Derp | Security Research
Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.
Security News
Exposed Robobox Infrastructure Links AI-Assisted Malware Toolkit to Coruna iOS C2opens in a new tab
Netaskari Substack
CrySyS Lab Introduces EMBeD Benchmark for IoT Malware Detectionopens in a new tab
malware.news
Leaked AWS IAM Key Used to Steal and Resell Paid Bedrock AI Accessopens in a new tab
Cyber Security
DPRK-Linked Contagious Interview Uses Trojanized macOS Installers to Deploy OtterCookieopens in a new tab
Lazarusholic Bluesky
Signed Shift Browser Adware Fingerprints Hosts Before Installing Browser Payloadopens in a new tab
Heimdalsecurity Com Threat Center
MECCHA CHAMELEON Steam Workshop Maps Enabled Two-Click RCEopens in a new tab
Aikido Dev
Wyden Urges NSA Warning That Single-Hop VPNs Enable Traffic Correlationopens in a new tab
malware.news
Goja TypedArray Memory Corruption Enables RCE in Zendesk and Nucleiopens in a new tab
Slcyber
Path Traversal and Upload Path Tampering in Telerik UI for ASP.NET AJAXopens in a new tab
malware.news
Russian National Extradited Over Freelancer Platform Malware Campaignopens in a new tab
Infosecurity Magazine
TukTuk Framework Enables Credential Theft and EDR Evasion for Gentlemen Ransomwareopens in a new tab
Cyber Security
Gambling Goblin Hijacks Brazilian Websites for Gambling SEO Fraudopens in a new tab
Infosecurity Magazine
Public Exploit Targets Cleo Harmony JWT Authentication Bypassopens in a new tab
Cyber Security
Knight Office AiTM Kit Steals Microsoft 365 Sessions and Establishes Entra Persistenceopens in a new tab
IT Security Guru
Kimsuky Uses Seafood Purchase Lure to Deploy Backblaze B2-Backed Malwareopens in a new tab
Lazarusholic Bluesky
AI-Assisted Ransomware Attack Compromised Enterprise via Public APIopens in a new tab
Unit 42
ExfilSquad Extorts UK Institutions With Stolen Cloud and CRM Dataopens in a new tab
malware.news
International Operation Sinkholes Sality Botnet and Seizes Payload Domainsopens in a new tab
Help Net Security
SafePay Ransomware Abuses OneDrive for Stealthy Data Exfiltrationopens in a new tab
malware.news
Microsoft to Enable Memory Integrity by Default on Eligible Windows 11 PCsopens in a new tab
Windowslatest
Actively Exploited SonicWall SMA1000 Flaws Enable SSRF and Command Executionopens in a new tab
BleepingComputer
Email Parsing Flaws Let Attackers Hijack AI Customer-Service Agentsopens in a new tab
Intigriti
Counterfeit Software Installers Deliver Silver Fox-Like Malware Campaignopens in a new tab
malware.news
Nexus Dark-Web Service Sells 153 Million Driver’s License Scansopens in a new tab
malware.news
Ransomware Groups Recruit Insiders for Corporate Network Accessopens in a new tab
Dark Reading
Phishing Campaign Abuses Faronics Deploy to Install ScreenConnectopens in a new tab
BleepingComputer
Leaked Bauman Records Expose Russian Military Cyber Recruitment Pipelineopens in a new tab
Gbhackers
Critical JFrog Artifactory Authentication Bypass Exploited for Admin Tokensopens in a new tab
Decipher Sc
Malicious npm Dependency Chain Delivers Cross-Platform Remote-Access Trojanopens in a new tab
Lazarusholic Bluesky
Chameleon SEO Poisoning Drives Banking Phishing Pages Above Search Resultsopens in a new tab
Knowbe4
ClickFix Campaign Abuses ChatGPT Links to Deploy NetSupport Remote-Access Malwareopens in a new tab
Cyber Security
Active Exploitation of Sangoma Switchvox SQL Injection Enables RCEopens in a new tab
Reddit Netsec
Attackers Exploit Critical Langflow RCE to Harvest Cloud and SSH Credentialsopens in a new tab
SecurityWeek
Indian Data Broker Sells Unauthorized KYC Records via Telegram and APIopens in a new tab
malware.news
Chrome Web Store Permanently Removes Manifest V2 Extensionsopens in a new tab
Thecybersecguru
BREEZE COMET Targets Brazilian Financial Networks for Fraudulent Transfersopens in a new tab
Mandiant
Trojanized Exodus Wallet Installer Deploys Modular Memory-Resident RATopens in a new tab
Huntress
MCPJacking Exposes 155 Stale MCP Registry Entries to Domain Takeoversopens in a new tab
Cyberveille
OEMPocalypse Exploit Chains Achieve Kernel Compromise on Major Android OEMsopens in a new tab
malware.news
Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attemptopens in a new tab
The Record Media
Rogue Free LLM Endpoint Captures Coding-Agent Context and Tool Accessopens in a new tab
malware.news
White House Launches Texas Water-System Cybersecurity Pilotopens in a new tab
Cyberscoop
Manic Android Trojan Relays Stolen Banking Data Through Nearby Devicesopens in a new tab
Kaspersky
Dependency Cooldowns Limit Exposure to Malicious Package Releasesopens in a new tab
The New Stack
Trojanized Packagist Themes Use FUNNULL-Hosted iPhone Spyware Chainopens in a new tab
Socket
Orova Claims Theft of 150,000 Cardiology Associates Patient Recordsopens in a new tab
malware.news
Global Ransomware Activity Reaches 2026 High With 894 July Victimsopens in a new tab
Zdnet
OpenClaw 2.0 Adds Credential, Plugin and AI-Agent Security Controlsopens in a new tab
Cyber Security
ValleyRAT Backdoor Delivered Through Trojanized QN Wallpaper Adwareopens in a new tab
malware.news
Spring Ring Uses Microsoft Teams Vishing to Pursue Domain Compromiseopens in a new tab
Unit 42
Nigerian Sextortion Suspects Extradited to Face Charges Linked to Teen Deathsopens in a new tab
BleepingComputer
China-Linked Fire Ant Abuses Trusted Infrastructure for Espionageopens in a new tab
The Hacker News
Fraudulent School Websites Target Students, Parents and Educatorsopens in a new tab
malware.news
Automated Bots Consume Nearly All git.kernel.org Trafficopens in a new tab
Opennet
TerminalFix ClickFix Campaign Establishes Reverse-Tunnel Access Through Compromised Hostsopens in a new tab
malware.news
McKesson Investigates Data Theft Claim After Third-Party Application Breachopens in a new tab
malware.news
OpenAPI React Query Codegen npm Releases Deliver Credential-Stealing Supply-Chain Malwareopens in a new tab
StepSecurity
Magecart Skimmers Abuse Stripe APIs and Ethereum Contracts for Payload Deliveryopens in a new tab
Confiant
KubeCap Identifies Excess Linux Capabilities in Kubernetes Workloadsopens in a new tab
Linuxsecurity
X Dismantles Suspected China-Linked Bot Farm Targeting AI Data-Center Debateopens in a new tab
Foxbusiness
Zoom macOS ZoomOpener Flaw Enabled Website-Triggered RCEopens in a new tab
Slcyber
Unauthenticated File Disclosure in Sitecore Can Lead to Remote Code Executionopens in a new tab
Slcyber
Great Firewall DNS Poisoning Enables Domain Hijacking and XSS Risksopens in a new tab
Slcyber
Citrix Bleed CVE-2023-4966 Leaks NetScaler Session Tokensopens in a new tab
Slcyber
Craft CMS RCE Exploits PHP argv Handling and FTP Template Loadingopens in a new tab
Slcyber
Cloudflare Pages Flaws Exposed Git Credentials and Enabled Container-to-Host Accessopens in a new tab
Slcyber
Citrix ADC CVE-2023-3519 Analysis Identifies Pre-Auth Memory-Corruption Pathsopens in a new tab
Slcyber
Metabase Setup Token Flaw Enables Unauthenticated Remote Code Executionopens in a new tab
Slcyber
Unauthenticated RCE in Citrix ShareFile StorageZones Controlleropens in a new tab
Slcyber
Flarum Avatar Flaw Enables Local File Disclosure and Blind SSRFopens in a new tab
Slcyber
CISA Flags Actively Exploited ownCloud, Linux Kernel and JFrog Artifactory Flawsopens in a new tab
Security Affairs
Root Backdoors Found in Globally Rebranded ZBT Router Firmwareopens in a new tab
Heise
Critical cPanel Flaw Lets Hosting Users Escalate to Root Server Controlopens in a new tab
The Hacker News
Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNsopens in a new tab
Csirt Italia
Trackers
Distribution
- 12,070
- unique hosts seen in 7 days
- 185
- families in the feed
Malware C2
- 4,498
- unique C2 hosts seen in 7 days
- 262
- families in the feed
PhaaS
- 16,045
- domains under tracking
- +1,669
- added in the last 7 days
ClickFix
- 25,223
- domains under tracking
- +2,078
- added in the last 7 days
Ransomware
- 246
- victims named in 7 days
- 86
- groups active in 30 days
npm
- 116
- releases flagged in 7 days
- 80
- confirmed malicious
Latest Research
8 min read
ClickFix via Cloudflare Zaraz and the BW Panel
A malicious Cloudflare Zaraz action on edgeupstudio[.]com loaded an ErrTraffic BW Panel bootstrap that looked up its panel address in a Polygon contract.
11 min read
1,509 WordPress sites feed an active SocGholish chain
One integrated WordPress-to-GhoLoader operation mapped to Proofpoint's TA2726 and TA569/SocGholish labels, followed by ClickFix on shared hosts.
15 min read
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.
23 min read
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor
Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.