Skip to content

Breaking

Fake Malware TOAD via Malvertizing PDFChampions YAPA Browser Hijacker/Loader Analysis  ConvertyFile Browser Hijacker Convert Master Browser Hijacker Analysis Teams Transcript Page Lure Delivers GoTo RMM

Malasada Tech

Da Samala Tech blogs on malware and stuffs

Malasada Tech

Da Samala Tech blogs on malware and stuffs

  • Home
  • About
ClickFix Malware Research Phishing

ClickFix Delivery Initiated via Phishing Email

Aaron Samala December 28, 2024 No Comments

TL;DR Phishing email uses ClickFix to initiate multi-stage delivery (incomplete analysis at final stage). Tactical Pause THE CONTENT, VIEWS, AND OPINIONS EXPRESSED ON THIS DOCUMENT ARE MY OWN AND DO…

Threat Intelligence

Silent Push to find SmartApeSG, LandUpdate808, and TA582 Infra

Aaron Samala December 27, 2024 1 Comment

Using Silent Push to find the following infrastructure TL;DR You can use Silent Push’s query builder to monitor certain adversary infrastructure based on simple properties such as ASN, name server,…

Lumma Stealer Threat Intelligence

Lumma Stealer Delivered via YouTube Videos for Cheats

Aaron Samala November 28, 2024 No Comments

TL;DR / Summary Up Front ALOHA! This shows how you can take WatchingRac‘s post, create a profile of the delivery behavior, and search YouTube for slight variations to find other…

ClickFix Threat Intelligence

ClickFix Baddys via RussianPanda’s Workflow

Aaron Samala November 26, 2024 No Comments

TL;DR This documents specific steps you can take to find ClickFix infrastructure via RussianPanda‘s workflow. Summary Up Front This document builds on RussianPanda’s workflow to find ClickFix infrastructure. You can…

Threat Intelligence

Open Directory Search Leads to Aged APT-C-35 Findings

Aaron Samala November 24, 2024 No Comments

TL;DR I saw a post on X that inspired me to search Shodan. I found an open directory associated with APT-C-35 (attribution based on file hashes that were listed in…

Gootloader Gootloader Backlinks Threat Intelligence

Gootloader: Updated Delivery Vector!

Aaron Samala November 11, 2024 No Comments

Intro @Gootloader recently published a new article showing how he found the Gootloader TA has updated their delivery vector. Previously, Gootloader was delivered by tricking the victim into thinking the…

Threat Intelligence

7-Zip FakeApp Serving NetSupport Rat!

Aaron Samala November 7, 2024 No Comments

There’s a 7-Zip-masquerading site that is serving NetSupport Rat. I’ve been monitoring for a new 7-Zip FakeApp for a little over a week. This quick post shows how I became…

Malware Research

First Lumma Stealer IOC!

Aaron Samala November 3, 2024 No Comments

Pretty stoked! I’ve been trying to see if I could find an unreported Lumma C2 domain since about August. At some point in August, I noticed ET Labs (https://x.com/ET_Labs) had…

Threat Intelligence

Additional TA569 Middleware Infra Observed

Aaron Samala October 29, 2024 No Comments

I’m a big fan of monitoring FakeUpdate stuff. It appears that TA569 may be increasing their infrastructure, as there was additional TA569 middleware infra observed. THE CONTENT, VIEWS, AND OPINIONS…

LandUpdate808 Threat Intelligence

New Behavior for LandUpdate808 Observed

Aaron Samala October 15, 2024 No Comments

Summary Up Front The LandUpdate808 actors have multiple domains responding to the same IP – and they all respond to the same endpoint used for the first stage of the…

Posts pagination

1 2 3 4 5

« Previous Page — Next Page »

Recent Posts

  • Fake Malware TOAD via Malvertizing
  • PDFChampions YAPA Browser Hijacker/Loader Analysis 
  • ConvertyFile Browser Hijacker
  • Convert Master Browser Hijacker Analysis
  • Teams Transcript Page Lure Delivers GoTo RMM

Recent Comments

  1. PDFChampions YAPA Browser Hijacker/Loader Analysis  - Malasada Tech on ConvertyFile Browser Hijacker
  2. PDFChampions YAPA Browser Hijacker/Loader Analysis  - Malasada Tech on Convert Master Browser Hijacker Analysis
  3. ConvertyFile Browser Hijacker - Malasada Tech on Convert Master Browser Hijacker Analysis
  4. Teams Transcript Page Lure Delivers GoTo RMM - Malasada Tech on Oyster Malware Delivery via Teams Fake App
  5. BLOG: My thoughts on improving analysis and reporting - Malasada Tech on Oyster Malware Delivery via Teams Fake App

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • May 2025
  • April 2025
  • March 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024

Categories

  • ClickFix
  • CopyPaste
  • Cybersecurity Trends
  • Gootkit
  • Gootloader
  • Gootloader Backlinks
  • LandUpdate808
  • Lumma Stealer
  • Malware Research
  • Phishing
  • Skimmer
  • SocGholish
  • Threat Intelligence
  • Thresearch
  • Thruntellisearch – Threat Hunting/Intelligence Research
  • Uncategorized

You Missed

Thruntellisearch - Threat Hunting/Intelligence Research

Fake Malware TOAD via Malvertizing

Malware Research Thruntellisearch - Threat Hunting/Intelligence Research

PDFChampions YAPA Browser Hijacker/Loader Analysis 

Malware Research

ConvertyFile Browser Hijacker

Malware Research Thruntellisearch - Threat Hunting/Intelligence Research

Convert Master Browser Hijacker Analysis

Malasada Tech

Da Samala Tech blogs on malware and stuffs

Copyright © All rights reserved | Blogarise by Themeansar.