TWINLOOT: When Microsoft Cloud Becomes a Hacker's "Control Center"Imagine a nightmare scenario for every SOC team: An attacker lies deep inside the internal network for weeks, silently opening up to 128 administrative connection streams (SMB, RDP, WinRM) to move latAug 31, 2026·11 min read
Fake Microsoft "SysScan": Bogus Security Scanner Invents Problems, Tricks Victims Into Uninstalling Their Antivirus, Then Funnels Them Into a Refund ScamAug 25, 2026·17 min read
SysScan Giả Mạo Microsoft: Máy Quét Bảo Mật "Phát Hiện" Lỗi Ảo, Dụ Nạn Nhân Gỡ Antivirus Rồi Dẫn Vào Bẫy Lừa Đảo Hoàn TiềnAug 25, 2026·24 min read
UAT-10147: Cybercrime Group Uses Agentic AI to Scale Server Attacks, Deploys SPECTRE Backdoor With Linux Rootkit and Vulnerable-Driver EDR BypassOverview On August 20, 2026, Cisco Talos published a two-part report on UAT-10147 — a financially motivated, Chinese-speaking cybercrime group targeting Windows and Linux web servers globally. VictimsAug 25, 2026·30 min read
UAT-10147: Nhóm tội phạm mạng dùng AI Agentic mở rộng quy mô tấn công máy chủ, triển khai backdoor SPECTRE với rootkit Linux và kỹ thuật qua mặt EDR bằng driver độc hạiTổng Quan Ngày 20/08/2026, Cisco Talos công bố báo cáo hai phần về UAT-10147 — một nhóm tội phạm mạng, có động cơ tài chính, đang nhắm vào máy chủ web Windows và Linux trên phạm vi toàn cầu. Nạn nhân Aug 25, 2026·38 min read
HoneyMyte Takes CoolClient Into the Kernel: When a Rootkit Changes What Windows Lets You SeeSummary CoolClient was already a fully capable espionage backdoor: keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and a plugin-based extension architectureAug 25, 2026·22 min read
HoneyMyte đưa CoolClient xuống kernel: khi rootkit thay đổi thứ Windows cho phép bạn nhìn thấyTóm tắt CoolClient vốn đã là một backdoor gián điệp đầy đủ chức năng: keylogging, đánh cắp clipboard, thu thập thông tin xác thực, quản lý file, trinh sát hệ thống, và kiến trúc mở rộng bằng plugin. BAug 25, 2026·27 min read
Evooo1Bot: When an Infected Router Stops Being Disposable Ammunition and Becomes Rentable InfrastructureSummary Evooo1Bot reuses the DDoS engine from the publicly leaked Mirai source code verbatim. That part is nothing new after ten years. What is new is everything bolted onto it: encrypted C2 communicaAug 25, 2026·21 min read
Evooo1Bot: khi router bị nhiễm không còn là đạn dùng một lần mà trở thành hạ tầng cho thuêTóm tắt Evooo1Bot dùng lại nguyên engine DDoS từ mã nguồn Mirai bị rò rỉ công khai. Phần đó không có gì mới sau mười năm. Cái mới nằm ở những thứ được gắn thêm vào: giao tiếp C2 mã hóa, scanner brute-Aug 25, 2026·25 min read