Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Sophos17 days agoLLM reporthigh

Initial access techniques used by Iran-based threat actors

Iranian-linked threat actors consistently utilize a core set of cost-effective initial access techniques, including social engineering, rapid exploitation of known vulnerabilities, and credential abuse. These groups frequently leverage legitimate RMM tools and trusted cloud services to establish persistence and evade detection, highlighting the need for robust identity management, prompt patching, and perimeter security.

WithSecure17 days agoLLM reporthigh

The Changing Economics of Cybercrime-as-a-Service: What Defenders Need to Know

The cybercrime-as-a-service ecosystem is evolving rapidly, characterized by a shift towards trading live session tokens, the integration of generative AI for dynamic payload generation, and a preference for data exfiltration over encryption. Defenders must adapt by prioritizing identity monitoring, rapid session revocation, and recognizing the blurring lines between commodity cybercrime and state-aligned operations.

Microsoft17 days agoLLM reporthigh

Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

Storm-2561 is conducting a credential theft campaign leveraging SEO poisoning to distribute fake enterprise VPN clients. The attack utilizes digitally signed payloads and DLL side-loading to deploy the Hyrax infostealer, which harvests VPN credentials and configuration data before redirecting victims to legitimate software to evade detection.

ANY.RUN17 days agoLLM reporthigh

MicroStealer Analysis: A Fast-Spreading Infostealer with Limited Detection

MicroStealer is a newly identified, fast-spreading infostealer that targets sensitive corporate and personal data, including browser credentials, session cookies, and cryptocurrency wallets. It employs a sophisticated NSIS to Electron to Java execution chain, combined with obfuscation and anti-analysis checks, to maintain a low detection rate across security vendors.

Check Point17 days agoLLM reportcritical

“Handala Hack” – Unveiling Group’s Modus Operandi

Handala Hack, an Iranian MOIS-affiliated threat actor also known as Void Manticore, conducts destructive wiping and hack-and-leak operations against US, Israeli, and Albanian targets. The group leverages compromised VPN credentials for initial access, uses NetBird for internal tunneling, and deploys multiple parallel wiping techniques—including custom MBR wipers, PowerShell scripts, and VeraCrypt—distributed via Active Directory Group Policy.

Socket17 days agoLLM reportlow

GCVE Launches Decentralized Publishing Ecosystem for Vulnerability Disclosure

GCVE, operated by CIRCL, has launched a decentralized vulnerability publishing ecosystem utilizing Vulnerability-Lookup 4.1.0 to address the limitations of the centralized CVE system. The federated model allows organizations to act as autonomous publishers (GNAs) while synchronizing vulnerability intelligence, sightings, and KEV data globally.

Zscaler ThreatLabz17 days agoLLM reporthigh

China-nexus Group Targets Persian Gulf Region | ThreatLabz

A China-nexus threat actor, assessed with medium confidence as Mustang Panda, targeted the Persian Gulf region using a multi-stage attack chain themed around the Middle East conflict. The campaign leverages LNK and CHM files to execute a heavily obfuscated shellcode loader via DLL sideloading, ultimately deploying a PlugX backdoor capable of HTTPS and DNS-over-HTTPS (DoH) C2 communications.

Cofense17 days agoLLM reporthigh

Weaponizing Telegram Bots: How Threat Actors Exfiltrate Credentials

Threat actors are increasingly weaponizing the legitimate Telegram Bot API to establish Command and Control (C2) channels and exfiltrate stolen data. This technique is widely adopted across credential phishing campaigns and malware families like Agent Tesla and Pure Logs Stealer, allowing attackers to bypass traditional network defenses by blending malicious traffic with legitimate Telegram communications.

Socket17 days agoLLM reporthigh

OpenClaw Advisory Surge Highlights Gaps Between GHSA and CVE Tracking

The rapid proliferation of GitHub Security Advisories (GHSAs) for the OpenClaw AI agent has highlighted a significant gap in vulnerability tracking, as many GHSAs lack corresponding CVE identifiers. This discrepancy creates critical blind spots for enterprise security tools that rely exclusively on CVEs, prompting debate over the future of decentralized vulnerability disclosure and the need for multi-source advisory tracking.

Sophos17 days agoLLM reporthigh

Evil evolution: ClickFix and macOS infostealers

Threat actors are evolving 'ClickFix' social engineering campaigns to target macOS users with the MacSync infostealer. Recent iterations bypass traditional security controls by tricking users into executing obfuscated terminal commands that deploy fileless, API-gated AppleScript payloads designed to harvest credentials, browser data, and cryptocurrency wallet seed phrases.

Trend Micro17 days agoLLM reporthigh

Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites

Trend Micro MDR uncovered an ongoing campaign by the KongTuke threat group utilizing compromised WordPress sites and fake CAPTCHA lures to trick users into executing malicious PowerShell commands. The attack leverages living-off-the-land binaries like finger.exe to deploy a Python-based backdoor known as modeloRAT, which focuses on enterprise environments for potential lateral movement and establishes persistence via scheduled tasks and registry keys.

ESET17 days agoLLM reportcritical

Sednit reloaded: Back in the trenches

The Sednit threat group (APT28) has deployed a modernized espionage toolkit targeting Ukrainian military personnel. The toolkit consists of custom implants SlimAgent and BeardShell, alongside a heavily modified version of the Covenant framework, utilizing legitimate cloud storage providers for resilient Command and Control (C&C).