Obfuscated dropper with ActiveX execution
Fallout, this week
What we caught this week while monitoring over 155,791,038 artifacts across 48 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
TODAY
Tue Sep 22 · 70 catches · 2 waves · 11 singlesWMI hidden process, persistence, obfuscation
Obfuscated PowerShell download and execution
Obfuscated VBS executes decoded payload
Obfuscated WSH dropper runs PowerShell payload
Obfuscated dropper, C2, PowerShell exec
Obfuscated install hook exfiltrates data
Dependency contains credential stealer
Empire C2 framework
Known offensive security toolkit
Clipboard exfiltration, obfuscated C2, wallet theft
YESTERDAY
Mon Sep 21 · 228 catches · 8 waves · 20 singlesMulti-arch botnet dropper
Webshell deployment exploit toolkit
Webshell and WordPress exploit kit
CMS exploit toolkit
Process injection and code patching
Downloads and executes remote binaries
Downloads and executes remote exploits
Credential theft, obfuscation, C2 tunnel
Crypto miner with persistence and C2
Obfuscated VBS malware with registry access
obfuscated WhatsApp bot with remote code execution
Exfiltrates Depop auth tokens to ngrok
curl-pipe-sh, credential theft, persistence
Obfuscated credential stealer
Exfiltrates screen captures to Discord
Credential theft, obfuscation, weak passwords
preinstall reverse shell C2