Malware & Criminal Tooling Intelligence
New malware families, crimeware updates, loader/dropper campaigns, C2 infrastructure, and initial access broker tooling emerging from criminal underground channels.
Malware & Criminal Tooling — Archive & Latest
FDMTP Implant via QuickFox Supply Chain Attack + ENDLESSDOORS Router Backdoor (CVE-2026-66747): OTX Detection Pack
Two supply chain campaigns exposed: trojanized QuickFox VPN installers deploying the FDMTP implant, and Zbtlink routers shipping with the pre-installed ENDLESSDOORS backdoor (CVE-2026-66747).
Microsoft Teams Help-Desk Vishing + RMM Lateral Movement: OTX Pulse Detection Pack
OTX flags Teams help-desk impersonation leading to malware execution and lateral movement; 8 IPv4 C2/RMM indicators. Enterprise SOC urgency: high.
ScreenConnect RMM Abuse + SockTz AI-Enabled Intrusions + Teams Help Desk Vishing: OTX Pulse Analysis — Enterprise Detection Pack
Multi-wave campaigns abuse ScreenConnect RMM, Cloudflare tunnels, AI tooling, and Teams vishing against LATAM and enterprise orgs. Detection pack included. Hunt immediately.
D2IP C2 Evasion + Rogue ScreenConnect Worm Activity + Teams Help Desk Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal 45% of malware bypassing DNS via direct-to-IP C2, worm-like rogue ScreenConnect RMM deployments dropping XMRig, and Teams help desk vishing. High urgency for education, government, and transportation sectors.
XCSSET v40 Supply Chain Surge + SakDriver Kernel Rootkit + Teams Help Desk Intrusion: OTX Detection Pack
OTX pulses reveal XCSSET v40 infecting Xcode dev environments, the SakDriver Ring-0 rootkit evading ETW, and Teams-based help desk intrusion with live C2. High urgency — hunt now.
EtherHiding Magecart Campaign: Blockchain-Staged Card Skimmers Targeting WooCommerce & Magento — OTX Detection Pack
OTX pulse reveals Magecart operators staging payment skimmers inside Ethereum smart contracts, compromising WooCommerce, PrestaShop and Magento storefronts. High urgency for retail/e-commerce defenders.
Spring Ring Teams Vishing + EtherHiding Magecart + Gryxa AI-Built Toolkit: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal Teams-based vishing (Spring Ring), blockchain-staged Magecart skimmers, and the AI-built Gryxa RMM toolkit. Retail & enterprise targets. High urgency.
Fake MP4 ISO-BMFF Trojan + NetSupport RAT: PowerShell Loader Campaign via Cloudflare Infrastructure — OTX Detection Pack
Active campaign hides encrypted NetSupport Manager RAT inside fake MP4 uuid boxes, delivered via Cloudflare-fronted PowerShell loaders. High urgency — deploy IOCs & hunts now.
ToxicPanda + BadBox OTX Pulse: AI-Guardrail Safety Penalties, Android Banking Fraud, and Botnet Detection Pack
OTX pulse links ToxicPanda/BadBox indicators to AI-guardrail failure risks in SOC workflows; education and finance face elevated fraud and botnet exposure.
AsyncAPI npm Supply Chain RAT, VShell/SNOWLIGHT Go Loader & AnonyMousKIT AI PhaaS: OTX Pulse Analysis — Enterprise Detection Pack
Three active campaigns: AsyncAPI npm supply chain RAT, VShell/SNOWLIGHT targeting China defense-tech, and AnonyMousKIT AI PhaaS across 506 domains. Immediate action required.
GoGRPC Backdoor + Teams Vishing IAB Campaign and Sliver Intrusions on Philippine Nuclear/Defense Targets: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal a Teams vishing IAB deploying GoGRPC/BlindDoor backdoors and a suspected Chinese-speaking operator hitting Philippine nuclear and naval targets. Act now.
RMM Phishing Campaign (Fake CRA T4 / SSA Lures): Living-Off-the-Land RMM Abuse — OTX Pulse Detection Pack
Phishing operation impersonating CRA, SSA & Adobe delivers legitimate RMM tooling via password-protected archives; 46 countries hit, 45% US. Hunt now.
wp2shell Pre-Auth RCE Chain (CVE-2026-63030 / CVE-2026-60137) Targeting WordPress Core: OTX Pulse Analysis — Enterprise Detection Pack
CRITICAL: Unauthenticated RCE chain 'wp2shell' in WordPress Core is under active mass exploitation. Webshells, SQLi, and batch API abuse observed. Patch and hunt now.
Grandoreiro DLL Sideloading Campaign + PRIVATELOADER Residential Proxy SDK: OTX Pulse Analysis — Enterprise Detection Pack
Grandoreiro banking trojan hits Mexico/Spain via DLL sideloading; PRIVATELOADER spreads Peer2Profit proxy SDK. 59 IOCs live. High urgency for finance.
Operation ASTERIX Crypto-Fraud Pipeline, FakeMBAM Deceptive Downloads & ScreenConnect Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose a crypto vishing/fraud pipeline, 41 bait-and-switch download sites pushing FakeMBAM, and receipt-lure phishing delivering ScreenConnect. High urgency for finance and enterprise endpoints.
Shadow-HVNC Loader Kit + Operation ASTERIX & Fake AML Checker Crypto-Drain Campaigns: OTX Pulse Detection Pack
OTX pulses expose Shadow-HVNC/Shadow Loader tooling, the Operation ASTERIX vishing-to-wallet-theft pipeline, and fake AML checker sites draining crypto wallets. Enterprise finance and crypto-holding users at high risk.
ValleyRAT Overwolf Sideload + Operation QUICSILVER + ASTERIX Crypto Fraud Pipeline: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose ValleyRAT sideloaded via signed Overwolf binaries, a China-nexus Go backdoor hitting Myanmar diplomats, and an 885K-record crypto vishing pipeline. Hunt now.
C2Looper Rust Backdoor, Operation QUICSILVER & ASTERIX: OTX Pulse Analysis — GitHub C2, QUIC Exfiltration & Crypto-Vishing Detection Pack
OTX pulses reveal three active campaigns: Rust-based C2Looper backdoor using GitHub C2, China-nexus QUICSILVER targeting Myanmar diplomats, and ASTERIX crypto-vishing fraud pipeline. Urgent.
Project CAV3RN Espionage Framework: Google Apps Script C2 + DNS Channel Rotation Targeting Israel — OTX Detection Pack
Modular espionage framework CAV3RN targets Israeli entities using DNS A-record logic to rotate between HTTPS and Google Apps Script C2. High urgency for Israel-facing orgs.
SocGholish Dropcatch Scavengers + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal dropcatched domains feeding SocGholish/Keitaro fraud and CAV3RN espionage framework using Google Apps Script C2 against Israel. High urgency.
TencShell/Vshell AI-Assisted Intrusions + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack
Two active campaigns exposed: AI-assisted intrusions hitting government networks across 4 nations, and CAV3RN espionage framework abusing Google Apps Script for stealth C2 in Israel. URGENT.
ShinyHunters OAuth Abuse + DarkHotel North Korea Lures + Jewelbug Antino Backdoor: OTX Pulse Analysis — Enterprise Detection Pack
OTX intel on ShinyHunters Salesforce OAuth vishing, DarkHotel MSI/shellcode phishing, and Jewelbug's Antino espionage backdoor. Defense, gov, SaaS targets. High urgency.
O&O Syspectr RAT Masquerading as CNN, Avast & Stremio Apps: Lookalike-Domain Social Engineering Campaign — OTX Pulse Analysis
Fake CNN, Avast, and Stremio sites push attacker-linked O&O Syspectr RMM installers. Windows users targeted. Block lookalike domains; hunt Syspectr installs now.
CNCMachineRMS RAT, Lazarus Operation Dream Job Zero-Day & APT-C-60 SpyGlace: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose a ClickFix-delivered CNCMachineRMS RAT, Lazarus zero-day job-lure attacks on defense/aerospace, and APT-C-60 SpyGlace campaigns hitting Japan. High urgency.
Project CAV3RN Espionage Framework: DNS-Driven C2 via Google Apps Script — OTX Pulse Detection Pack
Modular espionage framework Project CAV3RN targets Israeli entities using DNS A-record logic to pivot between HTTPS and Google Apps Script C2 relay channels.
Kimwolf v7 IoT Botnet + Project CAV3RN Espionage Framework: OTX Pulse Analysis — Blockchain C2 & Google Apps Script Detection Pack
OTX pulses reveal Kimwolf v7 botnet weaponizing Android TV boxes with Ethereum Name Service C2, and Project CAV3RN espionage framework abusing Google Apps Script against Israeli targets.
Multi-Stage PowerShell Loader Abusing Vercel Infrastructure: XOR/Base64 Obfuscation Chain Delivers Grape.exe & Trojanized draw.io — OTX Detection Pack
Active multi-stage PowerShell loader pulls ZIP payloads from Vercel hosting via dorenzaa.com; heavily obfuscated XOR/Base64 stages execute disguised binaries. Hunt now.
GigaWiper + Crucio-Derived Wiper Cluster: OTX Pulse Analysis — RabbitMQ C2 and Fake-Ransomware Destruction Detection Pack
OTX pulse: Golang GigaWiper backdoor fuses Crucio-derived wiping, fake ransomware and RabbitMQ C2; hunt hashes, AMQP, raw disk writes. High urgency.
ENDLESSDOORS Router Backdoor + Legion Loader TDS + MUSTANG PANDA ZOHOMURK: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal pre-installed IoT backdoors (ENDLESSDOORS), a 12,700-domain fake-CAPTCHA traffic distribution system, and MUSTANG PANDA espionage against India's government and energy sectors.
BINDCLOAK Modular Backdoor + MIXEDKEY Loader: OTX Pulse Analysis — Middle East Government Campaign Detection Pack
Multi-stage espionage campaign hits Middle East government & energy targets via BINDCLOAK backdoor, reflectively loaded by MIXEDKEY. Hunt C2 & IOCs now.
ScreenConnect RMM Abuse via WsgiDAV Staging & Cloudflare Tunnels: OTX Pulse Analysis — Enterprise Detection Pack
Active campaign abusing ScreenConnect RMM via phishing lures and Cloudflare tunnels. High urgency.
Phorpiex, Mozi, Mirai: Direct-to-IP C2 Tactics — OTX Pulse Analysis
OTX Alert: 45% of malware bypass DNS via Direct-to-IP. Phorpiex/Mozi active against Education/Gov. Immediate blocking required.
XCSSET v40 & SakDriver Rootkit: macOS Supply Chain & Windows Kernel Evasion
Active campaigns: XCSSET v40 targets macOS devs via Xcode; SakDriver kernel rootkit evades Windows defenses. High urgency.
The Crown Prince, Nezha: China Chopper, AntSword & Ghost RAT Web Shell Campaign
Active log poisoning campaign exploiting phpMyAdmin to deploy China Chopper, Nezha, and Ghost RAT. Global targets detected.
ValleyRAT Resurgence: SilverFox Fake Installer Campaigns & BYOVD Techniques
SilverFox actor targets Asia with ValleyRAT via fake installers, leveraging BYOVD and process injection to bypass defenses.
Supply Chain Attack: lib-mtop & aone-cli RAT Cluster — OTX Pulse Analysis
Typosquatting npm campaign delivering cross-platform RAT via lib-mtop and aone-cli targeting Alibaba developers. Critical supply chain risk.
GoGRPC Backdoor & Teams Vishing Campaign: Helpdesk Hijacker IAB Tactics — OTX Pulse Analysis
Active IAB campaign abusing Microsoft Teams vishing and Quick Assist to deploy GoGRPC backdoor. Critical urgency.
BabaDeda Loader + ClickFix Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack
Advanced BabaDeda loader using ClickFix social engineering targeting enterprise networks. High urgency - widespread detection recommended.
AsyncRAT & Remcos RATs + BabaDeda Loader: Multi-Stage Phishing & ClickFix Campaigns — Enterprise Detection Pack
Active phishing campaigns delivering AsyncRAT/Remcos via steganography and the BabaDeda ClickFix loader. Urgent blocking required.
TonRAT, AsyncRAT & BabaDeda Campaigns: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns delivering TonRAT, AsyncRAT, and BabaDeda via ZIPs, phishing, and ClickFix. High urgency for hospitality.
wp2shell RCE Chain & CMSmap Webshell Deployment: OTX Pulse Analysis — Enterprise Detection Pack
Active exploitation of CVE-2026-63030/CVE-2026-60137 'wp2shell' chain drops CMSmap webshells on default WordPress installs. Urgent.
ZimReaper, wp2shell, and IOCONTROL: OTX Pulse Analysis — Critical Infrastructure Threat Pack
Active exploitation of Zimbra (CVE-2025-66376) by TA488, widespread wp2shell RCE on WordPress, and Cyber Av3ngers targeting US ICS via IOCONTROL.
TrickBot DNS Tunneling Variant: C2 Infrastructure & Persistence Analysis
Active TrickBot variant detected using DNS tunneling for C2. High urgency due to evasion techniques.
ValleyRAT & Lampion Campaigns: Multi-Vector VBS/HTML Threats Targeting Finance & Global WhatsApp Users
OTX pulses reveal active VBS-distributing WhatsApp campaign (ValleyRAT/gh0st RAT) and Portugal-targeted banking trojan (Lampion) via obfuscated HTML.
TELESHIM, MIXEDKEY, BINDCLOAK: Targeted Middle East Government Attack — OTX Pulse Analysis
Active East Asia-linked campaign uses TELESHIM (Telegram C2) and MIXEDKEY to target Middle East gov entities. High urgency.
Popa Android Proxyware SDK: Residential Proxy Network Abuse — OTX Pulse Analysis
Android proxyware 'Popa' and variants infect consumer devices via IPTV apps for commercial proxy networks. Urgent block required.
NetSupport RMM via Python Side-Loading: MediaFire ZIP Attack Chain Analysis
Urgent: Active NetSupport RMM campaign using MediaFire ZIPs, Python DLL side-loading, and dllhost.exe injection.
HelloNet APT & Daxin Rootkit Resurgence: OTX Pulse Analysis — Enterprise Detection Pack
Active APT campaigns HelloNet (Russia) and Daxin (Taiwan) exploit software updates and Winlogon via DLL sideloading. High urgency.
TencShell, Lucide Proxy & BadIIS: OTX Pulse Analysis — AI-Powered Intrusions & DDoS Botnets
Active AI-powered espionage (TencShell), npm-based DDoS bots (Lucide), and SQLi-to-crypto persistence (BadIIS) detected. High urgency.
Vercel-Hosted Phishing Campaign Distributing LogMeIn RAT: OTX Pulse Analysis
Cybercriminals abuse Vercel to deliver LogMeIn RAT via fake PDF viewers. High urgency.
Showing 50 of 135 reports. Archive expands automatically as new intel is generated.
Every Malware & Criminal ToolingReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.