Tag: backdoor
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
Tags: advisory, backdoor, cisa, cyber, data-breach, exploit, malicious, microsoft, remote-code-execution, update, vulnerabilityA newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in July 2026, alongside a CISA advisory, confirm that multiple vulnerabilities are already being weaponized against…
-
Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026. Daxin is a Windows kernel-mode rootkit that Symantec first documented…
-
20+ Hijacked Government Websites BecameӬan Attack Channel
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions.The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign First seen on thehackernews.com Jump to…
-
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig.Daxin (“srt64.sys”), as the kernel-mode rootkit is referred to, was first documented by Broadcom-owned Symantec in March 2022, with evidence indicating its use in targeted attacks…
-
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/
-
Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/
-
GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/gigawiper-threat-actors-choose-their-own-destructive-attack
-
Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects
Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers. First seen on hackread.com Jump to article: hackread.com/siggen-backdoor-windows-developers-visual-studio-projects/
-
Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects
Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers. First seen on hackread.com Jump to article: hackread.com/siggen-backdoor-windows-developers-visual-studio-projects/
-
A hardware security AI assistant that checks chips for hidden backdoors
Chip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/hardware-security-ai-assistant-hidden-backdoors/
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
CERT Warns of Unpatched Tenda Firmware Backdoor Allowing Admin Access
The CERT Coordination Center (CERT/CC) has disclosed a critical security issue affecting multiple Tenda networking devices. Tracked as CVE-2026-11405, the vulnerability stems from an undocumented backdoor in Tenda firmware that allows unauthenticated attackers to gain administrative access to a device’s web management interface. The flaw remains unpatched, prompting CERT to recommend immediate mitigation measures for…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
Hidden Backdoor in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-in-tenda-router-firmware-a-32181
-
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-roundcube-flaw-to-spy-on-academic-researchers/
-
Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device’s web management panel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/
-
Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web…
-
Kazuar Backdoor Uses DLL Side-Loading and PowerShell Loaders for Stealthy Execution
Turla’s Kazuar backdoor has re-emerged as a technically sophisticated persistence and reconnaissance tool that combines DLL side-loading with PowerShell-based loaders to achieve stealthy execution and resilient command-and-control. This side-loading technique minimizes disk activity tied to novel executables and leverages trusted host processes to bypass naive allowlists and detection heuristics. The delivery chain frequently uses multi-layered,…
-
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday.”An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process First seen on thehackernews.com…
-
Malicious Agent Skills Can Steal Credentials, Exfiltrate Source Code, and Install Backdoors
Malicious AI agent skills can be packaged to steal credentials, exfiltrate source code, and install backdoors while still bypassing many current skill-auditing systems. The paper finds that static scanners are especially weak against payload-preserving evasions, while runtime behavior auditing is far more resilient. The core threat is simple but serious: an agent skill is not…
-
Alibaba Reportedly Bans Claude Code Over Alleged Backdoor Risk in AI Coding Tool
Alibaba is reportedly preparing to ban the use of Anthropic’s Claude Code across its internal environments starting July 10. This decision comes in light of allegations that the AI-powered coding assistant has a covert detection mechanism resembling a backdoor. The news, first reported by the Chinese financial outlet Yicai and later confirmed by Reuters, has…
-
Cato CTRL entdeckt neuen Backdoor-Trojaner TencShell – TencShell-Backdoor imitiert Tencent-API-Verkehr zur Tarnung
First seen on security-insider.de Jump to article: www.security-insider.de/tencshell-backdoor-tencent-api-tarnung-china-a-472ef6cffdd0059e47cb06194e619b51/
-
Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll
A newly identified Windows backdoor, dubbed Mistic, that has been observed in intrusions since April 2026 and appears designed for stealthy, long-term access. The malware uses DLL sideloading, in-memory execution, and self-deletion to blend into enterprise environments and minimize forensic traces. Mistic is introduced via a DLL sideloading chain that abuses a legitimate executable named…
-
âš¡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open.The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cleanup waiting.Here’s the full Monday recap.âš¡ Threat of…
-
STOCKSTAY Malware Uses WebSocket C2, RSA Encryption, and Environmental Keying for Stealth
Analysis of a .NET backdoor tracked as STOCKSTAY exposes a mature, modular espionage implant actively developed and deployed by the Russia-linked Turla cluster since at least December 2022. STOCKSTAY demonstrates several operational techniques designed to maximize stealth and survivability: secure WebSocket-based C2, asymmetric encryption using a 4096-bit RSA keypair, inter-component IPC, and environment-based keying of…
-
Chinese APT CL1062 targets Southeast Asia with new TinyRCT backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/chinese-apt-cl-sta-1062-targets-southeast-asia-with-new-tinyrct-backdoor
-
Turla group deploys new STOCKSTAY backdoor against Ukraine and Italy
First seen on scworld.com Jump to article: www.scworld.com/brief/turla-group-deploys-new-stockstay-backdoor-against-ukraine-and-italy
-
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia.The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which Palo…

