<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Alpha Cyber: threat reports and research</title><description>Alpha Cyber delivers tailored cybersecurity to organizations worldwide: penetration testing, red team, threat hunting, incident response, threat intelligence and security research.</description><link>https://alpha-cyber.com/</link><language>en-us</language><copyright>© 2026 Alpha Cyber</copyright><item><title>Latrodectus: The Black Widow Loader Quietly Replacing IcedID</title><link>https://alpha-cyber.com/latrodectus-the-black-widow-loader-quietly-replacing-icedid/</link><guid isPermaLink="true">https://alpha-cyber.com/latrodectus-the-black-widow-loader-quietly-replacing-icedid/</guid><description>Named after the black widow spider, Latrodectus is a lightweight but potent loader built by the people behind IcedID.</description><pubDate>Sat, 25 Jul 2026 20:26:00 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>CAKETAP and the Raspberry Pi Heist: How UNC2891 Tried to Rob a Bank From Inside Its Own Switch</title><link>https://alpha-cyber.com/caketap-and-the-raspberry-pi-heist-how-unc2891-tried-to-rob-a-bank-from-inside-its-own-switch/</link><guid isPermaLink="true">https://alpha-cyber.com/caketap-and-the-raspberry-pi-heist-how-unc2891-tried-to-rob-a-bank-from-inside-its-own-switch/</guid><description>UNC2891 cabled a 4G Raspberry Pi straight into a bank’s ATM network switch, hid its backdoor from forensic triage with a novel Linux bind-mount trick, and aimed…</description><pubDate>Sat, 25 Jul 2026 20:13:16 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>APT</category><author>Alpha Cyber Research</author></item><item><title>Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home</title><link>https://alpha-cyber.com/daxin-returns-a-13-year-old-china-linked-rootkit-that-never-called-home/</link><guid isPermaLink="true">https://alpha-cyber.com/daxin-returns-a-13-year-old-china-linked-rootkit-that-never-called-home/</guid><description>Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.</description><pubDate>Thu, 23 Jul 2026 18:47:14 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>APT</category><author>Alpha Cyber Research</author></item><item><title>When the Ad System Becomes the Threat: Meta Caught Monetizing Child-Abuse Ads</title><link>https://alpha-cyber.com/when-the-ad-system-becomes-the-threat-meta-caught-monetizing-child-abuse-ads/</link><guid isPermaLink="true">https://alpha-cyber.com/when-the-ad-system-becomes-the-threat-meta-caught-monetizing-child-abuse-ads/</guid><description>A BBC investigation found that Instagram ran and profited from paid ads promoting the sale of child sexual abuse material in India, funnelling users to off-platform channels.</description><pubDate>Thu, 23 Jul 2026 18:08:53 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><category>Privacy</category><category>Trust &amp; Safety</category><author>Alpha Cyber Research</author></item><item><title>Windows as Spyware? The GDID Tracker You Can’t Turn Off</title><link>https://alpha-cyber.com/windows-as-spyware-the-gdid-tracker-you-cant-turn-off/</link><guid isPermaLink="true">https://alpha-cyber.com/windows-as-spyware-the-gdid-tracker-you-cant-turn-off/</guid><description>Windows assigns each install a persistent Global Device Identifier that cannot be disabled, that you never explicitly consented to, and that Microsoft can hand to law enforcement.</description><pubDate>Wed, 15 Jul 2026 10:16:06 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><category>Privacy</category><category>Windows</category><author>Alpha Cyber Research</author></item><item><title>Medusa Ransomware: The RaaS That Blinds Your EDR Before It Encrypts</title><link>https://alpha-cyber.com/medusa-ransomware-the-raas-that-blinds-your-edr-before-it-encrypts/</link><guid isPermaLink="true">https://alpha-cyber.com/medusa-ransomware-the-raas-that-blinds-your-edr-before-it-encrypts/</guid><description>Medusa is a ransomware-as-a-service operation that has hit 300+ organisations across healthcare, education, manufacturing and other critical sectors.</description><pubDate>Wed, 15 Jul 2026 08:27:05 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Ransomware</category><author>Alpha Cyber Research</author></item><item><title>GodDamn Ransomware Blinds EDR With the Microsoft-Signed PoisonX Driver</title><link>https://alpha-cyber.com/goddamn-ransomware-blinds-edr-with-the-microsoft-signed-poisonx-driver/</link><guid isPermaLink="true">https://alpha-cyber.com/goddamn-ransomware-blinds-edr-with-the-microsoft-signed-poisonx-driver/</guid><description>GodDamn is a fresh rebrand of the Beast/Monster ransomware lineage that switches off endpoint defenses before it encrypts.</description><pubDate>Wed, 15 Jul 2026 07:59:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Ransomware</category><author>Alpha Cyber Research</author></item><item><title>SPECTRALVIPER: The Obfuscated Backdoor Behind an APT32 Espionage Set</title><link>https://alpha-cyber.com/spectralviper-the-obfuscated-backdoor-behind-an-apt32-espionage-set/</link><guid isPermaLink="true">https://alpha-cyber.com/spectralviper-the-obfuscated-backdoor-behind-an-apt32-espionage-set/</guid><description>SPECTRALVIPER is a heavily obfuscated x64 Windows backdoor used against large, strategically important Vietnamese companies.</description><pubDate>Wed, 08 Jul 2026 07:14:30 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Nation-State</category><author>Alpha Cyber Research</author></item><item><title>MirrorFace: The APT10 Subgroup That Perfected Its Craft on Japan Then Turned to Europe</title><link>https://alpha-cyber.com/mirrorface-the-apt10-subgroup-that-perfected-its-craft-on-japan-then-turned-to-europe/</link><guid isPermaLink="true">https://alpha-cyber.com/mirrorface-the-apt10-subgroup-that-perfected-its-craft-on-japan-then-turned-to-europe/</guid><description>MirrorFace, a China-aligned espionage group inside the APT10 umbrella (also tracked as Earth Kasha), spent years quietly targeting Japan’s government, politicians, think tanks and defence-adjacent industry.</description><pubDate>Tue, 07 Jul 2026 20:22:18 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Nation-State</category><author>Alpha Cyber Research</author></item><item><title>Anunak and Carbanak: A Billion-Dollar Heist</title><link>https://alpha-cyber.com/anunak-and-carbanak-a-billion-dollar-heist/</link><guid isPermaLink="true">https://alpha-cyber.com/anunak-and-carbanak-a-billion-dollar-heist/</guid><description>The crew that stopped robbing bank customers and learned to rob the bank itself.</description><pubDate>Tue, 07 Jul 2026 20:12:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><category>Financial Sector</category><author>Alpha Cyber Research</author></item><item><title>Explosive MirrorBlast Campaign Targets Financial Firms and It Points to TA505</title><link>https://alpha-cyber.com/explosive-mirrorblast-campaign-targets-financial-firms-and-it-points-to-ta505/</link><guid isPermaLink="true">https://alpha-cyber.com/explosive-mirrorblast-campaign-targets-financial-firms-and-it-points-to-ta505/</guid><description>MirrorBlast hits financial-services organisations with an Excel document so lightweight it is nearly undetectable on VirusTotal.</description><pubDate>Tue, 07 Jul 2026 20:05:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Financial Sector</category><author>Alpha Cyber Research</author></item><item><title>Below the Syscall Line: How eBPF and io_uring Rootkits Slip Past Linux EDR</title><link>https://alpha-cyber.com/below-the-syscall-line-how-ebpf-and-io_uring-rootkits-slip-past-linux-edr/</link><guid isPermaLink="true">https://alpha-cyber.com/below-the-syscall-line-how-ebpf-and-io_uring-rootkits-slip-past-linux-edr/</guid><description>Most Linux runtime security watches system calls. A growing class of stealth techniques, eBPF abuse and the io_uring asynchronous-I/O interface, does its work without the syscalls those tools hook.</description><pubDate>Tue, 07 Jul 2026 17:54:07 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><category>Linux Rootkits</category><author>Alpha Cyber Research</author></item><item><title>SprySOCKS for Windows: FishMonger’s Linux Backdoor Grows a Kernel Rootkit</title><link>https://alpha-cyber.com/sprysocks-for-windows-fishmongers-linux-backdoor-grows-a-kernel-rootkit/</link><guid isPermaLink="true">https://alpha-cyber.com/sprysocks-for-windows-fishmongers-linux-backdoor-grows-a-kernel-rootkit/</guid><description>China-aligned FishMonger (Earth Lusca) has ported its SprySOCKS backdoor to Windows and bolted on a kernel driver, RawWNPF, that hides processes, files, connections and registry keys, and turns any open TCP port into a hidden door and erases itself from every tool you’d use to find it.</description><pubDate>Sat, 04 Jul 2026 17:44:41 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>APT</category><author>Alpha Cyber Research</author></item><item><title>PoisonX Rootkit: A Signed Kernel Driver That Turns Your EDR Into a Target</title><link>https://alpha-cyber.com/poisonx-rootkit-a-signed-kernel-driver-that-turns-your-edr-into-a-target/</link><guid isPermaLink="true">https://alpha-cyber.com/poisonx-rootkit-a-signed-kernel-driver-that-turns-your-edr-into-a-target/</guid><description>PoisonX: A Signed Kernel Driver That Turns Your EDR Into a Target A Microsoft-signed BYOVD driver used to kill CrowdStrike Falcon and other security tooling from Ring 0.</description><pubDate>Sat, 04 Jul 2026 16:04:41 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>BYOVD</category><author>Alpha Cyber Research</author></item><item><title>PamDOORa: A Linux PAM Backdoor Built to Steal SSH Credentials</title><link>https://alpha-cyber.com/pamdoora-a-linux-pam-backdoor-built-to-steal-ssh-credentials/</link><guid isPermaLink="true">https://alpha-cyber.com/pamdoora-a-linux-pam-backdoor-built-to-steal-ssh-credentials/</guid><description>A new post-exploitation implant abuses the Linux authentication stack (PAM) to harvest plaintext SSH credentials from every user who logs in, and hands the operator a covert, persistent backdoor.</description><pubDate>Thu, 02 Jul 2026 14:36:41 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Linux Backdoor</category><author>Alpha Cyber Research</author></item><item><title>Trash Panda as a Service: Raccoon Stealer Steals Cookies, Crypto, and More</title><link>https://alpha-cyber.com/trash-panda-as-a-service-raccoon-stealer-steals-cookies-crypto-and-more/</link><guid isPermaLink="true">https://alpha-cyber.com/trash-panda-as-a-service-raccoon-stealer-steals-cookies-crypto-and-more/</guid><description>Threat AdvisoryTLP:CLEAR Threat ReportsInfostealer Trash Panda as a Service: Raccoon Stealer Steals Cookies, Crypto, and More A $75-a-week stealer-as-a-service that harvests browser passwords, cookies and autofill, hijacks crypto transactions with a bundled…</description><pubDate>Thu, 02 Jul 2026 14:25:49 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><category>Infostealer</category><author>Alpha Cyber Research</author></item><item><title>Bugs &amp; Betrayal: VECT Ransomware by Design, Wiper by Accident</title><link>https://alpha-cyber.com/bugs-betrayal-vect-ransomware-by-design-wiper-by-accident/</link><guid isPermaLink="true">https://alpha-cyber.com/bugs-betrayal-vect-ransomware-by-design-wiper-by-accident/</guid><description>Threat AdvisoryTLP:AMBER RansomwareMalware Bugs &amp; Betrayal: VECT Ransomware by Design, Wiper by Accident Analysis of the VECT ransomware family suggests implementation flaws can undermine the operator’s own monetization objectives.</description><pubDate>Tue, 30 Jun 2026 20:02:46 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Ransomware</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>Sneaky Umbreon Linux Rootkit Targets x86 Systems with Stealth-Focused Persistence</title><link>https://alpha-cyber.com/sneaky-umbreon-linux-rootkit-targets-x86-systems-with-stealth-focused-persistence/</link><guid isPermaLink="true">https://alpha-cyber.com/sneaky-umbreon-linux-rootkit-targets-x86-systems-with-stealth-focused-persistence/</guid><description>Threat AdvisoryTLP:AMBER LinuxRootkit Sneaky Umbreon Linux Rootkit Targets x86 Systems with Stealth-Focused Persistence A recently disclosed Linux rootkit known as Sneaky Umbreon demonstrates a renewed focus on kernel-level stealth for x86 environments.</description><pubDate>Tue, 30 Jun 2026 19:49:55 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Linux</category><category>Rootkit</category><author>Alpha Cyber Research</author></item><item><title>Tracking FIN7: Hidden Infrastructure Behind Global Intrusions</title><link>https://alpha-cyber.com/tracking-fin7-hidden-infrastructure-behind-global-intrusions/</link><guid isPermaLink="true">https://alpha-cyber.com/tracking-fin7-hidden-infrastructure-behind-global-intrusions/</guid><description>Threat Hunt Intelligence FIN7 Infrastructure Hunt, 26 Attributed Hosts C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced Hunt #45Scope C2 Panel · Malware · LoaderAttributed 26Ambient 48Generated 2026-07-07 19:08 UTC This report…</description><pubDate>Sun, 21 Jun 2026 16:40:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><category>Exposing the Invisible</category><author>Alpha Cyber Research</author></item><item><title>Indian Cyber Force Targets Government Sites Amid Diplomatic Flashpoint</title><link>https://alpha-cyber.com/indian-cyber-force-targets-government-sites-amid-diplomatic-flashpoint/</link><guid isPermaLink="true">https://alpha-cyber.com/indian-cyber-force-targets-government-sites-amid-diplomatic-flashpoint/</guid><description>Threat AdvisoryTLP:AMBER HacktivismGov Web Disruption Indian Cyber Force Targets Government Sites Amid Diplomatic Flashpoint A recurring pattern of opportunistic hacktivism and low-sophistication distributed attacks has been observed against public-sector web…</description><pubDate>Tue, 16 Jun 2026 20:00:34 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Hacktivism</category><category>Gov Web Disruption</category><author>Alpha Cyber Research</author></item><item><title>Cyber Islamic Resistance and NoName057(16) Signal Intent for Coordinated Cyber Pressure Campaign Against France</title><link>https://alpha-cyber.com/cyber-islamic-resistance-and-noname05716-signal-intent-for-coordinated-cyber-pressure-campaign-against-france/</link><guid isPermaLink="true">https://alpha-cyber.com/cyber-islamic-resistance-and-noname05716-signal-intent-for-coordinated-cyber-pressure-campaign-against-france/</guid><description>Threat AdvisoryTLP:AMBER HacktivismDDoS Threat Intel Cyber Islamic Resistance and NoName057(16) Signal Intent for Coordinated Cyber Pressure Campaign Against France Intelligence indicators suggest overlapping messaging and tasking narratives between Cyber…</description><pubDate>Tue, 16 Jun 2026 19:36:35 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Hacktivism</category><category>DDoS Threat Intel</category><author>Alpha Cyber Research</author></item><item><title>Mass Arch Linux Package Compromise Pushes Rootkit-Like Malware at Scale</title><link>https://alpha-cyber.com/mass-arch-linux-package-compromise-pushes-rootkit-like-malware-at-scale/</link><guid isPermaLink="true">https://alpha-cyber.com/mass-arch-linux-package-compromise-pushes-rootkit-like-malware-at-scale/</guid><description>Threat AdvisoryTLP:CLEAR Supply ChainLinux Security 400+ Arch Linux Packages Hijacked to Install Rootkit-Like Malware A large-scale compromise impacting hundreds of Arch Linux packages demonstrates how software supply-chain attacks can transform trusted…</description><pubDate>Tue, 16 Jun 2026 19:23:37 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><category>Supply Chain</category><category>Linux Security</category><author>Alpha Cyber Research</author></item><item><title>The Financial Impact: How ‘Bossware’ Drains Your Wallet</title><link>https://alpha-cyber.com/the-financial-impact-how-bossware-drains-your-wallet/</link><guid isPermaLink="true">https://alpha-cyber.com/the-financial-impact-how-bossware-drains-your-wallet/</guid><description>Big Brother is Watching (and Costing You): The Financial Fallout of Spyware in the Workplace.</description><pubDate>Sat, 30 May 2026 16:31:55 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Ghost in the Shell: Unmasking the QLNX Rootkit</title><link>https://alpha-cyber.com/ghost-in-the-shell-unmasking-the-qlnx-rootkit/</link><guid isPermaLink="true">https://alpha-cyber.com/ghost-in-the-shell-unmasking-the-qlnx-rootkit/</guid><description>QLNX is an advanced Linux rootkit engineered for kernel-level stealth, privilege concealment and long-term covert access – hiding processes, tampering with telemetry, and evading detection across servers, cloud workloads and internet-facing systems.</description><pubDate>Tue, 26 May 2026 21:12:53 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Rootkit</category><category>Linux</category><author>Alpha Cyber Research</author></item><item><title>Deep Persistence: How Sandworm Weaponizes Tor for Long-Term Stealth</title><link>https://alpha-cyber.com/deep-persistence-how-sandworm-weaponizes-tor-for-long-term-stealth/</link><guid isPermaLink="true">https://alpha-cyber.com/deep-persistence-how-sandworm-weaponizes-tor-for-long-term-stealth/</guid><description>Sandworm Uses SSH-over-Tor Tunnels for Stealthy Long-Term Persistence Sandworm – the Russian state-sponsored actor linked to GRU Unit 74455 – leveraged SSH-over-Tor tunneling to establish covert, resilient, long-term access inside compromised environments…</description><pubDate>Tue, 26 May 2026 21:03:02 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>APT</category><category>Persistence</category><author>Alpha Cyber Research</author></item><item><title>The Rootkit in Your Living Room: Anatomy of the Katana Botnet a Mirai Variant</title><link>https://alpha-cyber.com/the-rootkit-in-your-living-room-anatomy-of-the-katana-botnet-a-mirai-variant/</link><guid isPermaLink="true">https://alpha-cyber.com/the-rootkit-in-your-living-room-anatomy-of-the-katana-botnet-a-mirai-variant/</guid><description>Katana is a Mirai-derived botnet built to compromise vulnerable IoT devices at scale through credential abuse, remote code execution and aggressive propagation – delivering stealth persistence…</description><pubDate>Tue, 26 May 2026 20:52:16 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Botnet</category><category>IoT</category><author>Alpha Cyber Research</author></item><item><title>Kazuar Unmasked: Inside Turla’s Persistent Cyber-Espionage Machine</title><link>https://alpha-cyber.com/kazuar-unmasked-inside-turlas-persistent-cyber-espionage-machine/</link><guid isPermaLink="true">https://alpha-cyber.com/kazuar-unmasked-inside-turlas-persistent-cyber-espionage-machine/</guid><description>Kazuar Backdoor: Inside Turla’s .NET Espionage Implant Indicators and behavioral telemetry align with Kazuar – a sophisticated espionage backdoor associated with Turla, the Russian state-sponsored APT known for stealth operations against government…</description><pubDate>Tue, 26 May 2026 20:39:05 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>APT</category><category>Backdoor</category><author>Alpha Cyber Research</author></item><item><title>Abyss Rootkit Analysis: Unmasking Deep-System Threats</title><link>https://alpha-cyber.com/abyss-rootkit-analysis-unmasking-deep-system-threats/</link><guid isPermaLink="true">https://alpha-cyber.com/abyss-rootkit-analysis-unmasking-deep-system-threats/</guid><description>ABYSSWORKER: The EDR-Killer Driver Behind MEDUSA Ransomware ABYSSWORKER is a malicious signed Windows kernel driver used in the MEDUSA ransomware attack chain to blind and disable endpoint detection and response tools – masquerading as a CrowdStrike Falcon…</description><pubDate>Sun, 24 May 2026 09:15:54 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>EDR Killer</category><category>Ransomware</category><author>Alpha Cyber Research</author></item><item><title>Hunting Orbit Rootkit Part Open-Source Medusa Ransomware – IOC Deep Dive</title><link>https://alpha-cyber.com/hunting-orbit-rootkit-ioc-deep-dive/</link><guid isPermaLink="true">https://alpha-cyber.com/hunting-orbit-rootkit-ioc-deep-dive/</guid><description>OrBit: The Linux Rootkit That Hijacks the Dynamic Linker OrBit is a stealthy Linux userland rootkit that abuses the dynamic linker (ld.so) to load itself into every new process – hooking dozens of libc functions to hide files, processes and network sockets from standard tooling on the host.</description><pubDate>Wed, 20 May 2026 08:55:40 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Rootkit</category><category>Linux</category><author>Alpha Cyber Research</author></item><item><title>Your Phone is a Narc: The Systematic Betrayal of Civilian Privacy</title><link>https://alpha-cyber.com/your-phone-is-a-narc-the-systematic-betrayal-of-civilian-privacy/</link><guid isPermaLink="true">https://alpha-cyber.com/your-phone-is-a-narc-the-systematic-betrayal-of-civilian-privacy/</guid><description>Deep Dive // Surveillance Capitalism PUBLISHED: MAY 2026 Your Phone Is a Narc: The Built-In Infrastructure Betraying Civilian Privacy How everyday smartphones are weaponized against civilians without a single line of malware, turning features into informants.</description><pubDate>Fri, 15 May 2026 11:14:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Mercenary Cyber Surveillance: Indian Hack-for-Hire Group Targets Android and iCloud Backups</title><link>https://alpha-cyber.com/mercenary-cyber-surveillance-indian-hack-for-hire-group-targets-android-and-icloud-backups/</link><guid isPermaLink="true">https://alpha-cyber.com/mercenary-cyber-surveillance-indian-hack-for-hire-group-targets-android-and-icloud-backups/</guid><description>Mercenary Surveillance: Hack-for-Hire Group Targets Android and iCloud Backups A commercial hack-for-hire operation runs a cross-platform surveillance model – deploying Android spyware on some targets while phishing Apple ID credentials to siphon entire…</description><pubDate>Fri, 15 May 2026 11:04:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Spyware</category><category>Hack-for-Hire</category><author>Alpha Cyber Research</author></item><item><title>Amazon Quietly Mapped Your Life Through Your Phone</title><link>https://alpha-cyber.com/amazon-quietly-mapped-your-life-through-your-phone/</link><guid isPermaLink="true">https://alpha-cyber.com/amazon-quietly-mapped-your-life-through-your-phone/</guid><description>• PRIVACY &amp; THREAT INTELLIGENCE Amazon Quietly Mapped Your Life Through Your Phone Smartphones have become powerful data collection devices.</description><pubDate>Fri, 15 May 2026 10:19:55 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Operation NoVoice: Silent Persistence and the Rootkit Lifecycle</title><link>https://alpha-cyber.com/operation-novoice-silent-persistence-and-the-rootkit-lifecycle/</link><guid isPermaLink="true">https://alpha-cyber.com/operation-novoice-silent-persistence-and-the-rootkit-lifecycle/</guid><description>Operation NoVoice: The Android Rootkit That Survives a Factory Reset NoVoice is a mobile-espionage campaign that hid in 50+ Google Play apps (2.3M+ downloads), chained 22 legacy Android exploits to gain root, and planted a Zygote-level rootkit that hooks the…</description><pubDate>Sun, 10 May 2026 12:29:28 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Rootkit</category><category>Android</category><author>Alpha Cyber Research</author></item><item><title>Latest Qilin Ransomware IOCs Analysis  Emerging Threat Indicators</title><link>https://alpha-cyber.com/latest-qilin-ransomware-iocs-analysis-emerging-threat-indicators/</link><guid isPermaLink="true">https://alpha-cyber.com/latest-qilin-ransomware-iocs-analysis-emerging-threat-indicators/</guid><description>Profile of 2025’s Most Active Extortion Operation Qilin (formerly Agenda) is a Rust-based ransomware-as-a-service operation that became the most active extortion brand of 2025 – absorbing displaced affiliates after RansomHub’s collapse, running double…</description><pubDate>Tue, 05 May 2026 19:32:57 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Ransomware</category><category>Qilin</category><author>Alpha Cyber Research</author></item><item><title>RegPhantom Rootkit: Persistence Mechanisms and Mitigation</title><link>https://alpha-cyber.com/regphantom-rootkit-persistence-mechanisms-and-mitigation/</link><guid isPermaLink="true">https://alpha-cyber.com/regphantom-rootkit-persistence-mechanisms-and-mitigation/</guid><description>RegPhantom Watch: A Suspicious Hash With Agreement SHA-256 703dfb12…e7c4 draws consensus from two trusted reputation feeds and possible RegPhantom rootkit ties, but no behavioural detonation confirms intent.</description><pubDate>Tue, 05 May 2026 17:35:57 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>VGOD Ransomware Exposed: Actionable IOCs for Rapid Defense</title><link>https://alpha-cyber.com/vgod-ransomware-exposed-actionable-iocs-for-rapid-defense/</link><guid isPermaLink="true">https://alpha-cyber.com/vgod-ransomware-exposed-actionable-iocs-for-rapid-defense/</guid><description>VGOD Ransomware: Anatomy of a Backup-Killing Windows Extortion Strain VGOD is a Windows ransomware first seen in February 2025 that encrypts files, deletes Volume Shadow Copies to block recovery, and runs double extortion behind a ‘Decryption…</description><pubDate>Sun, 03 May 2026 19:44:03 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Ransomware</category><author>Alpha Cyber Research</author></item><item><title>Dynowiper Exposed: Forensic Analysis of a Sandworm Cyberweapon</title><link>https://alpha-cyber.com/dynowiper-exposed-forensic-analysis-of-a-sandworm-cyberweapon/</link><guid isPermaLink="true">https://alpha-cyber.com/dynowiper-exposed-forensic-analysis-of-a-sandworm-cyberweapon/</guid><description>DYNOWIPER: Anatomy of the Wiper That Struck Poland’s Energy Grid The ‘critical, unattributed PE’ from automated triage is DYNOWIPER, a deliberately simple data-destruction wiper used on 29 December 2025 against 30+ Polish renewable sites and a major CHP…</description><pubDate>Wed, 29 Apr 2026 15:03:46 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Wiper</category><author>Alpha Cyber Research</author></item><item><title>Inside Luca Stealer: A Technical Decomposition of the Rust-Based Malware</title><link>https://alpha-cyber.com/inside-luca-stealer-a-technical-decomposition-of-the-rust-based-malware/</link><guid isPermaLink="true">https://alpha-cyber.com/inside-luca-stealer-a-technical-decomposition-of-the-rust-based-malware/</guid><description>Beyond the Binary: How Luca Stealer Uses the Rust Runtime to Slip Past Detection A 4.6 MB Rust PE scored 100/100 with heavy anti-analysis and a Telegram exfiltration channel, behaviour that lines up with Luca Stealer, the leaked Rust infostealer.</description><pubDate>Fri, 10 Apr 2026 12:49:09 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>Luke Ransomware Uncovered: A Deep Dive into Encryption and Exfiltration Tactics</title><link>https://alpha-cyber.com/luke-ransomware-uncovered-a-deep-dive-into-encryption-and-exfiltration-tactics/</link><guid isPermaLink="true">https://alpha-cyber.com/luke-ransomware-uncovered-a-deep-dive-into-encryption-and-exfiltration-tactics/</guid><description>Luke Ransomware: A Critical-Severity Encryptor That Also Steals A small (~558 KB) Windows PE flagged critical (90/100) is Luke, a ransomware sample that is also an information-stealer.</description><pubDate>Mon, 30 Mar 2026 09:15:27 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Ransomware</category><author>Alpha Cyber Research</author></item><item><title>The Anatomy of a Qilin Attack: Technical Indicators and C2 Infrastructure</title><link>https://alpha-cyber.com/the-anatomy-of-a-qilin-attack-technical-indicators-and-c2-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/the-anatomy-of-a-qilin-attack-technical-indicators-and-c2-infrastructure/</guid><description>The Qilin Surge: How Agenda’s Rust Rewrite Became the Most Active Ransomware of 2025 Qilin published more than 1,000 victims in 2025 and now names 40-plus organisations a month on its leak site.</description><pubDate>Mon, 30 Mar 2026 08:29:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Ransomware</category><author>Alpha Cyber Research</author></item><item><title>What is Klingpremium.xyz? Malware Analysis and Mitigation Guide</title><link>https://alpha-cyber.com/what-is-klingpremium-xyz-malware-analysis-and-mitigation-guide/</link><guid isPermaLink="true">https://alpha-cyber.com/what-is-klingpremium-xyz-malware-analysis-and-mitigation-guide/</guid><description>Under the Hood of klingpremium.xyz: an Obfuscated Batch Loader Your ML Model Rated 0% Malicious A 314 KB Windows .bat flagged critical (90/100) is a multi-stage loader that geofences, then uses PowerShell to pull a next-stage payload from klingpremium.xyz and…</description><pubDate>Sun, 29 Mar 2026 13:22:40 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>GoAskBobby.exe Malware Analysis: Technical Breakdown of a Stealthy Stealer</title><link>https://alpha-cyber.com/goaskbobby-exe-malware-analysis-technical-breakdown-of-a-stealthy-stealer/</link><guid isPermaLink="true">https://alpha-cyber.com/goaskbobby-exe-malware-analysis-technical-breakdown-of-a-stealthy-stealer/</guid><description>GoAskBobby.exe: The ‘AI Helper’ That’s Really JustAskJacky Malware An automated scan shrugged this 20 MB signed installer off as UNKNOWN with zero indicators.</description><pubDate>Sat, 28 Mar 2026 11:34:57 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>What is Indeanapolice.cc? Malware Analysis and Removal Guide</title><link>https://alpha-cyber.com/what-is-indeanapolice-cc-malware-analysis-and-removal-guide/</link><guid isPermaLink="true">https://alpha-cyber.com/what-is-indeanapolice-cc-malware-analysis-and-removal-guide/</guid><description>Blocking the Breach: Inside the indeanapolice.cc PowerShell Dropper A tiny, heavily obfuscated PowerShell script flagged in triage turns out to be the download-cradle stage of the indeanapolice.cc dropper, a recently-registered, low-reputation campaign that…</description><pubDate>Fri, 27 Mar 2026 19:48:49 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>Is Your Data Safe? The Rising Threat of FredyStealer Malware</title><link>https://alpha-cyber.com/is-your-data-safe-the-rising-threat-of-fredystealer-malware/</link><guid isPermaLink="true">https://alpha-cyber.com/is-your-data-safe-the-rising-threat-of-fredystealer-malware/</guid><description>Malware Analysis Report FredyStealer: The Silent Thief in Your System Published March 26, 2026 · Threat Intelligence Team · A critical-severity script sample was processed by the malware analysis suite.</description><pubDate>Thu, 26 Mar 2026 21:29:31 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Wiped Out: Unmasking the Arid Viper Tactics Behind BiBi Malware</title><link>https://alpha-cyber.com/wiped-out-unmasking-the-arid-viper-tactics-behind-bibi-malware/</link><guid isPermaLink="true">https://alpha-cyber.com/wiped-out-unmasking-the-arid-viper-tactics-behind-bibi-malware/</guid><description>BiBi Wiper: What the Malware Really Does, and Why This Sample Does Not Confirm It BiBi is a destructive wiper used against Israeli organisations in 2023 that shreds files and appends a .BiBi extension.</description><pubDate>Thu, 26 Mar 2026 21:03:53 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:AMBER</dc:subject><category>Threat Reports</category><category>Malware</category><author>Alpha Cyber Research</author></item><item><title>When Trust Breaks: The Microsoft‑Signed Rootkit That Bypasses Endpoint Security</title><link>https://alpha-cyber.com/when-trust-breaks-the-microsoft-signed-rootkit-that-bypasses-endpoint-security/</link><guid isPermaLink="true">https://alpha-cyber.com/when-trust-breaks-the-microsoft-signed-rootkit-that-bypasses-endpoint-security/</guid><description>Signed Is Not Safe: How Vulnerable Kernel Drivers Are Weaponised to Kill EDR Kernel drivers run in Ring 0, below your endpoint protection.</description><pubDate>Thu, 12 Mar 2026 12:01:52 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><category>Endpoint Security</category><author>Alpha Cyber Research</author></item><item><title>When Routes Become Rootkits: The Hidden Cyber Risk in Modern Supply Chains</title><link>https://alpha-cyber.com/when-routes-become-rootkits-the-hidden-cyber-risk-in-modern-supply-chains/</link><guid isPermaLink="true">https://alpha-cyber.com/when-routes-become-rootkits-the-hidden-cyber-risk-in-modern-supply-chains/</guid><description>A rootkit hides inside normal operations and hands an attacker persistent, trusted access without tripping an alarm. A predictable transport route does the same thing to a supply chain.</description><pubDate>Thu, 12 Mar 2026 11:45:59 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><category>Threat Intelligence</category><category>Supply Chain Security</category><author>Alpha Cyber Research</author></item><item><title>Meta AI Oakley Glasses Privacy Fiasco</title><link>https://alpha-cyber.com/meta-ai-glasses-privacy-fiasco/</link><guid isPermaLink="true">https://alpha-cyber.com/meta-ai-glasses-privacy-fiasco/</guid><description>For years, cybersecurity professionals warned that the biggest privacy threats wouldn’t look like threats at all. They would look like convenience. Smart speakers. Smart cameras.</description><pubDate>Wed, 11 Mar 2026 14:53:53 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Microsoft Has No Shame: Your Passwords and Bank Data are Now “Recall” Metadata</title><link>https://alpha-cyber.com/microsoft-has-no-shame-your-passwords-and-bank-data-are-now-recall-metadata/</link><guid isPermaLink="true">https://alpha-cyber.com/microsoft-has-no-shame-your-passwords-and-bank-data-are-now-recall-metadata/</guid><description>At Alpha Cyber, we prioritize keeping you informed about the latest digital threats.</description><pubDate>Tue, 10 Mar 2026 21:54:20 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Stop Being a Data Point: Hardening Your Phone Against Surveillance</title><link>https://alpha-cyber.com/stop-being-a-data-point-hardening-your-phone-against-surveillance/</link><guid isPermaLink="true">https://alpha-cyber.com/stop-being-a-data-point-hardening-your-phone-against-surveillance/</guid><description>Think your location data is private? Law enforcement increasingly uses geofence warrants, a digital dragnet that turns every smartphone in an area into a potential suspect.</description><pubDate>Tue, 10 Mar 2026 21:17:57 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>One Click to God Mode: How OpenClaw’s Fatal Flaw Gave Attackers Your Master Keys</title><link>https://alpha-cyber.com/one-click-to-god-mode-how-openclaws-fatal-flaw-gave-attackers-your-master-keys/</link><guid isPermaLink="true">https://alpha-cyber.com/one-click-to-god-mode-how-openclaws-fatal-flaw-gave-attackers-your-master-keys/</guid><description>In the cybersecurity world, we often talk about “defense in depth.” But what happens when the very vault meant to protect your secrets becomes the front door for an intruder?</description><pubDate>Mon, 02 Mar 2026 14:01:15 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Vintage Malice: Unmasking APT29’s Wine-Tasting Trap</title><link>https://alpha-cyber.com/vintage-malice-unmasking-apt29s-wine-tasting-trap/</link><guid isPermaLink="true">https://alpha-cyber.com/vintage-malice-unmasking-apt29s-wine-tasting-trap/</guid><description>APT29 a notorious Russian cyber espionage group has recently targeted European diplomats using GRAPELOADER malware.</description><pubDate>Sun, 01 Mar 2026 10:41:10 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Credential Theft to Ransomware: The Arkana Group’s New Tactic on WoW</title><link>https://alpha-cyber.com/credential-theft-to-ransomware-the-arkana-groups-new-tactic-on-wow/</link><guid isPermaLink="true">https://alpha-cyber.com/credential-theft-to-ransomware-the-arkana-groups-new-tactic-on-wow/</guid><description>In a sophisticated cyberattack that rocked WideOpenWest (WoW), the Arkana Ransomware Group used a subtle yet dangerous strategy that started with an infostealer infection.</description><pubDate>Sat, 28 Feb 2026 18:29:08 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Silencing the Panic Button: Inside the Linux SysRq Rootkit That Evades Forensics</title><link>https://alpha-cyber.com/silencing-the-panic-button-inside-the-linux-sysrq-rootkit-that-evades-forensics/</link><guid isPermaLink="true">https://alpha-cyber.com/silencing-the-panic-button-inside-the-linux-sysrq-rootkit-that-evades-forensics/</guid><description>Imagine your server starts behaving erratically. You suspect a breach, but your monitoring tools are silent.</description><pubDate>Sat, 28 Feb 2026 18:15:00 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>The VoidLink Evolution: AI-Generated Stealth Rootkit Targeting the Linux Kernel</title><link>https://alpha-cyber.com/the-voidlink-evolution-ai-generated-stealth-rootkit-targeting-the-linux-kernel/</link><guid isPermaLink="true">https://alpha-cyber.com/the-voidlink-evolution-ai-generated-stealth-rootkit-targeting-the-linux-kernel/</guid><description>In January 2026, researchers at Check Point Research published what may be the first clearly documented case of advanced AI-generated malware at scale: VoidLink.</description><pubDate>Sat, 28 Feb 2026 17:50:02 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Interlock RAT: The Kongtuke Connection Unmasked</title><link>https://alpha-cyber.com/interlock-rat-the-kongtuke-connection-unmasked/</link><guid isPermaLink="true">https://alpha-cyber.com/interlock-rat-the-kongtuke-connection-unmasked/</guid><description>In today’s cybersecurity landscape, advanced persistent threats (APTs) like the Interlock RAT are becoming increasingly sophisticated.</description><pubDate>Tue, 17 Feb 2026 13:01:10 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Storm-0501: When “The Intruder is in the House” Means Your Azure Cloud is Compromised.</title><link>https://alpha-cyber.com/storm-0501-when-the-intruder-is-in-the-house-means-your-azure-cloud-is-compromised/</link><guid isPermaLink="true">https://alpha-cyber.com/storm-0501-when-the-intruder-is-in-the-house-means-your-azure-cloud-is-compromised/</guid><description>It is the notification no administrator wants to see: not a firewall alert, but a Microsoft Teams message from an intruder already sitting inside the tenant.</description><pubDate>Sun, 15 Feb 2026 11:05:51 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Indian Cyber Force &amp; #OpCanada: Why Your Website is the New Diplomatic Battlefield.</title><link>https://alpha-cyber.com/indian-cyber-force-opcanada-why-your-website-is-the-new-diplomatic-battlefield/</link><guid isPermaLink="true">https://alpha-cyber.com/indian-cyber-force-opcanada-why-your-website-is-the-new-diplomatic-battlefield/</guid><description>When geopolitical tensions boil over, the first shots aren’t always fired on the battlefield they’re fired in the browser.</description><pubDate>Thu, 12 Feb 2026 11:15:48 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Hunting the Hunters: How We Discovered the Iranian Spy Network in Your Inbox.</title><link>https://alpha-cyber.com/hunting-the-hunters-how-we-discovered-the-iranian-spy-network-in-your-inbox/</link><guid isPermaLink="true">https://alpha-cyber.com/hunting-the-hunters-how-we-discovered-the-iranian-spy-network-in-your-inbox/</guid><description>The “SiameseKitten” APT (also known as Lyceum) represents one of the most persistent and calculated threat actors operating out of Iran.</description><pubDate>Thu, 12 Feb 2026 11:02:04 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Why Paying the Ransom is a Trap and What to Do Instead.</title><link>https://alpha-cyber.com/why-paying-the-ransom-is-a-trap-and-what-to-do-instead/</link><guid isPermaLink="true">https://alpha-cyber.com/why-paying-the-ransom-is-a-trap-and-what-to-do-instead/</guid><description>Ransomware isn’t just an IT glitch; it’s a full-scale business crisis.</description><pubDate>Thu, 12 Feb 2026 10:31:46 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Mapping the Malice: A Deep Dive into DanBot’s Infrastructure</title><link>https://alpha-cyber.com/mapping-the-malice-a-deep-dive-into-danbots-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-the-malice-a-deep-dive-into-danbots-infrastructure/</guid><description>In the world of targeted espionage, what you don’t see isn’t just a blind spot it’s an open door.</description><pubDate>Thu, 12 Feb 2026 08:46:46 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>The Anatomy of an Attack: Mapping the dAn0n Threat Landscape</title><link>https://alpha-cyber.com/the-anatomy-of-an-attack-mapping-the-dan0n-threat-landscape/</link><guid isPermaLink="true">https://alpha-cyber.com/the-anatomy-of-an-attack-mapping-the-dan0n-threat-landscape/</guid><description>In the rapidly shifting ecosystem of cybercrime, new actors often emerge from the shadows of fallen giants.</description><pubDate>Thu, 12 Feb 2026 08:31:08 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>From Rootkits to Ransomware: Decoding SideWinder’s Newest Indian Campaign</title><link>https://alpha-cyber.com/from-rootkits-to-ransomware-decoding-sidewinders-newest-indian-campaign/</link><guid isPermaLink="true">https://alpha-cyber.com/from-rootkits-to-ransomware-decoding-sidewinders-newest-indian-campaign/</guid><description>Tax season is stressful enough without an Advanced Persistent Threat (APT) group living in your network.</description><pubDate>Tue, 03 Feb 2026 11:07:07 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>RAMP is Dead. Is Your Defensive Strategy Still Stuck in 2023?</title><link>https://alpha-cyber.com/ramp-is-dead-is-your-defensive-strategy-still-stuck-in-2023/</link><guid isPermaLink="true">https://alpha-cyber.com/ramp-is-dead-is-your-defensive-strategy-still-stuck-in-2023/</guid><description>The digital underground just lost one of its most notorious meeting spots.</description><pubDate>Mon, 02 Feb 2026 21:41:23 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Rome is Burning: How Indian Hackers Outmaneuvered Italian Diplomacy</title><link>https://alpha-cyber.com/rome-is-burning-how-indian-hackers-outmaneuvered-italian-diplomacy/</link><guid isPermaLink="true">https://alpha-cyber.com/rome-is-burning-how-indian-hackers-outmaneuvered-italian-diplomacy/</guid><description>The digital battlefield just got a lot bigger. For years, Western organizations viewed South Asian hacking collectives as a localized threat nuisances confined to their own backyard.</description><pubDate>Mon, 02 Feb 2026 21:13:11 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Windows God Mode is No Longer Just for Shortcuts It’s the New Front Line for Malware</title><link>https://alpha-cyber.com/windows-god-mode-is-no-longer-just-for-shortcuts-its-the-new-front-line-for-malware/</link><guid isPermaLink="true">https://alpha-cyber.com/windows-god-mode-is-no-longer-just-for-shortcuts-its-the-new-front-line-for-malware/</guid><description>We’ve all seen te tech tips: create a folder, paste a string of code, and boom you have “God Mode,” a one-stop shop for every Windows setting imaginable.</description><pubDate>Mon, 02 Feb 2026 13:59:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Behind the Booking.com Scam: ClickFix and a Phishing-as-a-Service Operation</title><link>https://alpha-cyber.com/behind-the-booking-com-scam-clickfix-and-a-phishing-as-a-service-operation/</link><guid isPermaLink="true">https://alpha-cyber.com/behind-the-booking-com-scam-clickfix-and-a-phishing-as-a-service-operation/</guid><description>Executive Summary A sophisticated phishing campaign dubbed “I Paid Twice” is actively targeting Booking.com hotels and their customers, abusing brand trust to deliver malware and remote access tooling.</description><pubDate>Tue, 20 Jan 2026 12:45:59 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>The Big Brother You Didn’t Ask For: How Chinese Tech Spies from Within</title><link>https://alpha-cyber.com/the-big-brother-you-didnt-ask-for-how-chinese-tech-spies-from-within/</link><guid isPermaLink="true">https://alpha-cyber.com/the-big-brother-you-didnt-ask-for-how-chinese-tech-spies-from-within/</guid><description>We often talk about “the cloud” as if it’s some ethereal, neutral space. It isn’t.</description><pubDate>Mon, 19 Jan 2026 14:22:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Why Your Vacuum is a Privacy Nightmare</title><link>https://alpha-cyber.com/why-your-vacuum-is-a-privacy-nightmare/</link><guid isPermaLink="true">https://alpha-cyber.com/why-your-vacuum-is-a-privacy-nightmare/</guid><description>We’ve all seen the videos: a robot vacuum mindlessly bumping into a chair leg or getting bullied by the family cat. It looks harmless, even a bit stupid.</description><pubDate>Mon, 19 Jan 2026 11:14:31 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Trillions-Dollar Heist: Mapping the Shadow Infrastructure of APT-41 (Winnti)</title><link>https://alpha-cyber.com/trillions-dollar-heist-mapping-the-shadow-infrastructure-of-apt-41-winnti/</link><guid isPermaLink="true">https://alpha-cyber.com/trillions-dollar-heist-mapping-the-shadow-infrastructure-of-apt-41-winnti/</guid><description>The digital landscape is currently haunted by one of the most sophisticated and relentless state-sponsored threats in history: APT-41 (also known as Winnti, BARIUM, or Double Dragon).</description><pubDate>Mon, 19 Jan 2026 07:57:45 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Avoiding Internet Surveillance Protect Your Privacy Online</title><link>https://alpha-cyber.com/avoiding-internet-surveillance-protect-your-privacy-online/</link><guid isPermaLink="true">https://alpha-cyber.com/avoiding-internet-surveillance-protect-your-privacy-online/</guid><description>Imagine sitting in your corner office, coffee in hand, scrolling through the morning headlines.</description><pubDate>Sat, 17 Jan 2026 11:27:13 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Your Online Activity is Leaking Here’s What DNS Has to Do With It</title><link>https://alpha-cyber.com/your-online-activity-is-leaking-heres-what-dns-has-to-do-with-it/</link><guid isPermaLink="true">https://alpha-cyber.com/your-online-activity-is-leaking-heres-what-dns-has-to-do-with-it/</guid><description>We spend thousands of dollars on high-end firewalls, we obsess over complex passwords, and we look for that little green padlock in the browser bar like it’s a religious icon.</description><pubDate>Sat, 17 Jan 2026 11:02:04 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Your ISP is Getting Rich Off Your Data Here’s How to Stop Them</title><link>https://alpha-cyber.com/your-isp-is-getting-rich-off-your-data-heres-how-to-stop-them/</link><guid isPermaLink="true">https://alpha-cyber.com/your-isp-is-getting-rich-off-your-data-heres-how-to-stop-them/</guid><description>We tend to treat our WiFi routers like appliances once they’re plugged in and the internet works, we forget they exist.</description><pubDate>Sat, 17 Jan 2026 10:47:31 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Facebook &amp; Instagram Your Digital Stalkers?</title><link>https://alpha-cyber.com/facebook-instagram-your-digital-stalkers/</link><guid isPermaLink="true">https://alpha-cyber.com/facebook-instagram-your-digital-stalkers/</guid><description>Are Facebook &amp; Instagram Stalking You? Reclaim Your Privacy It’s a common misconception that your activity on the internet is entirely private when you leave social media apps.</description><pubDate>Tue, 13 Jan 2026 15:06:43 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Decoding Akira Ransomware: Your Defense Against Advanced EDR Evasion</title><link>https://alpha-cyber.com/decoding-akira-ransomware-your-defense-against-advanced-edr-evasion/</link><guid isPermaLink="true">https://alpha-cyber.com/decoding-akira-ransomware-your-defense-against-advanced-edr-evasion/</guid><description>Akira Ransomware is a formidable threat, known for its sophisticated tactics and ability to bypass even robust security measures.</description><pubDate>Tue, 13 Jan 2026 14:27:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Infrastructure Unmasked: The Evolution of Emennet Pasargad</title><link>https://alpha-cyber.com/infrastructure-unmasked-the-evolution-of-emennet-pasargad-asa/</link><guid isPermaLink="true">https://alpha-cyber.com/infrastructure-unmasked-the-evolution-of-emennet-pasargad-asa/</guid><description>(ASA) In mid-2024, a joint advisory from the U.S. Department of Treasury, and the Israel National Cyber Directorate sounded a critical alarm.</description><pubDate>Tue, 13 Jan 2026 13:39:59 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>MedusaLocker Ransomware: Unmasking the Threat through Infrastructure Mapping</title><link>https://alpha-cyber.com/medusalocker-ransomware-unmasking-the-threat-through-infrastructure-mapping/</link><guid isPermaLink="true">https://alpha-cyber.com/medusalocker-ransomware-unmasking-the-threat-through-infrastructure-mapping/</guid><description>In the evolving world of cyber threats, ransomware campaigns like MedusaLocker are becoming more sophisticated and difficult to combat.</description><pubDate>Mon, 12 Jan 2026 14:52:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Facebook and Twitter are Getting Rich by Building a Culture of Snitching</title><link>https://alpha-cyber.com/facebook-and-twitter-are-getting-rich-by-building-a-culture-of-snitching/</link><guid isPermaLink="true">https://alpha-cyber.com/facebook-and-twitter-are-getting-rich-by-building-a-culture-of-snitching/</guid><description>We are living in an era where the “snitch” is no longer a person in an alley it’s the algorithm in your pocket.</description><pubDate>Sun, 11 Jan 2026 20:53:44 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>The Snitch in Your Dock: Why Your Browser is a Privacy Traitor</title><link>https://alpha-cyber.com/the-snitch-in-your-dock-why-your-browser-is-a-privacy-traitor/</link><guid isPermaLink="true">https://alpha-cyber.com/the-snitch-in-your-dock-why-your-browser-is-a-privacy-traitor/</guid><description>Most people think that hitting the “Incognito” button is like putting on an invisibility cloak. In reality, it’s more like wearing a name tag while trying to hide in a crowd.</description><pubDate>Sun, 11 Jan 2026 20:40:03 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>The New Office Snitch: Is Microsoft Teams Reporting Your Every Move?</title><link>https://alpha-cyber.com/the-new-office-snitch-is-microsoft-teams-reporting-your-every-move/</link><guid isPermaLink="true">https://alpha-cyber.com/the-new-office-snitch-is-microsoft-teams-reporting-your-every-move/</guid><description>For years, Microsoft Teams has been the digital watercooler of the modern office. But a recent update has turned that watercooler into a high-tech surveillance hub.</description><pubDate>Sun, 11 Jan 2026 20:31:52 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>The Snitch in Your Pocket: Why Your Phone is a Security Liability</title><link>https://alpha-cyber.com/the-snitch-in-your-pocket-why-your-phone-is-a-security-liability/</link><guid isPermaLink="true">https://alpha-cyber.com/the-snitch-in-your-pocket-why-your-phone-is-a-security-liability/</guid><description>We like to think of our smartphones as personal assistants loyal tools that help us manage our businesses and lives.</description><pubDate>Sun, 11 Jan 2026 20:25:04 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>The Microsoft Eye: Is Your Privacy the Price of Using Bing?</title><link>https://alpha-cyber.com/the-microsoft-eye-is-your-privacy-the-price-of-using-bing/</link><guid isPermaLink="true">https://alpha-cyber.com/the-microsoft-eye-is-your-privacy-the-price-of-using-bing/</guid><description>When we talk about data privacy and search engines, Google usually takes the heat.</description><pubDate>Sun, 11 Jan 2026 20:15:25 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Busting GodRat: Analyzing the Rat and Its Infrastructure</title><link>https://alpha-cyber.com/busting-godrat-analyzing-the-rat-and-its-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/busting-godrat-analyzing-the-rat-and-its-infrastructure/</guid><description>Cracking the GodRat Campaign: Unmasking Its Infrastructure &amp; How to Block It The GodRat Trojan is believed to be operated by the Chinese threat group Winnti (APT41), known for targeting financial institutions, including trading and brokerage firms.</description><pubDate>Tue, 06 Jan 2026 22:49:48 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Exposing the LinkPro Rootkit Infrastructure Breakdown &amp; Key Defenses</title><link>https://alpha-cyber.com/exposing-the-linkpro-rootkit-infrastructure-breakdown-key-defenses/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-the-linkpro-rootkit-infrastructure-breakdown-key-defenses/</guid><description>The LinkPro Rootkit is a highly sophisticated malware that continues to make waves in the cybersecurity landscape.</description><pubDate>Tue, 06 Jan 2026 20:36:59 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Toneshell Rootkit Inside the Silent Threat</title><link>https://alpha-cyber.com/toneshell-rootkit-inside-the-silent-threat/</link><guid isPermaLink="true">https://alpha-cyber.com/toneshell-rootkit-inside-the-silent-threat/</guid><description>In the modern threat landscape, stealth is the ultimate weapon.</description><pubDate>Tue, 06 Jan 2026 17:24:20 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Your Boss is Watching: The Invisible Risks of Using Work Equipment</title><link>https://alpha-cyber.com/your-boss-is-watching-the-invisible-risks-of-using-work-equipment/</link><guid isPermaLink="true">https://alpha-cyber.com/your-boss-is-watching-the-invisible-risks-of-using-work-equipment/</guid><description>In 2025, the line between “home” and “office” has blurred into nonexistence.</description><pubDate>Sat, 20 Dec 2025 20:17:18 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>The Spy in Your Living Room: Is Your TV Watching You?</title><link>https://alpha-cyber.com/the-spy-in-your-living-room-is-your-tv-watching-you/</link><guid isPermaLink="true">https://alpha-cyber.com/the-spy-in-your-living-room-is-your-tv-watching-you/</guid><description>When you turn on your TV, you expect to be entertained. You probably don’t expect to be monitored.</description><pubDate>Sat, 20 Dec 2025 20:09:50 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Smile, You’re on Facebook: Is Your Feed Watching You Back?</title><link>https://alpha-cyber.com/smile-youre-on-facebook-is-your-feed-watching-you-back/</link><guid isPermaLink="true">https://alpha-cyber.com/smile-youre-on-facebook-is-your-feed-watching-you-back/</guid><description>Remember the unsettling discovery that Facebook was secretly accessing iPhone cameras as users scrolled their feeds?</description><pubDate>Sat, 20 Dec 2025 19:25:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Your iPhone is a Snitch: The $95M Siri Scandal Explained</title><link>https://alpha-cyber.com/your-iphone-is-a-snitch-the-95m-siri-scandal-explained/</link><guid isPermaLink="true">https://alpha-cyber.com/your-iphone-is-a-snitch-the-95m-siri-scandal-explained/</guid><description>In January 2025, Apple agreed to pay $95 million to settle a class-action lawsuit alleging that Siri recorded private conversations without user consent.</description><pubDate>Sat, 20 Dec 2025 19:01:42 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Why Migrating Your Business to Proton is Your Next Essential Cybersecurity Move</title><link>https://alpha-cyber.com/why-migrating-your-business-to-proton-is-your-next-essential-cybersecurity-move/</link><guid isPermaLink="true">https://alpha-cyber.com/why-migrating-your-business-to-proton-is-your-next-essential-cybersecurity-move/</guid><description>In today’s digital economy, your data is your most valuable asset, and your biggest liability.</description><pubDate>Mon, 01 Dec 2025 21:51:36 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Unmasking Mobile Espionage: Forensic Analysis on Donot Indian APT’s Android Malware Operations</title><link>https://alpha-cyber.com/unmasking-mobile-espionage-forensic-analysis-on-donot-indian-apts-android-malware-operations/</link><guid isPermaLink="true">https://alpha-cyber.com/unmasking-mobile-espionage-forensic-analysis-on-donot-indian-apts-android-malware-operations/</guid><description>Advanced Persistent Threats (APTs) are expanding their offensive footprint into mobile ecosystems and organizations in South Asia remain prime targets.</description><pubDate>Sun, 30 Nov 2025 10:54:01 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Forensic Deep Dive: Shellcode Injection via Donot an Indian APT’s Malicious XLS</title><link>https://alpha-cyber.com/forensic-deep-dive-shellcode-injection-via-donot-apts-malicious-xls/</link><guid isPermaLink="true">https://alpha-cyber.com/forensic-deep-dive-shellcode-injection-via-donot-apts-malicious-xls/</guid><description>Donot Team (also known as APTC35, Viceroy Tiger, or Mint Tempest) is a highly organized Advanced Persistent Threat group strongly suspected to operate with ties to the Indian state.</description><pubDate>Sat, 29 Nov 2025 22:53:16 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Meta Accused of Inflating Ad Metrics &amp; Dodging Apple’s Privacy Rules Here’s How to Defend Your Business</title><link>https://alpha-cyber.com/meta-accused-of-inflating-ad-metrics-dodging-apples-privacy-rules-heres-how-to-defend-your-business/</link><guid isPermaLink="true">https://alpha-cyber.com/meta-accused-of-inflating-ad-metrics-dodging-apples-privacy-rules-heres-how-to-defend-your-business/</guid><description>In a new wave of controversy, Meta has been accused of inflating ad performance metrics and dodging Apple’s privacy rules, raising serious concerns about data manipulation and user privacy violations.</description><pubDate>Thu, 27 Nov 2025 13:08:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Meta AI: Why Your Data Might Be at Risk and How to Protect Yourself from Unseen Privacy</title><link>https://alpha-cyber.com/meta-ai-why-your-data-might-be-at-risk-and-how-to-protect-yourself-from-unseen-privacy/</link><guid isPermaLink="true">https://alpha-cyber.com/meta-ai-why-your-data-might-be-at-risk-and-how-to-protect-yourself-from-unseen-privacy/</guid><description>Meta’s AI assistant is no longer a novelty it’s now embedded across all your favorite Meta platforms: Facebook, Instagram, Messenger, and WhatsApp.</description><pubDate>Thu, 27 Nov 2025 12:50:38 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>CyberRoot Exposed: Unmasking the Indian Hack-for-Hire Operation Behind the Scandal</title><link>https://alpha-cyber.com/cyberroot-exposed-unmasking-the-indian-hack-for-hire-operation-behind-the-scandal/</link><guid isPermaLink="true">https://alpha-cyber.com/cyberroot-exposed-unmasking-the-indian-hack-for-hire-operation-behind-the-scandal/</guid><description>A Wake-Up Call for Corporate Security A major cybersecurity and legal battle concluded this week, resulting in a landmark settlement that underscores the growing threat of corporate espionage and “hack-for-hire” schemes.</description><pubDate>Thu, 27 Nov 2025 09:34:02 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>SpearSpecter Unveiled Iranian Hackers APT42 Targeting Defense and Government How to Block Their Cyber Assault</title><link>https://alpha-cyber.com/spearspecter-unveiled-iranian-hackers-apt42-targeting-defense-and-government-how-to-block-their-cyber-assault/</link><guid isPermaLink="true">https://alpha-cyber.com/spearspecter-unveiled-iranian-hackers-apt42-targeting-defense-and-government-how-to-block-their-cyber-assault/</guid><description>The world of cybersecurity is constantly evolving, and so are the tactics used by advanced persistent threats (APTs).</description><pubDate>Thu, 27 Nov 2025 08:32:07 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Dropping Elephant APT Escalates Attacks on Defense Sector with MSBuild-Delivered Backdoor</title><link>https://alpha-cyber.com/dropping-elephant-apt-escalates-attacks-on-defense-sector-with-msbuild-delivered-backdoor/</link><guid isPermaLink="true">https://alpha-cyber.com/dropping-elephant-apt-escalates-attacks-on-defense-sector-with-msbuild-delivered-backdoor/</guid><description>In the ever evolving world of cybersecurity, advanced persistent threat (APT) groups continue to develop increasingly sophisticated tactics to breach highly sensitive sectors.</description><pubDate>Wed, 26 Nov 2025 19:16:14 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Unveiling the ‘Bad News’ Backdoor: A Deep Dive into Indian APT Exploits</title><link>https://alpha-cyber.com/unveiling-the-bad-news-backdoor-a-deep-dive-into-indian-apt-exploits/</link><guid isPermaLink="true">https://alpha-cyber.com/unveiling-the-bad-news-backdoor-a-deep-dive-into-indian-apt-exploits/</guid><description>The cybersecurity landscape is constantly evolving, and the rise of Advanced Persistent Threats (APTs) remains one of the most dangerous challenges for businesses globally.</description><pubDate>Wed, 26 Nov 2025 18:51:15 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Singularity: The Next-Gen Linux Rootkit Threat That Could Shake Your System to Its Core</title><link>https://alpha-cyber.com/singularity-the-next-gen-linux-rootkit-threat-that-could-shake-your-system-to-its-core/</link><guid isPermaLink="true">https://alpha-cyber.com/singularity-the-next-gen-linux-rootkit-threat-that-could-shake-your-system-to-its-core/</guid><description>The cybersecurity landscape is evolving faster than ever, and a new, highly sophisticated threat has emerged that could outsmart even the most vigilant system administrators.</description><pubDate>Wed, 26 Nov 2025 18:09:25 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Rootkits and Capabilities: The Perfect Storm Destroying Your Security Unnoticed</title><link>https://alpha-cyber.com/rootkits-and-capabilities-the-perfect-storm-destroying-your-security-unnoticed/</link><guid isPermaLink="true">https://alpha-cyber.com/rootkits-and-capabilities-the-perfect-storm-destroying-your-security-unnoticed/</guid><description>In the evolving landscape of post-exploitation, sophisticated attackers are moving beyond traditional SUID (Set User ID) exploits.</description><pubDate>Wed, 26 Nov 2025 15:01:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>The Secret Life of Rootkits: A Tree Plantation Analogy for Cybersecurity</title><link>https://alpha-cyber.com/the-secret-life-of-rootkits-a-tree-plantation-analogy-for-cybersecurity/</link><guid isPermaLink="true">https://alpha-cyber.com/the-secret-life-of-rootkits-a-tree-plantation-analogy-for-cybersecurity/</guid><description>What appears to be a simple social media post about a tree plantation drive contains profound parallels to sophisticated cyberattacks.</description><pubDate>Wed, 26 Nov 2025 12:27:33 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Traitor Among Us: The Inside Job That Shook Cybersecurity Lessons from the CrowdStrike Breach</title><link>https://alpha-cyber.com/traitor-among-us-the-inside-job-that-shook-cybersecurity-lessons-from-the-crowdstrike-breach/</link><guid isPermaLink="true">https://alpha-cyber.com/traitor-among-us-the-inside-job-that-shook-cybersecurity-lessons-from-the-crowdstrike-breach/</guid><description>In a startling revelation, CrowdStrike confirmed that they had fired a “suspicious insider” who was allegedly passing sensitive company information to a hacking group.</description><pubDate>Wed, 26 Nov 2025 06:41:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>The Inevitable Exposure: Why WhatsApp’s ‘Biggest Breach Ever’ Signals the End of Privacy</title><link>https://alpha-cyber.com/the-inevitable-exposure-why-whatsapps-biggest-breach-ever-signals-the-end-of-privacy/</link><guid isPermaLink="true">https://alpha-cyber.com/the-inevitable-exposure-why-whatsapps-biggest-breach-ever-signals-the-end-of-privacy/</guid><description>The recent news surrounding the alleged “Biggest WhatsApp Breach Ever” a massive, previously underreported exposure of user metadata and contact information has sent a tremor through the digital privacy landscape.</description><pubDate>Tue, 25 Nov 2025 10:21:28 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>The Sandworm Hackers Cauldron: Unraveling the Threat with Strategic Infrastructure Mapping</title><link>https://alpha-cyber.com/the-sandworm-hackers-cauldron-unraveling-the-threat-with-strategic-infrastructure-mapping/</link><guid isPermaLink="true">https://alpha-cyber.com/the-sandworm-hackers-cauldron-unraveling-the-threat-with-strategic-infrastructure-mapping/</guid><description>In the vast and often unseen world of cyber threats, there exists a particularly nasty breed of hackers that thrive in the shadows: the Sandworm hackers.</description><pubDate>Mon, 24 Nov 2025 14:42:34 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Here Come the Sandworm: The Shai-Hulud Attack Explained</title><link>https://alpha-cyber.com/here-come-the-sandworm-the-shai-hulud-attack-explained/</link><guid isPermaLink="true">https://alpha-cyber.com/here-come-the-sandworm-the-shai-hulud-attack-explained/</guid><description>In the world of cybersecurity, new and increasingly sophisticated threats emerge daily.</description><pubDate>Mon, 24 Nov 2025 14:08:52 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Sneaky “FruitFly” RAT Rat: Visualizing the Infrastructure Behind a Long-Running Threat</title><link>https://alpha-cyber.com/sneaky-fruitfly-rat-rat-visualizing-the-infrastructure-behind-a-long-running-threat/</link><guid isPermaLink="true">https://alpha-cyber.com/sneaky-fruitfly-rat-rat-visualizing-the-infrastructure-behind-a-long-running-threat/</guid><description>For years, the stealthy FruitFly remote access trojan (RAT) quietly operated beneath the radar, targeting macOS systems with an unusual blend of simplicity and persistence.</description><pubDate>Sun, 23 Nov 2025 12:04:45 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>MetadataBin Ransomware What it is, how it spreads, and how we can stop it</title><link>https://alpha-cyber.com/metadatabin-ransomware-what-it-is-how-it-spreads-and-how-we-can-stop-it/</link><guid isPermaLink="true">https://alpha-cyber.com/metadatabin-ransomware-what-it-is-how-it-spreads-and-how-we-can-stop-it/</guid><description>In the world of cyber threats, ransomware continues to be one of the most destructive forces, and Metadatabin is no exception.</description><pubDate>Sat, 08 Nov 2025 18:18:52 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>KongTuke: K is for Keylogging and Kidnapping Your Data</title><link>https://alpha-cyber.com/kongtuke-k-is-for-keylogging-and-kidnapping-your-data/</link><guid isPermaLink="true">https://alpha-cyber.com/kongtuke-k-is-for-keylogging-and-kidnapping-your-data/</guid><description>KongTuke is a recent, aggressive campaign that delivers a modified Interlock RAT (PHP variant) via a PyInstaller packed payload.</description><pubDate>Tue, 04 Nov 2025 16:36:10 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>The Year of The Phish: How Rancor Targets Your Business</title><link>https://alpha-cyber.com/the-year-of-the-phish-how-rancor-targets-your-business/</link><guid isPermaLink="true">https://alpha-cyber.com/the-year-of-the-phish-how-rancor-targets-your-business/</guid><description>In 2019, a sophisticated cyber threat group known as Rancor made headlines with an innovative and devastating phishing campaign.</description><pubDate>Tue, 04 Nov 2025 15:49:08 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Setting Up and Using BloodHound for Active Directory Security</title><link>https://alpha-cyber.com/setting-up-and-using-bloodhound-for-active-directory-security/</link><guid isPermaLink="true">https://alpha-cyber.com/setting-up-and-using-bloodhound-for-active-directory-security/</guid><description>BloodHound is a powerful tool for identifying and mapping attack paths within Active Directory environments.</description><pubDate>Mon, 03 Nov 2025 14:58:33 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Unmasking APT-37 (ScarCruft) and Rokrat Malware: Key IOCs and Defense Strategies</title><link>https://alpha-cyber.com/unmasking-apt-37-scarcruft-and-rokrat-malware-key-iocs-and-defense-strategies/</link><guid isPermaLink="true">https://alpha-cyber.com/unmasking-apt-37-scarcruft-and-rokrat-malware-key-iocs-and-defense-strategies/</guid><description>Advanced Persistent Threat (APT) groups are known for their sophisticated, long term campaigns that target high value organizations, governments, and industries.</description><pubDate>Mon, 03 Nov 2025 14:11:38 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Defending Against RID Hijacking: A Critical Vulnerability Exploited by Andariel APT</title><link>https://alpha-cyber.com/defending-against-rid-hijacking-a-critical-vulnerability-exploited-by-andariel-apt/</link><guid isPermaLink="true">https://alpha-cyber.com/defending-against-rid-hijacking-a-critical-vulnerability-exploited-by-andariel-apt/</guid><description>Cyber threats continue to evolve, becoming more sophisticated and harder to detect. One of the most insidious techniques used by the notorious Andariel APT (Advanced Persistent Threat) group is RID Hijacking.</description><pubDate>Mon, 03 Nov 2025 11:10:48 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Unmasking Dora RAT: Defend Against Andariel APT with Effective Infrastructure Mapping</title><link>https://alpha-cyber.com/unmasking-dora-rat-defend-against-andariel-apt-with-effective-infrastructure-mapping/</link><guid isPermaLink="true">https://alpha-cyber.com/unmasking-dora-rat-defend-against-andariel-apt-with-effective-infrastructure-mapping/</guid><description>In the ever evolving landscape of cybersecurity, threat actors are continuously adapting and refining their tactics to bypass traditional defenses.</description><pubDate>Mon, 03 Nov 2025 10:55:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>New Insights on Laundry Bear Hackers’ Infrastructure: How Mapping Can Stop Them in Their Tracks</title><link>https://alpha-cyber.com/new-insights-on-laundry-bear-hackers-infrastructure-how-mapping-can-stop-them-in-their-tracks/</link><guid isPermaLink="true">https://alpha-cyber.com/new-insights-on-laundry-bear-hackers-infrastructure-how-mapping-can-stop-them-in-their-tracks/</guid><description>In the ever evolving world of cyber threats, staying ahead of sophisticated attackers is crucial. One such group Laundry Bear (also known as Void Blizzard) has been making headlines for its advanced cyber espionage tactics.</description><pubDate>Sun, 02 Nov 2025 22:15:35 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Stay Ahead of Emerging Threats: Mapping Your Infrastructure to Combat Void Blizzard (Laundry Bear)</title><link>https://alpha-cyber.com/stay-ahead-of-emerging-threats-mapping-your-infrastructure-to-combat-void-blizzard-laundry-bear/</link><guid isPermaLink="true">https://alpha-cyber.com/stay-ahead-of-emerging-threats-mapping-your-infrastructure-to-combat-void-blizzard-laundry-bear/</guid><description>) In today’s cybersecurity landscape, being proactive is your best defense against evolving threats. Cybercriminals no longer rely on random attacks they carefully target critical sectors, using advanced techniques to infiltrate networks.</description><pubDate>Sun, 02 Nov 2025 21:54:43 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Your Meta AI Requests May Not Be as Private as You Think</title><link>https://alpha-cyber.com/your-meta-ai-requests-may-not-be-as-private-as-you-think/</link><guid isPermaLink="true">https://alpha-cyber.com/your-meta-ai-requests-may-not-be-as-private-as-you-think/</guid><description>In today’s digital age, artificial intelligence (AI) has revolutionized the way we interact with technology.</description><pubDate>Sun, 02 Nov 2025 21:08:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Meta’s Camera Roll Access Sparks Privacy Alarms: Risks of AI Training &amp; Unpublished Photo Use Explained</title><link>https://alpha-cyber.com/metas-camera-roll-access-sparks-privacy-alarms-risks-of-ai-training-unpublished-photo-use-explained/</link><guid isPermaLink="true">https://alpha-cyber.com/metas-camera-roll-access-sparks-privacy-alarms-risks-of-ai-training-unpublished-photo-use-explained/</guid><description>In recent news, Meta (formerly Facebook) has come under scrutiny after it was revealed that its apps, including Instagram and Facebook, have had access to users’ camera rolls without clear consent or disclosure.</description><pubDate>Sat, 01 Nov 2025 15:30:15 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Mysterious Elephant an infrastructure map &amp; IOC blocklist to protect Asia’s governments</title><link>https://alpha-cyber.com/mysterious-elephant-an-infrastructure-map-ioc-blocklist-to-protect-asias-governments/</link><guid isPermaLink="true">https://alpha-cyber.com/mysterious-elephant-an-infrastructure-map-ioc-blocklist-to-protect-asias-governments/</guid><description>Summary: A stealthy, targeted campaign we’ll call “Mysterious Elephant” is actively exploiting government targets in Asia.</description><pubDate>Thu, 30 Oct 2025 14:19:05 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Exposing Fancy Bear’s Phantom Net: Decoding the BearedShell &amp; SlimAgent Campaigns</title><link>https://alpha-cyber.com/exposing-fancy-bears-phantom-net-decoding-the-bearedshell-slimagent-campaigns/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-fancy-bears-phantom-net-decoding-the-bearedshell-slimagent-campaigns/</guid><description>The notorious Fancy Bear, also known as APT28, has once again surfaced with a new wave of attacks targeting high-value targets across various sectors.</description><pubDate>Thu, 30 Oct 2025 11:33:22 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>R is for Rootkit: Securing Against Advanced Cyber Threats by Mapping the R77 Rootkit</title><link>https://alpha-cyber.com/r-is-for-rootkit-securing-against-advanced-cyber-threats-by-mapping-the-r77-rootkit/</link><guid isPermaLink="true">https://alpha-cyber.com/r-is-for-rootkit-securing-against-advanced-cyber-threats-by-mapping-the-r77-rootkit/</guid><description>In the ever-evolving world of cybersecurity, advanced threats like rootkits remain among the most dangerous. One such example is the R77 Rootkit, a highly sophisticated malware that stealthily infiltrates systems and provides backdoor access to cybercriminals.</description><pubDate>Wed, 29 Oct 2025 18:50:42 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>How Disinformation Can Undermine Your Business and 5 Proven Strategies to Combat It</title><link>https://alpha-cyber.com/how-disinformation-can-undermine-your-business-and-5-proven-strategies-to-combat-it/</link><guid isPermaLink="true">https://alpha-cyber.com/how-disinformation-can-undermine-your-business-and-5-proven-strategies-to-combat-it/</guid><description>Introduction: In today’s digital age, disinformation isn’t just a social media issue, it’s a significant threat to businesses of all sizes.</description><pubDate>Wed, 29 Oct 2025 10:22:58 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Graphing Fake “Kling AI” Malvertising Map, Block, Protect</title><link>https://alpha-cyber.com/graphing-fake-kling-ai-malvertising-map-block-protect/</link><guid isPermaLink="true">https://alpha-cyber.com/graphing-fake-kling-ai-malvertising-map-block-protect/</guid><description>Malvertisements promising AI tools and “instant video/article editing” are a lucrative bait for attackers.</description><pubDate>Sun, 26 Oct 2025 19:21:07 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Graphing Klingon RAT Infrastructure: Defend Against Evolving Threats</title><link>https://alpha-cyber.com/graphing-klingon-rat-infrastructure-defend-against-evolving-threats/</link><guid isPermaLink="true">https://alpha-cyber.com/graphing-klingon-rat-infrastructure-defend-against-evolving-threats/</guid><description>The threat landscape is constantly evolving, and as adversaries grow more sophisticated, defenders must stay one step ahead. One of the more persistent and damaging threats we’ve recently encountered is the Klingon RAT (Remote Access Trojan).</description><pubDate>Sun, 26 Oct 2025 18:35:33 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Graphing FuRootkit Infrastructure Rapid Infra Mapping &amp; IOC Blocklist</title><link>https://alpha-cyber.com/graphing-furootkit-infrastructure-rapid-infra-mapping-ioc-blocklist/</link><guid isPermaLink="true">https://alpha-cyber.com/graphing-furootkit-infrastructure-rapid-infra-mapping-ioc-blocklist/</guid><description>FuRootkit is not a single binary, it’s an infrastructure. Our Graphing FuRootkit Infrastructure service builds an actionable map of how this rootkit’s campaign is assembled (drop points → loaders → kernel hooks → C2/beacons → persistence), so defenders can see choke points, prioritize takedowns, and automate containment without calling out any mapping product names.</description><pubDate>Sun, 26 Oct 2025 18:16:46 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping IndigoDrop Malware &amp; Blocking Critical IOCs</title><link>https://alpha-cyber.com/mapping-indigograph-malware-blocking-critical-iocs/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-indigograph-malware-blocking-critical-iocs/</guid><description>Malicious campaigns like IndigoDrop are no longer single files or lone command-and-control servers. They behave like distributed, evolving infrastructures.</description><pubDate>Sun, 26 Oct 2025 17:59:14 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Unmasking SideWinder: LNK Phishing Attack Mapping for Enhanced Protection</title><link>https://alpha-cyber.com/unmasking-sidewinder-lnk-phishing-attack-mapping-for-enhanced-protection/</link><guid isPermaLink="true">https://alpha-cyber.com/unmasking-sidewinder-lnk-phishing-attack-mapping-for-enhanced-protection/</guid><description>The APT-C-24 (also known as SideWinder) hacker group has been actively employing LNK file phishing techniques in their recent attacks, posing significant risks to organizations worldwide.</description><pubDate>Sat, 18 Oct 2025 18:05:07 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Exposing the Indian SideWinder Hacker Group: Targeting Users with Fake Outlook/Zimbra</title><link>https://alpha-cyber.com/exposing-the-indian-sidewinder-hacker-group-targeting-users-with-fake-outlook-zimbra/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-the-indian-sidewinder-hacker-group-targeting-users-with-fake-outlook-zimbra/</guid><description>Blocking Critical IP and Domain IOCs In the world of cyber threats, attribution is key to understanding and mitigating attacks.</description><pubDate>Sat, 18 Oct 2025 17:41:32 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits</title><link>https://alpha-cyber.com/operation-zero-disco-attackers-exploit-cisco-snmp-vulnerability-to-deploy-rootkits/</link><guid isPermaLink="true">https://alpha-cyber.com/operation-zero-disco-attackers-exploit-cisco-snmp-vulnerability-to-deploy-rootkits/</guid><description>Summary: A targeted campaign dubbed Operation Zero Disco has been observed exploiting a Cisco SNMP vulnerability to gain footholds and deploy rootkits on compromised systems.</description><pubDate>Thu, 16 Oct 2025 13:42:49 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Inside the Indian Hack-for-Hire Scandal: How Appin Exposed Global Cybersecurity Gaps</title><link>https://alpha-cyber.com/inside-the-indian-hack-for-hire-scandal-how-appin-exposed-global-cybersecurity-gaps/</link><guid isPermaLink="true">https://alpha-cyber.com/inside-the-indian-hack-for-hire-scandal-how-appin-exposed-global-cybersecurity-gaps/</guid><description>Cybercrime-as-a-service is no longer science fiction it’s here.</description><pubDate>Thu, 16 Oct 2025 13:35:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mysterious Elephant Moves Beyond Recycled Malware: Infrastructure Mapping of a Harassment-Driven Cyber Campaign</title><link>https://alpha-cyber.com/mysterious-elephant-moves-beyond-recycled-malware-infrastructure-mapping-of-a-harassment-driven-cyber-campaign/</link><guid isPermaLink="true">https://alpha-cyber.com/mysterious-elephant-moves-beyond-recycled-malware-infrastructure-mapping-of-a-harassment-driven-cyber-campaign/</guid><description>Mysterious Elephant, a persistent threat group long associated with espionage operations in South Asia, is showing signs of evolution, moving beyond reusing old malware.</description><pubDate>Thu, 16 Oct 2025 11:00:01 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Stopping the Steal: Mapping Infrastructure Behind Fake Indian Banking Apps on Android</title><link>https://alpha-cyber.com/stopping-the-steal-mapping-infrastructure-behind-fake-indian-banking-apps-on-android/</link><guid isPermaLink="true">https://alpha-cyber.com/stopping-the-steal-mapping-infrastructure-behind-fake-indian-banking-apps-on-android/</guid><description>Fraudsters are luring users with convincing fake banking apps on Google Play and third‑party stores to harvest login credentials, OTPs, and other sensitive data.</description><pubDate>Wed, 15 Oct 2025 09:09:21 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Exposing Alice ATM Stealer: Infrastructure Mapping of a Financial Threat</title><link>https://alpha-cyber.com/exposing-alice-atm-stealer-infrastructure-mapping-of-a-financial-threat/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-alice-atm-stealer-infrastructure-mapping-of-a-financial-threat/</guid><description>Financial institutions remain top targets for cybercriminal groups focused on high-reward operations.</description><pubDate>Mon, 13 Oct 2025 18:51:40 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Exposing the Hidden Network: Mapping APT27’s ZXShell Rootkit Infrastructure</title><link>https://alpha-cyber.com/exposing-the-hidden-network-mapping-apt27s-zxshell-rootkit-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-the-hidden-network-mapping-apt27s-zxshell-rootkit-infrastructure/</guid><description>APT27, also known as Emissary Panda, is a well-documented threat group associated with cyber-espionage campaigns targeting government, defense, technology, and financial institutions worldwide.</description><pubDate>Sun, 12 Oct 2025 11:16:13 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>NoName057(16) Targets NATO Exposing DDosia / Bobik Infrastructure</title><link>https://alpha-cyber.com/noname05716-targets-nato-ddosia-bobik-infrastructure-iocs-to-block/</link><guid isPermaLink="true">https://alpha-cyber.com/noname05716-targets-nato-ddosia-bobik-infrastructure-iocs-to-block/</guid><description>Overview NoName057(16) is a pro‑Russian hacktivist group that has publicly targeted NATO‑aligned entities using the DDosia DDoS toolkit and related tooling (and overlaps observed with Bobik infrastructure).</description><pubDate>Sun, 12 Oct 2025 10:03:46 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Kematian Info Stealer: Infrastructure Map &amp; IOCs to Block</title><link>https://alpha-cyber.com/kematian-info-stealer-infrastructure-map-iocs-to-block/</link><guid isPermaLink="true">https://alpha-cyber.com/kematian-info-stealer-infrastructure-map-iocs-to-block/</guid><description>Overview Kematian is an info‑stealer that targets credentials, cookies, and local artifacts to support espionage and fraud.</description><pubDate>Sun, 12 Oct 2025 08:20:05 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>From IcedID to Dagon Locker in 29 Days Rapid Escalation Infrastructure Map &amp; Technical Deep Dive</title><link>https://alpha-cyber.com/from-icedid-to-dagon-locker-in-29-days-rapid-escalation-infrastructure-map-technical-deep-dive/</link><guid isPermaLink="true">https://alpha-cyber.com/from-icedid-to-dagon-locker-in-29-days-rapid-escalation-infrastructure-map-technical-deep-dive/</guid><description>Overview A rapid intruder progression has been observed in which IcedID initial access and loaders lead, within weeks, to Cobalt Strike activity and final Dagon Locker ransomware deployment.</description><pubDate>Sat, 11 Oct 2025 13:58:00 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Rancor APT: DDKong Plugin “King Kong Ain’t Got Nothin’ on Our Network”</title><link>https://alpha-cyber.com/rancor-ddkong-plugin-king-kong-aint-got-nothin-on-our-network/</link><guid isPermaLink="true">https://alpha-cyber.com/rancor-ddkong-plugin-king-kong-aint-got-nothin-on-our-network/</guid><description>Below is an expanded, technical explanation of how the DDKong plugin campaign operates, what to hunt for in logs and forensic artifacts, and additional detection / mitigation content you can drop directly into tooling.</description><pubDate>Sat, 11 Oct 2025 13:32:59 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Tracking NoName057(16): DDoS &amp; Bobik Stealer Infrastructure</title><link>https://alpha-cyber.com/tracking-noname05716-ddos-bobik-stealer-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/tracking-noname05716-ddos-bobik-stealer-infrastructure/</guid><description>The pro-Russian advanced persistent threat (APT) group NoName057(16) continues to escalate its cyber operations, targeting entities that support Ukraine.</description><pubDate>Sat, 11 Oct 2025 13:17:42 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Exposing BPFDoor Rootkit Mapping a Hidden Infrastructure Threat</title><link>https://alpha-cyber.com/exposing-bpfdoor-rootkit-mapping-a-hidden-infrastructure-threat/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-bpfdoor-rootkit-mapping-a-hidden-infrastructure-threat/</guid><description>In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls.</description><pubDate>Sun, 28 Sep 2025 20:44:38 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Exposing Darkmegi an Infrastructure Map Service to Find and Remove a Kernel Rootkit</title><link>https://alpha-cyber.com/exposing-darkmegi-an-infrastructure-map-service-to-find-and-remove-a-kernel-rootkit/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-darkmegi-an-infrastructure-map-service-to-find-and-remove-a-kernel-rootkit/</guid><description>Malicious kernel‑level malware like Darkmegi is one of the highest‑risk threats an enterprise can face: stealthy persistence, ability to tamper with security controls, and the power to hide lateral movement.</description><pubDate>Sun, 28 Sep 2025 09:53:52 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Stop the Silent Saboteur: Blocking “HTTP‑iframe Injecting” Linux Rootkits</title><link>https://alpha-cyber.com/stop-the-silent-saboteur-blocking-http-iframe-injecting-linux-rootkits/</link><guid isPermaLink="true">https://alpha-cyber.com/stop-the-silent-saboteur-blocking-http-iframe-injecting-linux-rootkits/</guid><description>Malicious rootkits that inject HTTP iframes into web traffic are a stealthy, high-impact threat to Linux servers and the organizations that rely on them.</description><pubDate>Sat, 27 Sep 2025 20:33:19 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>5 Ways to Secure Your Idea Data Online: Protect Your Business’s Most Valuable Asset</title><link>https://alpha-cyber.com/5-ways-to-secure-your-idea-data-online-protect-your-businesss-most-valuable-asset/</link><guid isPermaLink="true">https://alpha-cyber.com/5-ways-to-secure-your-idea-data-online-protect-your-businesss-most-valuable-asset/</guid><description>In today’s rapidly evolving digital landscape, securing your intellectual property (IP) and confidential business data online is more critical than ever.</description><pubDate>Sat, 27 Sep 2025 19:42:06 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Info-Stealing Malware Propagated Through Indian Software Products</title><link>https://alpha-cyber.com/info-stealing-malware-propagated-through-indian-software-products/</link><guid isPermaLink="true">https://alpha-cyber.com/info-stealing-malware-propagated-through-indian-software-products/</guid><description>In today’s digital age, cyber threats are becoming increasingly sophisticated and widespread, leaving organizations vulnerable to serious data breaches.</description><pubDate>Sat, 27 Sep 2025 19:33:29 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Unmasking Rana (APT‑39) Infrastructure Map Centered on the redjewelry.biz Malicious Domain</title><link>https://alpha-cyber.com/title-unmasking-rana-apt-39-infrastructure-map-centered-on-the-redjewelry-biz-malicious-domain/</link><guid isPermaLink="true">https://alpha-cyber.com/title-unmasking-rana-apt-39-infrastructure-map-centered-on-the-redjewelry-biz-malicious-domain/</guid><description>APT‑39, also known as “Chafer” or “Remix Kitten”, is a sophisticated Iranian cyber espionage group primarily associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) and its intelligence agencies.</description><pubDate>Sat, 27 Sep 2025 12:53:21 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping FredMaster (aka Brox) Android Banking Trojan: Infrastructure &amp; Defense</title><link>https://alpha-cyber.com/mapping-fredmaster-aka-brox-android-banking-trojan-infrastructure-defense/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-fredmaster-aka-brox-android-banking-trojan-infrastructure-defense/</guid><description>FredMaster, also tracked as Brox, is a modular Android banking trojan family that harvests credentials and performs fraudulent transactions through overlay attacks, accessibility abuse and SMS interception.</description><pubDate>Sat, 27 Sep 2025 10:45:51 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Defending Against Shrink Locker Ransomware: Infrastructure and IOCs to Block</title><link>https://alpha-cyber.com/defending-against-shrink-locker-ransomware-infrastructure-and-iocs-to-block/</link><guid isPermaLink="true">https://alpha-cyber.com/defending-against-shrink-locker-ransomware-infrastructure-and-iocs-to-block/</guid><description>Ransomware attacks have become one of the most significant cybersecurity threats in recent years, targeting both individuals and organizations across the globe.</description><pubDate>Fri, 26 Sep 2025 12:26:32 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>DeerStealer Rootkit Stealer Campaign: Infrastructure and Defense</title><link>https://alpha-cyber.com/deerstealer-rootkit-stealer-campaign-infrastructure-and-defense/</link><guid isPermaLink="true">https://alpha-cyber.com/deerstealer-rootkit-stealer-campaign-infrastructure-and-defense/</guid><description>In the ever-evolving landscape of cybersecurity threats, one of the most concerning emerging threats is the DeerStealer Rootkit Stealer Campaign.</description><pubDate>Fri, 26 Sep 2025 12:04:51 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping GodRouter Backdoor: Understanding FunnySwitch Backdoor and Defend Against It</title><link>https://alpha-cyber.com/securing-your-infrastructure-against-the-godrouter-backdoor-understanding-funnyswitch-and-how-to-defend-against-it/</link><guid isPermaLink="true">https://alpha-cyber.com/securing-your-infrastructure-against-the-godrouter-backdoor-understanding-funnyswitch-and-how-to-defend-against-it/</guid><description>In the world of cybersecurity, protecting your network and critical infrastructure from advanced persistent threats (APTs) is paramount.</description><pubDate>Wed, 24 Sep 2025 14:05:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping Chinese APT Violin Panda (AKA theb3g) C2 2014year.qpoe.com: Enhancing Your Defense Strategy</title><link>https://alpha-cyber.com/mapping-chinese-apt-violin-panda-aka-theb3g-c2-2014year-qpoe-com-enhancing-your-defense-strategy/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-chinese-apt-violin-panda-aka-theb3g-c2-2014year-qpoe-com-enhancing-your-defense-strategy/</guid><description>In the world of cybersecurity, Advanced Persistent Threats (APT) are some of the most sophisticated and dangerous attacks. One such threat is Violin Panda, a Chinese-based APT group also known as theb3g, which has been linked to various espionage campaigns.</description><pubDate>Tue, 23 Sep 2025 13:10:38 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping Elephant Beetle JSP Shell: Strengthening Your Digital Infrastructure</title><link>https://alpha-cyber.com/mapping-elephant-beetle-jsp-shell-strengthening-your-digital-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-elephant-beetle-jsp-shell-strengthening-your-digital-infrastructure/</guid><description>In the modern cyber threat landscape, attacks are becoming increasingly sophisticated.</description><pubDate>Tue, 23 Sep 2025 12:55:44 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>5 Ways to Improve Your Business Digital Privacy</title><link>https://alpha-cyber.com/5-ways-to-improve-your-business-digital-privacy/</link><guid isPermaLink="true">https://alpha-cyber.com/5-ways-to-improve-your-business-digital-privacy/</guid><description>In today’s fast-paced digital world, protecting your business’s online privacy is no longer optional it’s essential. Cyber threats are becoming more sophisticated, and companies of all sizes are at risk.</description><pubDate>Tue, 23 Sep 2025 10:18:43 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Behind the Trap: Mapping APT TH3BUG’s AKA Violin Panda Watering Hole Campaign with Poison Ivy</title><link>https://alpha-cyber.com/behind-the-trap-mapping-apt-th3bugs-aka-violin-panda-watering-hole-campaign-with-poison-ivy/</link><guid isPermaLink="true">https://alpha-cyber.com/behind-the-trap-mapping-apt-th3bugs-aka-violin-panda-watering-hole-campaign-with-poison-ivy/</guid><description>Advanced Persistent Threat (APT) actors continue to evolve but so do our methods to uncover and counter them.</description><pubDate>Sun, 21 Sep 2025 19:23:51 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Ghost in Action: Unmasking the Specter Botnet Infrastructure</title><link>https://alpha-cyber.com/ghost-in-action-unmasking-the-specter-botnet-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/ghost-in-action-unmasking-the-specter-botnet-infrastructure/</guid><description>As threat actors evolve, so do their methods of staying hidden. Modern botnets no longer rely solely on brute force or noisy traffic they’re stealthy, modular, and highly resilient.</description><pubDate>Sun, 21 Sep 2025 18:53:33 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Meta’s Failure to Protect Children: What You Need to Know About Online Safety</title><link>https://alpha-cyber.com/metas-failure-to-protect-children-what-you-need-to-know-about-online-safety/</link><guid isPermaLink="true">https://alpha-cyber.com/metas-failure-to-protect-children-what-you-need-to-know-about-online-safety/</guid><description>The online world has become a key part of our everyday lives, but for many children, this exposure is fraught with danger.</description><pubDate>Sat, 20 Sep 2025 13:31:38 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>5 Ways to Secure Yourself from BEC Scams</title><link>https://alpha-cyber.com/5-ways-to-secure-yourself-from-bec-scams/</link><guid isPermaLink="true">https://alpha-cyber.com/5-ways-to-secure-yourself-from-bec-scams/</guid><description>Business Email Compromise (BEC) is one of the fastest‑growing cyber threats. Attackers impersonate trusted contacts, manipulate email, and trick organizations into sending money or sensitive data. The financial, reputational, and legal costs can be devastating.</description><pubDate>Sun, 14 Sep 2025 10:18:54 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Exposing Godlike12 Backdoor Using Covert Google Drive C2 Channels</title><link>https://alpha-cyber.com/exposing-godlike12-backdoor-using-covert-google-drive-c2-channels/</link><guid isPermaLink="true">https://alpha-cyber.com/exposing-godlike12-backdoor-using-covert-google-drive-c2-channels/</guid><description>In today’s rapidly evolving threat landscape, adversaries are engineering malware to blend into trusted cloud platforms.</description><pubDate>Sat, 13 Sep 2025 18:47:21 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Graphing Fancy Bear’s Attack on Ubiquiti Routers: Infrastructure Mapping as a Service</title><link>https://alpha-cyber.com/graphing-fancy-bears-attack-on-ubiquiti-routers-infrastructure-mapping-as-a-service/</link><guid isPermaLink="true">https://alpha-cyber.com/graphing-fancy-bears-attack-on-ubiquiti-routers-infrastructure-mapping-as-a-service/</guid><description>In the ever-evolving cyber threat landscape, advanced persistent threats (APTs) continue to grow in complexity and scale.</description><pubDate>Tue, 09 Sep 2025 20:45:04 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping Fancy Bear’s Gamefish Infrastructure</title><link>https://alpha-cyber.com/mapping-fancy-bears-gamefish-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-fancy-bears-gamefish-infrastructure/</guid><description>Unmasking Advanced Threat Operations Behind the Hash: 9b10685b774a783eabfecdb6119a8aa3 In the evolving world of cyber conflict, few adversaries operate with the consistency and sophistication of Fancy Bear (APT28).</description><pubDate>Mon, 08 Sep 2025 17:36:26 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping Shifu Banking Trojan Infrastructure</title><link>https://alpha-cyber.com/mapping-shifu-banking-trojan-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-shifu-banking-trojan-infrastructure/</guid><description>As the cybersecurity landscape evolves, sophisticated banking trojans continue to exploit digital vulnerabilities, putting financial institutions and their clients at constant risk.</description><pubDate>Mon, 08 Sep 2025 17:20:54 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Violet Typhoon’s Warlock Ransomware Campaign: Mapping SharePoint Vulnerability Exploits</title><link>https://alpha-cyber.com/violet-typhoons-warlock-ransomware-campaign-mapping-sharepoint-vulnerability-exploits/</link><guid isPermaLink="true">https://alpha-cyber.com/violet-typhoons-warlock-ransomware-campaign-mapping-sharepoint-vulnerability-exploits/</guid><description>How Enterprise Collaboration Tools Became a Gateway for Advanced Ransomware Campaigns The cyber threat landscape has shifted from opportunistic attacks to highly coordinated, multi-stage operations orchestrated by some of the most advanced adversaries in the world.</description><pubDate>Sat, 06 Sep 2025 12:58:29 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Patchwork Unmasked: Mapping the Espionage Infrastructure Behind chinastrats.com</title><link>https://alpha-cyber.com/patchwork-unmasked-mapping-the-espionage-infrastructure-behind-chinastrats-com/</link><guid isPermaLink="true">https://alpha-cyber.com/patchwork-unmasked-mapping-the-espionage-infrastructure-behind-chinastrats-com/</guid><description>From Governments to Global Industry The Growing Reach of a Persistent Threat Group Cyber-espionage is no longer confined to state secrets.</description><pubDate>Sat, 06 Sep 2025 12:07:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping Dropping Elephant’s AKA ChinastRats AutoIT Malware Campaign Infrastructure</title><link>https://alpha-cyber.com/mapping-dropping-elephants-autoit-malware-campaign-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-dropping-elephants-autoit-malware-campaign-infrastructure/</guid><description>With a Surprising Twist: Shared Infrastructure Linked to GandCrab Ransomware Sophisticated, stealthy, and persistent. These are the hallmarks of the latest campaign attributed to the Dropping Elephant (aka Chinastrats) threat group.</description><pubDate>Fri, 05 Sep 2025 20:27:25 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Graphing Rhadamanthys bonus-mirror.com Phishing Domain: Deep Infrastructure Mapping to Protect Your Organization</title><link>https://alpha-cyber.com/graphing-rhadamanthys-bonus-mirror-com-phishing-domain-deep-infrastructure-mapping-to-protect-your-organization/</link><guid isPermaLink="true">https://alpha-cyber.com/graphing-rhadamanthys-bonus-mirror-com-phishing-domain-deep-infrastructure-mapping-to-protect-your-organization/</guid><description>Phishing attacks continue to be one of the most effective and damaging methods used by cybercriminals to infiltrate organizations worldwide.</description><pubDate>Fri, 05 Sep 2025 19:45:03 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Inside Fancy Bear’s Latest Attack Vector: Outlook-Based Backdoor with DNS &amp; Email Exfiltration</title><link>https://alpha-cyber.com/inside-fancy-bears-latest-attack-vector-outlook-based-backdoor-with-dns-email-exfiltration/</link><guid isPermaLink="true">https://alpha-cyber.com/inside-fancy-bears-latest-attack-vector-outlook-based-backdoor-with-dns-email-exfiltration/</guid><description>In today’s threat landscape, attackers aren’t just breaking down doors they’re walking right through the front, disguised as trusted tools and workflows.</description><pubDate>Fri, 05 Sep 2025 19:21:32 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Dropping Elephant India-Linked Hackers Target Missile Firm in Sophisticated Cyber Espionage</title><link>https://alpha-cyber.com/dropping-elephant-india-linked-hackers-target-missile-firm-in-sophisticated-cyber-espionage/</link><guid isPermaLink="true">https://alpha-cyber.com/dropping-elephant-india-linked-hackers-target-missile-firm-in-sophisticated-cyber-espionage/</guid><description>2025 has seen a dramatic escalation in nation-state cyber threats, with “Dropping Elephant” an India-linked APT group (also known as Patchwork) spearheading a highly targeted campaign against Türkiye’s defense sector.</description><pubDate>Wed, 03 Sep 2025 22:36:44 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Meta’s AI System ‘Cicero’ Learning How to Lie and Deceive Humans</title><link>https://alpha-cyber.com/metas-ai-system-cicero-learning-how-to-lie-and-deceive-humans/</link><guid isPermaLink="true">https://alpha-cyber.com/metas-ai-system-cicero-learning-how-to-lie-and-deceive-humans/</guid><description>When Artificial Intelligence Learns to Deceive, Businesses Need to Rethink Security In a recent development raising both eyebrows and alarms, Meta’s AI system ‘Cicero’, originally built to master negotiation and diplomacy in games like Diplomacy, has demonstrated a chilling new skill: the ability to strategically lie and deceive human players to win.</description><pubDate>Wed, 03 Sep 2025 22:15:33 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Protect Yourself from Rootkit Attacks Hidden in Phishing Emails</title><link>https://alpha-cyber.com/protect-yourself-from-rootkit-attacks-hidden-in-phishing-emails/</link><guid isPermaLink="true">https://alpha-cyber.com/protect-yourself-from-rootkit-attacks-hidden-in-phishing-emails/</guid><description>In today’s digital threat landscape, not all cyberattacks come with flashing red warnings or immediate signs of compromise. One of the most dangerous forms of modern malware operates in the shadows, undetectable, persistent, and devastating.</description><pubDate>Wed, 03 Sep 2025 15:48:00 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Qilin Ransomware’s Evolving Threat: A New Botnet Alliance</title><link>https://alpha-cyber.com/qilin-ransomwares-evolving-threat-a-new-botnet-alliance/</link><guid isPermaLink="true">https://alpha-cyber.com/qilin-ransomwares-evolving-threat-a-new-botnet-alliance/</guid><description>At Alpha Cyber, our threat intelligence division constantly monitors the evolving threat landscape, analyzing attacker behavior, infrastructure, and payload delivery methods.</description><pubDate>Sat, 30 Aug 2025 17:11:22 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Sophisticated Indian Cyber Threats Are Imitating Governments and Militaries Are You Prepared?</title><link>https://alpha-cyber.com/sophisticated-indian-cyber-threats-are-imitating-governments-and-militaries-are-you-prepared/</link><guid isPermaLink="true">https://alpha-cyber.com/sophisticated-indian-cyber-threats-are-imitating-governments-and-militaries-are-you-prepared/</guid><description>How Spoofed Government &amp; Military Interfaces Are Used to Harvest Login Credentials, and How to Shield Against It Recent intelligence has exposed a highly adaptive cyber campaign that targets government and defense institutions by deploying near-authentic fake login portals.</description><pubDate>Mon, 25 Aug 2025 00:28:04 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Five Ways to Secure Yourself from ISP Surveillance</title><link>https://alpha-cyber.com/five-ways-to-secure-yourself-from-isp-surveillance/</link><guid isPermaLink="true">https://alpha-cyber.com/five-ways-to-secure-yourself-from-isp-surveillance/</guid><description>Your Internet Service Provider (ISP) sees more than you think. From the websites you visit to the apps you use, ISPs often log, analyze, and sometimes sell your browsing data, legally.</description><pubDate>Thu, 21 Aug 2025 07:43:48 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>5 Ways to Minimize Your Digital Footprint</title><link>https://alpha-cyber.com/5-ways-to-minimize-your-digital-footprint/</link><guid isPermaLink="true">https://alpha-cyber.com/5-ways-to-minimize-your-digital-footprint/</guid><description>Protect Your Online Presence Before It Becomes a Liability In today’s hyper-connected world, every search, click, download, and login leaves a trail.</description><pubDate>Wed, 20 Aug 2025 14:59:56 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>GodRAT: A Stealthy RAT Targeting Financial Institutions Through Complex Malware Infrastructure</title><link>https://alpha-cyber.com/godrat-a-stealthy-rat-targeting-financial-institutions-through-complex-malware-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/godrat-a-stealthy-rat-targeting-financial-institutions-through-complex-malware-infrastructure/</guid><description>A newly observed Remote Access Trojan (RAT) campaign is targeting financial institutions, using stealth and social engineering to penetrate secure environments.</description><pubDate>Wed, 20 Aug 2025 08:09:00 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>How Attackers Hijack Web Traffic Through System-Level CeidPageLock Rootkits</title><link>https://alpha-cyber.com/how-attackers-hijack-web-traffic-through-system-level-ceidpagelock-rootkits/</link><guid isPermaLink="true">https://alpha-cyber.com/how-attackers-hijack-web-traffic-through-system-level-ceidpagelock-rootkits/</guid><description>CeidPageLock is a stealthy, kernel-level Chinese rootkit primarily distributed through the RIG exploit kit.</description><pubDate>Tue, 19 Aug 2025 12:37:06 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Uncovering the Unseen: Rootkit Infrastructure Mapping and What It Means for Your Business</title><link>https://alpha-cyber.com/uncovering-the-unseen-rootkit-infrastructure-mapping-and-what-it-means-for-your-business/</link><guid isPermaLink="true">https://alpha-cyber.com/uncovering-the-unseen-rootkit-infrastructure-mapping-and-what-it-means-for-your-business/</guid><description>Cyber threats are evolving, and many organizations don’t realize just how far attackers will go to stay hidden.</description><pubDate>Mon, 18 Aug 2025 20:20:06 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Project ‘Ghostbusters’: Facebook’s Secret Surveillance Operation What It Means for Your Business</title><link>https://alpha-cyber.com/project-ghostbusters-facebooks-secret-surveillance-operation-what-it-means-for-your-business/</link><guid isPermaLink="true">https://alpha-cyber.com/project-ghostbusters-facebooks-secret-surveillance-operation-what-it-means-for-your-business/</guid><description>A recent exposé has revealed disturbing details about an internal Facebook program codenamed “Project Ghostbusters.” According to newly surfaced documents, Facebook allegedly used secret methods to spy on data from rival platform Snapchat, exploiting internal systems to track encrypted user activity.</description><pubDate>Sun, 17 Aug 2025 15:43:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Meta Illegally Collected Flo Users’ Menstrual Data: A Wake-Up Call for Businesses on Data Privacy</title><link>https://alpha-cyber.com/meta-illegally-collected-flo-users-menstrual-data-a-wake-up-call-for-businesses-on-data-privacy/</link><guid isPermaLink="true">https://alpha-cyber.com/meta-illegally-collected-flo-users-menstrual-data-a-wake-up-call-for-businesses-on-data-privacy/</guid><description>In today’s data-driven world, the privacy and security of user information have become more than just a technical issue, they’re a matter of public trust, legal compliance, and business survival.</description><pubDate>Sun, 17 Aug 2025 15:34:59 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>5 Facebook Settings to Help Prevent Business Information Leakage</title><link>https://alpha-cyber.com/5-facebook-settings-to-help-prevent-business-information-leakage/</link><guid isPermaLink="true">https://alpha-cyber.com/5-facebook-settings-to-help-prevent-business-information-leakage/</guid><description>In today’s hyperconnected world, social media isn’t just a personal risk, it’s a corporate one.</description><pubDate>Wed, 13 Aug 2025 10:06:54 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Akira Exploits SonicWall SSLVPN Rootkit in Suspected Zero-Day Attacks</title><link>https://alpha-cyber.com/akira-exploits-sonicwall-sslvpn-rootkit-in-suspected-zero-day-attacks/</link><guid isPermaLink="true">https://alpha-cyber.com/akira-exploits-sonicwall-sslvpn-rootkit-in-suspected-zero-day-attacks/</guid><description>How Infrastructure Mapping Can Help Detect and Prevent the Next Breach In the latest wave of targeted ransomware attacks, the Akira ransomware group is now exploiting a previously unknown vulnerability in SonicWall SSLVPN appliances, giving them direct access to corporate networks.</description><pubDate>Mon, 11 Aug 2025 06:14:47 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Facebook’s VPN Deception: How VPN Compromised Millions in the Name of Privacy</title><link>https://alpha-cyber.com/facebooks-vpn-deception-how-vpn-compromised-millions-in-the-name-of-privacy/</link><guid isPermaLink="true">https://alpha-cyber.com/facebooks-vpn-deception-how-vpn-compromised-millions-in-the-name-of-privacy/</guid><description>In an era where privacy is increasingly under threat, the line between protection and surveillance is growing dangerously thin.</description><pubDate>Sat, 09 Aug 2025 16:49:27 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Inside Scranos Mapping a Cross-Platform, Rootkit-Enabled Spyware Operation</title><link>https://alpha-cyber.com/inside-scranos-mapping-a-cross-platform-rootkit-enabled-spyware-operation/</link><guid isPermaLink="true">https://alpha-cyber.com/inside-scranos-mapping-a-cross-platform-rootkit-enabled-spyware-operation/</guid><description>In today’s threat landscape, cybercriminals are no longer relying on single-layer malware. Instead, they’re deploying fully integrated infrastructures to maintain persistence, monetize user data, and avoid detection.</description><pubDate>Wed, 06 Aug 2025 19:41:58 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Coordinated Cyber Strike: Five Families Syndicate Targets Alpha Automation in Brazil</title><link>https://alpha-cyber.com/coordinated-cyber-strike-five-families-syndicate-targets-alpha-automation-in-brazil/</link><guid isPermaLink="true">https://alpha-cyber.com/coordinated-cyber-strike-five-families-syndicate-targets-alpha-automation-in-brazil/</guid><description>A new wave of coordinated cyberattacks has emerged from a threat actor group known as the Five Families Collective, recently targeting Alpha Automation, a leading industrial automation firm in Brazil.</description><pubDate>Mon, 04 Aug 2025 11:41:33 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Signed to Deceive: The Return of FiveSys Rootkits</title><link>https://alpha-cyber.com/signed-to-deceive-the-return-of-fivesys-rootkits/</link><guid isPermaLink="true">https://alpha-cyber.com/signed-to-deceive-the-return-of-fivesys-rootkits/</guid><description>How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits.</description><pubDate>Mon, 04 Aug 2025 11:35:25 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Bobby Trapped Phishing Attacks Hijack Microsoft Teams to Spread Malware Is Your Organization at Risk?</title><link>https://alpha-cyber.com/attackers-use-microsoft-teams-calls-to-deploy-matanbuchus-ransomware/</link><guid isPermaLink="true">https://alpha-cyber.com/attackers-use-microsoft-teams-calls-to-deploy-matanbuchus-ransomware/</guid><description>Cybercriminals are exploiting legitimate collaboration tools in increasingly sophisticated ways.</description><pubDate>Mon, 04 Aug 2025 08:14:05 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>The Next Big Scandal: Meta Can Access Your Private, Unpublished Photos</title><link>https://alpha-cyber.com/the-next-big-scandal-meta-can-access-your-private-unpublished-photos/</link><guid isPermaLink="true">https://alpha-cyber.com/the-next-big-scandal-meta-can-access-your-private-unpublished-photos/</guid><description>Published by Alpha Cyber | Trusted Cybersecurity Services for Data Privacy and Protection What You Don’t Post Can Still Be Seen A growing wave of privacy concerns has resurfaced after leaked documents and whistleblower reports revealed something deeply unsettling: Meta (formerly Facebook) may have access to your private, unpublished photos, even those you never intended to share.</description><pubDate>Sat, 02 Aug 2025 16:58:11 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Remote Administration Tools (RATs): The Hidden Threat Recording Your Screens</title><link>https://alpha-cyber.com/remote-administration-tools-rats-the-hidden-threat-recording-your-screens/</link><guid isPermaLink="true">https://alpha-cyber.com/remote-administration-tools-rats-the-hidden-threat-recording-your-screens/</guid><description>Remote Administration Tools are a category of malware used to gain complete control of a machine. Weaponized RATs are stealthy and capable of watching employees in real time.</description><pubDate>Fri, 01 Aug 2025 19:24:14 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Combatting Insider Threats: Protecting Your Business from Within</title><link>https://alpha-cyber.com/combatting-insider-threats-protecting-your-business-from-within/</link><guid isPermaLink="true">https://alpha-cyber.com/combatting-insider-threats-protecting-your-business-from-within/</guid><description>Published by Alpha Cyber | Cybersecurity Services That Secure What Matters Most The Hidden Danger Inside Your Organization When people think of cybersecurity, they often imagine hackers in dark rooms breaking into systems from afar.</description><pubDate>Thu, 31 Jul 2025 11:58:44 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Facebook Got Caught Phishing for Friend</title><link>https://alpha-cyber.com/facebook-got-caught-phishing-for-friend/</link><guid isPermaLink="true">https://alpha-cyber.com/facebook-got-caught-phishing-for-friend/</guid><description>In the digital age, data is currency, and trust is everything. Yet even global tech giants like Meta have shown that mishandling data can come at a cost.</description><pubDate>Tue, 29 Jul 2025 13:57:29 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Mapping the Invisible Enemy: Sidewinder (APT-04) Indian-Linked Cyber Threat Infrastructure</title><link>https://alpha-cyber.com/mapping-the-invisible-enemy-sidewinder-apt-04-indian-linked-cyber-threat-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-the-invisible-enemy-sidewinder-apt-04-indian-linked-cyber-threat-infrastructure/</guid><description>In the modern threat landscape, advanced persistent threats (APTs) operate like invisible war machines, strategic, highly coordinated, and capable of maintaining long-term access to their targets.</description><pubDate>Tue, 29 Jul 2025 12:13:03 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Mapping “Indian Cyber Force” Infrastructure Using Social Media &amp; OSINT</title><link>https://alpha-cyber.com/mapping-indian-cyber-force-infrastructure-using-social-media-osint/</link><guid isPermaLink="true">https://alpha-cyber.com/mapping-indian-cyber-force-infrastructure-using-social-media-osint/</guid><description>As geopolitical tensions increasingly manifest online, the Indian Cyber Force (ICF), a politically motivated hacktivist group has emerged as a visible threat through waves of DDoS attacks, website defacements, and alleged data leaks.</description><pubDate>Sat, 26 Jul 2025 11:50:40 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Microsoft Identifies China-Backed Nation-State Hackers Targeting SharePoint: Protect Your Infrastructure</title><link>https://alpha-cyber.com/microsoft-identifies-china-backed-nation-state-hackers-targeting-sharepoint-protect-your-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/microsoft-identifies-china-backed-nation-state-hackers-targeting-sharepoint-protect-your-infrastructure/</guid><description>Microsoft recently confirmed that China-backed nation-state hackers, including the notorious group known as Violet Typhoon, are actively targeting Microsoft SharePoint servers worldwide.</description><pubDate>Fri, 25 Jul 2025 19:39:43 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Meta’s Covert Android Tracking What You Need to Know</title><link>https://alpha-cyber.com/metas-covert-android-tracking-what-you-need-to-know/</link><guid isPermaLink="true">https://alpha-cyber.com/metas-covert-android-tracking-what-you-need-to-know/</guid><description>Unsurprising News: Meta Caught Spying on Android Users Again! We’ve heard it before, and it’s happening again.</description><pubDate>Mon, 21 Jul 2025 10:32:38 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>SecondDate_CnC Equation Group God of Espionage Lurks in Your Network</title><link>https://alpha-cyber.com/seconddate_cnc-equation-group-god-of-espionage-lurks-in-your-network/</link><guid isPermaLink="true">https://alpha-cyber.com/seconddate_cnc-equation-group-god-of-espionage-lurks-in-your-network/</guid><description>A highly sophisticated backdoor, SecondDate_CnC, attributed to the elite Equation Group, has resurfaced in targeted infrastructure attacks.</description><pubDate>Mon, 21 Jul 2025 09:53:25 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Threat Spotlight: SonicWall VPNs Compromised by Stealthy Rootkit Backdoor</title><link>https://alpha-cyber.com/threat-spotlight-sonicwall-vpns-compromised-by-stealthy-rootkit-backdoor/</link><guid isPermaLink="true">https://alpha-cyber.com/threat-spotlight-sonicwall-vpns-compromised-by-stealthy-rootkit-backdoor/</guid><description>A sophisticated cyber campaign has been discovered targeting SonicWall VPN appliances, embedding a stealthy rootkit backdoor deep in the system, invisible to standard endpoint protection.</description><pubDate>Mon, 21 Jul 2025 08:22:27 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Chinese Group “Silver Fox” Uses Fake Sites to Deliver Sainbox RAT &amp; Hidden Rootkit</title><link>https://alpha-cyber.com/chinese-group-silver-fox-uses-fake-sites-to-deliver-sainbox-rat-hidden-rootkit/</link><guid isPermaLink="true">https://alpha-cyber.com/chinese-group-silver-fox-uses-fake-sites-to-deliver-sainbox-rat-hidden-rootkit/</guid><description>A sophisticated campaign attributed to the China-affiliated group Silver Fox (aka Void Arachne) is targeting Chinese‑speaking users via spoofed websites mimicking popular apps like WPS Office, Sogou, and DeepSeek.</description><pubDate>Tue, 15 Jul 2025 12:46:06 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Meta’s Privacy Fiasco: A Cautionary Tale for Big Tech</title><link>https://alpha-cyber.com/metas-privacy-fiasco-a-cautionary-tale-for-big-tech/</link><guid isPermaLink="true">https://alpha-cyber.com/metas-privacy-fiasco-a-cautionary-tale-for-big-tech/</guid><description>Meta’s recent privacy scandals have become a stark warning for the entire tech industry.</description><pubDate>Sun, 13 Jul 2025 20:28:38 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Bing AI Claims It Spied on Microsoft Employees Through Their Webcams</title><link>https://alpha-cyber.com/bing-ai-claims-it-spied-on-microsoft-employees-through-their-webcams/</link><guid isPermaLink="true">https://alpha-cyber.com/bing-ai-claims-it-spied-on-microsoft-employees-through-their-webcams/</guid><description>Why AI Security Matters More Than Ever A recent headline sent shockwaves through the tech world: Bing AI reportedly claimed it spied on Microsoft employees through their webcams.</description><pubDate>Sun, 13 Jul 2025 20:16:26 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>GodLoader Malware: How Attackers Exploit the Godot Engine Threat Insights</title><link>https://alpha-cyber.com/godloader-malware-how-attackers-exploit-the-godot-engine-threat-insights/</link><guid isPermaLink="true">https://alpha-cyber.com/godloader-malware-how-attackers-exploit-the-godot-engine-threat-insights/</guid><description>Cybercriminals are exploiting the Godot Engine in a new wave of attacks using the GodLoader malware, infecting over 17,000 systems in just three months.</description><pubDate>Sun, 13 Jul 2025 07:48:35 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Unmasking GodLua: A Glimpse into Malware’s Hidden Infrastructure</title><link>https://alpha-cyber.com/unmasking-godlua-a-glimpse-into-malwares-hidden-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/unmasking-godlua-a-glimpse-into-malwares-hidden-infrastructure/</guid><description>Unveiling the GodLua DNS over HTTPS Malware Infrastructure In today’s rapidly evolving cyber threat landscape, GodLua DNS over HTTPS (DoH) malware stands out as a sophisticated and stealthy adversary.</description><pubDate>Sat, 12 Jul 2025 12:23:45 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Unmasking the “God of Espionage” Bvp47 Backdoor’s Infrastructure Revealed!</title><link>https://alpha-cyber.com/unmasking-the-god-of-espionage-bvp47-backdoors-infrastructure-revealed/</link><guid isPermaLink="true">https://alpha-cyber.com/unmasking-the-god-of-espionage-bvp47-backdoors-infrastructure-revealed/</guid><description>The Bvp47 backdoor, dubbed the “God of Espionage,” is a top-tier Linux malware platform attributed to the Equation Group, with strong ties to the US NSA.</description><pubDate>Wed, 09 Jul 2025 13:12:47 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Bert Ransomware Mapping the 185.100.157.74 Infrastructure</title><link>https://alpha-cyber.com/bert-ransomware-mapping-the-185-100-157-74-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/bert-ransomware-mapping-the-185-100-157-74-infrastructure/</guid><description>A new ransomware threat called Bert is targeting organizations across Asia, Europe, and the US, especially in healthcare, technology, and event services.</description><pubDate>Wed, 09 Jul 2025 07:18:03 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Beyond the Surface: Mapping the Facefish Rootkit’s Digital Footprint</title><link>https://alpha-cyber.com/beyond-the-surface-mapping-the-facefish-rootkits-digital-footprint/</link><guid isPermaLink="true">https://alpha-cyber.com/beyond-the-surface-mapping-the-facefish-rootkits-digital-footprint/</guid><description>In the shadowy world of cyber threats, some malware aims not just to steal data, but to disappear.</description><pubDate>Mon, 07 Jul 2025 22:08:53 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Beyond the Inbox: Mapping SideWinder’s Stealthy C2 Infrastructure</title><link>https://alpha-cyber.com/beyond-the-inbox-mapping-sidewinders-stealthy-c2-infrastructure/</link><guid isPermaLink="true">https://alpha-cyber.com/beyond-the-inbox-mapping-sidewinders-stealthy-c2-infrastructure/</guid><description>The Threat:The Sidewinder APT group, believed to be aligned with Indian interests, is actively targeting government, military, and critical infrastructure across South Asia, including Bangladesh, Pakistan, and Sri Lanka.</description><pubDate>Mon, 07 Jul 2025 16:37:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Sneaky 2FA Phishing: Unmasking the Invisible Threat</title><link>https://alpha-cyber.com/sneaky-2fa-phishing-unmasking-the-invisible-threat/</link><guid isPermaLink="true">https://alpha-cyber.com/sneaky-2fa-phishing-unmasking-the-invisible-threat/</guid><description>Two-Factor Authentication (2FA) is vital, but attackers are bypassing it with 2FA Phishing-as-a-Service (PhaaS). These sophisticated platforms, like “Sneaky 2FA,” act as a “reverse proxy,” intercepting real-time credentials and 2FA codes.</description><pubDate>Mon, 07 Jul 2025 12:28:58 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Privacy Alert: Microsoft May Be Storing Bing Chat &amp; Copilot Conversations</title><link>https://alpha-cyber.com/privacy-alert-microsoft-may-be-storing-bing-chat-copilot-conversations/</link><guid isPermaLink="true">https://alpha-cyber.com/privacy-alert-microsoft-may-be-storing-bing-chat-copilot-conversations/</guid><description>In an increasingly digital world, our online interactions leave a significant footprint.</description><pubDate>Mon, 07 Jul 2025 08:12:18 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Kubernetes Cloud Attacks A Risk Every Organization Should Know</title><link>https://alpha-cyber.com/kubernetes-cloud-attacks-a-risk-every-organization-should-know/</link><guid isPermaLink="true">https://alpha-cyber.com/kubernetes-cloud-attacks-a-risk-every-organization-should-know/</guid><description>🚨 As businesses move to the cloud, more organizations rely on Kubernetes to manage applications and microservices. But along with flexibility and scalability come serious security risks. 🔍 Why is this happening?</description><pubDate>Thu, 03 Jul 2025 07:21:40 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Case Study: Transforming Cybersecurity at Blossom</title><link>https://alpha-cyber.com/case-study-transforming-cybersecurity-at-blossom/</link><guid isPermaLink="true">https://alpha-cyber.com/case-study-transforming-cybersecurity-at-blossom/</guid><description>Client: BlossomIndustry: TechnologyEngagement Period: 2021–2023 Background When Blossom, a fast-growing tech company, recognized the increasing threat landscape, they sought to elevate their cybersecurity posture. The challenge?</description><pubDate>Wed, 02 Jul 2025 16:01:14 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Case Studies</category><author>Alpha Cyber Research</author></item><item><title>Linux Forensic 101</title><link>https://alpha-cyber.com/linux-forensic-101/</link><guid isPermaLink="true">https://alpha-cyber.com/linux-forensic-101/</guid><description>Linux Security Tips: When Expertise Feels Like Driving a Manual GTR Operating a Linux OS as an expert is like driving a brand-new manual Nissan GTR. You control everything.</description><pubDate>Wed, 28 Dec 2022 13:58:06 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Mitigating Data Exfiltration Attacks</title><link>https://alpha-cyber.com/mitigating-data-exfiltration-attacks/</link><guid isPermaLink="true">https://alpha-cyber.com/mitigating-data-exfiltration-attacks/</guid><description>A Comprehensive Guide In today’s digital landscape, data security is paramount. Your data encompasses more than just your name. It reflects your preferences, behaviors, and personal insights.</description><pubDate>Sat, 10 Dec 2022 21:25:10 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Easy Malware Evasion</title><link>https://alpha-cyber.com/easy-malware-evasion/</link><guid isPermaLink="true">https://alpha-cyber.com/easy-malware-evasion/</guid><description>In today’s cybersecurity landscape, traditional malware evasion techniques are no longer enough.</description><pubDate>Fri, 09 Dec 2022 09:44:27 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Browser Security Tutorial</title><link>https://alpha-cyber.com/browser-security-tutorial/</link><guid isPermaLink="true">https://alpha-cyber.com/browser-security-tutorial/</guid><description>When it comes to protecting your digital environment, browser security is one of the simplest, yet most critical, measures you can take.</description><pubDate>Thu, 08 Dec 2022 14:10:33 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Hardening Linux In 10 Steps</title><link>https://alpha-cyber.com/hardening-linux-in-10-steps/</link><guid isPermaLink="true">https://alpha-cyber.com/hardening-linux-in-10-steps/</guid><description>Long live Linux! But for a healthy and secure system, it’s crucial to know how to harden and monitor your Linux servers effectively.</description><pubDate>Tue, 06 Dec 2022 19:45:59 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>New Pacman Attack Targeting Mac Devices</title><link>https://alpha-cyber.com/new-pacman-attack-targeting-mac-devices/</link><guid isPermaLink="true">https://alpha-cyber.com/new-pacman-attack-targeting-mac-devices/</guid><description>Thanks To The Hacker News For This Article A novel hardware attack dubbed PACMAN has been demonstrated against Apple’s M1 processor chipsets, potentially arming a malicious actor with the capability to gain arbitrary code execution on macOS systems.</description><pubDate>Sat, 11 Jun 2022 17:08:40 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Russian Hackers Are On The Rise !</title><link>https://alpha-cyber.com/russian-apt-attack-are-on-the-rise/</link><guid isPermaLink="true">https://alpha-cyber.com/russian-apt-attack-are-on-the-rise/</guid><description>As the war in Ukraine enters its fourth month, the battlefield has expanded beyond conventional warfare into cyberspace.</description><pubDate>Sun, 05 Jun 2022 20:32:36 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>AWS S3 Security Tutorial</title><link>https://alpha-cyber.com/aws-s3-security-tutorial/</link><guid isPermaLink="true">https://alpha-cyber.com/aws-s3-security-tutorial/</guid><description>Amazon Web Services (AWS) is the world’s leading cloud platform, offering businesses access to the same powerful infrastructure Amazon uses to run its global operations.</description><pubDate>Fri, 03 Jun 2022 15:10:47 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Cell Phone Privacy In The 21 Century</title><link>https://alpha-cyber.com/cell-phone-privacy-in-the-21-century/</link><guid isPermaLink="true">https://alpha-cyber.com/cell-phone-privacy-in-the-21-century/</guid><description>Thanks To Defender Shield For This Great Article. Solidifying your cell phone privacy is a crucial part of keeping your personal information safe and protected.</description><pubDate>Fri, 03 Jun 2022 13:56:20 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>How To Detect Hidden Cameras</title><link>https://alpha-cyber.com/how-to-detect-hidden-cameras/</link><guid isPermaLink="true">https://alpha-cyber.com/how-to-detect-hidden-cameras/</guid><description>What are the ways to detect hidden spy secret cameras in your apartment, house, or hotel room? How to find hidden security cameras behind mirrors?</description><pubDate>Mon, 30 May 2022 17:09:51 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>NVIDIA Fixes Ten Vulnerabilities In Windows GPU Display Drivers</title><link>https://alpha-cyber.com/nvidia-fixes-ten-vulnerabilities-in-windows-gpu-display-drivers/</link><guid isPermaLink="true">https://alpha-cyber.com/nvidia-fixes-ten-vulnerabilities-in-windows-gpu-display-drivers/</guid><description>NVIDIA has released a security update for a wide range of graphics card models, addressing four high-severity and six medium-severity vulnerabilities in its GPU drivers.</description><pubDate>Wed, 18 May 2022 12:54:07 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>HTML attachments remain popular among phishing actors in 2022</title><link>https://alpha-cyber.com/html-attachments-remain-popular-among-phishing-actors-in-2022/</link><guid isPermaLink="true">https://alpha-cyber.com/html-attachments-remain-popular-among-phishing-actors-in-2022/</guid><description>HTML files remain one of the most popular attachments used in phishing attacks for the first four months of 2022, showing that the technique remains effective against antispam engines and works well on the victims themselves.</description><pubDate>Wed, 18 May 2022 09:36:24 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Experts Sound Alarm on DCRat Backdoor Being Sold on Russian Hacking Forums</title><link>https://alpha-cyber.com/experts-sound-alarm-on-dcrat-backdoor-being-sold-on-russian-hacking-forums-2/</link><guid isPermaLink="true">https://alpha-cyber.com/experts-sound-alarm-on-dcrat-backdoor-being-sold-on-russian-hacking-forums-2/</guid><description>Cybersecurity researchers have shed light on an actively maintained remote access trojan called DCRat (aka DarkCrystal RAT) that’s offered on sale for “dirt cheap” prices, making it accessible to professional cybercriminal groups and novice actors alike.</description><pubDate>Mon, 16 May 2022 17:20:37 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Hackers Can Now Run Malware On Your Phone When Its Off</title><link>https://alpha-cyber.com/hackers-can-now-run-malware-on-your-phone-when-its-off-2/</link><guid isPermaLink="true">https://alpha-cyber.com/hackers-can-now-run-malware-on-your-phone-when-its-off-2/</guid><description>Thanks To The Hacker News For This Great Article A first-of-its-kind security analysis of iOS Find My function has identified a novel attack surface that makes it possible to tamper with the firmware and load malware onto a Bluetooth chip that’s executed…</description><pubDate>Mon, 16 May 2022 17:10:47 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>News</category><author>Alpha Cyber Research</author></item><item><title>Hardening Windows Server</title><link>https://alpha-cyber.com/hardening-windows-server-machine/</link><guid isPermaLink="true">https://alpha-cyber.com/hardening-windows-server-machine/</guid><description>Windows servers are often responsible for critical infrastructure and sensitive data.</description><pubDate>Thu, 05 May 2022 20:32:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Connecting Securely To Tor Network</title><link>https://alpha-cyber.com/connecting-securely-to-tor-network/</link><guid isPermaLink="true">https://alpha-cyber.com/connecting-securely-to-tor-network/</guid><description>The internet is a powerful tool, but privacy isn’t something you should take for granted. The Tor network is one of the best ways to browse anonymously, masking your identity and location online.</description><pubDate>Mon, 02 May 2022 20:24:10 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>10 Hardening Configuration Any Linux System Should Have</title><link>https://alpha-cyber.com/10-hardening-configuration-any-linux-system-should-have/</link><guid isPermaLink="true">https://alpha-cyber.com/10-hardening-configuration-any-linux-system-should-have/</guid><description>If you’re a Linux user, you likely appreciate its performance, efficiency, and built-in security. But no system is invulnerable, and adding extra layers of protection is always a smart move.</description><pubDate>Sat, 30 Apr 2022 15:50:27 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Praying Mantis APT Hackers Group Using ASP.NET Exploits To Attack Windows IIS</title><link>https://alpha-cyber.com/praying-mantis-apt-hackers-group-using-asp-net-exploits-to-attack-windows-iis/</link><guid isPermaLink="true">https://alpha-cyber.com/praying-mantis-apt-hackers-group-using-asp-net-exploits-to-attack-windows-iis/</guid><description>Thanks to cybersecuritynews for this great article Sygnia Incident Response Team found an advanced and persistent threat actor named “Praying Mantis” or “TG2021”, operating completely in memory.</description><pubDate>Thu, 28 Apr 2022 13:28:26 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>North Korean Hackers Targeting Journalists With Novel Malware</title><link>https://alpha-cyber.com/north-korean-hackers-targeting-journalists-with-novel-malware/</link><guid isPermaLink="true">https://alpha-cyber.com/north-korean-hackers-targeting-journalists-with-novel-malware/</guid><description>North Korean state-sponsored hackers known as APT37 have been discovered targeting journalists specializing in the DPRK with a novel malware strain.</description><pubDate>Tue, 26 Apr 2022 06:25:26 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>NTLM Relay With Inveigh</title><link>https://alpha-cyber.com/ntlm-relay-with-inveigh/</link><guid isPermaLink="true">https://alpha-cyber.com/ntlm-relay-with-inveigh/</guid><description>With Inveigh, an attacker can perform NTLM relay attacks, enabling them to intercept and relay NTLM authentication hashes within a target network.What is NTLM?</description><pubDate>Mon, 18 Apr 2022 14:00:06 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Extracting Password From DPAPI With Mimikatz</title><link>https://alpha-cyber.com/extracting-password-from-dpapi-with-mimikatz/</link><guid isPermaLink="true">https://alpha-cyber.com/extracting-password-from-dpapi-with-mimikatz/</guid><description>DPAPI (Data Protection API) is a native Windows encryption mechanism designed to securely protect sensitive data such as saved credentials, browser secrets and certificates.</description><pubDate>Mon, 18 Apr 2022 11:43:58 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Kerberos Authentication</title><link>https://alpha-cyber.com/kerberos-authentication/</link><guid isPermaLink="true">https://alpha-cyber.com/kerberos-authentication/</guid><description>Explained Kerberos is a powerful authentication protocol designed to securely verify users and services over insecure networks, commonly used in Active Directory environments, POSIX authentication, NFS, and Samba.</description><pubDate>Mon, 18 Apr 2022 02:08:37 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>DCSync Attack With Mimikatz</title><link>https://alpha-cyber.com/dcsync-attack-with-mimikatz/</link><guid isPermaLink="true">https://alpha-cyber.com/dcsync-attack-with-mimikatz/</guid><description>In the complex landscape of Active Directory security, understanding the tactics adversaries employ is paramount.</description><pubDate>Sun, 17 Apr 2022 22:45:17 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Kerberos Golden Tickets</title><link>https://alpha-cyber.com/kerberos-golden-tickets/</link><guid isPermaLink="true">https://alpha-cyber.com/kerberos-golden-tickets/</guid><description>A golden ticket in Active Directory grants the bearer unlimited access. An attacker holding one can reach any service, for an unlimited time.</description><pubDate>Sat, 16 Apr 2022 19:06:51 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Pass The Hash Attack With Mimikatz</title><link>https://alpha-cyber.com/pass-the-hash-attack-with-mimikatz/</link><guid isPermaLink="true">https://alpha-cyber.com/pass-the-hash-attack-with-mimikatz/</guid><description>Pass the Hash attack is when the attacker can authenticate without clear text password. similiar to pass the ticket but in pass the hash attack our access is not limited to 10 hours.</description><pubDate>Wed, 13 Apr 2022 12:24:43 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Abusing Sudo</title><link>https://alpha-cyber.com/abusing-sudo/</link><guid isPermaLink="true">https://alpha-cyber.com/abusing-sudo/</guid><description>In Linux systems, the /etc/sudoers file dictates user privileges, specifying which users can execute commands with elevated (root) permissions.</description><pubDate>Mon, 11 Apr 2022 18:32:12 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>DanderSpritz Framework Is Causing Problems</title><link>https://alpha-cyber.com/danderspritz-framework-is-causing-problems/</link><guid isPermaLink="true">https://alpha-cyber.com/danderspritz-framework-is-causing-problems/</guid><description>In April 2017, the hacking collective known as the Shadow Brokers leaked a sophisticated malware framework attributed to the NSA’s Equation Group.</description><pubDate>Sun, 10 Apr 2022 11:43:37 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Threat Reports</category><author>Alpha Cyber Research</author></item><item><title>Blue Screen of Death With Mimikatz</title><link>https://alpha-cyber.com/blue-screen-of-death-with-mimikatz/</link><guid isPermaLink="true">https://alpha-cyber.com/blue-screen-of-death-with-mimikatz/</guid><description>Mimikatz is a post exploitation tools used for clear text dumping credentials and many else Dumping credentials with mimiktatz 1.first this first clone the script with git clone https://github.com/ParrotSec/mimikatz 2.run mimikatz.exe in X64 directory…</description><pubDate>Tue, 22 Feb 2022 20:08:01 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Secure and encrypt C2 setup with redirectors</title><link>https://alpha-cyber.com/secure-and-encrypt-c2-setup-with-redirectors/</link><guid isPermaLink="true">https://alpha-cyber.com/secure-and-encrypt-c2-setup-with-redirectors/</guid><description>This post will teach you how to setup a simple red team c2 infrastructure with encrypted socat HTTPS redirectors Requirements: Attacker C2 Server: Kali with metasploit Redirector Server: Ubuntu with socat Victim Machine: Windows10 1.First open metasploit with…</description><pubDate>Sat, 12 Feb 2022 18:40:40 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item><item><title>Dumping Credentials With Evil Mimikatz</title><link>https://alpha-cyber.com/dumping-credentials-with-evil-mimikatz/</link><guid isPermaLink="true">https://alpha-cyber.com/dumping-credentials-with-evil-mimikatz/</guid><description>Mimikatz is a post exploitation tools used for clear text dumping credentials and many else Dumping credentials with mimiktatz 1.first this first clone the script with git clone https://github.com/ParrotSec/mimikatz 2.run mimikatz.exe in X64 directory…</description><pubDate>Sun, 05 Dec 2021 16:14:39 GMT</pubDate><dc:creator>Alpha Cyber Research</dc:creator><dc:subject>TLP:CLEAR</dc:subject><category>Blog</category><author>Alpha Cyber Research</author></item></channel></rss>