Alpha Cyber

Cyber security insight

Latest News & Articles

236 reports, research notes and advisories, all of it written in-house.

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT
SprySocks Rootkit
Threat ReportsTLP:AMBER

SprySOCKS for Windows: FishMonger’s Linux Backdoor Grows a Kernel Rootkit

China-aligned FishMonger (Earth Lusca) has ported its SprySOCKS backdoor to Windows and bolted on a kernel driver, RawWNPF, that hides processes, files, connections and registry keys, and turns any open TCP port into a hidden door and erases itself from every tool you’d use to find it.

6 min readAPT
PamDOORa SSH Backdoor
Threat ReportsTLP:AMBER

PamDOORa: A Linux PAM Backdoor Built to Steal SSH Credentials

A new post-exploitation implant abuses the Linux authentication stack (PAM) to harvest plaintext SSH credentials from every user who logs in, and hands the operator a covert, persistent backdoor.

3 min readLinux Backdoor
Trash Panda Stealer
Threat Reports

Trash Panda as a Service: Raccoon Stealer Steals Cookies, Crypto, and More

Threat AdvisoryTLP:CLEAR Threat ReportsInfostealer Trash Panda as a Service: Raccoon Stealer Steals Cookies, Crypto, and More A $75-a-week stealer-as-a-service that harvests browser passwords, cookies and autofill, hijacks crypto transactions with a bundled…

4 min readInfostealer
Vect 2.0 Ransomware Bugs & Betrayal
Threat ReportsTLP:AMBER

Bugs & Betrayal: VECT Ransomware by Design, Wiper by Accident

Threat AdvisoryTLP:AMBER RansomwareMalware Bugs & Betrayal: VECT Ransomware by Design, Wiper by Accident Analysis of the VECT ransomware family suggests implementation flaws can undermine the operator’s own monetization objectives.

2 min readRansomware · Malware
FIN7 Infrastructure Breakdown
Threat Reports

Tracking FIN7: Hidden Infrastructure Behind Global Intrusions

Threat Hunt Intelligence FIN7 Infrastructure Hunt, 26 Attributed Hosts C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced Hunt #45Scope C2 Panel · Malware · LoaderAttributed 26Ambient 48Generated 2026-07-07 19:08 UTC This report…

7 min readExposing the Invisible
Indian Cyber Force Escalation
Threat ReportsTLP:AMBER

Indian Cyber Force Targets Government Sites Amid Diplomatic Flashpoint

Threat AdvisoryTLP:AMBER HacktivismGov Web Disruption Indian Cyber Force Targets Government Sites Amid Diplomatic Flashpoint A recurring pattern of opportunistic hacktivism and low-sophistication distributed attacks has been observed against public-sector web…

2 min readHacktivism · Gov Web Disruption
Arch Linux Rootkit
Threat Reports

Mass Arch Linux Package Compromise Pushes Rootkit-Like Malware at Scale

Threat AdvisoryTLP:CLEAR Supply ChainLinux Security 400+ Arch Linux Packages Hijacked to Install Rootkit-Like Malware A large-scale compromise impacting hundreds of Arch Linux packages demonstrates how software supply-chain attacks can transform trusted…

2 min readSupply Chain · Linux Security
Ghost in the Shell QLNX Rootkit
Threat ReportsTLP:AMBER

Ghost in the Shell: Unmasking the QLNX Rootkit

QLNX is an advanced Linux rootkit engineered for kernel-level stealth, privilege concealment and long-term covert access – hiding processes, tampering with telemetry, and evading detection across servers, cloud workloads and internet-facing systems.

2 min readRootkit · Linux
Sandworm Tor Persistent
Threat ReportsTLP:AMBER

Deep Persistence: How Sandworm Weaponizes Tor for Long-Term Stealth

Sandworm Uses SSH-over-Tor Tunnels for Stealthy Long-Term Persistence Sandworm – the Russian state-sponsored actor linked to GRU Unit 74455 – leveraged SSH-over-Tor tunneling to establish covert, resilient, long-term access inside compromised environments…

2 min readAPT · Persistence
Turla Kazuar Backdoor
Threat ReportsTLP:AMBER

Kazuar Unmasked: Inside Turla’s Persistent Cyber-Espionage Machine

Kazuar Backdoor: Inside Turla’s .NET Espionage Implant Indicators and behavioral telemetry align with Kazuar – a sophisticated espionage backdoor associated with Turla, the Russian state-sponsored APT known for stealth operations against government…

2 min readAPT · Backdoor
Abyss Rootkit Analysis
Threat ReportsTLP:AMBER

Abyss Rootkit Analysis: Unmasking Deep-System Threats

ABYSSWORKER: The EDR-Killer Driver Behind MEDUSA Ransomware ABYSSWORKER is a malicious signed Windows kernel driver used in the MEDUSA ransomware attack chain to blind and disable endpoint detection and response tools – masquerading as a CrowdStrike Falcon…

4 min readEDR Killer · Ransomware
Hunting Orbit Rootkit
Threat ReportsTLP:AMBER

Hunting Orbit Rootkit Part Open-Source Medusa Ransomware – IOC Deep Dive

OrBit: The Linux Rootkit That Hijacks the Dynamic Linker OrBit is a stealthy Linux userland rootkit that abuses the dynamic linker (ld.so) to load itself into every new process – hooking dozens of libc functions to hide files, processes and network sockets from standard tooling on the host.

3 min readRootkit · Linux
Your Phone is a Narc
News

Your Phone is a Narc: The Systematic Betrayal of Civilian Privacy

Deep Dive // Surveillance Capitalism PUBLISHED: MAY 2026 Your Phone Is a Narc: The Built-In Infrastructure Betraying Civilian Privacy How everyday smartphones are weaponized against civilians without a single line of malware, turning features into informants.

3 min read
Operation NoVoice Rootkit
Threat ReportsTLP:AMBER

Operation NoVoice: Silent Persistence and the Rootkit Lifecycle

Operation NoVoice: The Android Rootkit That Survives a Factory Reset NoVoice is a mobile-espionage campaign that hid in 50+ Google Play apps (2.3M+ downloads), chained 22 legacy Android exploits to gain root, and planted a Zygote-level rootkit that hooks the…

4 min readRootkit · Android
Latest Qilin Ransomware IOC Analysis
Threat ReportsTLP:AMBER

Latest Qilin Ransomware IOCs Analysis Emerging Threat Indicators

Profile of 2025’s Most Active Extortion Operation Qilin (formerly Agenda) is a Rust-based ransomware-as-a-service operation that became the most active extortion brand of 2025 – absorbing displaced affiliates after RansomHub’s collapse, running double…

4 min readRansomware · Qilin
RegPhantom Rootkit
Threat ReportsTLP:AMBER

RegPhantom Rootkit: Persistence Mechanisms and Mitigation

RegPhantom Watch: A Suspicious Hash With Agreement SHA-256 703dfb12…e7c4 draws consensus from two trusted reputation feeds and possible RegPhantom rootkit ties, but no behavioural detonation confirms intent.

2 min readMalware
VGOD Ransomware
Threat ReportsTLP:AMBER

VGOD Ransomware Exposed: Actionable IOCs for Rapid Defense

VGOD Ransomware: Anatomy of a Backup-Killing Windows Extortion Strain VGOD is a Windows ransomware first seen in February 2025 that encrypts files, deletes Volume Shadow Copies to block recovery, and runs double extortion behind a ‘Decryption…

4 min readRansomware
Dynowiper Sandworm
Threat ReportsTLP:AMBER

Dynowiper Exposed: Forensic Analysis of a Sandworm Cyberweapon

DYNOWIPER: Anatomy of the Wiper That Struck Poland’s Energy Grid The ‘critical, unattributed PE’ from automated triage is DYNOWIPER, a deliberately simple data-destruction wiper used on 29 December 2025 against 30+ Polish renewable sites and a major CHP…

4 min readWiper
Luca Stealer Cover Photo New
Threat ReportsTLP:AMBER

Inside Luca Stealer: A Technical Decomposition of the Rust-Based Malware

Beyond the Binary: How Luca Stealer Uses the Rust Runtime to Slip Past Detection A 4.6 MB Rust PE scored 100/100 with heavy anti-analysis and a Telegram exfiltration channel, behaviour that lines up with Luca Stealer, the leaked Rust infostealer.

5 min readMalware
KlingPremium-xyz cover photo new
Threat ReportsTLP:AMBER

What is Klingpremium.xyz? Malware Analysis and Mitigation Guide

Under the Hood of klingpremium.xyz: an Obfuscated Batch Loader Your ML Model Rated 0% Malicious A 314 KB Windows .bat flagged critical (90/100) is a multi-stage loader that geofences, then uses PowerShell to pull a next-stage payload from klingpremium.xyz and…

4 min readMalware
Indeanapolice.cc Cover Photo
Threat ReportsTLP:AMBER

What is Indeanapolice.cc? Malware Analysis and Removal Guide

Blocking the Breach: Inside the indeanapolice.cc PowerShell Dropper A tiny, heavily obfuscated PowerShell script flagged in triage turns out to be the download-cradle stage of the indeanapolice.cc dropper, a recently-registered, low-reputation campaign that…

4 min readMalware
FredyStealer Cover Photo
Threat Reports

Is Your Data Safe? The Rising Threat of FredyStealer Malware

Malware Analysis Report FredyStealer: The Silent Thief in Your System Published March 26, 2026 · Threat Intelligence Team · A critical-severity script sample was processed by the malware analysis suite.

3 min read
BiBi Wiper Arid Viper Cover Photo
Threat ReportsTLP:AMBER

Wiped Out: Unmasking the Arid Viper Tactics Behind BiBi Malware

BiBi Wiper: What the Malware Really Does, and Why This Sample Does Not Confirm It BiBi is a destructive wiper used against Israeli organisations in 2023 that shreds files and appends a .BiBi extension.

5 min readMalware
Meta AI Glasses Privacy Scandal
Blog

Meta AI Oakley Glasses Privacy Fiasco

For years, cybersecurity professionals warned that the biggest privacy threats wouldn’t look like threats at all. They would look like convenience. Smart speakers. Smart cameras.

3 min read
Your Vacuum is a privacy Nightmare
Blog

Why Your Vacuum is a Privacy Nightmare

We’ve all seen the videos: a robot vacuum mindlessly bumping into a chair leg or getting bullied by the family cat. It looks harmless, even a bit stupid.

2 min read
Facebook and instagram stalkers
Blog

Facebook & Instagram Your Digital Stalkers?

Are Facebook & Instagram Stalking You? Reclaim Your Privacy It’s a common misconception that your activity on the internet is entirely private when you leave social media apps.

2 min read
GodRat PIC
Threat Reports

Busting GodRat: Analyzing the Rat and Its Infrastructure

Cracking the GodRat Campaign: Unmasking Its Infrastructure & How to Block It The GodRat Trojan is believed to be operated by the Chinese threat group Winnti (APT41), known for targeting financial institutions, including trading and brokerage firms.

4 min read
Klingon Rat
Threat Reports

Graphing Klingon RAT Infrastructure: Defend Against Evolving Threats

The threat landscape is constantly evolving, and as adversaries grow more sophisticated, defenders must stay one step ahead. One of the more persistent and damaging threats we’ve recently encountered is the Klingon RAT (Remote Access Trojan).

3 min read
Fu-rootkit-hide-process
Threat Reports

Graphing FuRootkit Infrastructure Rapid Infra Mapping & IOC Blocklist

FuRootkit is not a single binary, it’s an infrastructure. Our Graphing FuRootkit Infrastructure service builds an actionable map of how this rootkit’s campaign is assembled (drop points → loaders → kernel hooks → C2/beacons → persistence), so defenders can see choke points, prioritize takedowns, and automate containment without calling out any mapping product names.

3 min read
BPFDoor Rootkit
Threat Reports

Exposing BPFDoor Rootkit Mapping a Hidden Infrastructure Threat

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls.

4 min read
Digital Privacy Behind You
Blog

5 Ways to Improve Your Business Digital Privacy

In today’s fast-paced digital world, protecting your business’s online privacy is no longer optional it’s essential. Cyber threats are becoming more sophisticated, and companies of all sizes are at risk.

3 min read
BEC Scams
Blog

5 Ways to Secure Yourself from BEC Scams

Business Email Compromise (BEC) is one of the fastest‑growing cyber threats. Attackers impersonate trusted contacts, manipulate email, and trick organizations into sending money or sensitive data. The financial, reputational, and legal costs can be devastating.

2 min read
FancyBear
Threat Reports

Mapping Fancy Bear’s Gamefish Infrastructure

Unmasking Advanced Threat Operations Behind the Hash: 9b10685b774a783eabfecdb6119a8aa3 In the evolving world of cyber conflict, few adversaries operate with the consistency and sophistication of Fancy Bear (APT28).

2 min read
Shifu Banking Trojan
Threat Reports

Mapping Shifu Banking Trojan Infrastructure

As the cybersecurity landscape evolves, sophisticated banking trojans continue to exploit digital vulnerabilities, putting financial institutions and their clients at constant risk.

2 min read
Meta Cicero AI Liar
News

Meta’s AI System ‘Cicero’ Learning How to Lie and Deceive Humans

When Artificial Intelligence Learns to Deceive, Businesses Need to Rethink Security In a recent development raising both eyebrows and alarms, Meta’s AI system ‘Cicero’, originally built to master negotiation and diplomacy in games like Diplomacy, has demonstrated a chilling new skill: the ability to strategically lie and deceive human players to win.

2 min read
Rootkit Virus Worm
Blog

Protect Yourself from Rootkit Attacks Hidden in Phishing Emails

In today’s digital threat landscape, not all cyberattacks come with flashing red warnings or immediate signs of compromise. One of the most dangerous forms of modern malware operates in the shadows, undetectable, persistent, and devastating.

2 min read
How-Does-Your-ISP-Keep-an-Eye-on-You
Blog

Five Ways to Secure Yourself from ISP Surveillance

Your Internet Service Provider (ISP) sees more than you think. From the websites you visit to the apps you use, ISPs often log, analyze, and sometimes sell your browsing data, legally.

2 min read
Digital Footprint COVER
Blog

5 Ways to Minimize Your Digital Footprint

Protect Your Online Presence Before It Becomes a Liability In today’s hyper-connected world, every search, click, download, and login leaves a trail.

2 min read
Akira Rootkit Graph
Threat Reports

Akira Exploits SonicWall SSLVPN Rootkit in Suspected Zero-Day Attacks

How Infrastructure Mapping Can Help Detect and Prevent the Next Breach In the latest wave of targeted ransomware attacks, the Akira ransomware group is now exploiting a previously unknown vulnerability in SonicWall SSLVPN appliances, giving them direct access to corporate networks.

2 min read
FiveSys Rootkit
Threat Reports

Signed to Deceive: The Return of FiveSys Rootkits

How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits.

1 min read
Meta Privacy Scandal
News

The Next Big Scandal: Meta Can Access Your Private, Unpublished Photos

Published by Alpha Cyber | Trusted Cybersecurity Services for Data Privacy and Protection What You Don’t Post Can Still Be Seen A growing wave of privacy concerns has resurfaced after leaked documents and whistleblower reports revealed something deeply unsettling: Meta (formerly Facebook) may have access to your private, unpublished photos, even those you never intended to share.

2 min read
Combatting Insider Threats: Protecting Your Business from Within
Blog

Combatting Insider Threats: Protecting Your Business from Within

Published by Alpha Cyber | Cybersecurity Services That Secure What Matters Most The Hidden Danger Inside Your Organization When people think of cybersecurity, they often imagine hackers in dark rooms breaking into systems from afar.

2 min read
Facebook caught phishing friends
News

Facebook Got Caught Phishing for Friend

In the digital age, data is currency, and trust is everything. Yet even global tech giants like Meta have shown that mishandling data can come at a cost.

2 min read
Sneaky 2FA Phishing: Unmasking the Invisible Threat
Threat Reports

Sneaky 2FA Phishing: Unmasking the Invisible Threat

Two-Factor Authentication (2FA) is vital, but attackers are bypassing it with 2FA Phishing-as-a-Service (PhaaS). These sophisticated platforms, like “Sneaky 2FA,” act as a “reverse proxy,” intercepting real-time credentials and 2FA codes.

1 min read
Case Studies

Case Study: Transforming Cybersecurity at Blossom

Client: BlossomIndustry: TechnologyEngagement Period: 2021–2023 Background When Blossom, a fast-growing tech company, recognized the increasing threat landscape, they sought to elevate their cybersecurity posture. The challenge?

2 min read
Linux Forensic 101
Blog

Linux Forensic 101

Linux Security Tips: When Expertise Feels Like Driving a Manual GTR Operating a Linux OS as an expert is like driving a brand-new manual Nissan GTR. You control everything.

2 min read
Linux Info Stealers
Blog

Mitigating Data Exfiltration Attacks

A Comprehensive Guide In today’s digital landscape, data security is paramount. Your data encompasses more than just your name. It reflects your preferences, behaviors, and personal insights.

2 min read
Purple Malware Pyramid
Blog

Easy Malware Evasion

In today’s cybersecurity landscape, traditional malware evasion techniques are no longer enough.

4 min read
Browser Security
Blog

Browser Security Tutorial

When it comes to protecting your digital environment, browser security is one of the simplest, yet most critical, measures you can take.

2 min read
Hardening Linux In 10 Steps
Blog

Hardening Linux In 10 Steps

Long live Linux! But for a healthy and secure system, it’s crucial to know how to harden and monitor your Linux servers effectively.

4 min read
Security Cover Photo
News

New Pacman Attack Targeting Mac Devices

Thanks To The Hacker News For This Article A novel hardware attack dubbed PACMAN has been demonstrated against Apple’s M1 processor chipsets, potentially arming a malicious actor with the capability to gain arbitrary code execution on macOS systems.

3 min read
Russian Hackers Are On The Rise !
News

Russian Hackers Are On The Rise !

As the war in Ukraine enters its fourth month, the battlefield has expanded beyond conventional warfare into cyberspace.

2 min read
S3 Bucket
Blog

AWS S3 Security Tutorial

Amazon Web Services (AWS) is the world’s leading cloud platform, offering businesses access to the same powerful infrastructure Amazon uses to run its global operations.

3 min read
Blog

Cell Phone Privacy In The 21 Century

Thanks To Defender Shield For This Great Article. Solidifying your cell phone privacy is a crucial part of keeping your personal information safe and protected.

7 min read
Blog

How To Detect Hidden Cameras

What are the ways to detect hidden spy secret cameras in your apartment, house, or hotel room? How to find hidden security cameras behind mirrors?

1 min read
News

HTML attachments remain popular among phishing actors in 2022

HTML files remain one of the most popular attachments used in phishing attacks for the first four months of 2022, showing that the technique remains effective against antispam engines and works well on the victims themselves.

2 min read
Threat Reports

Experts Sound Alarm on DCRat Backdoor Being Sold on Russian Hacking Forums

Cybersecurity researchers have shed light on an actively maintained remote access trojan called DCRat (aka DarkCrystal RAT) that’s offered on sale for “dirt cheap” prices, making it accessible to professional cybercriminal groups and novice actors alike.

2 min read
News

Hackers Can Now Run Malware On Your Phone When Its Off

Thanks To The Hacker News For This Great Article A first-of-its-kind security analysis of iOS Find My function has identified a novel attack surface that makes it possible to tamper with the firmware and load malware onto a Bluetooth chip that’s executed…

3 min read
Windows Server Hardening Check List
Blog

Hardening Windows Server

Windows servers are often responsible for critical infrastructure and sensitive data.

3 min read
Blog

Connecting Securely To Tor Network

The internet is a powerful tool, but privacy isn’t something you should take for granted. The Tor network is one of the best ways to browse anonymously, masking your identity and location online.

2 min read
Blog

NTLM Relay With Inveigh

With Inveigh, an attacker can perform NTLM relay attacks, enabling them to intercept and relay NTLM authentication hashes within a target network.What is NTLM?

1 min read
Blog

Extracting Password From DPAPI With Mimikatz

DPAPI (Data Protection API) is a native Windows encryption mechanism designed to securely protect sensitive data such as saved credentials, browser secrets and certificates.

2 min read
Blog

Kerberos Authentication

Explained Kerberos is a powerful authentication protocol designed to securely verify users and services over insecure networks, commonly used in Active Directory environments, POSIX authentication, NFS, and Samba.

1 min read
Blog

DCSync Attack With Mimikatz

In the complex landscape of Active Directory security, understanding the tactics adversaries employ is paramount.

4 min read
Blog

Kerberos Golden Tickets

A golden ticket in Active Directory grants the bearer unlimited access. An attacker holding one can reach any service, for an unlimited time.

1 min read
Blog

Pass The Hash Attack With Mimikatz

Pass the Hash attack is when the attacker can authenticate without clear text password. similiar to pass the ticket but in pass the hash attack our access is not limited to 10 hours.

1 min read
Blog

Abusing Sudo

In Linux systems, the /etc/sudoers file dictates user privileges, specifying which users can execute commands with elevated (root) permissions.

1 min read
Threat Reports

DanderSpritz Framework Is Causing Problems

In April 2017, the hacking collective known as the Shadow Brokers leaked a sophisticated malware framework attributed to the NSA’s Equation Group.

2 min read
Blog

Blue Screen of Death With Mimikatz

Mimikatz is a post exploitation tools used for clear text dumping credentials and many else Dumping credentials with mimiktatz 1.first this first clone the script with git clone https://github.com/ParrotSec/mimikatz 2.run mimikatz.exe in X64 directory…

1 min read
Blog

Secure and encrypt C2 setup with redirectors

This post will teach you how to setup a simple red team c2 infrastructure with encrypted socat HTTPS redirectors Requirements: Attacker C2 Server: Kali with metasploit Redirector Server: Ubuntu with socat Victim Machine: Windows10 1.First open metasploit with…

1 min read
Blog

Dumping Credentials With Evil Mimikatz

Mimikatz is a post exploitation tools used for clear text dumping credentials and many else Dumping credentials with mimiktatz 1.first this first clone the script with git clone https://github.com/ParrotSec/mimikatz 2.run mimikatz.exe in X64 directory…

1 min read

Topics

Most covered topics

The 14 subjects we publish on most, of 33 in the archive. Counts are across every report and note.

  • Malware8
  • Ransomware8
  • APT5
  • Rootkit4
  • Linux3
  • Financial Sector2
  • Hacktivism2
  • Nation-State2
  • Privacy2
  • Android1
  • Backdoor1
  • Botnet1
  • BYOVD1
  • DDoS Threat Intel1

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]