#DLLsideloading
Cisco Talos scopre un’operazione persistente con file di collegamento malevoli, PowerShell offuscati e DLL sideloading per infettare con Remcos

#apt #backdoor #c2 #DLLsideloading #Gamaredon #guerracibernetica #lnk #malware #PHISHING #Powershell #Remcos #talo
www.matricedigitale.it/sicurezza-in...
March 29, 2025 at 6:04 PM
Cisco Talos scopre un’operazione persistente con file di collegamento malevoli, PowerShell offuscati e DLL sideloading per infettare con Remcos

#apt #backdoor #c2 #DLLsideloading #Gamaredon #guerracibernetica #lnk #malware #PHISHING #Powershell #Remcos #talo
www.matricedigitale.it/sicurezza-in...
March 29, 2025 at 6:04 PM
QWCrypt è il ransomware usato da RedCurl per attacchi mirati su hypervisor: un’operazione tecnica e silenziosa, con alta personalizzazione.

#crittografiamirata #DLLsideloading #livingofftheland #phishingIMG #QWCrypt #ransomwarehypervisor #RedCurl
www.matricedigitale.it/sicurezza-in...
March 26, 2025 at 3:58 PM
Apt29 rilancia le campagne phishing su diplomatici europei con Grapeloader e Wineloader usando side-loading e shellcode evasivi

#apt29 #CozyBear #cyberspionaggio #DLLsideloading #grapeloader #guerracibernetica #malwaremodulare #phishingdiplomatico #rc4
www.matricedigitale.it/sicurezza-in...
April 16, 2025 at 6:05 AM
Cybercriminals exploit OneDrive.exe via DLL sideloading to execute malicious code undetected. Learn how to protect your systems from this sophisticated attack. #CyberSecurity #DLLSideloading #OneDrive Link: thedailytechfeed.com/cybercrimina...
November 6, 2025 at 6:48 PM
2024-09-19 (Thurs): As early as 2024-09-10, this infection chain abuses steamerrorreporter64.exe to side-load vstdlib_s64.dll as a downloader to retrieve & run #LummaStealer. Details at bit.ly/3zrV0yY
#DllSideLoading #Lumma #TimelyThreatIntel #Unit42ThreatIntel
Unit42-timely-threat-intel/2024-09-19-IOCs-for-file-downloader-to-Lumma-Stealer.txt at main · PaloAltoNetworks/Unit42-timely-threat-intel
A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence. - PaloAltoNetworks/Unit42-timely-threat-intel
bit.ly
September 20, 2024 at 8:56 PM
QWCrypt è il ransomware usato da RedCurl per attacchi mirati su hypervisor: un’operazione tecnica e silenziosa, con alta personalizzazione.

#crittografiamirata #DLLsideloading #livingofftheland #phishingIMG #QWCrypt #ransomwarehypervisor #RedCurl
www.matricedigitale.it/sicurezza-in...
March 26, 2025 at 3:59 PM
Cisco Talos scopre un’operazione persistente con file di collegamento malevoli, PowerShell offuscati e DLL sideloading per infettare con Remcos

#apt #backdoor #c2 #DLLsideloading #Gamaredon #guerracibernetica #lnk #malware #PHISHING #Powershell #Remcos #talo
www.matricedigitale.it/sicurezza-in...
March 29, 2025 at 6:03 PM
Resolverrat colpisce sanità e farmaceutica con phishing localizzati e caricamento in memoria tramite dll e framework .net #accessoremoto #DLLsideloading #evasione #malware #PHISHING #resolverrat #sanità #sideloading www.matricedigitale.it/sicurezza-in...
April 15, 2025 at 9:36 AM
~Trendmicro~
A campaign targets job seekers with email lures, using a weaponized Foxit PDF Reader for DLL side-loading to deploy ValleyRAT.
-
IOCs: 196. 251. 86. 145, 51. 79. 214. 125, 154. 90. 58. 164
-
#DLLSideloading #ThreatIntel #ValleyRAT
ValleyRAT Targets Job Seekers via Foxit Reader
www.trendmicro.com
December 3, 2025 at 12:36 PM
QWCrypt è il ransomware usato da RedCurl per attacchi mirati su hypervisor: un’operazione tecnica e silenziosa, con alta personalizzazione.

#crittografiamirata #DLLsideloading #livingofftheland #phishingIMG #QWCrypt #ransomwarehypervisor #RedCurl
www.matricedigitale.it/sicurezza-in...
March 26, 2025 at 3:58 PM
Researchers discovered two open-source #PyPI packages, NP6HelperHttptest and NP6HelperHttper, leveraged by threat actors to infiltrate systems via #DLLsideloading, evading detection tools and raising #supplychain concerns.
The Rise of Malicious Packages in DevOps - SOCRadar® Cyber Intelligence Inc.
July 21, 2023: On July 18, 2023, GitHub identified a social engineering campaign that targets the personal accounts of employees of technology firms,
socradar.io
February 22, 2024 at 8:39 PM