« Reports in 2026

508 reports

2026-07-30 • S2W

S2W analyzed three malware clusters targeting South Korea that combine legitimate-process abuse, DLL side-loading, encrypted payload staging, and manual PE mapping. Two chains deploy SIGNBT v0.0.1 or v1.2 from service-registry blobs or embedded containers…

#Fileless #SIGNBT #T1027.013 #T1082 #T1059.003 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1071.001 #T1083 #T1036.005 #T1105 #T1620 #T1573.001 #T1049 #T1016 #T1070.006 #T1027.007 #T1574.001 #T1055.001 #T1033 #T1569.002 #T1012
2026-07-28 • Socket

Two Joyfill beta packages contained an import-time JavaScript implant that used Tron, Aptos, and BNB Smart Chain transactions to resolve mutable payloads. The recovered chain delivered a DEV#POPPER Node.js RAT capable of remote command execution, file tra…

#SupplyChain #NPM #DevPopper #OmniStealer #PolinRider #T1027.013 #T1071.001 #T1195.002 #T1115 #T1059.006 #T1059.007 #T1059.004 #T1027 #T1105 #Joyfill
2026-07-27 • Rekt

Compromise of AFX Trade's off-chain validator signing system allowed five signatures to authorize a fraudulent withdrawal of approximately $24.15 million in USDC from its Arbitrum bridge on July 22, 2026. The attacker bridged the assets to Ethereum, conve…

#DeFi #UNC4899 #AFX