Visualização normal

Antes de ontemUnit 42

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

31 de Agosto de 2026, 07:00

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

25 de Agosto de 2026, 07:00

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.

The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Identity Abuse Through Trusted Communication Channels

20 de Agosto de 2026, 07:00

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.

The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

Kimwolf v7: An Evolution of the Kimwolf Botnet

11 de Agosto de 2026, 07:00

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.

The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

10 de Agosto de 2026, 19:00

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.

The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

  • ✇Unit 42
  • ChainDrop: Inside a Self-Propagating npm Worm Unit 42
    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
     

ChainDrop: Inside a Self-Propagating npm Worm

6 de Agosto de 2026, 19:26

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.

The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

6 de Agosto de 2026, 07:00

Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.

The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.

Almost Half of Malware Samples Communicate Direct to IP

4 de Agosto de 2026, 09:50

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.

The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

3 de Agosto de 2026, 07:00

Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.

The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42.

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

31 de Julho de 2026, 07:00

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.

The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

15 de Julho de 2026, 07:00

TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.

The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination.

The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

25 de Junho de 2026, 19:00

Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor.

The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud.

The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.

Trust No Skill: Integrity Verification for AI Agent Supply Chains

11 de Junho de 2026, 07:00

Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains.

The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42.

Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

2 de Junho de 2026, 07:00

Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework.

The post Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor appeared first on Unit 42.

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

22 de Maio de 2026, 10:00

Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns.

The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.

Tracking TamperedChef Clusters via Certificate and Code Reuse

20 de Maio de 2026, 07:00

Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets.

The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.

❌
❌