marktsec @marktsec.bsky.social · 15hAutoLogin - Phishing Automation Framework Update: Google AutoLogin v2 Phishing kits are becoming automation frameworks #ThreatIntel 110
marktsec @marktsec.bsky.social · 02/10/2026A very interesting Windows persistence technique from Praetorian. The research abuses mandatory user profiles and ntuser.man to achieve registry-based persistence without modifying the live registry through the usual APIs. praetorian.com/blog/corrupt... 110
marktsec @marktsec.bsky.social · 21/09/2026AI infrastructure is becoming another underground service. A new marketplace advertises one API key for multiple LLMs, plus custom "uncensored coder" models targeting reverse engineering, malware, exploits and automation. 242
marktsec @marktsec.bsky.social · 20/09/2026ShinyHunters reportedly breached and defaced Cl0p's leak site and is now publicly demanding payment from the operators. A new DLS update gives Cl0p 66 hours and threatens to expose alleged payment information from previous victims. 122
marktsec @marktsec.bsky.social · 19/09/2026ICMacOS is building a MaaS offering around macOS malware. The stealer claims support for macOS 10.12+ across Intel and Apple Silicon. Its panel adds build/log analytics, custom VPS integration and Telegram alerts for incoming logs. 262
marktsec @marktsec.bsky.social · 12/09/20261/ A new Dark Project ransomware affiliate program is advertising a Go-based locker targeting Windows, UNIX, ESXi, NAS and BSD environments. The program also offers a separate "data ransom" model with a 90/10 affiliate split. #ThreatIntel 111
marktsec @marktsec.bsky.social · 11/09/2026Detecting and countering misuse of AI: September 2026 www.anthropic.com/threat-intel...anthropic.comCountering misuse of AI: September 2026 / AnthropicCase studies from threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse. 000
marktsec @marktsec.bsky.social · 04/09/2026thehackernews.com/2026/09/russ...thehackernews.comRussia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI AnalysisRussia-aligned UAC-0099 used GuardBreaker prompt injection in a malicious VBS script to interfere with AI-assisted code analysis. 010
marktsec @marktsec.bsky.social · 04/09/2026Detection evasion is being sold as a service. A new underground service advertises EXE "crypting" with: - SmartScreen bypass - Defender bypass - EDR bypass - EXE/DLL sideloading - ClickFix support - Custom stubs They claim to process RATs, stealers and other files. 111
marktsec @marktsec.bsky.social · 29/08/2026AI isn't just finding vulnerabilities anymore. James Kettle from PortSwigger asked a more interesting question: Can an autonomous AI system actually invent new attack techniques? Their answer: apparently, yes. portswigger.net/research/can...portswigger.netCan AI do novel security research? Meet the HTTP TerminatorAbstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi 021
marktsec @marktsec.bsky.social · 28/08/2026Hyflock RaaS is building an AI-powered C2 The ransomware group claims its new custom C2 uses an LLM agent to operate the platform and interact with custom modules. 123
marktsec @marktsec.bsky.social · 22/08/20261/ 🚨 A new Trezor-focused phishing tool is being advertised on underground forums. Unlike typical fake-wallet phishing, the seller claims it can inject the phishing flow directly into Trezor Suite without modifying the legitimate application files. #ThreatIntel 120
marktsec @marktsec.bsky.social · 21/08/2026A new research from SpecterOps shows how Chromium extensions can be abused as a persistence mechanism effectively turning the browser itself into a C2 channel. specterops.io/blog/2026/08...specterops.ioAttack of The ExtensionsLearn how Chromium browser extensions can be silently sideloaded to establish persistent C2 access and how to detect it with Sysmon. 010
marktsec @marktsec.bsky.social · 21/08/2026🧵 1/ A newly advertised Windows remote administration tool, Hydra Remote, combines HVNC with browser-session cloning and credential recovery. The most interesting capability: cloning existing browser profiles into a hidden session. #ThreatIntel 141
marktsec @marktsec.bsky.social · 15/08/2026🧵1/ Volta Stealer v2.0 released, and the update is focused heavily on scaling operations. The new release adds major changes to its delivery infrastructure, data collection, filtering and operator workflow. Here are some of the more interesting changes: #ThreatIntel 120
marktsec @marktsec.bsky.social · 15/08/2026🧵 1/ A relatively new MaaS stealer called Remus is positioning itself as more than another credential stealer. Its standout feature isn't just what it collects, but how it measures whether the collection actually succeeded. #ThreatIntel 120
marktsec @marktsec.bsky.social · 14/08/2026🧵 1/ A new wave of ransomware brands is emerging, but the interesting part isn't the encryption. Across recent RaaS programs, operators are competing on operational capabilities and victim pressure, not just lockers. #ThreatIntel #Ransomware 164
marktsec @marktsec.bsky.social · 08/08/20261/ 🧵 A new Bee Stealer v2.1 update introduces an interesting feature: an AI-generated profile of the victim. Instead of simply collecting credentials, the stealer reportedly feeds parts of the stolen log to an AI model to generate a summary of the victim. #ThreatIntel 122
marktsec @marktsec.bsky.social · 08/08/20261/ 🧵 A relatively new infostealer called WARDEN is being advertised with an interesting architecture. Rather than focusing only on collecting credentials, the project appears designed as a large-scale data collection and processing platform. #ThreatIntel 121
marktsec @marktsec.bsky.social · 31/07/2026🧵1/5 The developers behind Stealc have released Stealc v3, a major redesign that shifts the project beyond a traditional stealer. The most notable changes aren't new collection capabilities, they're improvements to deployment, scalability and operator experience. #ThreatIntel 111
marktsec @marktsec.bsky.social · 25/07/2026🧵1/ The Gentlemen RaaS operators have announced several updates for affiliates, but two additions stand out: Active Directory credential harvesting and an AI-assisted data analysis service designed to support ransom negotiations.#ThreatIntel #Ransomware #RaaS 121
marktsec @marktsec.bsky.social · 25/07/2026🧵1/ A recently advertised phishing framework "AutoLogin Phishing kit" suggests phishing tooling is evolving beyond static login pages. The project is marketed as a browser automation platform using real Chrome instances to interact with legitimate login flows. #ThreatIntel 121
marktsec @marktsec.bsky.social · 17/07/2026🧵1/ A custom ransomware project was recently advertised on cybercrime forum, and its feature list provides an interesting snapshot of what operators now market as a "premium" ransomware offering. #ThreatIntel #Ransomware 142
marktsec @marktsec.bsky.social · 02/07/2026🧵1/ An underground vendor selling code-signing certificates has revised its offering following Microsoft's recent reputation changes. The update suggests certificate possession alone is no longer sufficient to reliably bypass SmartScreen. #ThreatIntel #infosec 110
marktsec @marktsec.bsky.social · 01/07/2026🧵 1/ A newly advertised ransomware operation, SevyWare RaaS, is promoting an unusual addition to its affiliate offering: "Violence as a Service." #ThreatIntel #Ransomware 111
marktsec @marktsec.bsky.social · 30/06/2026🧵1/ Since its public debut in early June, the emerging VOLTA MaaS stealer has maintained a rapid development cadence, with 6 public updates released in less than a month. Below is a timeline of its development 👇 #ThreatIntel #infosec 121
marktsec @marktsec.bsky.social · 29/06/2026🧵1/ The developers behind the Stealc malware have announced the sale of the complete Stealc v2 source code ahead of the planned v3 release. According to the advertisement, only two copies of the source code will be sold for $60,000 each. #ThreatIntel #Malware #secops 145
marktsec @marktsec.bsky.social · 28/06/2026🧵1/ A new update to the ErrTraffic ClickFix framework was recently advertised on a Russian-language cybercrime forum. The release focuses less on new delivery techniques and more on scaling affiliate operations. #ThreatIntel #ClickFix #infosec 154
marktsec @marktsec.bsky.social · 28/06/2026When Three Threats Meet One Inbox Against Japan ransom-isac.com/blog/three-t...ransom-isac.comWhen Three Threats Meet One Inbox Against JapanThree unrelated Chinese-nexus operators — CoGUI email phishing, the Smishing Triad SMS/iMessage ecosystem, and MirrorFace espionage — converge on Japanese inboxes simultaneously, producing a single-ca... 000
marktsec @marktsec.bsky.social · 18/06/2026Someone's Hands Are on Your Keyboard Then Your Whole Network. Courtesy of ClickFix, Potemkin, RMMProject and EtherRAT www.huntress.com/blog/potemki...huntress.comPotemkin Loader & RMMProject The Anatomy of a ClickFix Attack | HuntressA ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts. 010
marktsec @marktsec.bsky.social · 18/06/2026FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices www.bleepingcomputer.com/news/securit...bleepingcomputer.comFortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. 000
marktsec @marktsec.bsky.social · 15/06/2026APT28, an evolution of tradecraft blog.sekoia.io/apt28-an-evo...blog.sekoia.ioAPT28, an evolution of tradecraftContext Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years. The intrusion set, also known as Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm or Sednit and public... 000
marktsec @marktsec.bsky.social · 14/06/2026My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli www.pillar.security/blog/my-agen...pillar.securityMy Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli 010
marktsec @marktsec.bsky.social · 10/06/2026Nightmare-Eclipse is back. RoguePlanet Windows Defender Vulnerability github.com/MSNightmare/...github.comGitHub - MSNightmare/RoguePlanet: RoguePlanet Windows Defender VulnerabilityRoguePlanet Windows Defender Vulnerability. Contribute to MSNightmare/RoguePlanet development by creating an account on GitHub. 011
marktsec @marktsec.bsky.social · 09/06/2026Enter the WasmForge: Compiling Sliver into WebAssembly www.praetorian.com/blog/wasmfor...praetorian.comEnter the WasmForge: Compiling Sliver into WebAssemblyExpose how compiling Sliver into WebAssembly beats EDR: WasmForge produces opsec-safe binaries with zero changes to the tool source. 000
marktsec @marktsec.bsky.social · 03/06/2026TierOne forum has moved to a new onion domain. The old site now points users to the replacement address, but the new service is currently throwing an Internal Server Error. #OSINT #ThreatIntel #DarkWeb 100
marktsec @marktsec.bsky.social · 28/05/2026The Gentlemen Leak Analysis (Part 2) — JA456 Follow-on ransom-isac.org/blog/the-gen...ransom-isac.orgThe Gentlemen Leak Analysis (Part 2) — JA456 Follow-onAnalysis of JA456, a follow-on package to the original Gentlemen Leaks that exposes operator-side artifacts — MEGA session history, a Synology NAS shadow dump, and wipe-in-progress screenshots — yield... 000
marktsec @marktsec.bsky.social · 20/05/2026Weaponizing a signed lenovo kernel driver to terminate any process — including EDR/AV protected processes. github.com/redteamfortr...github.comGitHub - redteamfortress/PhantomKiller: Another BYOVD process killer. works on all EDR's. fully signed.Another BYOVD process killer. works on all EDR's. fully signed. - redteamfortress/PhantomKiller 100
marktsec @marktsec.bsky.social · 16/05/2026Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoad harfanglab.io/insidethelab...harfanglab.ioGamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoadIdentifier: TRR260501. Summary Investigating Gamaredon’s abuse of CVE-2025-8088, we identified a dozen waves of spearphishing emails against Ukrainian state institutions in a campaign that is still ac... 000
marktsec @marktsec.bsky.social · 15/05/2026The Gentlemen Ransomware Group — Leak Analysis ransom-isac.org/blog/the-gen...ransom-isac.orgThe Gentlemen Ransomware Group — Leak AnalysisA 120-minute technical intelligence whitepaper analysing the leaked Rocket.Chat corpus of The Gentlemen RaaS — 3,366 messages, 66 confirmed victims, custom G-BOT C2, Fortinet exploitation, AI-assisted... 010
marktsec @marktsec.bsky.social · 12/05/2026🚨 Storm Stealer operators announced a major feature update focused on Google’s DBSC protections. The group claims to have developed a “DBSC cookie bypass” module targeting Chrome 147 on Windows. #ThreatIntel #Infostealer #CyberSecurity 100
marktsec @marktsec.bsky.social · 04/05/2026This article walks through three authentication paths that impacket-net supports NTLM hash (Pass-the-Hash), Kerberos ticket, and AES key. www.hackingarticles.in/impacket-for...hackingarticles.inImpacket for Pentester: NetMaster impacket-net to enumerate & manage Active Directory using NTLM hash, Kerberos ticket, or AES key auth. 000
marktsec @marktsec.bsky.social · 04/05/2026Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks www.bleepingcomputer.com/news/securit...bleepingcomputer.comCritrical cPanel flaw mass-exploited in "Sorry" ransomware attacksA new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in "Sorry" ransomware attacks. 010
marktsec @marktsec.bsky.social · 30/04/2026EasterBunny, APT29's sophisticated malware github.com/blackorbird/...github.com 000
marktsec @marktsec.bsky.social · 26/04/2026The first publicly available decryption method for The Gentlemen ransomware. github.com/Bedrock-Safe...github.comGitHub - Bedrock-Safeguard/gentlemen-decryptor: First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35 file...First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35 files decrypted. Research by Bedrock Safeguard In... 000
marktsec @marktsec.bsky.social · 20/04/2026Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency www.seqrite.com/blog/operati...seqrite.comOperation GhostMail: Russian APT Exploits Zimbra XSS to Target Ukraine GovernmentOperation GhostMail uncovers a Russian APT campaign exploiting a Zimbra XSS vulnerability (CVE-2025-66376) to target a Ukrainian government agency via phishing emails and browser-based data exfiltrati... 000
marktsec @marktsec.bsky.social · 17/04/2026RedSun: How Windows Defender's Remediation Became a SYSTEM File Write nefariousplan.com/posts/redsun...nefariousplan.comRedSun: How Windows Defender's Remediation Became a SYSTEM File Write — nefariousplan.comA technical teardown of the RedSun zero-day — the second Defender escalation in two weeks from the same researcher — grounded in the actual source code. 010
marktsec @marktsec.bsky.social · 16/04/2026The Red Sun vulnerability repository github.com/Nightmare-Ec...github.comGitHub - Nightmare-Eclipse/RedSun: The Red Sun vulnerability repositoryThe Red Sun vulnerability repository. Contribute to Nightmare-Eclipse/RedSun development by creating an account on GitHub. 010
marktsec @marktsec.bsky.social · 09/04/2026You’re Driving Me Crazy: Analysing and Detecting BYOVD ransom-isac.com/blog/analysi...ransom-isac.comYou’re Driving Me Crazy: Analysing and Detecting BYOVDA deep-dive technical reference for SOC teams and threat hunters covering BYOVD attack analysis and detection. 010
marktsec @marktsec.bsky.social · 08/04/2026A DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. www.lumen.com/blog-and-new...lumen.comFrostarmada forest blizzard dns hijackingA DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. In FrostArmada, Lumen observed Forest Blizzard using that technique ... 000