Visualização normal

Antes de ontemAnalyst
  • ✇The DFIR Report
  • Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware editor
    The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.
     

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

Por:editor
11 de Maio de 2026, 11:05

The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […]

The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

  • ✇The DFIR Report
  • Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira editor
    Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in May of 2025 Cyjax reported on a campaign using this method again, impersonating various IT tools. We observed a similar campaign in […] The post Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira appeared first on The DFIR Report.
     

Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

Por:editor
5 de Agosto de 2025, 18:30

Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in May of 2025 Cyjax reported on a campaign using this method again, impersonating various IT tools. We observed a similar campaign in […]

The post Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira appeared first on The DFIR Report.

  • ✇The DFIR Report
  • KongTuke FileFix Leads to New Interlock RAT Variant editor
    Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.
     

KongTuke FileFix Leads to New Interlock RAT Variant

Por:editor
13 de Julho de 2025, 21:50

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […]

The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.

❌
❌