CuraSec

tag: Backdoor · 6 items

2026-08-28 · The Hacker News · source ↗ #apt28#backdoor#espionage
  • Engineer — Skip
  • SOC/IR — Act: APT28-linked HOOKEDGE is a new Windows batch-script backdoor actively used against government and diplomatic targets in Europe; hunt for suspicious batch-script persistence mechanisms and lateral movement patterns consistent with APT28 TTPs (ATT&CK: T1059.003) in Windows endpoint telemetry since September 2025.
  • Leader — Learn: APT28 has deployed a novel backdoor against European government and diplomatic organizations — relevant for sector-risk awareness and to brief leadership if your organization has European government ties or similar exposure profile.
2026-08-26 · The Hacker News · source ↗ #windows-malware#dll-sideloading#backdoor
  • Engineer — Learn: Novel DLL side-loading backdoor with a magic-packet trigger and custom bytecode interpreter — no KEV, PoC, or active exploitation reported. Worth understanding the side-loading pattern to evaluate unsigned DLL monitoring and application allowlisting posture, but no immediate patch or config change is required.
  • SOC/IR — Learn: The dormant-until-triggered approach and custom bytecode execution are evasion techniques worth noting for future DLL side-loading hunt logic, but no IOCs, campaign attribution, or active exploitation are documented in this single-researcher report — nothing actionable to hunt or tune against today.
  • Leader — Skip
2026-08-25 · The Hacker News · source ↗ #cyber-espionage#apt#backdoor
  • Engineer — Learn: The use of QUIC as a C2 transport is a design consideration for network detection architecture — traditional TLS inspection won’t catch it. No patch or configuration change required; assess whether your network egress controls can flag unexpected QUIC traffic.
  • SOC/IR — Learn: QUIC-tunneled C2 (QUICAgent) is an evasion technique worth adding to detection gap reviews; however, no IOCs or ATT&CK mappings are provided in this report, and targeting is narrowly confined to Myanmar government/IT — no immediate hunt warranted for a typical enterprise estate.
  • Leader — Skip
2026-08-09 · BleepingComputer · source ↗ #supply-chain#backdoor#video-conferencing
  • Engineer — Plan: TrueConf is niche in US/global enterprise (primarily Russia/CIS), but if deployed, verify installer hashes against known-good versions and audit endpoints for signs of backdoor execution before using any previously downloaded client packages.
  • SOC/IR — Learn: Head Mare’s installer-replacement supply chain tactic is worth cataloguing for actor awareness, but no IOCs or ATT&CK-mapped behaviors are published yet, leaving no immediate hunt to run.
  • Leader — Learn: This breach illustrates supply chain risk via trojanized software distribution; TrueConf is unlikely to be in most enterprise stacks, but the pattern reinforces vendor software-integrity questions in any video conferencing procurement review.
2026-08-05 · The Hacker News · source ↗ #supply-chain#backdoor#vpn
  • Engineer — Skip
  • SOC/IR — Learn: The trojanized-installer supply chain vector delivering a custom backdoor (FDMTP) is worth tracking as a technique, but the summary provides no IOCs and the target population is narrow, so no hunt or detection work is actionable yet.
  • Leader — Skip
2026-07-28 · The Hacker News · source ↗ #apt#backdoor#iranian-threat-actor
  • Engineer — Learn: NightLedger is a novel Windows backdoor with WebSocket tunneling capability; no KEV listing or PoC signals exploitation of specific software you’d patch, but understanding the relay technique informs network egress controls and endpoint detection posture.
  • SOC/IR — Plan: Build detections for anomalous WebSocket tunneling behavior from Windows hosts and hunt for NightLedger IOCs once Recorded Future or similar publishes indicators; ATT&CK mapping to C2-over-WebSocket and proxy relay techniques warrants a new detection rule this quarter.
  • Leader — Learn: Nimbus Manticore campaign context is useful for sector risk briefings if your organization has exposure in Middle East, Africa, or South Asia operations, but no immediate board-level action required without confirmed targeting of your industry.