Rapid7 finds a North Korea-linked toolkit hiding inside trojanized HAProxy builds at two South Korean firms.
New Windows implant TWINLOOT abuses SharePoint and Teams to steal credentials and move laterally.
Group-IB discovered HOLLOWGRAPH, malware that uses Microsoft 365 calendars as covert command channels with events dated to 2050.
The memory resident Rust based trojan reuses the transport layer from an open source anti-censorship proxy framework to create encrypted…
A junior attacker used Tailscale and OpenSSH as a backup channel to maintain access to a compromised automotive business after…