Sign in

World Watch OCD

@ocdworldwatch.bsky.social
49 followers 90 following 28 posts

World Watch CTI team from Orange Cyberdefense www.orangecyberdefense.com/global/o…

PostsRepliesMedia
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
Ressources and more STX RAT campaigns: CPUID: x.com/d0cTB/status... Kaspersky: securelist.com/tr/cpu-z/119... eSentire: www.esentire.com/blog/stx-rat... Alyac: blog.alyac.co.kr/5738 Jerome Segura: jeromesegura.com/malvertising...
x.com
Doc TB on X: "Here is the small statement I sent to everyone... 😓 Hi, Investigations are still ongoing, but it appears that a secondary feature (basically a side API) was compromised for approximately six hours between April 9 and April 10, causing the main website to randomly display" / X
Here is the small statement I sent to everyone... 😓 Hi, Investigations are still ongoing, but it appears that a secondary feature (basically a side API) was compromised for approximately six hours between April 9 and April 10, causing the main website to randomly display
001
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
Bottom line: different lures, similar staging, same malware outcome. We published a full advisory for our customers on the infection chain, overlaps, and malware analysis. Related IoCs are also available in our public GitHub repository: github.com/cert-orangec...
github.com
cti/STX-RAT at main · cert-orangecyberdefense/cti
IOCs for World Watch investigations. Contribute to cert-orangecyberdefense/cti development by creating an account on GitHub.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
Notably, credential theft is only activated after successful C2 interaction.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
At the malware level, STX RAT is a Windows RAT with infostealer and HVNC capabilities. It uses a custom multi-stage unpacking chain, communicates over a proprietary TCP-based protocol with both clearweb and Tor fallback, and exposes broad post-exploitation functionality.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
Separately, eSentire later described a related script-based branch involving VBScript → JScript → TAR (1.bin + 2.txt) → PowerShell, which is consistent with the broader staging logic we observed across the cluster.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
In the overlapping script-based activity we tracked, VBS / PowerShell stages and TAR-delivered components (1.bin and 2.txt) led to in-memory payload execution.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
In the FileZilla branch, the sideloaded loader performed anti-analysis and anti-virtualization checks, resolved C2 via DNS-over-HTTPS, and used callback logic with tracking parameters.
110
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
Key overlap points included infrastructure involving supp0v3[.]com, cdn0v3[.]com, and 147.45.178[.]61, multiple pages[.]dev staging hosts, and similar callback / tracking logic observed across the linked chains.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
We identified overlaps with: - A malvertising chain using VBS lures impersonating Google Drive or LibreOffice - A ClickFix lure reported by a private source These branches were supported by shared infrastructure and staging patterns
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
In both cases, filezilla.exe sideloaded the DLL and triggered a staged infection chain that ultimately delivered a RAT.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
The campaign used two delivery variants: - A portable archive containing the legitimate FileZilla package plus a malicious version.dll - A single EXE installer dropping the same DLL during installation
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
Our investigation identified overlaps across these campaigns, and related samples were later publicly identified as STX RAT. It started from the publicly documented FileZilla campaign, which used a fake FileZilla website to distribute trojanized FileZilla 3.69.5 packages.
100
World Watch OCD @ocdworldwatch.bsky.social · 05/05/2026
🧵 Since March 2026, Orange Cyberdefense has been tracking a malware delivery cluster linking a fake FileZilla campaign with other software-themed lures, including LibreOffice and Google Drive Setup, as well as a ClickFix-based one. #CTI #ThreatIntel #STXRAT @asmalansari.bsky.social
Scheme showing overlaps between payloads and infrastructure elements.
122
World Watch OCD @ocdworldwatch.bsky.social · 23/09/2025
🔗 Related IoCs could be found on GitHub: github.com/cert-orangec...
github.com
010
World Watch OCD @ocdworldwatch.bsky.social · 23/09/2025
☣ The main lure deploys a full Python environment and runs a Python script responsible for fetching the next stage from a remote C2. Then it opens a decoy file in Word. C2 are now inactive but have been tied to Pure malware family.
This is a scheme describing the infection chain. 
1. Email received.
2. Download a ZIP file from an actor-controlled website.
3. User clicks on an executable that sideloads a malicious DLL.
4. The malicious DLL unpacks an archive contained in the ZIP file, opens a Word document, and executes a Python script or a BAT file to fetch the final payload.
110
World Watch OCD @ocdworldwatch.bsky.social · 23/09/2025
✉ The campaigns are initiated from the legitimate noreply[@]appsheet.com address and deliver various payloads, with lures targeting corporate sales, marketing, and legal teams. We advise to hunt for emails from this sender.
100
World Watch OCD @ocdworldwatch.bsky.social · 23/09/2025
✨ AppSheet is a Google platform that enables no-code development of mobile, tablet, and web applications. Knowbe4, RavenMail, and MalwareHunterTeam have also previously mentioned such campaigns. x.com/i/web/status... ravenmail.io/blog/appshee... blog.knowbe4.com/impersonatin...
x.com
MalwareHunterTeam on X: ""invoice.bat": ebc3a6999612cc73ab2162c2e461018967748245cd150798c268c5821f8af10b Another case when the file is FUD on VT for the vendors, but there are @thor_scanner comments... 🤷‍♂️ bestsaleshoppingday[.]com 166.0.184[.]127 162.218.115[.]218 https://t.co/SeTWXQetyG" / X
"invoice.bat": ebc3a6999612cc73ab2162c2e461018967748245cd150798c268c5821f8af10b Another case when the file is FUD on VT for the vendors, but there are @thor_scanner comments... 🤷‍♂️ bestsaleshoppingday[.]com 166.0.184[.]127 162.218.115[.]218 https://t.co/SeTWXQetyG
100
World Watch OCD @ocdworldwatch.bsky.social · 23/09/2025
🎣🧀 Since early September 2025, the Orange Cyberdefense CSIRT and CyberSOC teams have detected phishing campaigns impersonating Meta, AppSheet and Paypal, leading to malware delivery. Our team tracks this activity under the alias "Metappenzeller". #CTI #ThreatIntel #Metappenzeller #phishing
101
World Watch OCD @ocdworldwatch.bsky.social · 03/07/2025
The new version has removed these notable behaviours and is seen in campaign with fake invoices lures. New indicators of compromise (IoCs) are available on our GitHub: github.com/cert-orangec...
github.com
012
World Watch OCD @ocdworldwatch.bsky.social · 03/07/2025
🤖These detection opportunities were presented during the Botconf 2025: www.botconf.eu/wp-content/u...
botconf.eu
112
World Watch OCD @ocdworldwatch.bsky.social · 03/07/2025
⛪🔎Historically, new MintsLoader JS samples were easy to find because the obfuscation strings consistently used text from a book, Andrew Melville by William Morison. The associated infrastructure could be tracked thanks to specific patterns and campaign IDs in the C2 URLs: archive.org/details/cu31...
archive.org
Andrew Melville : Morison, William : Free Download, Borrow, and Streaming : Internet Archive
The metadata below describe the original scanning. Follow the All Files: HTTP link in the View the book box to the left to find XML files that contain more...
112
World Watch OCD @ocdworldwatch.bsky.social · 03/07/2025
🧀 Update on MintsLoader: a thread 🔽 MintsLoader is a JavaScript/PowerShell loader that was first detailed by OCD in 2024. A new version has been around at least since early-June 2025. #threatintel #cti #mintsloader
124
World Watch OCD @ocdworldwatch.bsky.social · 20/02/2025
Written in C++, #NailaoLocker is relatively unsophisticated and poorly designed. The ransomware uses the “.locked” extension. It is loaded through DLL search-order hijacking.
000
World Watch OCD @ocdworldwatch.bsky.social · 20/02/2025
➡️The full article on the Green Nailao cluster is available here: orangecyberdefense.com/global/blog/... ➡️IOCs and Yara can be found on our GitHub: github.com/cert-orangec...
orangecyberdefense.com
100
World Watch OCD @ocdworldwatch.bsky.social · 20/02/2025
🆕We publish today the result of a deep-dive investigation into a malicious campaign leveraging #ShadowPad and #PlugX to distribute a previously-undocumented ransomware, dubbed #NailaoLocker. This campaign targeted 🇪🇺 organizations during S2 2024 and is tied to Chinese TA 🇨🇳.
110
World Watch OCD @ocdworldwatch.bsky.social · 05/12/2024
We provide a #Yara Rule to hunt for Edam Dropper, as well as related #Iocs and technical details, available on GitHub. 🤝The infection chain was also analyzed by @strikereadylabs.com last week, and could be tied to 🇷🇺 #Sandworm APT (low confidence). strikeready.com/blog/ru-apt-...
021
World Watch OCD @ocdworldwatch.bsky.social · 05/12/2024
While monitoring recent #Emmenhtal iterations, we observed a distinct politically-aligned cluster 🇪🇺, strongly differing from usual financially motivated Emmenhtal distribs. This cluster drops another malware we dubbed #Edam Dropper🧀 github.com/cert-orangec... Targets: European #energy sector🔋
github.com
GitHub - cert-orangecyberdefense/edam: Edam dropper
Edam dropper. Contribute to cert-orangecyberdefense/edam development by creating an account on GitHub.
120
World Watch OCD @ocdworldwatch.bsky.social · 25/11/2024
📍For more than 8 months, our threat researchers from OCD have worked on mapping China's civil-military–industrial complex when it comes to #cyberespionage operations. ⛯ Consult our newly published deep-dive report and interactive map here: research.cert.orangecyberdefense.com/hidden-netwo...
research.cert.orangecyberdefense.com
Orange Cyberdefense CERT Threat Research: The hidden network map
052