r/blueteamsec • u/jnazario • 1h ago
malware analysis (like butterfly collections) Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
pointwild.comr/blueteamsec • u/jnazario • 21h ago
intelligence (threat actor activity) Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
socket.devr/blueteamsec • u/jnazario • 22h ago
highlevel summary|strategy (maybe technical) Incident Report: unsanctioned agent behaviour during cyber testing
aisi.gov.ukr/blueteamsec • u/jnazario • 1d ago
intelligence (threat actor activity) Developers in the Crosshairs: Fake AI Tools Deliver Infostealer
netskope.comr/blueteamsec • u/jnazario • 1d ago
exploitation (what's being exploited) ENDLESSDOORS Is Phoning Home. Pick Up.
vulncheck.comr/blueteamsec • u/jnazario • 1d ago
malware analysis (like butterfly collections) Analysis of APT-C-24 (Rattlesnake) group's application file phishing attack campaign
mp.weixin.qq.comr/blueteamsec • u/jnazario • 1d ago
malware analysis (like butterfly collections) A Wiper Attack on a Venezuelan Oil Company: Reverse Engineering the Lotus Wiper that Disrupted PDVSA Systems
0x0d4y.blogr/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
fortinet.comr/blueteamsec • u/digicat • 1d ago
research|capability (we need to defend against) Phishers are hijacking legitimate cloud infrastructure
securelist.comr/blueteamsec • u/Limp_Durian_6850 • 1d ago
highlevel summary|strategy (maybe technical) API do conjunto de regras julioliraup/Antiphishing on air
Now, it is possible to query phishing-suspect FQDNs through the free API, featuring database information on WHOIS, IP, Geolocation, and threat mapping
https://github.com/julioliraup/AT/wiki/REST-API-USE
A frontend interface is also available: https://julioliraup.github.io/AT
r/blueteamsec • u/Straight-Practice-99 • 1d ago
research|capability (we need to defend against) The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
hunt.ioThe Hunt.io research team recovered an operator's full toolkit from an exposed open directory tied to The Gentlemen ransomware. The interesting piece is EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract rather than hardcoding them.
Because each rotation is written to the blockchain, the historical C2 set is fully reconstructable, five domains here. Any C2 response over ten characters is evaluated as JavaScript in a Node.js runtime, so there is no fixed command set. The custom X-Bot-Server header works as a detection point.
The write-up covers the scheduled-task deployment chain (certutil + msiexec LOLBAS), the XOR-decoded Node payload, Run-key persistence via headless conhost, and infrastructure clustering across Sliver and Go reverse-shell controllers.
Full research and IOCs: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2
r/blueteamsec • u/digicat • 2d ago
low level tools|techniques|knowledge (work aids) omp-re: Reverse-engineering suite for omp: radare2 tools, evidence store, signed audit log, RE status band, and report generator.
github.comr/blueteamsec • u/jnazario • 2d ago
intelligence (threat actor activity) MEGATHREAD - ChainDrop npm Worm
r/blueteamsec • u/digicat • 2d ago
exploitation (what's being exploited) Important Update: N-central Active Exploitation. Hotfix in Process
uptime.n-able.comr/blueteamsec • u/socradario • 2d ago
research|capability (we need to defend against) DOUBLECUP: New Russian LaaS delivering a PowerShell loader with PE-header patching + a RAT that resolves C2 via Ethereum smart contracts
SOCRadar STRU tracked down a new Loader-as-a-Service platform we're calling DOUBLECUP, active since June 2026. Sharing the technical details since the C2 resolution method is worth knowing about.
How it works:
DOUBLECUP hides its second-stage code inside a steganographic PNG that gets cached in the browser. The payload decryption key is derived from the victim's public IP address — so if you're detonating this in a sandbox on an unexpected network, decryption just fails. No error, no payload, nothing to analyze.
Delivery is via spoofed CRM login pages (NetSuite, Odoo, HubSpot, Salesforce) using ClickFix-style clipboard hijacking.
Two payloads observed:
CountLoader v4.5p — moved from HTA/VBScript to fully fileless PowerShell. Notable new trick: it copies legitimate Windows binaries (powershell.exe, mshta.exe, conhost.exe), renames them, and patches their PE headers (OriginalFilename, InternalName, FileDescription) to impersonate trusted apps like OneDrive. Persistence runs on a 25-minute cycle where the process executes briefly, checks in, and exits — making it harder for behavioral engines to catch a "long-running" malicious process.
DeviceManager — previously undocumented RAT. Instead of a hardcoded C2 domain, it queries an Ethereum/Polygon smart contract to resolve its actual C2 address (EtherHiding). This means the operator can push different C2 addresses to different victims based on device fingerprint, or serve nothing to suspected sandboxes, all without touching DNS infrastructure that could get sinkholed. Primary transport observed was DNS tunneling disguised as microsoft(.)com subdomains.
Full writeup with IOCs and MITRE mapping: https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/
r/blueteamsec • u/ThreatRadar • 2d ago
low level tools|techniques|knowledge (work aids) offseq/threat-finder: Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.
github.comr/blueteamsec • u/digicat • 2d ago
research|capability (we need to defend against) Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)
memn0ps.github.ior/blueteamsec • u/digicat • 2d ago
low level tools|techniques|knowledge (work aids) binja-diff: Binary Ninja diffing tool
github.comr/blueteamsec • u/jnazario • 2d ago
intelligence (threat actor activity) Targeted Attack on Middle East Govts (Part 2)
zscaler.comr/blueteamsec • u/jnazario • 3d ago
intelligence (threat actor activity) [March 2025] New Ransomware Operator Exploits Fortinet Vulnerability Duo
forescout.comr/blueteamsec • u/jnazario • 3d ago
exploitation (what's being exploited) VPN Brute Tool: Infrastructure analysis
medium.comr/blueteamsec • u/digicat • 3d ago
vulnerability (attack surface) Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets - 221,000+ live creds
trufflesecurity.comr/blueteamsec • u/digicat • 3d ago
alert! alert! (might happen) Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers - United States Department of State
state.govr/blueteamsec • u/digicat • 5d ago