Alpha Cyber

Resources

Threat Reports

Adversary infrastructure, malware teardowns and copy-ready IOCs.

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT
SprySocks Rootkit
Threat ReportsTLP:AMBER

SprySOCKS for Windows: FishMonger’s Linux Backdoor Grows a Kernel Rootkit

China-aligned FishMonger (Earth Lusca) has ported its SprySOCKS backdoor to Windows and bolted on a kernel driver, RawWNPF, that hides processes, files, connections and registry keys, and turns any open TCP port into a hidden door and erases itself from every tool you’d use to find it.

6 min readAPT
PamDOORa SSH Backdoor
Threat ReportsTLP:AMBER

PamDOORa: A Linux PAM Backdoor Built to Steal SSH Credentials

A new post-exploitation implant abuses the Linux authentication stack (PAM) to harvest plaintext SSH credentials from every user who logs in, and hands the operator a covert, persistent backdoor.

3 min readLinux Backdoor
Trash Panda Stealer
Threat Reports

Trash Panda as a Service: Raccoon Stealer Steals Cookies, Crypto, and More

Threat AdvisoryTLP:CLEAR Threat ReportsInfostealer Trash Panda as a Service: Raccoon Stealer Steals Cookies, Crypto, and More A $75-a-week stealer-as-a-service that harvests browser passwords, cookies and autofill, hijacks crypto transactions with a bundled…

4 min readInfostealer
Vect 2.0 Ransomware Bugs & Betrayal
Threat ReportsTLP:AMBER

Bugs & Betrayal: VECT Ransomware by Design, Wiper by Accident

Threat AdvisoryTLP:AMBER RansomwareMalware Bugs & Betrayal: VECT Ransomware by Design, Wiper by Accident Analysis of the VECT ransomware family suggests implementation flaws can undermine the operator’s own monetization objectives.

2 min readRansomware · Malware
FIN7 Infrastructure Breakdown
Threat Reports

Tracking FIN7: Hidden Infrastructure Behind Global Intrusions

Threat Hunt Intelligence FIN7 Infrastructure Hunt, 26 Attributed Hosts C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced Hunt #45Scope C2 Panel · Malware · LoaderAttributed 26Ambient 48Generated 2026-07-07 19:08 UTC This report…

7 min readExposing the Invisible
Indian Cyber Force Escalation
Threat ReportsTLP:AMBER

Indian Cyber Force Targets Government Sites Amid Diplomatic Flashpoint

Threat AdvisoryTLP:AMBER HacktivismGov Web Disruption Indian Cyber Force Targets Government Sites Amid Diplomatic Flashpoint A recurring pattern of opportunistic hacktivism and low-sophistication distributed attacks has been observed against public-sector web…

2 min readHacktivism · Gov Web Disruption
Arch Linux Rootkit
Threat Reports

Mass Arch Linux Package Compromise Pushes Rootkit-Like Malware at Scale

Threat AdvisoryTLP:CLEAR Supply ChainLinux Security 400+ Arch Linux Packages Hijacked to Install Rootkit-Like Malware A large-scale compromise impacting hundreds of Arch Linux packages demonstrates how software supply-chain attacks can transform trusted…

2 min readSupply Chain · Linux Security
Ghost in the Shell QLNX Rootkit
Threat ReportsTLP:AMBER

Ghost in the Shell: Unmasking the QLNX Rootkit

QLNX is an advanced Linux rootkit engineered for kernel-level stealth, privilege concealment and long-term covert access – hiding processes, tampering with telemetry, and evading detection across servers, cloud workloads and internet-facing systems.

2 min readRootkit · Linux
Sandworm Tor Persistent
Threat ReportsTLP:AMBER

Deep Persistence: How Sandworm Weaponizes Tor for Long-Term Stealth

Sandworm Uses SSH-over-Tor Tunnels for Stealthy Long-Term Persistence Sandworm – the Russian state-sponsored actor linked to GRU Unit 74455 – leveraged SSH-over-Tor tunneling to establish covert, resilient, long-term access inside compromised environments…

2 min readAPT · Persistence
Turla Kazuar Backdoor
Threat ReportsTLP:AMBER

Kazuar Unmasked: Inside Turla’s Persistent Cyber-Espionage Machine

Kazuar Backdoor: Inside Turla’s .NET Espionage Implant Indicators and behavioral telemetry align with Kazuar – a sophisticated espionage backdoor associated with Turla, the Russian state-sponsored APT known for stealth operations against government…

2 min readAPT · Backdoor
Abyss Rootkit Analysis
Threat ReportsTLP:AMBER

Abyss Rootkit Analysis: Unmasking Deep-System Threats

ABYSSWORKER: The EDR-Killer Driver Behind MEDUSA Ransomware ABYSSWORKER is a malicious signed Windows kernel driver used in the MEDUSA ransomware attack chain to blind and disable endpoint detection and response tools – masquerading as a CrowdStrike Falcon…

4 min readEDR Killer · Ransomware
Hunting Orbit Rootkit
Threat ReportsTLP:AMBER

Hunting Orbit Rootkit Part Open-Source Medusa Ransomware – IOC Deep Dive

OrBit: The Linux Rootkit That Hijacks the Dynamic Linker OrBit is a stealthy Linux userland rootkit that abuses the dynamic linker (ld.so) to load itself into every new process – hooking dozens of libc functions to hide files, processes and network sockets from standard tooling on the host.

3 min readRootkit · Linux
Operation NoVoice Rootkit
Threat ReportsTLP:AMBER

Operation NoVoice: Silent Persistence and the Rootkit Lifecycle

Operation NoVoice: The Android Rootkit That Survives a Factory Reset NoVoice is a mobile-espionage campaign that hid in 50+ Google Play apps (2.3M+ downloads), chained 22 legacy Android exploits to gain root, and planted a Zygote-level rootkit that hooks the…

4 min readRootkit · Android
Latest Qilin Ransomware IOC Analysis
Threat ReportsTLP:AMBER

Latest Qilin Ransomware IOCs Analysis Emerging Threat Indicators

Profile of 2025’s Most Active Extortion Operation Qilin (formerly Agenda) is a Rust-based ransomware-as-a-service operation that became the most active extortion brand of 2025 – absorbing displaced affiliates after RansomHub’s collapse, running double…

4 min readRansomware · Qilin
RegPhantom Rootkit
Threat ReportsTLP:AMBER

RegPhantom Rootkit: Persistence Mechanisms and Mitigation

RegPhantom Watch: A Suspicious Hash With Agreement SHA-256 703dfb12…e7c4 draws consensus from two trusted reputation feeds and possible RegPhantom rootkit ties, but no behavioural detonation confirms intent.

2 min readMalware
VGOD Ransomware
Threat ReportsTLP:AMBER

VGOD Ransomware Exposed: Actionable IOCs for Rapid Defense

VGOD Ransomware: Anatomy of a Backup-Killing Windows Extortion Strain VGOD is a Windows ransomware first seen in February 2025 that encrypts files, deletes Volume Shadow Copies to block recovery, and runs double extortion behind a ‘Decryption…

4 min readRansomware
Dynowiper Sandworm
Threat ReportsTLP:AMBER

Dynowiper Exposed: Forensic Analysis of a Sandworm Cyberweapon

DYNOWIPER: Anatomy of the Wiper That Struck Poland’s Energy Grid The ‘critical, unattributed PE’ from automated triage is DYNOWIPER, a deliberately simple data-destruction wiper used on 29 December 2025 against 30+ Polish renewable sites and a major CHP…

4 min readWiper
Luca Stealer Cover Photo New
Threat ReportsTLP:AMBER

Inside Luca Stealer: A Technical Decomposition of the Rust-Based Malware

Beyond the Binary: How Luca Stealer Uses the Rust Runtime to Slip Past Detection A 4.6 MB Rust PE scored 100/100 with heavy anti-analysis and a Telegram exfiltration channel, behaviour that lines up with Luca Stealer, the leaked Rust infostealer.

5 min readMalware
KlingPremium-xyz cover photo new
Threat ReportsTLP:AMBER

What is Klingpremium.xyz? Malware Analysis and Mitigation Guide

Under the Hood of klingpremium.xyz: an Obfuscated Batch Loader Your ML Model Rated 0% Malicious A 314 KB Windows .bat flagged critical (90/100) is a multi-stage loader that geofences, then uses PowerShell to pull a next-stage payload from klingpremium.xyz and…

4 min readMalware
Indeanapolice.cc Cover Photo
Threat ReportsTLP:AMBER

What is Indeanapolice.cc? Malware Analysis and Removal Guide

Blocking the Breach: Inside the indeanapolice.cc PowerShell Dropper A tiny, heavily obfuscated PowerShell script flagged in triage turns out to be the download-cradle stage of the indeanapolice.cc dropper, a recently-registered, low-reputation campaign that…

4 min readMalware
FredyStealer Cover Photo
Threat Reports

Is Your Data Safe? The Rising Threat of FredyStealer Malware

Malware Analysis Report FredyStealer: The Silent Thief in Your System Published March 26, 2026 · Threat Intelligence Team · A critical-severity script sample was processed by the malware analysis suite.

3 min read
BiBi Wiper Arid Viper Cover Photo
Threat ReportsTLP:AMBER

Wiped Out: Unmasking the Arid Viper Tactics Behind BiBi Malware

BiBi Wiper: What the Malware Really Does, and Why This Sample Does Not Confirm It BiBi is a destructive wiper used against Israeli organisations in 2023 that shreds files and appends a .BiBi extension.

5 min readMalware
GodRat PIC
Threat Reports

Busting GodRat: Analyzing the Rat and Its Infrastructure

Cracking the GodRat Campaign: Unmasking Its Infrastructure & How to Block It The GodRat Trojan is believed to be operated by the Chinese threat group Winnti (APT41), known for targeting financial institutions, including trading and brokerage firms.

4 min read
Klingon Rat
Threat Reports

Graphing Klingon RAT Infrastructure: Defend Against Evolving Threats

The threat landscape is constantly evolving, and as adversaries grow more sophisticated, defenders must stay one step ahead. One of the more persistent and damaging threats we’ve recently encountered is the Klingon RAT (Remote Access Trojan).

3 min read
Fu-rootkit-hide-process
Threat Reports

Graphing FuRootkit Infrastructure Rapid Infra Mapping & IOC Blocklist

FuRootkit is not a single binary, it’s an infrastructure. Our Graphing FuRootkit Infrastructure service builds an actionable map of how this rootkit’s campaign is assembled (drop points → loaders → kernel hooks → C2/beacons → persistence), so defenders can see choke points, prioritize takedowns, and automate containment without calling out any mapping product names.

3 min read
BPFDoor Rootkit
Threat Reports

Exposing BPFDoor Rootkit Mapping a Hidden Infrastructure Threat

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls.

4 min read
FancyBear
Threat Reports

Mapping Fancy Bear’s Gamefish Infrastructure

Unmasking Advanced Threat Operations Behind the Hash: 9b10685b774a783eabfecdb6119a8aa3 In the evolving world of cyber conflict, few adversaries operate with the consistency and sophistication of Fancy Bear (APT28).

2 min read
Shifu Banking Trojan
Threat Reports

Mapping Shifu Banking Trojan Infrastructure

As the cybersecurity landscape evolves, sophisticated banking trojans continue to exploit digital vulnerabilities, putting financial institutions and their clients at constant risk.

2 min read
Akira Rootkit Graph
Threat Reports

Akira Exploits SonicWall SSLVPN Rootkit in Suspected Zero-Day Attacks

How Infrastructure Mapping Can Help Detect and Prevent the Next Breach In the latest wave of targeted ransomware attacks, the Akira ransomware group is now exploiting a previously unknown vulnerability in SonicWall SSLVPN appliances, giving them direct access to corporate networks.

2 min read
FiveSys Rootkit
Threat Reports

Signed to Deceive: The Return of FiveSys Rootkits

How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits.

1 min read
Sneaky 2FA Phishing: Unmasking the Invisible Threat
Threat Reports

Sneaky 2FA Phishing: Unmasking the Invisible Threat

Two-Factor Authentication (2FA) is vital, but attackers are bypassing it with 2FA Phishing-as-a-Service (PhaaS). These sophisticated platforms, like “Sneaky 2FA,” act as a “reverse proxy,” intercepting real-time credentials and 2FA codes.

1 min read
Threat Reports

Experts Sound Alarm on DCRat Backdoor Being Sold on Russian Hacking Forums

Cybersecurity researchers have shed light on an actively maintained remote access trojan called DCRat (aka DarkCrystal RAT) that’s offered on sale for “dirt cheap” prices, making it accessible to professional cybercriminal groups and novice actors alike.

2 min read
Threat Reports

DanderSpritz Framework Is Causing Problems

In April 2017, the hacking collective known as the Shadow Brokers leaked a sophisticated malware framework attributed to the NSA’s Equation Group.

2 min read

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]