Skip to content

Breaking

TA569 SocGholish Overlap w/TA582 Infra Copy/Paste Technique Used to Deliver XWORM PDF Lure Delivering GoTo (LogMeIn) RMM Unsuccessful Crypto Phishing Attempt on Me SVG Capabilities and Behaviors

Malasada Tech

Da Samala Tech blogs on malware and stuffs

Malasada Tech

Da Samala Tech blogs on malware and stuffs

  • Home
  • About
ClickFix SocGholish

TA569 SocGholish Overlap w/TA582 Infra

Aaron Samala May 25, 2025 No Comments

Intro This is the long form of my post from here: https://x.com/MalasadaTech/status/1924982337689027063. While browsing urlscan scan tasks, I found crypto-js.min.js usage for obfuscation linked to Tycoon and Storm1747 in Any…

CopyPaste

Copy/Paste Technique Used to Deliver XWORM

Aaron Samala May 16, 2025 No Comments

XWORM is observed being distributed via Copy/Paste. XWORM C2 traffic uses a pattern that can be matched. Using Discord webhooks for C2 is not new, but it’s new to me.…

Threat Intelligence

PDF Lure Delivering GoTo (LogMeIn) RMM

Aaron Samala May 12, 2025 No Comments

This documents chrunting for delivery sites that connect to api.telegramorg, finding a malicious GoTo RMM, and developing masq-monitor and Snort/Suricata detections. Tactical Pause THE CONTENT, VIEWS, AND OPINIONS EXPRESSED ON…

Phishing

Unsuccessful Crypto Phishing Attempt on Me

Aaron Samala April 7, 2025 No Comments

This documents the analysis I performed on a crypto phishing domain that a phisher DM’d me. It documents how I was able to pivot on file hashes the site served,…

Malware Research Phishing

SVG Capabilities and Behaviors

Aaron Samala March 16, 2025 No Comments

TL;DR This documents my research into three methods an attacker could use, with an SVG file, in a phishing attack to direct the victim to the next stage in the…

ClickFix LandUpdate808 Malware Research

Updated LandUpdate808 Analysis

Aaron Samala January 5, 2025 No Comments

It’s been a while since I’ve posted about LandUpdate808. There was a compromised site that is local to Hawaii that I recently noticed, and it prompted me to research the…

ClickFix Malware Research Phishing

ClickFix Delivery Initiated via Phishing Email

Aaron Samala December 28, 2024 No Comments

TL;DR Phishing email uses ClickFix to initiate multi-stage delivery (incomplete analysis at final stage). Tactical Pause THE CONTENT, VIEWS, AND OPINIONS EXPRESSED ON THIS DOCUMENT ARE MY OWN AND DO…

Threat Intelligence

Silent Push to find SmartApeSG, LandUpdate808, and TA582 Infra

Aaron Samala December 27, 2024 1 Comment

Using Silent Push to find the following infrastructure TL;DR You can use Silent Push’s query builder to monitor certain adversary infrastructure based on simple properties such as ASN, name server,…

Lumma Stealer Threat Intelligence

Lumma Stealer Delivered via YouTube Videos for Cheats

Aaron Samala November 28, 2024 No Comments

TL;DR / Summary Up Front ALOHA! This shows how you can take WatchingRac‘s post, create a profile of the delivery behavior, and search YouTube for slight variations to find other…

ClickFix Threat Intelligence

ClickFix Baddys via RussianPanda’s Workflow

Aaron Samala November 26, 2024 No Comments

TL;DR This documents specific steps you can take to find ClickFix infrastructure via RussianPanda‘s workflow. Summary Up Front This document builds on RussianPanda’s workflow to find ClickFix infrastructure. You can…

Posts pagination

1 2 … 4

Next Page »

Recent Posts

  • TA569 SocGholish Overlap w/TA582 Infra
  • Copy/Paste Technique Used to Deliver XWORM
  • PDF Lure Delivering GoTo (LogMeIn) RMM
  • Unsuccessful Crypto Phishing Attempt on Me
  • SVG Capabilities and Behaviors

Recent Comments

  1. Updated LandUpdate808 Analysis - Malasada Tech on Silent Push to find SmartApeSG, LandUpdate808, and TA582 Infra
  2. Navy Federal Credit Union Masquerades Found! - Malasada Tech on USAA Masquerades Found!
  3. Aaron Samala on USAA Masquerades Found!
  4. Emiliano Carlesi on USAA Masquerades Found!
  5. Gootkit is broken right now - Malasada Tech on Gootloader Isn’t Broken

Archives

  • May 2025
  • April 2025
  • March 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024

Categories

  • ClickFix
  • CopyPaste
  • Cybersecurity Trends
  • Gootkit
  • Gootloader
  • Gootloader Backlinks
  • LandUpdate808
  • Lumma Stealer
  • Malware Research
  • Phishing
  • Skimmer
  • SocGholish
  • Threat Intelligence

You Missed

ClickFix SocGholish

TA569 SocGholish Overlap w/TA582 Infra

CopyPaste

Copy/Paste Technique Used to Deliver XWORM

Threat Intelligence

PDF Lure Delivering GoTo (LogMeIn) RMM

Phishing

Unsuccessful Crypto Phishing Attempt on Me

Malasada Tech

Da Samala Tech blogs on malware and stuffs

Copyright © All rights reserved | Blogarise by Themeansar.