Dark Side Intelligence Category

Malware & Criminal Tooling Intelligence

New malware families, crimeware updates, loader/dropper campaigns, C2 infrastructure, and initial access broker tooling emerging from criminal underground channels.

152 reports available•Refreshed every 5 minutes

Malware & Criminal Tooling — Archive & Latest

50 reports loaded
Malware & Criminal Tooling

OpenSUpdater SFX Evasion, Sliver C2 Against Philippine Nuclear/Defense, and SilentXMRMiner On-Endpoint Compilation: OTX Pulse Analysis — Enterprise Detection Pack

Three active campaigns: OpenSUpdater hidden in recompiled 7zip SFX, Chinese-speaking APT exfiltrating 9GB from Philippine nuclear/defense targets, and silent Monero miners compiled directly on endpoints. High urgency.

Sep 25, 2026
Read →
Malware & Criminal Tooling

AvisLoader Windows Loader: Tox P2P C2 + ClickFix Social Engineering — OTX Detection & Hunting Pack

New AvisLoader malware uses Tox P2P encrypted C2 to survive takedowns. Delivered via ClickFix lures with UAC bypass and shortcut persistence. Hunt now.

Sep 23, 2026
Read →
Malware & Criminal Tooling

Equation of Compromise: npm Supply-Chain Loader with Ethereum Smart Contract C2 — OTX Pulse Detection Pack

Sophisticated 6-month npm supply-chain campaign targets DeFi/quant developers via math libraries with encrypted loaders and Ethereum-based C2. Urgent hunt advised.

Sep 22, 2026
Read →
Malware & Criminal Tooling

Brevo Supply Chain Compromise: WordPress Backdoor + ClickFix Dual-Payload Campaign — OTX Detection Pack

CRITICAL: Brevo CDN compromise poisoned 100k+ sites with WordPress backdoors and ClickFix overlays. IOCs, Sigma rules, KQL hunts, and response guidance inside.

Sep 18, 2026
Read →
Malware & Criminal Tooling

ShadowHVNC RAT Kit + Brevo Supply-Chain ClickFix Campaign: OTX Pulse Analysis — Enterprise Detection Pack

Two active campaigns: ShadowHVNC/Shadow Loader RAT kit and a Brevo CDN supply-chain compromise pushing WordPress backdoors and ClickFix lures to 100k+ sites.

Sep 18, 2026
Read →
Malware & Criminal Tooling

MovieReaper Torrent Loader, HEAVYGRAM Telegram Backdoor & Fake HTS Ransomware: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose MovieReaper torrent malware, Handala Hack's HEAVYGRAM Telegram backdoor, and fake HTS ransomware targeting finance. High urgency.

Sep 18, 2026
Read →
Malware & Criminal Tooling

ValleyRAT via Signed Overwolf Sideloading + SilkParasite SpiceRAT C2 Cluster: OTX Pulse Analysis — Enterprise Detection Pack

ValleyRAT sideloaded via signed Overwolf binary targets Indian tax-themed phishing victims; SilkParasite SpiceRAT infrastructure hits government/energy across Central Asia. Hunt now.

Sep 17, 2026
Read →
Malware & Criminal Tooling

Mythic C2 Infrastructure Exposure + Operation QUICSILVER (QUICAgent): OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose 131 Mythic C2 servers and Operation QUICSILVER, a China-nexus campaign hitting Myanmar diplomats with VHD-delivered Go backdoors. Hunt now.

Sep 16, 2026
Read →
Malware & Criminal Tooling

C2Looper Rust Backdoor, Exposed Mythic C2 Fleet & Operation QUICSILVER: OTX Pulse Detection Pack — GitHub C2 Abuse, ClickFix Chains & QUIC Backdoors

OTX pulse analysis: Rust-based C2Looper backdoor abusing GitHub C2, 131 exposed Mythic C2 servers, and China-nexus Operation QUICSILVER targeting Myanmar diplomats. High urgency.

Sep 16, 2026
Read →
Malware & Criminal Tooling

PIVOTPIPE .NET Beacon & Mythic C2 Infrastructure at Scale: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal PIVOTPIPE, a new .NET Cobalt Strike-style beacon, plus 131 internet-exposed Mythic C2 servers. Block IOCs and hunt for beaconing now.

Sep 16, 2026
Read →
Malware & Criminal Tooling

JFrog Artifactory CVE-2026-42016/42018/82329 Exploit Chain + Rust Backdoor: OTX Detection Pack

Active in-the-wild chaining of three JFrog Artifactory CVEs for auth bypass, admin compromise, Groovy plugin abuse and Rust backdoor deployment. Patch and hunt now.

Sep 13, 2026
Read →
Malware & Criminal Tooling

Project CAV3RN Google Apps Script C2 Framework + JFrog Artifactory CVE-2026-42016/42018/82329 Exploitation: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose Project CAV3RN espionage framework using DNS-selected Google Apps Script C2 against Israeli targets, plus active in-the-wild JFrog Artifactory CVE chaining. Hunt now.

Sep 13, 2026
Read →
Malware & Criminal Tooling

Kimwolf v7 IoT Botnet, CAV3RN Espionage Framework & Malicious Crypto Extensions: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose Kimwolf v7 IoT DDoS botnet with blockchain C2, CAV3RN espionage framework targeting Israel, and browser extensions stealing crypto trader sessions. Act now.

Sep 12, 2026
Read →
Malware & Criminal Tooling

WindRelay NFC Fraud Combo, SloppyRAT ClickFix Chains & Head Mare TrueConf Zero-Day: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal NFC-relay banking fraud (WindRelay/SpyNote), ransomware-stage SloppyRAT via ClickFix, and Head Mare APT exploiting TrueConf servers. High urgency.

Sep 11, 2026
Read →
Malware & Criminal Tooling

Mantax Otax Mobile Ransomware, CAV3RN Espionage Framework & Browser Extension Crypto Theft: OTX Pulse Detection Pack

OTX pulses reveal Indonesian mobile ransomware-spyware, a Google Apps Script C2 espionage framework hitting Israel, and malicious browser extensions stealing crypto sessions. High urgency.

Sep 10, 2026
Read →
Malware & Criminal Tooling

Redis Cryptomining Botnet (3,562 Compromised Servers) + Hagaseca Android RAT Loader: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose a rogue-replication Redis botnet mining Monero across 3,562 servers and Hagaseca, a packed Android RAT spreading via exposed ADB. Hunt now.

Sep 9, 2026
Read →
Malware & Criminal Tooling

StyleSmuggler 0-Day (CVE-2025-54236): Unauthenticated RCE Campaign Against Magento & Adobe Commerce — OTX Pulse Analysis + Detection Pack

Actively exploited zero-day in Magento/Adobe Commerce enables unauthenticated RCE via style property injection and payment email templates. IOCs, Sigma, KQL, and hunt scripts inside.

Sep 7, 2026
Read →
Malware & Criminal Tooling

FDMTP Implant via QuickFox Supply Chain Attack + ENDLESSDOORS Router Backdoor (CVE-2026-66747): OTX Detection Pack

Two supply chain campaigns exposed: trojanized QuickFox VPN installers deploying the FDMTP implant, and Zbtlink routers shipping with the pre-installed ENDLESSDOORS backdoor (CVE-2026-66747).

Sep 4, 2026
Read →
Malware & Criminal Tooling

Microsoft Teams Help-Desk Vishing + RMM Lateral Movement: OTX Pulse Detection Pack

OTX flags Teams help-desk impersonation leading to malware execution and lateral movement; 8 IPv4 C2/RMM indicators. Enterprise SOC urgency: high.

Sep 3, 2026
Read →
Malware & Criminal Tooling

ScreenConnect RMM Abuse + SockTz AI-Enabled Intrusions + Teams Help Desk Vishing: OTX Pulse Analysis — Enterprise Detection Pack

Multi-wave campaigns abuse ScreenConnect RMM, Cloudflare tunnels, AI tooling, and Teams vishing against LATAM and enterprise orgs. Detection pack included. Hunt immediately.

Sep 3, 2026
Read →
Malware & Criminal Tooling

D2IP C2 Evasion + Rogue ScreenConnect Worm Activity + Teams Help Desk Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal 45% of malware bypassing DNS via direct-to-IP C2, worm-like rogue ScreenConnect RMM deployments dropping XMRig, and Teams help desk vishing. High urgency for education, government, and transportation sectors.

Sep 3, 2026
Read →
Malware & Criminal Tooling

XCSSET v40 Supply Chain Surge + SakDriver Kernel Rootkit + Teams Help Desk Intrusion: OTX Detection Pack

OTX pulses reveal XCSSET v40 infecting Xcode dev environments, the SakDriver Ring-0 rootkit evading ETW, and Teams-based help desk intrusion with live C2. High urgency — hunt now.

Sep 2, 2026
Read →
Malware & Criminal Tooling

EtherHiding Magecart Campaign: Blockchain-Staged Card Skimmers Targeting WooCommerce & Magento — OTX Detection Pack

OTX pulse reveals Magecart operators staging payment skimmers inside Ethereum smart contracts, compromising WooCommerce, PrestaShop and Magento storefronts. High urgency for retail/e-commerce defenders.

Aug 31, 2026
Read →
Malware & Criminal Tooling

Spring Ring Teams Vishing + EtherHiding Magecart + Gryxa AI-Built Toolkit: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal Teams-based vishing (Spring Ring), blockchain-staged Magecart skimmers, and the AI-built Gryxa RMM toolkit. Retail & enterprise targets. High urgency.

Aug 31, 2026
Read →
Malware & Criminal Tooling

Fake MP4 ISO-BMFF Trojan + NetSupport RAT: PowerShell Loader Campaign via Cloudflare Infrastructure — OTX Detection Pack

Active campaign hides encrypted NetSupport Manager RAT inside fake MP4 uuid boxes, delivered via Cloudflare-fronted PowerShell loaders. High urgency — deploy IOCs & hunts now.

Aug 31, 2026
Read →
Malware & Criminal Tooling

ToxicPanda + BadBox OTX Pulse: AI-Guardrail Safety Penalties, Android Banking Fraud, and Botnet Detection Pack

OTX pulse links ToxicPanda/BadBox indicators to AI-guardrail failure risks in SOC workflows; education and finance face elevated fraud and botnet exposure.

Aug 29, 2026
Read →
Malware & Criminal Tooling

AsyncAPI npm Supply Chain RAT, VShell/SNOWLIGHT Go Loader & AnonyMousKIT AI PhaaS: OTX Pulse Analysis — Enterprise Detection Pack

Three active campaigns: AsyncAPI npm supply chain RAT, VShell/SNOWLIGHT targeting China defense-tech, and AnonyMousKIT AI PhaaS across 506 domains. Immediate action required.

Aug 28, 2026
Read →
Malware & Criminal Tooling

GoGRPC Backdoor + Teams Vishing IAB Campaign and Sliver Intrusions on Philippine Nuclear/Defense Targets: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal a Teams vishing IAB deploying GoGRPC/BlindDoor backdoors and a suspected Chinese-speaking operator hitting Philippine nuclear and naval targets. Act now.

Aug 26, 2026
Read →
Malware & Criminal Tooling

RMM Phishing Campaign (Fake CRA T4 / SSA Lures): Living-Off-the-Land RMM Abuse — OTX Pulse Detection Pack

Phishing operation impersonating CRA, SSA & Adobe delivers legitimate RMM tooling via password-protected archives; 46 countries hit, 45% US. Hunt now.

Aug 26, 2026
Read →
Malware & Criminal Tooling

wp2shell Pre-Auth RCE Chain (CVE-2026-63030 / CVE-2026-60137) Targeting WordPress Core: OTX Pulse Analysis — Enterprise Detection Pack

CRITICAL: Unauthenticated RCE chain 'wp2shell' in WordPress Core is under active mass exploitation. Webshells, SQLi, and batch API abuse observed. Patch and hunt now.

Aug 22, 2026
Read →
Malware & Criminal Tooling

Grandoreiro DLL Sideloading Campaign + PRIVATELOADER Residential Proxy SDK: OTX Pulse Analysis — Enterprise Detection Pack

Grandoreiro banking trojan hits Mexico/Spain via DLL sideloading; PRIVATELOADER spreads Peer2Profit proxy SDK. 59 IOCs live. High urgency for finance.

Aug 21, 2026
Read →
Malware & Criminal Tooling

Operation ASTERIX Crypto-Fraud Pipeline, FakeMBAM Deceptive Downloads & ScreenConnect Phishing: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose a crypto vishing/fraud pipeline, 41 bait-and-switch download sites pushing FakeMBAM, and receipt-lure phishing delivering ScreenConnect. High urgency for finance and enterprise endpoints.

Aug 20, 2026
Read →
Malware & Criminal Tooling

Shadow-HVNC Loader Kit + Operation ASTERIX & Fake AML Checker Crypto-Drain Campaigns: OTX Pulse Detection Pack

OTX pulses expose Shadow-HVNC/Shadow Loader tooling, the Operation ASTERIX vishing-to-wallet-theft pipeline, and fake AML checker sites draining crypto wallets. Enterprise finance and crypto-holding users at high risk.

Aug 20, 2026
Read →
Malware & Criminal Tooling

ValleyRAT Overwolf Sideload + Operation QUICSILVER + ASTERIX Crypto Fraud Pipeline: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose ValleyRAT sideloaded via signed Overwolf binaries, a China-nexus Go backdoor hitting Myanmar diplomats, and an 885K-record crypto vishing pipeline. Hunt now.

Aug 18, 2026
Read →
Malware & Criminal Tooling

C2Looper Rust Backdoor, Operation QUICSILVER & ASTERIX: OTX Pulse Analysis — GitHub C2, QUIC Exfiltration & Crypto-Vishing Detection Pack

OTX pulses reveal three active campaigns: Rust-based C2Looper backdoor using GitHub C2, China-nexus QUICSILVER targeting Myanmar diplomats, and ASTERIX crypto-vishing fraud pipeline. Urgent.

Aug 18, 2026
Read →
Malware & Criminal Tooling

Project CAV3RN Espionage Framework: Google Apps Script C2 + DNS Channel Rotation Targeting Israel — OTX Detection Pack

Modular espionage framework CAV3RN targets Israeli entities using DNS A-record logic to rotate between HTTPS and Google Apps Script C2. High urgency for Israel-facing orgs.

Aug 14, 2026
Read →
Malware & Criminal Tooling

SocGholish Dropcatch Scavengers + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal dropcatched domains feeding SocGholish/Keitaro fraud and CAV3RN espionage framework using Google Apps Script C2 against Israel. High urgency.

Aug 14, 2026
Read →
Malware & Criminal Tooling

TencShell/Vshell AI-Assisted Intrusions + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack

Two active campaigns exposed: AI-assisted intrusions hitting government networks across 4 nations, and CAV3RN espionage framework abusing Google Apps Script for stealth C2 in Israel. URGENT.

Aug 13, 2026
Read →
Malware & Criminal Tooling

ShinyHunters OAuth Abuse + DarkHotel North Korea Lures + Jewelbug Antino Backdoor: OTX Pulse Analysis — Enterprise Detection Pack

OTX intel on ShinyHunters Salesforce OAuth vishing, DarkHotel MSI/shellcode phishing, and Jewelbug's Antino espionage backdoor. Defense, gov, SaaS targets. High urgency.

Aug 13, 2026
Read →
Malware & Criminal Tooling

O&O Syspectr RAT Masquerading as CNN, Avast & Stremio Apps: Lookalike-Domain Social Engineering Campaign — OTX Pulse Analysis

Fake CNN, Avast, and Stremio sites push attacker-linked O&O Syspectr RMM installers. Windows users targeted. Block lookalike domains; hunt Syspectr installs now.

Aug 12, 2026
Read →
Malware & Criminal Tooling

CNCMachineRMS RAT, Lazarus Operation Dream Job Zero-Day & APT-C-60 SpyGlace: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose a ClickFix-delivered CNCMachineRMS RAT, Lazarus zero-day job-lure attacks on defense/aerospace, and APT-C-60 SpyGlace campaigns hitting Japan. High urgency.

Aug 12, 2026
Read →
Malware & Criminal Tooling

Project CAV3RN Espionage Framework: DNS-Driven C2 via Google Apps Script — OTX Pulse Detection Pack

Modular espionage framework Project CAV3RN targets Israeli entities using DNS A-record logic to pivot between HTTPS and Google Apps Script C2 relay channels.

Aug 11, 2026
Read →
Malware & Criminal Tooling

Kimwolf v7 IoT Botnet + Project CAV3RN Espionage Framework: OTX Pulse Analysis — Blockchain C2 & Google Apps Script Detection Pack

OTX pulses reveal Kimwolf v7 botnet weaponizing Android TV boxes with Ethereum Name Service C2, and Project CAV3RN espionage framework abusing Google Apps Script against Israeli targets.

Aug 11, 2026
Read →
Malware & Criminal Tooling

Multi-Stage PowerShell Loader Abusing Vercel Infrastructure: XOR/Base64 Obfuscation Chain Delivers Grape.exe & Trojanized draw.io — OTX Detection Pack

Active multi-stage PowerShell loader pulls ZIP payloads from Vercel hosting via dorenzaa.com; heavily obfuscated XOR/Base64 stages execute disguised binaries. Hunt now.

Aug 10, 2026
Read →
Malware & Criminal Tooling

GigaWiper + Crucio-Derived Wiper Cluster: OTX Pulse Analysis — RabbitMQ C2 and Fake-Ransomware Destruction Detection Pack

OTX pulse: Golang GigaWiper backdoor fuses Crucio-derived wiping, fake ransomware and RabbitMQ C2; hunt hashes, AMQP, raw disk writes. High urgency.

Aug 9, 2026
Read →
Malware & Criminal Tooling

ENDLESSDOORS Router Backdoor + Legion Loader TDS + MUSTANG PANDA ZOHOMURK: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal pre-installed IoT backdoors (ENDLESSDOORS), a 12,700-domain fake-CAPTCHA traffic distribution system, and MUSTANG PANDA espionage against India's government and energy sectors.

Aug 7, 2026
Read →
Malware & Criminal Tooling

BINDCLOAK Modular Backdoor + MIXEDKEY Loader: OTX Pulse Analysis — Middle East Government Campaign Detection Pack

Multi-stage espionage campaign hits Middle East government & energy targets via BINDCLOAK backdoor, reflectively loaded by MIXEDKEY. Hunt C2 & IOCs now.

Aug 5, 2026
Read →
Malware & Criminal Tooling

ScreenConnect RMM Abuse via WsgiDAV Staging & Cloudflare Tunnels: OTX Pulse Analysis — Enterprise Detection Pack

Active campaign abusing ScreenConnect RMM via phishing lures and Cloudflare tunnels. High urgency.

Aug 5, 2026
Read →
Malware & Criminal Tooling

Phorpiex, Mozi, Mirai: Direct-to-IP C2 Tactics — OTX Pulse Analysis

OTX Alert: 45% of malware bypass DNS via Direct-to-IP. Phorpiex/Mozi active against Education/Gov. Immediate blocking required.

Aug 4, 2026
Read →
Malware & Criminal Tooling

XCSSET v40 & SakDriver Rootkit: macOS Supply Chain & Windows Kernel Evasion

Active campaigns: XCSSET v40 targets macOS devs via Xcode; SakDriver kernel rootkit evades Windows defenses. High urgency.

Aug 3, 2026
Read →

Showing 50 of 152 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every Malware & Criminal Tooling Report Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.