Malware
ForestTiger
Also known as: ScoringMathTea
Indicators of Compromise 7
MITRE ATT&CK TTPs 13
T1001 T1055 T1059.001 T1071.001 T1078 T1085 T1090 T1134 T1203 T1218 T1480 T1548 T1566
Data Obfuscation
Command And Control
Process Injection
Defense Evasion
PowerShell
Execution
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
T1085
Proxy
Command And Control
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
System Binary Proxy Execution
Defense Evasion
Execution Guardrails
Defense Evasion
Abuse Elevation Control Mechanism
Privilege Escalation
Phishing
Initial Access
Source Articles
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Multiple active threats were reported this week, including exploitation of critical vulnerabilities in VMware, Apple macOS, and GeoServer, as well as ongoing campaigns by state-linked actors. A suspected China-nexus APT exploited CVE-2026-59310 in VMware vCenter to deploy Babuk-derived ransomware, likely as a forensic distraction. The Lazarus Group leveraged a Windows zero-day (CVE-2026-68820) in a campaign dubbed Operation Dream Job, targeting aerospace and defense sectors. GeoServer faced active exploitation of a critical SQL injection flaw prior to patching. Additionally, new macOS malware Amnesia Stealer enables real-time browser hijacking via Chrome DevTools Protocol, stealing authenticated sessions and sensitive data.
hacker-news ·2w ago
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.
hacker-news ·3w ago