NEW#0001FFortinet6 days ago12 min▣LLM reportcritical Evooo1Bot is a previously undocumented Linux botnet family that extends the publicly leaked Mirai DDoS engine with encrypted C2 communications, SSH brute-force scanning, SOCKS relay functionality, credential sniffing, and an integrated exploit arsenal targeting 19 known vulnerabilities. Active since July 2026, it exploits Internet-facing devices across diverse regions using a loader script at 91.92.40.118/wget.sh. The malware employs multi-layer string obfuscation (AES-256-CTR, ChaCha20, XOR) and anti-analysis checks to evade detection.
#0002FFortinet15 days ago14 min▣LLM reportmedium A supply chain attack on the QuickFox VPN/game accelerator application trojanized versions 3.51.0 through 3.59.5 by injecting malicious JavaScript into an Electron renderer HTML file. The JavaScript downloaded an obfuscated loader from a typosquatting domain (cdns3.51quickfox.cn) that enforced execution guardrails before deploying an FDMTP implant via DLL sideloading using a legitimate Microsoft binary (csmonitor.exe). The FDMTP implant established C2 via a custom protocol on ports 20800-20816, collected host information, and supported remote plugin deployment through registry-based storage. Infrastructure remains active and shares technical overlap with the Twill Typhoon threat actor.
#0003FFortinet28 days ago11 min▣LLM reporthigh FortiGuard Labs identified a TrickBot variant that uses DNS tunneling for C2 communication instead of HTTP, embedding XOR-encrypted data in DNS queries and encoding response payloads within IPv4 address octets. The malware establishes persistence via Windows Task Scheduler disguised as software updates, stores configuration in NTFS Alternate Data Streams, and employs runtime string decryption and hash-based API resolution to evade analysis. Its modular architecture supports process injection (hollowing, doppelgänging), DLL execution via rundll32, PowerShell execution, and raw shellcode execution, retaining the full capability set of the TrickBot family.
#0004FFortinetabout 1 month ago13 min▣LLM reporthigh A global phishing campaign active since late March 2026 deploys heavily obfuscated JScript droppers that launch LuaJIT or AutoIt-based loaders disguised as TrueType Font (.ttf) files to deliver multiple RATs and infostealers including Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant dubbed Best Private LOGGER. The Lua loader leverages LuaJIT's Foreign Function Interface to call native Windows APIs for in-memory shellcode execution, employing advanced evasion techniques such as decoy memory allocation, Donut header patching, AMSI/ETW bypass, API unhooking, and VEH-based segmented shellcode decryption. The campaign has evolved from October 2025 through June 2026 with progressively more sophisticated anti-analysis capabilities.
#0005FFortinetabout 1 month ago14 min▣LLM reporthigh Threat actors are weaponizing AI-themed lure documents to deliver a complex multi-stage infection chain culminating in AsyncRAT and a custom .NET RAT called clay_Client. The attack uses hidden LNK files inside compressed archives to initiate a chain of PowerShell scripts that extract, decrypt, and execute payloads from disguised PDF containers using AES-CBC, XOR, and GZip decompression. AutoHotkey scripts perform process hollowing into legitimate .NET Framework executables, while defense evasion includes adding Microsoft Defender exclusions and restoring disabled VBS execution. The final RAT provides full remote control with screen capture, input simulation, fileless assembly loading, and process injection capabilities.
#0006FFortinetabout 1 month ago13 min▣LLM reporthigh The Shai Hulud supply chain worm, attributed to TeamPCP, compromises CI/CD pipelines by injecting malicious npm/PyPI packages that harvest build credentials and pivot into production AWS cloud infrastructure. In a confirmed breach, attackers stole Jenkins EC2 instance role credentials via the Instance Metadata Service (IMDS), used them from external IPs, escalated privileges by creating an IAM user with AdministratorAccess, modified Redshift and Aurora security groups to open network paths, enumerated Secrets Manager for warehouse credentials, and exfiltrated data via the Redshift Data API. The attack demonstrates that pipeline identity equals production identity, with explicit attacker naming conventions (exfil-s3-* policies, exfil STS session names) providing high-fidelity detection opportunities.
#0007FFortinetabout 1 month ago11 min▣LLM reporthigh FortiGuard Labs identified an ongoing Ousaban banking Trojan campaign targeting users in Spain and Portugal, delivered via phishing PDFs that redirect victims to geofenced malicious webpages. The attack chain involves a VBS script extracting a ZIP payload from a steganographic image, with the final Ousaban EXE establishing persistence via registry Run keys and communicating with C2 servers resolved through daily-changing DDNS hostnames. The malware targets over 25 Spanish and Portuguese financial institutions and employs a custom encryption algorithm shared with the Casbaneiro family to evade detection.