Malware

AdaptixC2

AdaptixC2 is a open-source post-exploitation and adversarial emulation framework that lets penetration testers control compromised hosts and execute system actions. While being created for red-teaming it is also used by threat actors for attacks.

Indicators of Compromise 19

MITRE ATT&CK TTPs 25

Source Articles

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1d ago
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·1d ago
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
A China-nexus threat actor tracked as JadeProx has been conducting cyberattacks against government, healthcare, and education sectors in Asia and Latin America using a previously undocumented Windows loader named TriBack Loader. The attacks leverage DLL sideloading techniques and phishing campaigns, including a fake Anthropic Claude website, to deploy backdoors such as Beagle and AdaptixC2. The operators also perform large-scale scanning for known vulnerabilities and maintain persistence via malicious startup entries and webshells.
hacker-news ·5d ago