Sign in

marktsec

@marktsec.bsky.social
108 followers 15 following 717 posts

💫Threat Intel💫 Automation💫 Threat Analysis 💫OSINT💫 Testing 💫Network Security💫 github.com/marktsec

PostsRepliesMedia
marktsec @marktsec.bsky.social · 16h
Phishing infrastructure is evolving beyond static credential pages toward adaptive, browser-driven workflows.
010
marktsec @marktsec.bsky.social · 16h
The [BiTM/R3B00T] AutoLogin developer has announced a new version with: - Native build + GUI dashboard - Morelogin and OctoBrowser support - Improved login-flow error handling - Desktop/mobile-aware browser interaction - Proxy and GeoIP/ASN support
110
marktsec @marktsec.bsky.social · 16h
AutoLogin - Phishing Automation Framework Update: Google AutoLogin v2 Phishing kits are becoming automation frameworks #ThreatIntel
110
marktsec @marktsec.bsky.social · 02/10/2026
Offreg.dll, Microsoft's Offline Registry Library, can modify registry hives offline. That means the persistence can avoid the standard RegSetValue / RegCreateKey activity that EDRs commonly monitor. Praetorian released Swarmer, a tool implementing the technique.
010
marktsec @marktsec.bsky.social · 02/10/2026
A very interesting Windows persistence technique from Praetorian. The research abuses mandatory user profiles and ntuser.man to achieve registry-based persistence without modifying the live registry through the usual APIs. praetorian.com/blog/corrupt...
110
marktsec @marktsec.bsky.social · 21/09/2026
The service provides ready-to-use configs for Claude Code, Cursor and OpenCode, token-based billing, crypto auto-deposits and affiliate access. The product isn't an AI tool, it's access to an AI development stack.
010
marktsec @marktsec.bsky.social · 21/09/2026
AI infrastructure is becoming another underground service. A new marketplace advertises one API key for multiple LLMs, plus custom "uncensored coder" models targeting reverse engineering, malware, exploits and automation.
242
marktsec @marktsec.bsky.social · 20/09/2026
010
marktsec @marktsec.bsky.social · 20/09/2026
ShinyHunters reportedly breached and defaced Cl0p's leak site and is now publicly demanding payment from the operators. A new DLS update gives Cl0p 66 hours and threatens to expose alleged payment information from previous victims.
122
marktsec @marktsec.bsky.social · 19/09/2026
Infrastructure + analytics + notifications + encrypted tokens + ongoing updates + customer support. This is less "buy a stealer" and more a subscription service for macOS data theft.
021
marktsec @marktsec.bsky.social · 19/09/2026
ICMacOS isn't just targeting browser credentials. Its latest "Dev Secrets" module advertises collection across: .env, SSH, Git, AWS, GCP, Docker, Kubernetes, Terraform, npm, databases It also tracks Keychain-related sources separately.
131
marktsec @marktsec.bsky.social · 19/09/2026
ICMacOS is building a MaaS offering around macOS malware. The stealer claims support for macOS 10.12+ across Intel and Apple Silicon. Its panel adds build/log analytics, custom VPS integration and Telegram alerts for incoming logs.
262
marktsec @marktsec.bsky.social · 12/09/2026
3/ Cross-platform tooling, affiliate management, negotiation assistance and media support are packaged into one ransomware business model. Ransomware-as-a-service continues to look more like an organized service industry.
030
marktsec @marktsec.bsky.social · 12/09/2026
2/ The affiliate rules set a $100K minimum ransom and exclude several victim categories and regions. The panel includes build configuration, target communications, negotiation support and callback services.
110
marktsec @marktsec.bsky.social · 12/09/2026
1/ A new Dark Project ransomware affiliate program is advertising a Go-based locker targeting Windows, UNIX, ESXi, NAS and BSD environments. The program also offers a separate "data ransom" model with a 90/10 affiliate split. #ThreatIntel
111
marktsec @marktsec.bsky.social · 11/09/2026
Detecting and countering misuse of AI: September 2026 www.anthropic.com/threat-intel...
anthropic.com
Countering misuse of AI: September 2026 / Anthropic
Case studies from threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse.
000
marktsec @marktsec.bsky.social · 04/09/2026
thehackernews.com/2026/09/russ...
thehackernews.com
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Russia-aligned UAC-0099 used GuardBreaker prompt injection in a malicious VBS script to interfere with AI-assisted code analysis.
010
marktsec @marktsec.bsky.social · 04/09/2026
Evasion is becoming a productized service, not just a malware developer's problem.
010
marktsec @marktsec.bsky.social · 04/09/2026
Detection evasion is being sold as a service. A new underground service advertises EXE "crypting" with: - SmartScreen bypass - Defender bypass - EDR bypass - EXE/DLL sideloading - ClickFix support - Custom stubs They claim to process RATs, stealers and other files.
111
marktsec @marktsec.bsky.social · 29/08/2026
AI isn't just finding vulnerabilities anymore. James Kettle from PortSwigger asked a more interesting question: Can an autonomous AI system actually invent new attack techniques? Their answer: apparently, yes. portswigger.net/research/can...
portswigger.net
Can AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
021
marktsec @marktsec.bsky.social · 28/08/2026
The LLM is positioned as an operational layer for the C2 itself. Hyflock says this is only the first version, with further development planned.
010
marktsec @marktsec.bsky.social · 28/08/2026
Their demo shows: - Real-time shell & file manager - AI-powered sensitive-data analysis - Custom APIs and plugins - Integration with additional offensive tooling - Automated interaction with compromised hosts - UAC bypass / Defender-related activity
110
marktsec @marktsec.bsky.social · 28/08/2026
Hyflock RaaS is building an AI-powered C2 The ransomware group claims its new custom C2 uses an LLM agent to operate the platform and interact with custom modules.
123
marktsec @marktsec.bsky.social · 22/08/2026
3/ The broader trend is worth watching: Crypto phishing is moving beyond cloned websites toward abusing trusted desktop wallet interfaces. If the claims are accurate, compromising the user's trust in the legitimate application may be more effective than impersonating the wallet.
020
marktsec @marktsec.bsky.social · 22/08/2026
2/ The claimed flow is particularly interesting: A fake error is shown first, followed by "troubleshooting" steps designed to create urgency before the victim is prompted for their seed phrase. The tool reportedly also captures passphrases and survives reboots.
110
marktsec @marktsec.bsky.social · 22/08/2026
1/ 🚨 A new Trezor-focused phishing tool is being advertised on underground forums. Unlike typical fake-wallet phishing, the seller claims it can inject the phishing flow directly into Trezor Suite without modifying the legitimate application files. #ThreatIntel
120
marktsec @marktsec.bsky.social · 21/08/2026
A new research from SpecterOps shows how Chromium extensions can be abused as a persistence mechanism effectively turning the browser itself into a C2 channel. specterops.io/blog/2026/08...
specterops.io
Attack of The Extensions
Learn how Chromium browser extensions can be silently sideloaded to establish persistent C2 access and how to detect it with Sysmon.
010
marktsec @marktsec.bsky.social · 21/08/2026
7/ There is a combination of HVNC + browser profile cloning + session recovery. This moves beyond simply stealing credentials: the operator is attempting to reproduce the victim's authenticated browser environment inside a hidden session.
011
marktsec @marktsec.bsky.social · 21/08/2026
6/ The infrastructure is designed for persistent remote operation as well. Advertised features include automatic reconnect, backup C2 hosts, multiple listener ports and per-installation communication keys. The builder produces an obfuscated x64 client for Windows 10/11.
110
marktsec @marktsec.bsky.social · 21/08/2026
5/ Hydra also combines this with conventional remote access capabilities: - Keylogging - Password/cookie recovery - Remote shell - File management - Webcam access - Process/registry management - SOCKS5/HTTP proxy - Crypto clipping
110
marktsec @marktsec.bsky.social · 21/08/2026
4/ Another notable capability is Profile Replace. The operator can transfer the hidden browser profile onto the real profile, replacing the existing profile after terminating browser processes.
110
marktsec @marktsec.bsky.social · 21/08/2026
3/ The tool also claims support for Chrome App-Bound encryption bypass inside the hidden session. This potentially allows browser credentials and cookies to be accessed without simply taking over the victim's visible desktop.
110
marktsec @marktsec.bsky.social · 21/08/2026
2/ Hydra's HVNC runs a hidden desktop alongside the victim's visible session. It advertises support for Chrome, Edge, Brave, Firefox and Vivaldi, with existing browser logins, cookies and sessions carried into the hidden environment.
110
marktsec @marktsec.bsky.social · 21/08/2026
🧵 1/ A newly advertised Windows remote administration tool, Hydra Remote, combines HVNC with browser-session cloning and credential recovery. The most interesting capability: cloning existing browser profiles into a hidden session. #ThreatIntel
141
marktsec @marktsec.bsky.social · 15/08/2026
7/ What stands out to me isn't simply the growing collection list. Volta v2.0 looks increasingly like an operational data-processing platform: faster ingestion, queues, filtering, sorting, deduplication and flexible exports.
000
marktsec @marktsec.bsky.social · 15/08/2026
6/ Volta also claims significant runtime changes: - Updated system calls - New protection-bypass capabilities - Runtime/scantime testing against popular AV products The claims are vendor-provided and would require independent validation.
100
marktsec @marktsec.bsky.social · 15/08/2026
5/ Another notable change: customization. Operators can now specify their own browsers and wallet extensions by defining the browser name, path, engine or extension ID. The loader also gained configurable drop paths and launch arguments.
100
marktsec @marktsec.bsky.social · 15/08/2026
4/ The operator tooling received a major upgrade. Smart filters now support combinations of: - Domains - URLs - Wallets - Endpoints - Importance / labels Search+ also adds filtering by GPU and OS. A built-in sorter now includes 16 presets and multiple export formats.
100
marktsec @marktsec.bsky.social · 15/08/2026
3/ The scale of collection was also expanded. Volta now advertises: 215 Chromium browsers 64 Gecko browsers +95 new crypto wallets It also added Windows key collection and changed collection prioritization so cookies and passwords are processed before other data.
100
marktsec @marktsec.bsky.social · 15/08/2026
2/ One of the biggest changes is the backend. Volta introduced: - A new traffic encryption protocol - Key rotation per connection - New wire format - Server-side queues - Receive buffers for traffic spikes - Improved chunked uploads - A redesigned log processor
100
marktsec @marktsec.bsky.social · 15/08/2026
🧵1/ Volta Stealer v2.0 released, and the update is focused heavily on scaling operations. The new release adds major changes to its delivery infrastructure, data collection, filtering and operator workflow. Here are some of the more interesting changes: #ThreatIntel
120
marktsec @marktsec.bsky.social · 15/08/2026
6/ The interesting part here is the shift toward measuring and optimizing collection quality. Stealers are increasingly being developed like scalable data-collection platforms, with telemetry, reliability mechanisms and operator-facing analytics.
010
marktsec @marktsec.bsky.social · 15/08/2026
5/ The project is also actively evolving. Recent updates include: - Roblox search - Improved Claude collection - Filter import/export - Build cleanup - Changes to proxy handling - "Neighbor analysis" for logs
100
marktsec @marktsec.bsky.social · 15/08/2026
4/ The infrastructure is also designed around reliability. Remus advertises: - Server-side queues - Caching - Multiple beaconing servers - Docker deployment - Microservice architecture - Encrypted/compressed communications - Custom communication protocol
100
marktsec @marktsec.bsky.social · 15/08/2026
3/ Interesting operational approach: Log completeness monitoring. Remus tracks where data collection or beaconing fails, down to which browsers/files are causing problems. The operator can then modify collection rules to improve the percentage of "complete" logs.
100
marktsec @marktsec.bsky.social · 15/08/2026
2/ Remus claims extensive collection capabilities: - 21 browsers - 181 Chrome wallet extensions - 43 password managers - 38 applications - Browser history - Cards + CVV - Important files, seed phrases & private keys - Mozilla extensions and wallets
100
marktsec @marktsec.bsky.social · 15/08/2026
🧵 1/ A relatively new MaaS stealer called Remus is positioning itself as more than another credential stealer. Its standout feature isn't just what it collects, but how it measures whether the collection actually succeeded. #ThreatIntel
120
marktsec @marktsec.bsky.social · 14/08/2026
7/ The pattern I'm watching: Ransomware → RaaS → operational platform → multiple pressure mechanisms The locker is becoming just one component of a much broader criminal service ecosystem.
031
marktsec @marktsec.bsky.social · 14/08/2026
6/ ECLIPSE is another example of this expansion, advertising support across Windows, Linux/NAS, ESXi and Nutanix alongside additional services such as DDoS, caller and brute-force capabilities.
220
marktsec @marktsec.bsky.social · 14/08/2026
5/ SHIBA also advertises automated calls to executives and employees, including TTS, scheduled calls and randomized caller IDs. This adds a direct human-pressure layer to the traditional ransomware workflow.
131