July 17, 2026

ACR Stealer: Two observed intrusion chains amid increased threat activity

In this article Campaign 1: WebDAV-based ClickFix with Python loaders and blockchain C2 Campaign 2: MSHTA-initiated PowerShell chain with steganographic payload delivery Mitigation and protection guidance […]
July 10, 2026

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

In this article A wiper inside a backdoor Backdoor capabilities How GigaWiper was assembled Conclusion: Multiple destructive capabilities consolidated into a single implant Defending against destructive […]
June 25, 2026

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

In this article The role of infostealers: From credential theft to intrusion StealC: Infostealer for rent Amadey: Malware-as-a-service for delivery of infostealers Defending against StealC and […]
June 18, 2026

From package to postinstall payload: Inside the Mastra npm supply chain compromise

In this article Attack chain overview Discovery and initial indicators Dependency injection: the poisoned package.json Typosquat analysis: easy-day-js Staged delivery pattern Obfuscation and payload analysis TLS […]