Cybersecurity News

Filters
Tag
Reset

Filtered by tag: powershell × Clear

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Researchers at Check Point identified a ransomware operation called StopAndProtect in May 2026. The campaign uses the ClickFix social-engineering technique to trick victims into running a PowerShell command, triggering a multi-stage downloader chain. Thousands of hacked WordPress sites serve as infrastructure for the operation, which researchers have now partially unmasked through analysis of its infection chain and supporting infrastructure.

AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress

Threat actors are using AI tools to generate custom PowerShell malware for Active Directory attacks. Huntress researchers analyzed real "vibe-coded" samples, finding that AI-assisted scripts can enumerate AD environments effectively even without deep attacker expertise. The shift lowers the barrier for creating functional malware, complicating detection since AI-generated code may lack the patterns defenders typically recognize.

LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress

Attackers increasingly use "Living off the Land" techniques, abusing legitimate tools like PowerShell, WMI, and RMM software to blend in with normal IT activity. Key red flags include scripts running outside business hours, encoded commands, unusual parent-child process relationships, and tools accessing systems they don't normally touch. Context and behavioral baselines are critical for distinguishing malicious use from routine administrator work.