2026 July(3) August(34) September(41) October(2) November(0) December(0) | STATISTICS (0) MALWARE TRAFFICS | YARA-X's 1.20.0 Wireshark 4.6.8 Released Wireshark 4.6.9 Released YARA-X's 1.21.0
| DATE | NAME | INFO | CATEGORIE | WEB | |
|
6.10.26 |
![]() |
ATOMIC MACOS (AMOS) STEALER INFECTION FROM MALICIOUS AD IMPERSONATING CLAUDE CODE |
Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. | MALWARE TRAFFICS | MALWARE TRAFFIC |
|
6.10.26 |
![]() |
User Agent Strings Curiosities | Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs. | Security | SANS |
|
6.10.26 |
![]() |
TTY Logs and the Data it Captures |
For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data. |
Security | SANS |
|
5.10.26 |
|
UAC-0277: ClickFix on compromised websites to spread LUNEXSTEALER | In September 2026, CERT-UA specialists discovered over 100 compromised websites to which malicious JavaScript code had been added by attackers. When visiting such a site, the user was shown a fake Cloudflare verification page, which, under the pretext of confirming that the visitor was a human, offered to execute a command. Executing the command resulted in downloading and installing an MSI package from a remote server (ClickFix technique). | BATTLE OF UKRAINE | BATTLE OF UKRAINE |
|
2.10.26 |
![]() |
Gotta breach 'em all! The journey of ShinyHunters | ShinyHunters has outlasted forum takedowns, multiple arrests, and its own founders' convictions. This report traces six years of activity and tactical evolution. From stolen S3 buckets to zero-day exploits, we attempted to explain why the brand keeps surviving what should have ended it. | APT | SEKOIA |