My Courses

  • Lazarus Group boosts malware tools with PondRAT, ThemeForestRAT, & RemotePE

    Lazarus Group boosts malware tools with PondRAT, ThemeForestRAT, & RemotePE

    The North Korea-linked threat actor known as the Lazarus Group has been linked to a social engineering campaign that distributes three distinct pieces of cross-platform malware: PondRAT, ThemeForestRAT, and RemotePE. This attack, observed by NCC Group’s Fox-IT in 2024, targeted an organisation in the Decentralised Finance (DeFi) sector, ultimately leading to the compromise of an…

  • Remote hiring fraud increasing quickly

    Remote hiring fraud increasing quickly

    What if the star engineer that an organisation just hired is actually an attacker in disguise? This scenario is not about phishing; it involves infiltration through the onboarding process. Meet “Jordan from Colorado,” who possesses a strong resume, convincing references, a clean background check, and a digital footprint that checks out. On their first day,…

  • MystRodX backdoor uses DNS and ICMP triggers for covert manipulation

    MystRodX backdoor uses DNS and ICMP triggers for covert manipulation

    Cybersecurity researchers have recently unveiled a sophisticated backdoor known as MystRodX, which is designed to capture sensitive data from compromised systems. Implemented in C++, MystRodX boasts features such as file management, port forwarding, reverse shell, and socket management. According to QiAnXin XLab, this backdoor distinguishes itself from typical variants through its exceptional stealth and flexibility.…

  • Can AI agents identify threats that your Security Operations Center overlooks?

    Can AI agents identify threats that your Security Operations Center overlooks?

    A new research project called NetMoniAI demonstrates how AI agents could transform network monitoring and security. Developed by a team at Texas Tech University, the framework integrates distributed monitoring at the edge with AI-driven analysis at the centre. Although still in the research stage, it provides Chief Information Security Officers (CISOs) with insights into the…

  • Iranian cybercriminals compromise over 100 diplomatic email accounts

    Iranian cybercriminals compromise over 100 diplomatic email accounts

    An Iran-nexus group has been linked to a “coordinated” and “multi-wave” spear-phishing campaign targeting embassies and consulates across Europe and other regions globally. This activity has been attributed to Iranian-aligned operators associated with a group known as Homeland Justice, as reported by Israeli cybersecurity company Dream. The campaign involved sending emails that disguised legitimate diplomatic…

  • Connected vehicles are intelligent, user-friendly, and vulnerable to cyberattack

    Connected vehicles are intelligent, user-friendly, and vulnerable to cyberattack

    Consumers are increasingly concerned about vulnerabilities in their vehicles, which significantly impacts their purchasing behaviour and brand loyalty, according to RunSafe Security. Modern vehicles operate on over 100 million lines of code, surpassing that of most fighter jets, yet they often lack adequate cybersecurity measures. While innovations such as over-the-air (OTA) updates and smartphone integration…

  • Fake npm packages stealing Ethereum wallet keys

    Fake npm packages stealing Ethereum wallet keys

    A new set of four malicious packages has been discovered in the NPM package registry, designed to steal cryptocurrency wallet credentials from Ethereum developers. These packages masquerade as legitimate cryptographic utilities and Flashbots MEV infrastructure while secretly exfiltrating private keys and mnemonic seeds to a Telegram bot controlled by the threat actor. Socket researcher Kush…

  • North Korean fake job interview schemes

    North Korean fake job interview schemes

    North Korean hackers have been observed actively monitoring cyber threat intelligence to identify and reconstruct exposed infrastructure. This strategic approach enables them to exploit vulnerabilities and target unsuspecting individuals. Recently, these hackers launched a series of fake job interview attacks, successfully reaching hundreds of potential victims. By masquerading as legitimate employers, they aimed to extract…

  • TAG-150 creates CastleRAT using Python and C, broadening the capabilities of CastleLoader malware.

    TAG-150 creates CastleRAT using Python and C, broadening the capabilities of CastleLoader malware.

    The threat actor known as TAG-150 is behind the malware-as-a-service (MaaS) framework and loader called CastleLoader, as well as a remote access trojan (RAT) named CastleRAT. CastleRAT is available in both Python and C variants, with its core functionalities including the collection of system information, downloading and executing additional payloads, and executing commands via CMD…