Malware
AdaptixC2
AdaptixC2 is a open-source post-exploitation and adversarial emulation framework that lets penetration testers control compromised hosts and execute system actions. While being created for red-teaming it is also used by threat actors for attacks.
Indicators of Compromise 22
Domain claude-pro[.]com Domain claudefix-panel[.]org Domain clickfix-lure[.]com Domain corepack[.]org Domain gouvvbo[.]top Domain kali365-host[.]cf Domain license[.]claude-pro[.]com Domain sylverixstrategy[.]com Domain update-crowdstrike[.]com Domain update-sentinelone[.]com Domain update-trellix[.]com Domain vertextrust-advisors[.]com Filename GoFlyDrv.sys Filename MacSyncStealer.dmg Filename PhantomStealer.js Filename lib/.threadpool.rb Filename putty SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5 IP 13[.]229[.]10[.]100 IP 165[.]154[.]236[.]93 IP 43[.]106[.]71[.]28
MITRE ATT&CK TTPs 33
T1003.001 T1006 T1012 T1014 T1027 T1048 T1053.005 T1055 T1055.015 T1056.001 T1059.001 T1059.003 T1068 T1070.004 T1071 T1071.001 T1071.003 T1071.004 T1082 T1083 T1098 T1105 T1114 T1190 T1203 T1204.002 T1485 T1496 T1548.002 T1555 T1566 T1570 T1588
LSASS Memory
Credential Access
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Obfuscated Files or Information
Defense Evasion
Exfiltration Over Alternative Protocol
Exfiltration
Scheduled Task
Execution
Process Injection
Defense Evasion
ListPlanting
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Windows Command Shell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Email Collection
Collection
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Malicious File
Execution
Data Destruction
Impact
Resource Hijacking
Impact
Bypass User Account Control
Privilege Escalation
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Lateral Tool Transfer
Lateral Movement
Obtain Capabilities
Resource Development
Source Articles
Exploits and vulnerabilities in Q2 2026
In Q2 2026, a significant increase in registered vulnerabilities was observed, driven by AI-assisted discovery tools. Multiple critical vulnerabilities were exploited in both Windows and Linux systems, including local privilege escalation flaws in the Linux kernel's caching subsystem (e.g., Dirty Frag family) and newly disclosed Windows Defender and BitLocker bypass vulnerabilities. Exploitation of AI/LLM platforms such as OpenClaw, Dify, and Open WebUI surged, with vulnerabilities enabling session compromise, unauthorized access, and message manipulation. APT groups increasingly targeted newly published and zero-day vulnerabilities, using C2 frameworks like Sliver and Metasploit for post-exploitation. The report highlights growing risks from insecure AI tooling and the need for enhanced access controls and real-time monitoring.
securelist ·1w ago
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news ·4w ago
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1mo ago
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·1mo ago
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
A China-nexus threat actor tracked as JadeProx has been conducting cyberattacks against government, healthcare, and education sectors in Asia and Latin America using a previously undocumented Windows loader named TriBack Loader. The attacks leverage DLL sideloading techniques and phishing campaigns, including a fake Anthropic Claude website, to deploy backdoors such as Beagle and AdaptixC2. The operators also perform large-scale scanning for known vulnerabilities and maintain persistence via malicious startup entries and webshells.
hacker-news ·1mo ago