A ClickFix case brought our team down a BabaDeda chain that led to an undocumented end: CNCMachineRMS, a 1.14 MB RAT with zero imports, every string built on the stack, and its own scripting language.
The full research + PDF report below. ⤵️
The elite security team at @LevelBlueCyber. Response & Investigations. Analysis & Testing. Research & Development. Follow for info on the latest threats.
- 🪝#Phishing Alert: LevelBlue #MailMarshal has detected a phishing campaign targeting hotels, venues, and wedding service providers. Threat actors are sending convincing fake business inquiries covering wedding venues, event planning, and related services to trick recipients into
- Some teams follow alerts. SpiderLabs follows behavior, patterns, intent, and instinct, long before it reaches your environment. 🕷️💡 Precision matters when threats evolve overnight. Take a closer look at how that kind of visibility shows up in the real world. ⤵️
- Our gift to you: we have decided to do something for the community, with the hopes that more security vendors follow suit. We've been developing an advanced open-source Linux engine - dubbed owLSM - and have made it accessible for free, just for YOU. Meet owLSM: ⭐ A full Sigma
- A fake photo. A legitimate http://Node.js download. A blockchain-hosted C2. This campaign layers familiar tools and emerging techniques to stay hidden. hubs.ly/Q04pvSWB0

