Downloads and executes hidden PowerShell payload
Fallout in go, Aug 31 – Sep 6
What we caught this week while monitoring over 163,107,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Sep 6 · 4 catches · 0 waves · 3 singlesOR/Downloadinstruction/junk-insertion
Process injection APIs present
payload/encryptedtiming/evasion
cookie exfil, credential harvesting, autonomous agent
Dec21/SoftOR/Download
SATURDAY
Sat Sep 5 · 15 catches · 0 waves · 3 singlesObfuscated Lua dropper in archive
code-metrics/structurehidden-payload/exec
Fake GitHub domain impersonates AWS ECS Agent
http/upload
Obfuscated dropper with anti-analysis
code-metrics/structureexecution/build
FRIDAY
Fri Sep 4 · 6 catches · 0 waves · 3 singlesEmbedded agent installer with persistence
Obfuscated font file executes C2
delivery/blockchaintrigger/ide
Encoded subprocess, useradd, cloned repo
exploit/scannerpayload/encoded
THURSDAY
Thu Sep 3 · 6 catches · 0 waves · 3 singlesSigned with malicious 'ollypwn' cert
Exploit/CVE20200601
Post-exploitation framework with obfuscation
backdoor/emp3r0rtrojanized/package
SQL injection attack tool
reverse-shell/dupoffensive/metasploit
WEDNESDAY
Wed Sep 2 · 1 catch · 0 waves · 1 singleObfuscated PHP webshell included
And/Hexdomain/tld
MONDAY
Mon Aug 31 · 6 catches · 0 waves · 3 singlesembedded eval webshell payload
PHP/Gzinflatedrecon-exfil/pipeline
Mythic C2 framework source
framework/dockerfile
Mythic C2 framework source
framework/dockerfile
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories