More info on this activity at github.com/PaloAltoNetw...
More info on this activity at github.com/PaloAltoNetw...
Details at github.com/malware-traf...
Details at github.com/malware-traf...
Not sure what type of #malware this is, but it's not Koi Stealer.
Details at github.com/malware-traf...
Not sure what type of #malware this is, but it's not Koi Stealer.
Details at github.com/malware-traf...
This is from a file disguised as a cracked version of software, and I usually see #LummaStealer from this.
This is from a file disguised as a cracked version of software, and I usually see #LummaStealer from this.
A #pcap of the infection traffic, the associated malware, and IOCs are at www.malware-traffic-analysis.net/2025/09/03/i...
A #pcap of the infection traffic, the associated malware, and IOCs are at www.malware-traffic-analysis.net/2025/09/03/i...
warpdrive[.]top <-- domain used for SmartAgeSG injected script and to display ClickFix page.
sos-atlanta[.]com <-- domain from script injected into clipboard and to retrieve #NetSupportRAT malware package
warpdrive[.]top <-- domain used for SmartAgeSG injected script and to display ClickFix page.
sos-atlanta[.]com <-- domain from script injected into clipboard and to retrieve #NetSupportRAT malware package
The mr.d0x article announcing FileFix calls it a ClickFix alternative, but it's really a -variant- of ClickFix. Just using File Manager instead of a Run window.