Malware
XWorm
Malware with wide range of capabilities ranging from RAT to ransomware.
Indicators of Compromise 3
MITRE ATT&CK TTPs 23
T1006 T1012 T1014 T1021.001 T1021.002 T1053.005 T1055 T1055.015 T1059.001 T1068 T1070.004 T1070.009 T1071.001 T1078 T1082 T1083 T1090 T1110.003 T1204.002 T1482 T1548.002 T1557 T1566
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Scheduled Task
Execution
Process Injection
Defense Evasion
ListPlanting
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Clear Persistence
Defense Evasion
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Password Spraying
Credential Access
Malicious File
Execution
Domain Trust Discovery
Discovery
Bypass User Account Control
Privilege Escalation
Adversary-in-the-Middle
Credential Access
Phishing
Initial Access
Source Articles
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet, a financially motivated threat actor active since 2023 and previously tracked as UNC5669, has targeted Brazilian financial, retail, and e-commerce organizations to conduct fraudulent transactions via payment systems like Pix, STR, and Boleto. The group gains initial access through password spraying, social engineering via WhatsApp, and exploitation of vulnerable JBoss AS servers to deploy web shells. They use a suite of custom backdoors such as LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, along with tools like COBALTSPIN for lateral movement and SOCKS5 tunneling, to maintain persistence and execute hundreds of fraudulent transactions. The actor leverages compromised government websites for C2 infrastructure, disables Windows Defender via PowerShell, and uses LLMs to accelerate malware development, indicating a shift toward more sophisticated, infrastructure-level financial attacks.
hacker-news ·1d ago
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1mo ago