Tag: backdoor
-
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/tortoiseshell-new-backdoor-ssh/
-
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted developer tooling can be turned into an effective execution layer for malware while reducing the value of file-signature and hash-based detection. The…
-
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be…
-
Core Werewolf Hackers Deploy New CoreRAT Malware Against Russian Government and Defense Organizations
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector bodies and defense-industry organizations. The shift is notable because Core Werewolf, previously associated with the abuse of legitimate UltraVNC remote-access software and smaller custom backdoors, now operates a full-featured C++ RAT of its own.…
-
Russian Backdoor Found in Slovak Traffic Cameras
SMS Messages Could Enable Remote Access to Live Traffic Feeds. Slovakian cyber authorities have suspended the rollout of high-speed traffic cameras after a security investigation uncovered backdoors and multiple software weaknesses. The devices were reportedly rebranded versions of Russian-made cameras sold through a Cyprus-based company. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/russian-backdoor-found-in-slovak-traffic-cameras-a-32645
-
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent.The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate…
-
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.”When the module loads, it”¯locates”¯the bundled binary, marks it executable, and launches it as a detached background process,” TrendAI, Trend Micro’s First seen…
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
Attackers impersonate popular AI brands to spread malware
Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/
-
Supply-Chain-Angriff: Backdoor in millionenfach geladene Rust Crates eingeschleust
Angreifern ist es gelungen, mehrere populäre Rust Crates mit einer Backdoor-Malware zu verseuchen. Entwickler sollten dringend handeln. First seen on golem.de Jump to article: www.golem.de/news/supply-chain-angriff-backdoor-in-millionenfach-geladene-rust-crates-eingeschleust-2608-212158.html
-
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and Microsoft Copilot into convincing lures for infostealers, browser hijackers and remote-access backdoors. Sophos X-Ops reviewed 12 months of Managed Detection and Response (MDR) investigations, spanning July 2, 2025 to June 29, 2026. They…
-
China-Nexus Hackers Target Myanmar Diplomats With QUICAgent Go Backdoor via Malicious VHD Files
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based backdoor, dubbed QUICAgent, through Virtual Hard Disk (VHD) files disguised as benign images. The campaign relies on highly targeted social engineering. One malicious file, named TrainingAnnouncement.jpg, is not an image but a VHD container.…
-
Slowakei: Russische Backdoor in Verkehrskameras entdeckt
Tags: backdoorDie Slowakei hat im Rahmen eines Sanierungspakets 279 neue Verkehrskameras gekauft. Die Geräte kamen unerwartet aus Russland – inklusive Backdoor. First seen on golem.de Jump to article: www.golem.de/news/slowakei-russische-backdoor-in-verkehrskameras-entdeckt-2608-212088.html
-
RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors
The RAVEN offensive framework can turn compromised Elasticsearch and Kibana environments into durable data-theft and persistence operations. RAVEN, short for Reconnaissance & Attack on Vulnerable Elasticsearch Nodes, is an open-source modular framework built to assess Elasticsearch and Kibana security posture across reconnaissance, exploitation, exfiltration, persistence, and cleanup workflows. Its latest walkthrough focuses on post-exploitation against…
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
New PATCHCORD backdoor targets Afghan telecom and South Asian infrastructure
First seen on scworld.com Jump to article: www.scworld.com/brief/new-patchcord-backdoor-targets-afghan-telecom-and-south-asian-infrastructure
-
LiteLLM Supply-Chain Attack Technology, Banking and Healthcare the Most Affected
Tags: attack, backdoor, banking, credentials, cybersecurity, data-breach, finance, healthcare, supply-chain, technologyThe SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences. By compromising a…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
âš¡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed…
-
WordPress Plugins Compromised Without a Single File Change
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/
-
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/
-
Zbtlink denies backdoor claims amid firmware download pause
First seen on scworld.com Jump to article: www.scworld.com/brief/zbtlink-denies-backdoor-claims-amid-firmware-download-pause
-
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of…
-
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.Nothing here…
-
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to…
-
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/quickfox-vpn-targeted-in-long-standing-supply-chain-attack-delivering-fdmtp-backdoor
-
VulnCheck Warns That Chinese Zbtlink Routers Include a Backdoor
VulnCheck researcher say at least 100,000 Chinese-made Zbtlink routers around the world may include an intentionally implanted backdoor dubbed “Endlessdoors” that could give threat actors access to devices on the network. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/vulncheck-warns-that-chinese-zbtlink-routers-include-a-backdoor/

