
BleepingComputer
AI Coding Agents Installed Unclaimed Packages Referenced in llms.txt Filesopens in a new tab
Arstechnica Security
Criminal Forums Commercialize AI Tools for Ransomware and Spear-Phishingopens in a new tab
Knowbe4
CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Red Hat Flawsopens in a new tab
Infosecurity Magazine
Misconfigured AD CS Templates Enable Domain Privilege Escalationopens in a new tab
Guidepoint Security
Polymorphic JavaScript Phishing Page Evades Detection and Can Hang Browsersopens in a new tab
malware.news
ICS Malware Blocking Falls to Four-Year Low as Email Threats Riseopens in a new tab
Securelist
Trackers
Distribution
- 12,587
- unique hosts seen in 7 days
- 190
- families in the feed
Malware C2
- 4,648
- unique C2 hosts seen in 7 days
- 269
- families in the feed
PhaaS
- 15,756
- domains under tracking
- +1,504
- added in the last 7 days
ClickFix
- 24,990
- domains under tracking
- +2,126
- added in the last 7 days
Ransomware
- 253
- victims named in 7 days
- 85
- groups active in 30 days
npm
- 126
- releases flagged in 7 days
- 76
- confirmed malicious
Latest Research
8 min read
ClickFix via Cloudflare Zaraz and the BW Panel
A malicious Cloudflare Zaraz action on edgeupstudio[.]com loaded an ErrTraffic BW Panel bootstrap that looked up its panel address in a Polygon contract.
11 min read
1,509 WordPress sites feed an active SocGholish chain
One integrated WordPress-to-GhoLoader operation mapped to Proofpoint's TA2726 and TA569/SocGholish labels, followed by ClickFix on shared hosts.
15 min read
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.
23 min read
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor
Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.