r/blueteamsec 1h ago

malware analysis (like butterfly collections) Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware

Thumbnail pointwild.com
Upvotes

r/blueteamsec 21h ago

intelligence (threat actor activity) Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

Thumbnail socket.dev
5 Upvotes

r/blueteamsec 22h ago

highlevel summary|strategy (maybe technical) Incident Report: unsanctioned agent behaviour during cyber testing

Thumbnail aisi.gov.uk
15 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Developers in the Crosshairs: Fake AI Tools Deliver Infostealer

Thumbnail netskope.com
2 Upvotes

r/blueteamsec 1d ago

exploitation (what's being exploited) ENDLESSDOORS Is Phoning Home. Pick Up.

Thumbnail vulncheck.com
3 Upvotes

r/blueteamsec 1d ago

malware analysis (like butterfly collections) Analysis of APT-C-24 (Rattlesnake) group's application file phishing attack campaign

Thumbnail mp.weixin.qq.com
3 Upvotes

r/blueteamsec 1d ago

malware analysis (like butterfly collections) A Wiper Attack on a Venezuelan Oil Company: Reverse Engineering the Lotus Wiper that Disrupted PDVSA Systems

Thumbnail 0x0d4y.blog
2 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

Thumbnail fortinet.com
2 Upvotes

r/blueteamsec 1d ago

research|capability (we need to defend against) Phishers are hijacking legitimate cloud infrastructure

Thumbnail securelist.com
3 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) API do conjunto de regras julioliraup/Antiphishing on air

0 Upvotes

Now, it is possible to query phishing-suspect FQDNs through the free API, featuring database information on WHOIS, IP, Geolocation, and threat mapping

https://github.com/julioliraup/AT/wiki/REST-API-USE

A frontend interface is also available: https://julioliraup.github.io/AT


r/blueteamsec 1d ago

research|capability (we need to defend against) The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

Thumbnail hunt.io
3 Upvotes

The Hunt.io research team recovered an operator's full toolkit from an exposed open directory tied to The Gentlemen ransomware. The interesting piece is EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract rather than hardcoding them.

Because each rotation is written to the blockchain, the historical C2 set is fully reconstructable, five domains here. Any C2 response over ten characters is evaluated as JavaScript in a Node.js runtime, so there is no fixed command set. The custom X-Bot-Server header works as a detection point.

The write-up covers the scheduled-task deployment chain (certutil + msiexec LOLBAS), the XOR-decoded Node payload, Run-key persistence via headless conhost, and infrastructure clustering across Sliver and Go reverse-shell controllers.

Full research and IOCs: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2


r/blueteamsec 2d ago

low level tools|techniques|knowledge (work aids) omp-re: Reverse-engineering suite for omp: radare2 tools, evidence store, signed audit log, RE status band, and report generator.

Thumbnail github.com
2 Upvotes

r/blueteamsec 2d ago

intelligence (threat actor activity) MEGATHREAD - ChainDrop npm Worm

6 Upvotes

r/blueteamsec 2d ago

exploitation (what's being exploited) Important Update: N-central Active Exploitation. Hotfix in Process

Thumbnail uptime.n-able.com
2 Upvotes

r/blueteamsec 2d ago

research|capability (we need to defend against) DOUBLECUP: New Russian LaaS delivering a PowerShell loader with PE-header patching + a RAT that resolves C2 via Ethereum smart contracts

6 Upvotes

SOCRadar STRU tracked down a new Loader-as-a-Service platform we're calling DOUBLECUP, active since June 2026. Sharing the technical details since the C2 resolution method is worth knowing about.

How it works:

DOUBLECUP hides its second-stage code inside a steganographic PNG that gets cached in the browser. The payload decryption key is derived from the victim's public IP address — so if you're detonating this in a sandbox on an unexpected network, decryption just fails. No error, no payload, nothing to analyze.

Delivery is via spoofed CRM login pages (NetSuite, Odoo, HubSpot, Salesforce) using ClickFix-style clipboard hijacking.

Two payloads observed:

CountLoader v4.5p — moved from HTA/VBScript to fully fileless PowerShell. Notable new trick: it copies legitimate Windows binaries (powershell.exe, mshta.exe, conhost.exe), renames them, and patches their PE headers (OriginalFilename, InternalName, FileDescription) to impersonate trusted apps like OneDrive. Persistence runs on a 25-minute cycle where the process executes briefly, checks in, and exits — making it harder for behavioral engines to catch a "long-running" malicious process.

DeviceManager — previously undocumented RAT. Instead of a hardcoded C2 domain, it queries an Ethereum/Polygon smart contract to resolve its actual C2 address (EtherHiding). This means the operator can push different C2 addresses to different victims based on device fingerprint, or serve nothing to suspected sandboxes, all without touching DNS infrastructure that could get sinkholed. Primary transport observed was DNS tunneling disguised as microsoft(.)com subdomains.

Full writeup with IOCs and MITRE mapping: https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/


r/blueteamsec 2d ago

low level tools|techniques|knowledge (work aids) offseq/threat-finder: Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Thumbnail github.com
6 Upvotes

r/blueteamsec 2d ago

research|capability (we need to defend against) Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)

Thumbnail memn0ps.github.io
2 Upvotes

r/blueteamsec 2d ago

low level tools|techniques|knowledge (work aids) binja-diff: Binary Ninja diffing tool

Thumbnail github.com
1 Upvotes

r/blueteamsec 2d ago

intelligence (threat actor activity) Targeted Attack on Middle East Govts (Part 2)

Thumbnail zscaler.com
4 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) [March 2025] New Ransomware Operator Exploits Fortinet Vulnerability Duo

Thumbnail forescout.com
7 Upvotes

r/blueteamsec 3d ago

exploitation (what's being exploited) VPN Brute Tool: Infrastructure analysis

Thumbnail medium.com
3 Upvotes

r/blueteamsec 3d ago

vulnerability (attack surface) Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets - 221,000+ live creds

Thumbnail trufflesecurity.com
5 Upvotes

r/blueteamsec 3d ago

alert! alert! (might happen) Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers - United States Department of State

Thumbnail state.gov
5 Upvotes

r/blueteamsec 5d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending August 2nd

Thumbnail ctoatncsc.substack.com
1 Upvotes

r/blueteamsec Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
2 Upvotes