top of page
Posts
North Korean Recruitment Campaign Deploys Malware Through Fake Coding Assessments
Key Findings DPRK-aligned group REF9403 running active social engineering campaign targeting software developers with trojanized coding projects Malware payload hidden in SVG image files within legitimate-looking coding repositories, evading antivirus detection Four-part stealer modules collect browser credentials, crypto wallets, developer keys, and grant remote shell access across Windows, macOS, and Linux Campaign active since at least 2022; some victims unknowingly pushed
Jul 253 min read
GoSerpent Backdoor: Five-Year Espionage Campaign Targeting Southeast Asian Governments and Biometric Systems
Key Findings GoSerpent backdoor has targeted Southeast Asian government and diplomatic networks since at least 2021 Campaign demonstrates extreme patience, with operators waiting weeks between infection and data exfiltration to evade log retention systems Stolen credentials enable final data theft to appear as legitimate internal file-share access, bypassing standard network monitoring Toolchain includes GoSerpent RAT, ThumbcacheService collector, credential dumpers, Stowaway
Jul 243 min read
UAC-0099 Deploys MATCHBOIL.V2 Malware via Counterfeit Notepad++ Plugin
Key Findings UAC-0099, a Russia-aligned threat group active since mid-2022, is distributing MATCHBOIL.V2 malware through trojanized Notepad++ plugins via phishing campaigns Attack chain begins with a phishing email containing an image that, when clicked, downloads a VBScript disguised as a PDF document from a file-sharing service The VBScript downloads Notepad++ version 8.8.3 bundled with a malicious DLL plugin called LUNCHPOKE that establishes persistence through scheduled t
Jul 243 min read
AI Agent Attack: Thai Finance Ministry Targeted by Unattended Hermes System with Hades Implant Deployment
Key Findings Attacker deployed Hermes AI agent in "YOLO mode" (disabling permission checks) against Thailand's Ministry of Finance, automating reconnaissance and privilege escalation attempts Exposed staging server in Hong Kong contained 585 files, 470 MB of attack tooling, active AI agent logs, web shells, and stolen credentials with directory listing enabled Agent performed unattended reconnaissance including kernel vulnerability scanning, privilege escalation checks, and f
Jul 244 min read
Tego AI Reveals Second Claude Vulnerability in a Week: Hidden Links Covertly Transmit Files to Attackers
Key Findings Tego AI disclosed a second vulnerability in Anthropic's Claude ecosystem within one week, this time affecting Claude Code, the command-line coding tool A malicious repository can use symbolic links in a CLAUDE.md file to trick Claude Code into reading files outside the project directory and sending them to Anthropic's servers without user warning or approval The vulnerability exploits a gap in Anthropic's previous fixes—two similar flaws were patched in CVE-2025-
Jul 243 min read
bottom of page
