# backdoor

An undocumented means of gaining access to a computer system that poses a security risk.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## China's Salt Typhoon backdoors Latin American orgs with new snooping malware

DevFeed: [China's Salt Typhoon backdoors Latin American orgs with new snooping malware](<https://devfeed.tech/articles/china-s-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware-42150.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286>)

Author: Jessica Lyons

Published: 2026-09-17T18:00:17Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [infosec](<https://devfeed.tech/topics/infosec.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [backdoor-malware](<https://devfeed.tech/tags/backdoor-malware.md>), [china](<https://devfeed.tech/tags/china.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [salt-typhoon](<https://devfeed.tech/tags/salt-typhoon.md>), [security](<https://devfeed.tech/tags/security.md>), [sparrowocky](<https://devfeed.tech/tags/sparrowocky.md>)

### AI overview

A news report about Salt Typhoon using new snooping backdoors and malware against organizations in Latin America.

### Source excerpt

Beware the SparroWocky, my son! The backdoor that bites...

## ESET Researchers Analyze SparroWocky, a New C++ Backdoor Used by FamousSparrow

DevFeed: [ESET Researchers Analyze SparroWocky, a New C++ Backdoor Used by FamousSparrow](<https://devfeed.tech/articles/beware-the-sparrowock-the-backdoor-that-bites-the-commands-that-catch-42136.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/>)

Author: Alexandre Côté Cyr Romain Dumont

Published: 2026-09-17T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [apt](<https://devfeed.tech/topics/apt.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [malware](<https://devfeed.tech/tags/malware.md>), [sparrowocky](<https://devfeed.tech/tags/sparrowocky.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-internals](<https://devfeed.tech/tags/windows-internals.md>)

### AI overview

ESET researchers analyze SparroWocky, a modular C++ backdoor that the China-aligned FamousSparrow group has deployed against organizations in Latin America since at least August 2025.

### Source excerpt

ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group

## Laravel Scalpel Scans for Filesystem Intrusion Evidence

DevFeed: [Laravel Scalpel Scans for Filesystem Intrusion Evidence](<https://devfeed.tech/articles/laravel-scalpel-scans-for-filesystem-intrusion-evidence-41327.md>)

Original publisher: [Read original article](<https://laravel-news.com/laravel-scalpel>)

Author: Yannick Lyn Fatt

Published: 2026-09-17T01:38:29Z

Content type: article

Language: en

Sources: [Laravel](<https://devfeed.tech/sources/laravel.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [PHP](<https://devfeed.tech/topics/php.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [laravel-packages](<https://devfeed.tech/tags/laravel-packages.md>), [php](<https://devfeed.tech/tags/php.md>), [security](<https://devfeed.tech/tags/security.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>)

### AI overview

Laravel Scalpel is an intrusion-evidence scanner that runs inside Laravel applications. It checks filesystems for rogue PHP files, obfuscated code, altered server directives, environment issues, and changes from a trusted baseline.

### Source excerpt

Laravel Scalpel scans Laravel filesystems for rogue PHP files, obfuscated backdoors, altered directives, environment issues, and file changes. The post Laravel Scalpel Scans for Filesystem Intrusion Evidence appeared first on Laravel News. Join the Laravel Newsletter to get Laravel articles like this directly in your inbox.

## Forensic Walkthrough of a Compromised MikroTik Router and Its Persistence Mechanisms

DevFeed: [Forensic Walkthrough of a Compromised MikroTik Router and Its Persistence Mechanisms](<https://devfeed.tech/articles/a-first-hand-forensic-walkthrough-of-a-real-router-compromise-40164.md>)

Original publisher: [Read original article](<https://blog.j2sw.com/netops/mikrotik-router-compromise-forensic-walkthrough/>)

Author: j2sw

Published: 2026-09-16T13:32:46Z

Content type: article

Language: en

Sources: [Justin Wilson (j2sw)](<https://devfeed.tech/sources/justin-wilson-j2sw.md>)

Topics: [MikroTik](<https://devfeed.tech/topics/mikrotik.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [forensics](<https://devfeed.tech/tags/forensics.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [mikortrick](<https://devfeed.tech/tags/mikortrick.md>), [mikrotik](<https://devfeed.tech/tags/mikrotik.md>), [network-operations](<https://devfeed.tech/tags/network-operations.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A forensic walkthrough examines a compromised MikroTik router in a honeypot. The intruders established persistence and remote access through scheduled tasks, scripts, new users, and tunnels. The author suspects, but cannot prove, that the compromise involved the MikroTrick RouterOS vulnerability chain.

### Source excerpt

What it looks like when an intruder tries to make your own router work against you. A note before we start: Anything in this post that could identify my network, my organization, or my router's real hostname and IP address has been redacted or made generic. The attacker's own infrastructure, such as IP addresses, ports, ... Read more The post A first-hand forensic walkthrough of a real router compromise appeared first on Justin Wilson (j2sw).

## Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

DevFeed: [Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](<https://devfeed.tech/articles/untracked-nightmares-the-threats-hiding-behind-commodity-infrastructure-7757.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/>)

Author: Rem Dudas

Published: 2026-09-09T10:00:55Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [ARKTunnel](<https://devfeed.tech/topics/arktunnel.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [arktunnel](<https://devfeed.tech/tags/arktunnel.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cl-cri-1171](<https://devfeed.tech/tags/cl-cri-1171.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [docro-hijacker](<https://devfeed.tech/tags/docro-hijacker.md>), [gaming](<https://devfeed.tech/tags/gaming.md>), [malware](<https://devfeed.tech/tags/malware.md>), [pay-per-install](<https://devfeed.tech/tags/pay-per-install.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [youtube](<https://devfeed.tech/tags/youtube.md>)

### AI overview

An investigation of the CL-CRI-1171 cybercrime campaign describes how YouTube gaming lures and SEO poisoning delivered malware through a custom loader. It covers Docro Hijacker, ARKTunnel, and the Insomnia remote access Trojan.

### Source excerpt

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

## 'ChainDrop' worm compromises hundreds of popular npm packages

DevFeed: ['ChainDrop' worm compromises hundreds of popular npm packages](<https://devfeed.tech/articles/chaindrop-worm-compromises-hundreds-of-popular-npm-packages-8296.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/>)

Author: Christophe Tafani-Dereeper, Nick Frichette, Sebastian Obregoso, Martin McCloskey

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>)

### AI overview

ChainDrop is an npm worm that spread a backdoor through hundreds of compromised packages. The article analyzes its loader, which downloads or invokes Bun to run a second-stage payload.

### Source excerpt

On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware.

## Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor

DevFeed: [Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor](<https://devfeed.tech/articles/not-so-anonymous-telemetry-the-injectivelabs-sdk-ts-backdoor-8295.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/>)

Author: Sebastian Obregoso, Christophe Tafani-Dereeper, Eslam Salem

Published: 2026-07-09T00:00:00Z

Content type: news

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Git](<https://devfeed.tech/topics/git.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [TypeScript](<https://devfeed.tech/topics/typescript.md>), [servers](<https://devfeed.tech/topics/servers.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Prettier](<https://devfeed.tech/topics/prettier.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code](<https://devfeed.tech/tags/code.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [http](<https://devfeed.tech/tags/http.md>), [malware](<https://devfeed.tech/tags/malware.md>), [server](<https://devfeed.tech/tags/server.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [typescript](<https://devfeed.tech/tags/typescript.md>)

### AI overview

A malicious commit briefly compromised the Injective blockchain's @injectivelabs/sdk-ts npm package by disguising a credential-stealing backdoor as telemetry code. The malware captured wallet mnemonic seed phrases and private keys, encoded them, and exfiltrated them through HTTP requests to a remote endpoint before the code was reverted.

### Source excerpt

A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.

## MetaStealer traffic, new DGAs and analyzing the "tracker" backdoor DGA with AI

DevFeed: [MetaStealer traffic, new DGAs and analyzing the "tracker" backdoor DGA with AI](<https://devfeed.tech/articles/metastealer-traffic-new-dgas-and-analyzing-the-tracker-backdoor-dga-with-ai-22543.md>)

Original publisher: [Read original article](<https://medium.com/walmartglobaltech/metastealer-traffic-new-dgas-and-analyzing-the-tracker-backdoor-dga-with-ai-96ea63dc7c01?source=rss----905ea2b3d4d1---4>)

Author: Jason Reaves

Published: 2026-06-17T21:54:01Z

Content type: article

Language: en

Sources: [Walmart Global Tech](<https://devfeed.tech/sources/walmart-global-tech.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [payload](<https://devfeed.tech/topics/payload.md>), [Python](<https://devfeed.tech/topics/python.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [capture](<https://devfeed.tech/tags/capture.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-ai](<https://devfeed.tech/tags/claude-ai.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [ip](<https://devfeed.tech/tags/ip.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [port](<https://devfeed.tech/tags/port.md>), [python](<https://devfeed.tech/tags/python.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>)

### AI overview

The article examines new MetaStealer domain-generation algorithms and explains that its gate servers rely more on IP addresses, ports, URIs, and HTTP headers than on domains. It also analyzes RuntimeSync, a developing malware sample with RAT and backdoor capabilities, and describes using Claude.ai Sonnet 4.6 to reverse engineer its DGA and produce Python simulation code.

### Source excerpt

By: Jason Reaves and Joshua Platt In this blog we simply want to highlight a few new additions to what appears to be related to MetaStealer, one is a new wordlist based DGA used by MetaStealer. We also want to highlight that MetaStealer's proxies or 'gates' don't actually care what domain gets used as it's just a config item; they simply pass on the traffic to another server. We also want to highlight a task that was seen delivered to a few bots which is related to MetaStealer but appears to still be in development. This turned out to be a piece of malware that contains RAT/backdoor functionality. Leveraging Claude.ai Sonnet 4.6 we were able to systematically guide the AI to automatically reverse engineer the DGA used in the backdoor malware and provide working python code to simulate it. MetaStealer DGA: As previously mentioned MetaStealers new DGA is based on a wordlist. Below are some recent examples: sea-vast-send.com 46bbaceb6073f196bf7737c67f5394a6465e396bbcbbac1afe5f2f866c995fd0hxxp://pestrear-lamp.xyz:443 d57e132866286f9b4227c7fb1cd77f16a461e76a3f3e71362734741aab6b9a96hxxp://anus-staylard.xyz:443 d1b88ded80f0e616362b8984334c69da1ea2f32d0828480e32978d1a710f40c5 This does not mean, however, that the older DGA is no longer in use; it remains active. The threat actor (TA) has designed their gate servers in such a way that they are largely agnostic to the domain being used. Instead, the IP address, port, URI, and HTTP headers are the more important factors. 155.117.20.75 qocyeicmusmegouw.xyz 213.139.77.254 uumcceymkuymmqou.xyz We didn't focus on this DGA though because during our investigation we stumbled on a piece of malware being actively developed by the same TA that also had a DGA. Backdoor "tracker" During the investigation, we observed a peculiar payload being delivered to several machines: an installer named RuntimeSync, example hash: 82c218357266ce314f523946bdd661cc335a120981c471e95d70af7fbd4d9141 RuntimeSyncExe: PE32+ executable (GUI) x86-64, for MS Win

## FishMonger's arsenal upgraded: SprySOCKS for Windows

DevFeed: [FishMonger's arsenal upgraded: SprySOCKS for Windows](<https://devfeed.tech/articles/fishmonger-s-arsenal-upgraded-sprysocks-for-windows-8368.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/>)

Author: ESET Research

Published: 2026-06-16T08:54:04Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [china](<https://devfeed.tech/tags/china.md>), [communication](<https://devfeed.tech/tags/communication.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [government](<https://devfeed.tech/tags/government.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET reports two previously undocumented Windows variants of the SprySOCKS backdoor attributed to FishMonger. The variants use TCP, UDP, and WebSocket communications; WIN_DRV uses a kernel driver to conceal artifacts and redirect specially crafted TCP traffic.

### Source excerpt

ESET researchers have discovered SprySOCKS for Windows, FishMonger's backdoor weaponizing a kernel driver for advanced stealthiness

## OceanLotus: From external espionage to domestic targeting

DevFeed: [OceanLotus: From external espionage to domestic targeting](<https://devfeed.tech/articles/oceanlotus-from-external-espionage-to-domestic-targeting-8378.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/>)

Author: ESET Research

Published: 2026-06-11T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [dns](<https://devfeed.tech/tags/dns.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [linux](<https://devfeed.tech/tags/linux.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

The article analyzes OceanLotus's shift toward domestic espionage and two SPECTRALVIPER campaigns in Vietnam: a targeted supply-chain compromise of investor software and a prolonged intrusion against a construction corporation.

### Source excerpt

A shift in operational pattern of the infamous Vietnam-aligned APT group

## LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine

DevFeed: [LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine](<https://devfeed.tech/articles/labscon25-replay-gamaredon-x-turla-unveiling-a-2025-espionage-alliance-targeting-ukraine-8316.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/labscon25-replay-gamaredon-x-turla-unveiling-a-2025-espionage-alliance-targeting-ukraine/>)

Author: LABScon

Published: 2026-06-02T13:00:58Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [LABScon](<https://devfeed.tech/topics/labscon.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [conferences](<https://devfeed.tech/tags/conferences.md>), [labscon](<https://devfeed.tech/tags/labscon.md>), [labscon25](<https://devfeed.tech/tags/labscon25.md>), [malware](<https://devfeed.tech/tags/malware.md>), [presentation](<https://devfeed.tech/tags/presentation.md>), [research](<https://devfeed.tech/tags/research.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>)

### AI overview

ESET researchers present technical evidence that Gamaredon facilitated Turla's access to high-value Ukrainian targets between February and June 2025. The presentation examines their operational collaboration, the deployment of Turla's Kazuar backdoor, and the implications for defenders tracking Russian cyberespionage.

### Source excerpt

ESET researchers show how Gamaredon facilitated Turla access to Ukrainian targets, revealing rare cooperation between FSB-linked espionage groups.

## Webworm: New burrowing techniques

DevFeed: [Webworm: New burrowing techniques](<https://devfeed.tech/articles/webworm-new-burrowing-techniques-8383.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/>)

Author: Eric Howard

Published: 2026-05-20T08:40:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Discord](<https://devfeed.tech/topics/discord.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [API](<https://devfeed.tech/topics/api.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bash](<https://devfeed.tech/tags/bash.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [github](<https://devfeed.tech/tags/github.md>), [ip](<https://devfeed.tech/tags/ip.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [s3](<https://devfeed.tech/tags/s3.md>), [server](<https://devfeed.tech/tags/server.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

ESET researchers analyze Webworm's 2025 activity, including its shift toward Europe, new Discord- and Microsoft Graph API-based backdoors, proxy tools, reconnaissance activity, and GitHub-hosted malware staging.

### Source excerpt

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

## Backdoored node-ipc npm releases steal developer credentials through DNS queries

DevFeed: [Backdoored node-ipc npm releases steal developer credentials through DNS queries](<https://devfeed.tech/articles/backdoored-node-ipc-npm-releases-steal-developer-credentials-through-dns-queries-8294.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/node-ipc-npm-malware-analysis/>)

Author: Nick Frichette

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [payload](<https://devfeed.tech/topics/payload.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>), [Code](<https://devfeed.tech/topics/code.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [database](<https://devfeed.tech/tags/database.md>), [developer](<https://devfeed.tech/tags/developer.md>), [dns](<https://devfeed.tech/tags/dns.md>), [fork](<https://devfeed.tech/tags/fork.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [payload](<https://devfeed.tech/tags/payload.md>), [process](<https://devfeed.tech/tags/process.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This article analyzes three backdoored node-ipc releases published to npm on May 14, 2026. The malicious CommonJS entrypoint launches a detached process, collects environment, host, developer, cloud, package manager, source control, Kubernetes, database, and SSH credentials, archives the data, and attempts DNS TXT exfiltration.

### Source excerpt

An analysis of backdoored node-ipc npm releases that add an obfuscated credential collection and DNS exfiltration payload to the CommonJS entrypoint.

## A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

DevFeed: [A rigged game: ScarCruft compromises gaming platform in a supply-chain attack](<https://devfeed.tech/articles/a-rigged-game-scarcruft-compromises-gaming-platform-in-a-supply-chain-attack-8381.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/>)

Author: Filip Jurčacko

Published: 2026-05-05T08:55:27Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [LineageOS](<https://devfeed.tech/topics/lineageos.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Python](<https://devfeed.tech/topics/python.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [android](<https://devfeed.tech/tags/android.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [gaming](<https://devfeed.tech/tags/gaming.md>), [government](<https://devfeed.tech/tags/government.md>), [logging](<https://devfeed.tech/tags/logging.md>), [platform](<https://devfeed.tech/tags/platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [voice](<https://devfeed.tech/tags/voice.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET researchers describe a ScarCruft supply-chain attack that trojanized Windows and Android components of a Yanbian-themed gaming platform. The BirdCall backdoor supports espionage capabilities including collecting data and documents, screenshots, and voice recordings.

### Source excerpt

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

## Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers

DevFeed: [Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers](<https://devfeed.tech/articles/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers-8011.md>)

Original publisher: [Read original article](<https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/>)

Author: Liran Tal

Published: 2026-04-27T23:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [data observability](<https://devfeed.tech/topics/data-observability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Python](<https://devfeed.tech/topics/python.md>), [data-engineering](<https://devfeed.tech/topics/data-engineering.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [aws](<https://devfeed.tech/tags/aws.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [data-engineering](<https://devfeed.tech/tags/data-engineering.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [docker](<https://devfeed.tech/tags/docker.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Attackers compromised the elementary-data Python package's GitHub Actions publication pipeline through script injection and released malicious content that stole cloud credentials and SSH secrets from data engineering environments.

### Source excerpt

Attackers exploited a GitHub Actions script injection vulnerability to publish a malicious version of the elementary-data Python CLI (v0.23.3), embedding a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments.

## GopherWhisper: A burrow full of malware

DevFeed: [GopherWhisper: A burrow full of malware](<https://devfeed.tech/articles/gopherwhisper-a-burrow-full-of-malware-8372.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/>)

Author: Eric Howard

Published: 2026-04-23T08:59:18Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [go](<https://devfeed.tech/tags/go.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [slack](<https://devfeed.tech/tags/slack.md>)

### AI overview

ESET Research describes GopherWhisper, a China-aligned APT group targeting a Mongolian government entity. Its largely Go-based malware toolset uses backdoors, injectors, loaders, and legitimate services including Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control and exfiltration.

### Source excerpt

ESET Research has discovered a new China-aligned APT group that we've named GopherWhisper, which targets Mongolian governmental institutions

## Compromised axios npm package delivers cross-platform RAT

DevFeed: [Compromised axios npm package delivers cross-platform RAT](<https://devfeed.tech/articles/compromised-axios-npm-package-delivers-cross-platform-rat-8274.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/>)

Author: Christophe Tafani-Dereeper

Published: 2026-03-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [payload](<https://devfeed.tech/topics/payload.md>), [npm](<https://devfeed.tech/topics/npm.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [linux](<https://devfeed.tech/tags/linux.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article analyzes a March 31, 2026 supply-chain compromise in which an attacker hijacked an axios npm maintainer account and published two malicious releases. The releases added a typosquatted dependency that installed a cross-platform remote access trojan, though bugs limited the Windows and Linux payloads. The compromise lasted about three hours before npm removed the packages.

### Source excerpt

An attacker hijacked an axios maintainer's npm account to publish malicious releases that deliver a cross-platform RAT.

## Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise

DevFeed: [Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise](<https://devfeed.tech/articles/snyk-finds-prompt-injection-in-36-1467-malicious-payloads-in-a-toxicskills-study-of-agent-skills-supply-chain-compromise-8218.md>)

Original publisher: [Read original article](<https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [malware](<https://devfeed.tech/tags/malware.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk's ToxicSkills audit examined 3,984 AI agent skills and found that 36.82% had at least one security flaw. The research identified malware, credential theft, prompt injection, exposed secrets, backdoors, and data exfiltration affecting users of OpenClaw, Claude Code, and Cursor.

### Source excerpt

Snyk's ToxicSkills research reveals 36% of AI agent skills contain security flaws, including 1,467 vulnerable skills and active malicious payloads targeting OpenClaw, Claude Code, and Cursor users.

## Backdoors in VStarcam cameras

DevFeed: [Backdoors in VStarcam cameras](<https://devfeed.tech/articles/backdoors-in-vstarcam-cameras-36630.md>)

Original publisher: [Read original article](<https://palant.info/2026/01/07/backdoors-in-vstarcam-cameras/>)

Author: Wladimir Palant

Published: 2026-01-07T13:01:48Z

Content type: article

Language: en

Sources: [Almost Secure](<https://devfeed.tech/sources/almost-secure.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cameras](<https://devfeed.tech/tags/cameras.md>), [p2p](<https://devfeed.tech/tags/p2p.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An investigation of VStarcam cameras finds that firmware mechanisms systematically undermine administrator-password protection by leaking passwords and exposing cameras through internet-connected P2P functionality. The article also examines insecure firmware updates delivered over plain HTTP and recommends restricting internet access with a network firewall or using custom firmware.

### Source excerpt

VStarcam is an important brand of cameras based on the PPPP protocol. Unlike the LookCam cameras I looked into earlier, these are often being positioned as security cameras. And they in fact do a few things better like... well, like having a mostly working authentication mechanism. In order to access the camera one has to know its administrator password. So much for the theory. When I looked into the firmware of the cameras I discovered a surprising development: over the past years this protection has been systematically undermined. Various mechanisms have been added that leak the access password, and in several cases these cannot be explained as accidents. The overall tendency is clear: for some reason VStarcam really wants to have access to their customer's passwords. A reminder: "P2P" functionality based on the PPPP protocol means that these cameras will always communicate with and be accessible from the internet, even when located on a home network behind NAT. Short of installing a custom firmware this can only addressed by configuring the network firewall to deny internet access. Contents How to recognize affected cameras Downloading the firmware Caveats of this survey VStarcam's authentication approach Endpoint protection Unauthenticated log access Explicit password leaking via logs Log uploading Password-leaking backdoor Establishing a timeline The impact Coordinated disclosure attempt Recommendations How to recognize affected cameras Not every VStarcam camera has "VStarcam" printed on the side. I have seen reports of VStarcam cameras being sold under the brand names Besder, MVPower, AOMG, OUSKI, and there are probably more. Most cameras should be recognizable by the app used to manage them. Any camera managed by one of these apps should be a VStarcam camera: Eye4, EyeCloud, FEC Smart Home, HOTKam, O-KAM Pro, PnPCam, VeePai, VeeRecon, Veesky, VKAM, VsCam, VStarcam Ultra. Downloading the firmware VStarcam cameras have a mechanism to deliver firmware updates (Loo

## LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

DevFeed: [LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan](<https://devfeed.tech/articles/longnosedgoblin-tries-to-sniff-out-governmental-affairs-in-southeast-asia-and-japan-8374.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/>)

Author: Anton Cherepanov Peter Strýček

Published: 2025-12-18T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [.NET](<https://devfeed.tech/topics/net.md>), [enterprise deployment](<https://devfeed.tech/topics/enterprise-deployment.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [browser](<https://devfeed.tech/tags/browser.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-services](<https://devfeed.tech/tags/cloud-services.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [google](<https://devfeed.tech/tags/google.md>), [japan](<https://devfeed.tech/tags/japan.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [policy](<https://devfeed.tech/tags/policy.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET describes LongNosedGoblin, a China-aligned APT group conducting cyberespionage against governmental entities in Southeast Asia and Japan. The group deploys malware through Group Policy and uses tools including the NosyDoor backdoor and the C#/.NET NosyHistorian application.

### Source excerpt

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

## MuddyWater: Snakes by the riverbank

DevFeed: [MuddyWater: Snakes by the riverbank](<https://devfeed.tech/articles/muddywater-snakes-by-the-riverbank-8376.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/>)

Author: ESET Research

Published: 2025-12-02T10:00:15Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c](<https://devfeed.tech/tags/c.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [iran](<https://devfeed.tech/tags/iran.md>), [malware](<https://devfeed.tech/tags/malware.md>), [memory](<https://devfeed.tech/tags/memory.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [socks5](<https://devfeed.tech/tags/socks5.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET analyzes a MuddyWater campaign targeting organizations in Israel and Egypt that uses custom loaders, credential stealers, reverse tunnels, and the MuddyViper backdoor to evade defenses and maintain access.

### Source excerpt

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook

## Espressif says ESP32 undocumented Bluetooth HCI commands are not a backdoor

DevFeed: [Espressif says ESP32 undocumented Bluetooth HCI commands are not a backdoor](<https://devfeed.tech/articles/esp32-undocumented-bluetooth-commands-clearing-the-air-13684.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2025/03/esp32-bluetooth-clearing-the-air/>)

Author: John Lee

Published: 2025-03-10T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Bluetooth](<https://devfeed.tech/topics/bluetooth.md>), [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [bluetooth](<https://devfeed.tech/tags/bluetooth.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [hci](<https://devfeed.tech/tags/hci.md>), [iot](<https://devfeed.tech/tags/iot.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Espressif explains that the reported undocumented ESP32 Bluetooth HCI commands are controller debug commands. It says they do not participate in normal HCI communication with NimBLE or Bluedroid and do not pose a security threat or backdoor.

### Source excerpt

Overview# Espressif has already provided a formal response to the recently published claims about ESP32 Bluetooth controller serving as a potential "backdoor" or having "undocumented features" that can cause security concerns. This post highlights the technical details about the relevant commands (HCI Commands) that were undocumented and establishes that the mentioned undocumented HCI commands do not pose a security threat and are certainly not a "backdoor".

## 6 Ways Shadow Access Creates Risk in Your Infrastructure

DevFeed: [6 Ways Shadow Access Creates Risk in Your Infrastructure](<https://devfeed.tech/articles/6-ways-shadow-access-creates-risk-in-your-infrastructure-29851.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/six-ways-shadow-access-creates-risk-in-your-infrastructure/>)

Author: jpitts@goteleport.com (Jack Pitts)

Published: 2025-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Kubernetes clusters](<https://devfeed.tech/topics/kubernetes-clusters.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [breach](<https://devfeed.tech/tags/breach.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This article explains shadow access: unauthorized or unmonitored infrastructure and application access created by unmanaged credentials, shared SSH keys, hard-coded API tokens, and undocumented backdoors. It describes the resulting security, breach, and compliance risks and presents Teleport as a way to address their root causes.

### Source excerpt

Shadow access is one of the most dangerous threats to your infrastructure. Learn what it is, where it comes from, and how Teleport eliminates its root causes.

## Do not pass GO - Malicious Package Alert

DevFeed: [Do not pass GO - Malicious Package Alert](<https://devfeed.tech/articles/do-not-pass-go-malicious-package-alert-7943.md>)

Original publisher: [Read original article](<https://snyk.io/blog/go-malicious-package-alert/>)

Author: Vandana Verma Sehgal

Published: 2025-02-12T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [database](<https://devfeed.tech/tags/database.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [go](<https://devfeed.tech/tags/go.md>), [interest](<https://devfeed.tech/tags/interest.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article reports that a typosquatted BoltDB Go module contained a backdoor and remained available through Go module caching. It describes the reported impact and the removal of the module from GitHub and the Go module proxy.

### Source excerpt

Recently, researchers have found another Software Supply Chain issue in BoltDB, a popular database tool in the Go programming environment. The BoltDB Go Module was found backdoored and contained hidden malicious code.

[Next page](<https://devfeed.tech/topics/backdoor.md?cursor=WyIyMDI1LTAyLTEyVDA1OjAwOjAwKzAwOjAwIiwgImJlNmIwNDFiLWIzYjUtNGIxMS04NDdiLWZkODVjMDM2N2E3NCJd>)