Skip to content
.ca
sign in

DFIR · deception · detection

Posts I wrote, intel from the CTI pipeline, and redacted engagement reports from the honeypot fleet.

Proofpointabout 3 hours ago15 minLLM reporthigh

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service

Cruciferra is a sophisticated Mono-based crypter-as-a-service offering used by multiple cybercrime threat clusters to obfuscate and deliver commodity malware including AsyncRAT, XWorm, zgRAT, AgentTesla, and others. It employs DLL side-loading for initial execution, then applies extensive defense-evasion techniques including indirect syscalls, API/IAT unhooking, BYOVD-based EDR tampering via vulnerable kernel drivers, UAC bypass, and a modified Process Ghosting variant that patches EDR inspection functions. The crypter uses over 90 polymorphically generated custom encryption algorithms derived from components of established ciphers, significantly complicating static analysis and signature-based detection.

Canadian Centre for Cyber Securityabout 4 hours ago6 minLLM reporthigh

Cyber Centre Daily Advisory Digest — 2026-07-20 (7 advisories)

The Canadian Centre for Cyber Security published a daily advisory digest on 2026-07-20 compiling 7 vendor security advisories from IBM, Dell, Ubuntu, CISA ICS, Red Hat, GitHub, and Zimbra. The advisories address vulnerabilities across a broad range of enterprise software, server infrastructure, Linux kernels, industrial control systems, and collaboration platforms. No specific CVEs, exploit details, or threat actor information are provided in the digest; it serves as a patch management notification directing administrators to vendor advisories for remediation guidance.

Spiderlabsabout 7 hours ago7 minLLM reporthigh

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

Security researcher Nightmare-Eclipse publicly disclosed LegacyHive, an unpatched Local Privilege Escalation vulnerability in the Windows User Profile component. The flaw allows attackers to load other users' registry hives without requiring user credentials, potentially exposing application data and Windows Explorer history. The vulnerability affects all Windows desktop and server versions, including those updated with July 2026 Patch Tuesday, and remains unacknowledged and unpatched by Microsoft.

Check Pointabout 7 hours ago10 minLLM reportcritical

20th July – Threat Intelligence Report

This weekly threat intelligence report covers major breaches including Ernst & Young, Coca-Cola's Fairlife subsidiary, and Nihon Kotsu, along with a Jscrambler npm supply chain compromise. Six critical CVEs were disclosed across Microsoft, WordPress, and SonicWall products, with four under active exploitation by ransomware operators. AI-enabled threats are highlighted including China-linked actors using Claude Code and DeepSeek for automated attack generation, and weaknesses in AI coding assistants exposing source code and credentials. Threat actor campaigns from ShinyHunters, CylindricalCanine/GoldenEyeDog, and Spirals ransomware are also documented.

about 20 hours ago17 minRecapJul 13 – Jul 20

Weekly Recap — 2026-07-13 -> 2026-07-20

ClickFix Goes Industrial as Zero-Day Chains Shatter Perimeter Defenses ClickFix has matured from a clever social-engineering trick into a full criminal industry this week, with subscription-based attack kits and new variants targeting Mac users through Google ads for Claude AI chats. The technique tricks people into pasting malicious commands via fake CAPTCHA prompts, and because it leverages trusted system tools, endpoint security products are structurally blind to the execution chain. Multiple malware families including TELEPUZ, ACR Stealer, and MacSync Stealer adopted ClickFix as their delivery method, and their control servers increasingly hide on blockchains where takedown is nearly impossible. Attackers simultaneously punched through perimeter defenses with chained zero-day exploits: UTA0533 combined two SonicWall SMA flaws (CVE-2026-15409 and CVE-2026-15410) for root-level remote code execution on VPN appliances, while three chained vulnerabilities in Siemens ROX II industrial switches enable persistent root compromise. Microsoft confirmed two actively exploited zero-days (CVE-2026-56155 and CVE-2026-56164) in its July Patch Tuesday, and forgotten UEFI shim bootloaders undermine Secure Boot on most modern PCs. AI continues arming both sides — a solo criminal built a botnet in six minutes using Gemini, while Iranian state hackers accelerated phishing and malware development with LLMs. Defenders should immediately patch the two Microsoft zero-days already exploited in the wild, update any SonicWall SMA VPN appliances against the chained zero-day attack, and train staff that legitimate websites never ask you to copy-paste commands into Terminal or the Run dialog.

Volexity3 days ago14 minLLM reportcritical

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Volexity discovered threat actor UTA0533 exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to achieve root-level remote code execution. CVE-2026-15409 enables pre-auth SSRF via /wsproxy to tunnel to localhost services, while CVE-2026-15410 enables command injection via path traversal in the sysCtrl.execRemoveHotfix endpoint. The actor deployed custom malware including KNUCKLEBALL (Java agent injector), ORANGETAIL (webshell), and ROOTRUN (privilege escalation binary), then used tcpdump to capture LDAP credentials and attempted lateral movement from over 200 IP addresses.

Akamai3 days ago9 minLLM reporthigh

From Recon to Free Flights: Precision Prompt Attacks on AI Agents

The article details a precision prompt injection attack methodology against AI agents, using a fictional travel agent called 'Varda' as a case study. The attack follows a kill chain approach: reconnaissance to extract system prompt logic, enumerate tools, and learn data schemas; then weaponization to craft a fake payment confirmation that satisfies the agent's preconditions for booking flights. The core vulnerability is that the LLM treats conversation history as trusted context, allowing attackers to inject fabricated tool responses and fake assistant messages that bypass sequential validation checks, enabling unauthorized action execution without proper authorization.

Spiderlabs3 days ago12 minLLM reporthigh

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle (APT-C-36) has evolved its toolkit with three new obfuscation schemes, a GitHub-staged AutoIt3 RunPE loader, and a significantly upgraded AsyncRAT build codenamed JC-46 featuring WNF-based process injection, HVNC banking-fraud with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. A shared internal builder is evidenced by identical 'Photo Studio' persistence artifacts across three separately obfuscated toolchains. The group continues to rely on VBScript-to-PowerShell delivery chains and commodity RATs while selectively investing in components that directly serve banking-fraud objectives.

Elastic Security Labs3 days ago12 minLLM reporthigh

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs discovered a new Contagious Interview campaign (REF9403) attributed to DPRK-aligned threat actors that uses fake coding challenges to deliver malware hidden via SVG steganography. The trojanized repositories contain a four-stage JavaScript payload aligned with OTTERCOOKIE, combining browser credential/crypto wallet theft, file exfiltration, a Socket.IO RAT, and clipboard stealing. The malware uses obfuscator.io for code protection, custom Base64 decoding to evade detection, and masquerades as npm-cache processes while exfiltrating data to rightwidth.dev C2 infrastructure.

Canadian Centre for Cyber Security3 days ago7 minLLM reporthigh

Cyber Centre Daily Advisory Digest — 2026-07-17 (3 advisories)

The Canadian Centre for Cyber Security published three security advisories on 2026-07-17 covering critical vulnerabilities in FreePBX (unauthenticated RCE and SQL injection), VMware Avi Load Balancer (seven CVEs under VMSA-2026-0005), and Google Chrome for Desktop. All advisories urge immediate patching to the latest versions.

Zscaler ThreatLabz3 days ago9 minLLM reporthigh

GuLoader Malware Obfuscation Techniques Analyzed

GuLoader is a highly obfuscated malware-as-a-service downloader that has evolved since 2019 to deliver secondary payloads such as RATs and information stealers. It employs polymorphic code for dynamic constant construction, exception-based control flow obfuscation using five distinct CPU exception types, encrypted strings with stack-based decryption, and modified DJB2 API hashing. Payloads are hosted on trusted cloud platforms (Google Drive, OneDrive) to evade reputation-based detection, and the malware continues to receive updates increasing analysis complexity.

Palo Alto Networks3 days ago10 minLLM reportcritical

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A chained exploit comprising three zero-day vulnerabilities in Siemens ROX II OT switches allows an attacker to escalate from arbitrary file disclosure to full persistent root-level access. CVE-2025-40948 leverages a root-privileged xz utility to read any file on the filesystem, CVE-2025-40947 exploits unsanitized input in the feature key signature verification to achieve command injection as root, and CVE-2025-40949 enables persistent code execution by injecting commands into the root cron table via the web management task scheduler. Siemens has released firmware V2.17.1 to address all three vulnerabilities.

Microsoft3 days ago11 minLLM reporthigh

ACR Stealer: Two observed intrusion chains amid increased threat activity

Microsoft Defender Experts identified two prevalent ClickFix-based intrusion chains delivering ACR Stealer, a MaaS information stealer rebranded from Amatera Stealer. Campaign 1 leverages rundll32-driven WebDAV DLL loading, obfuscated PowerShell, Python loaders, scheduled-task persistence, and Fiber-API in-memory shellcode execution, with a subset using blockchain RPC endpoints (EtherHiding) as dead-drop C2 resolvers. Campaign 2 achieves near-fully fileless execution via MSHTA/COM-launched PowerShell that retrieves a payload hidden in JPEG steganography and executes it reflectively in memory, with both chains ultimately harvesting browser credentials, DPAPI secrets, and sensitive documents for exfiltration.

Reversinglabs4 days ago10 minLLM reporthigh

The tale of ClickFix: 5 takeaways from RL’s new threat report

ClickFix is a social engineering technique that uses fake CAPTCHA pages to trick users into pasting malicious commands into Run dialogs or terminals, executing payloads in memory via LOLBins without triggering traditional AV or EDR signatures. The threat has commoditized through MaaS subscriptions ($250–$1,800), expanded its payload catalog beyond infostealers to include RATs, loaders, and rootkits, and is actively evolving with variants like CrashFix, FileFix, PromptFix, and ConsentFix. ReversingLabs released an open-source multi-condition YARA rule that detects ClickFix lures by correlating fake verification characteristics, PowerShell payload indicators, and clipboard manipulation before payload execution.

Reversinglabs4 days ago10 minLLM reporthigh

ClickFix doesn't attack your knowledge. It attacks your trust.

ClickFix is a mature Malware-as-a-Service attack methodology that uses fake verification prompts to silently poison the user's clipboard with malicious commands, which are then pasted into Windows Run or macOS Terminal. The execution chain relies entirely on living-off-the-land binaries (PowerShell, mshta.exe, curl, rundll32.exe), making it invisible to traditional EDR and AV tooling. A specific watering hole attack on a university site delivered zuhe.dll, a Go-based RAT, using blockchain-based C2 via Ethereum smart contracts to evade infrastructure takedowns.

Canadian Centre for Cyber Security4 days ago10 minLLM reporthigh

Cyber Centre Daily Advisory Digest — 2026-07-16 (7 advisories)

The Canadian Centre for Cyber Security published 7 security advisories on July 16, 2026, covering Zoom, Splunk, JetBrains, Grafana, Microsoft, and Fortinet products. The most critical items are three Microsoft CVEs (CVE-2026-56164, CVE-2026-56155, CVE-2026-58644) and three Fortinet FortiSandbox CVEs (CVE-2026-25089, CVE-2026-39813, CVE-2026-39808) that have been confirmed as actively exploited and added to CISA's Known Exploited Vulnerabilities database. Splunk Enterprise also has critical vulnerabilities including a CSRF-based SPL command bypass and a path traversal in the App Install REST endpoint.

Spiderlabs4 days ago11 minLLM reporthigh

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

A large-scale ClickFix campaign compromises hundreds of WordPress websites to deliver a macOS infostealer via fake Cloudflare CAPTCHA overlays. The campaign uses a Polygon blockchain smart contract to store the C2 URL, making it resistant to DNS takedowns. Victims are tricked into pasting a Terminal command that downloads an in-memory payload via curl, which uses osascript to harvest Keychain data, browser credentials, SSH keys, and screenshots before exfiltrating them in chunks to an attacker-controlled server.

Mandiant4 days ago9 minLLM reportlow

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

This article provides a structural blueprint for safely integrating LLM agents into vulnerability management workflows, covering both enterprise vulnerability management and product security tracks. It outlines operational guardrails including pre-agent data security, workload isolation, least-privileged machine identities, toxic flow analysis, and supply chain resilience for AI skills. The guidance emphasizes that LLMs augment but do not replace deterministic controls, human threat modeling, and secure-by-design principles, and recommends phasing memory-safe languages into new development as a long-term strategy.

Kaspersky4 days ago12 minLLM reporthigh

HelloNet campaign — new malicious modules launched through the ViPNet update system

The HelloNet campaign is an active APT operation targeting large Russian organizations through the ViPNet secure networking software suite. Attackers achieve persistence by placing a malicious wtsapi32.dll in the ViPNet Update System directory, which is sideloaded by itcsrvup64.exe at OS startup. The loader (HelloInjector) injects into svchost.exe and deploys a modular toolkit including a network proxy, command executor, log cleaner, and a Rust-based backdoor. The campaign uses renamed PuTTY/Plink utilities for SSH reverse tunneling to C2 servers and employs IOCTL hooking to evade user-mode security solutions.

Fortinet4 days ago13 minLLM reporthigh

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

A global phishing campaign active since late March 2026 deploys heavily obfuscated JScript droppers that launch LuaJIT or AutoIt-based loaders disguised as TrueType Font (.ttf) files to deliver multiple RATs and infostealers including Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant dubbed Best Private LOGGER. The Lua loader leverages LuaJIT's Foreign Function Interface to call native Windows APIs for in-memory shellcode execution, employing advanced evasion techniques such as decoy memory allocation, Donut header patching, AMSI/ETW bypass, API unhooking, and VEH-based segmented shellcode decryption. The campaign has evolved from October 2025 through June 2026 with progressively more sophisticated anti-analysis capabilities.