Shellcode injection and AV evasion
Fallout in go, Sep 14 – Sep 20
What we caught this week while monitoring over 159,750,626 artifacts across 46 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Sep 20 · 85 catches · 0 waves · 3 singlesShellcode injection and AMSI bypass
PowerShell Empire C2 framework
SATURDAY
Sat Sep 19 · 79 catches · 2 waves · 3 singlesC2 framework with RAT capabilities
Contains actual malware samples
Contains actual malware samples
Embedded PHP webshell payload
C2 framework with RAT capabilities
C2 framework with RAT capabilities
FRIDAY
Fri Sep 18 · 67 catches · 0 waves · 3 singlesPost-exploitation C2 framework
Mirai botnet malware source
Mirai botnet malware source
CTF webshells and exploits included
THURSDAY
Thu Sep 17 · 17 catches · 0 waves · 3 singlesPost-exploitation framework with obfuscation
Credential theft and persistence
WEDNESDAY
Wed Sep 16 · 3 catches · 0 waves · 3 singlesJava deserialization exploit tool
PowerShell dropper in main.go
Credential theft and persistence
MONDAY
Mon Sep 14 · 3 catches · 0 waves · 3 singlesContains PHP webshell and obfuscation
Impacket offensive security toolkit
Obfuscated payload in eslint config