The elite security team at @LevelBlueCyber. Response & Investigations. Analysis & Testing. Research & Development. Follow for info on the latest threats.

Everywhere
Noise is everywhere. Signal is rare. 🎯 #SpiderLabs focuses on what actually matters so your team can move faster with fewer distractions. 🕷️ Take a closer look at how that kind of visibility shows up in the real world:   hubs.ly/Q04pPTc00
407
🪝 We are observing active PDF #phishing campaigns impersonating #Adobe and #Microsoft that redirect victims to #Wazza Kit device code phishing pages hosted on workers.dev. - #MailMarshal detected phishing emails from compromised accounts containing PDF attachments with document-themed lures - The broader campaign leverages Google Sites (sites.google.com), Cloudflare Workers (workers.dev), and .eu Top Level Domains to host phishing content and related infrastructure - Wazza kit supports 19 themes via the ‘?thm=‘ URL parameter across six lure categories: file-sharing, account, document, payment, HR, cloud and brand impersonation. - The kit validates URL patterns, including subdomain and slug checks, to selectively serve phishing content and redirect non-targets to decoy pages.   #IOCs: beacon-surge-sync[.]workers[.]dev beton-beton[.]eu bike-msca[.]eu bodi-project[.]eu bruoth-family[.]eu cardamomo[.]eu coppietersrecherche[.]eu diabetesnet[.]eu dymowski[.]eu euniverza[.]eu hutspotmaken[.]eu illuminatedminds[.]eu jetcapital[.]eu languagesforwork[.]eu lesbolides[.]eu mdiament[.]eu nbi-training[.]eu nellarmonia[.]eu originalpizza[.]eu polskaprezydencjacsr[.]eu robologic[.]eu safetystock[.]eu electroloys[.]com hacsg[.]com sites[.]google[.]com/view/hgfdsqazxcvhjoswwqq/home sites[.]google[.]com/view/adobe-docus/home sites[.]google[.]com/view/miticabo/home sites[.]google[.]com/view/ctfvygbuhgyftvbgyfpoiuytrftgyh/home sites[.]google[.]com/view/kjvcfdswqazxcfvghjoplkjmnbvcf/home sites[.]google[.]com/view/securespdf/home sites[.]google[.]com/view/onwajuly/home dv0psh-purv3w-azfn-b2c0-msauth3-m365svc-s3ntln-4zrfn3x-cntnrx[.]workers[.]dev ssosvc-m365s-kvl-dv0pshb-s3ntln-c0mply-4zrmonx-apimgwx-evnthb[.]workers[.]dev wndws-pip3ln-sql3-waf3-purv3-gdprsx-dfn-azfn-appsvc-0ffapx[.]workers[.]dev purv3w3-t3ms4pp-certs-intun3-sbussvx-4zredg-siemsv-pip3ln-0ffc3[.]workers[.]dev
1
4
5
799
Some vulnerabilities patch. Some vulnerabilities keep sending follow-up emails. Just days after Microsoft's September Patch Tuesday, Nightmare-Eclipse dropped ShieldCrash, the latest chapter in a Defender bypass lineage we've been tracking through RoguePlanet and ShieldBreak. 3️⃣ PoCs. 2️⃣ patches. 1️⃣ underlying mechanism that's proven remarkably difficult to evict. Our testing found the public release is more "skeleton" than fully weaponized exploit, but buried in the artifacts, telemetry, and object-manager activity is a bigger lesson for defenders: understanding how a technique survives remediation often matters as much as understanding the vulnerability itself. hubs.ly/Q04xP4GN0
1
589
Our researchers recently found a 7-stage exploit chain that abuses Cloud Files, Windows Object Manager namespaces, Defender remediation and Windows Error Reporting to escalate from a standard user to SYSTEM on fully patched Windows systems. levelblue.com/blogs/spiderla…
3
3
763
A ClickFix case brought our team down a BabaDeda chain that led to an undocumented end: CNCMachineRMS, a 1.14 MB RAT with zero imports, every string built on the stack, and its own scripting language. The full research + PDF report below. ⤵️ hubs.ly/Q04swfMb0
2
4
843
🪝#Phishing Alert: LevelBlue #MailMarshal has detected a phishing campaign targeting hotels, venues, and wedding service providers. Threat actors are sending convincing fake business inquiries covering wedding venues, event planning, and related services to trick recipients into responding. The initial emails contain no links or attachments and use recently registered Reply-To domains. Once a target replies, attackers follow up with another email with either phishing links or malware attachments. IOCs: absolutdmc[.]com apexvistaventures[.]com aurellefashion[.]com eu-starstups[.]com eventr[.]cc grandcrestevents[.]com grandstayrental[.]com inwoods-hotels[.]com iwonderpicture[.]com quantumtradecollective[.]com shinilglobals[.]art sophiaevent10[.]com sophiatech[.]xyz westsinvalencia[.]com westpeakproperties[.]net
6
5
832
Some teams follow alerts. SpiderLabs follows behavior, patterns, intent, and instinct, long before it reaches your environment. 🕷️💡 Precision matters when threats evolve overnight.   Take a closer look at how that kind of visibility shows up in the real world. ⤵️ hubs.ly/Q04pPM7H0
1
511
Our gift to you: we have decided to do something for the community, with the hopes that more security vendors follow suit. We've been developing an advanced open-source Linux engine - dubbed owLSM - and have made it accessible for free, just for YOU. Meet owLSM: ⭐ A full Sigma rules engine in the kernel, implemented with eBPF LSM (Linux Security Module). ⭐ Kernel prevention capabilities that allow us to block operations before they occur. ⭐ Broad anti-tampering capabilities. ⭐ Security-focused system monitoring where each event contains all the context a security expert needs. Explore how owLSM can help you mitigate vulnerabilities: hubs.ly/Q04pwTrm0
3
2
699
A fake photo. A legitimate http://Node.js download. A blockchain-hosted C2. This campaign layers familiar tools and emerging techniques to stay hidden. hubs.ly/Q04pvSWB0
1
5
616
🚨#BEC Alert: We recently detected a Business Email Compromise (BEC) attack targeting newly hired employees. In an effort to bypass corporate email security defenses, threat actors sent messages to both employees' corporate and personal email accounts. After the initial welcome message, victims are instructed to purchase gift cards for a fake employee gift-giving initiative. Always stay vigilant as threats don't stop in the corporate inbox! IoC: oofficemail[.]co[.]nz@mail[.]ru
2
2
681
Threat activity is already in motion before it gets named, tracked, or reported. #SpiderLabs stays on the moving edge, turning live activity into decisions teams can act on without slowing down. 🕷️ Threat intelligence that holds up when operations are moving at full speed: it’s the SpiderLabs standard. hubs.ly/Q04pbnNc0
2
3
848
🪝#Phishing Alert: Over the past several weeks, we have detected multiple waves of phishing emails impersonating various investment trading platforms, including Interactive Brokers, CommSec, and CMC Markets. The emails contain a link using randomly generated .live domains, which lead to phishing pages or #malware payloads. The infrastructure uses Cloudflare Turnstile to evade automated scanning and analysis.   #IOCs: api[.]0bbo[.]com/* (POST) api[.]0bbr[.]com/* (POST) api[.]absgarter[.]live/* (POST) api[.]jobkt[.]com/* (POST) hxxps[://]6o8f3eui3yz320if6dc8qbjra5gi75[.]live/ hxxps[://]gur8vrlsi9w9e179cejslf[.]live/ hxxps[://]oy22gp4f128y3xxzhhwm109lim6[.]live hxxps[://]t27m7mub0c2hyqzxsrk38u[.]live/ hxxps[://]u40wbrah1rswgqs5f3i83kr1l[.]live/ hxxps[://]wtwabq60q6zya592w83v7s[.]live/   Observed endpoints: /pre-check/, /turnstile/site-key/, /site/frontend-config/
5
9
1,014
🪝#Phishing Alert: LevelBlue SpiderLabs has observed an increase in phishing campaign impersonating Robinhood, using fake sign-in alerts to lure recipients into calling an attacker-controlled number. This is a callback phishing attack tactic that relies on phone-based social engineering. #IOCs: 1 \[877\] 228 \ 4295 1 \[877\] 300 \ 7084 1 \[877\] 306 \ 1853 1 \[877\] 848 \ 7740 1 \[877\] 867 \ 1838 1 \[888\] 202 \ 5301 1 \[888\] 237 \ 3125 1 \[888\] 247 \ 5688 1 \[888\] 291 \ 6324 1 \[888\] 417 \ 0225 1 \[888\] 635 \ 2148 1 \[888\] 718 \ 5529 1 \[888\] 910 \ 1062 1 \[888\] 959 \ 4423
7
8
3,049
ValleyRAT activity is accelerating and getting harder to see. From fake installers to #phishing emails, the campaign blends DLL sideloading, RC4-encrypted payloads, and fileless execution to evade detection (all while targeting regional users as entry points into global enterprises). Here's what we know on #ValleyRAT: hubs.ly/Q04nnCV70
3
10
1,452
🪝🚨#Phishing Alert: Recently, we observed some compromised URLs that uses 'Secure Message' as lure and redirects to a device code phishing page. The device code phishing page is hosted on the domain 'workers.dev' that is also being abused in phishing activity. IoCs: hxxps://lva[.]com[.]au/documentation/ hxxps://page-8-xls-vft-lvfsa[.]pefferarley83249[.]workers[.]dev/ #MailMarshal #EmailSecurity #Cybersecurity
4
12
1,600
🚨 #BEC Alert: We detected a notable uptick in Business Email Compromise (BEC) activity leveraging Zoho infrastructure, where emails are sent via external clients and relayed through Zoho servers. Campaigns use newly registered domains in sender addresses and employ fake overdue invoices or requests for victims' personal contact details as lures. IoCs: partnerinvoices@consultant[.]com csuitexecutive[.]com postlt[.]xyz dolloberfacer[.]org micromailpost[.]com maillerwebspae[.]com #MailMarshal #Cybersecurity #EmailSecurity
4
14
1,066
A decade later and LokiBot is still living up to its reputation. From JScript obfuscation to multi-stage injection and API hashing, this latest campaign shows how "old" malware doesn't disappear; it adapts, framgents, and quietly persists. Same trickster, new disguises. hubs.ly/Q04m-Tr_0
2
690
🎣 Phishing Alert: A #phishing email delivers an HTML attachment that mimics an online banking portal. The HTML hides its payload using Unicode Braille characters, then decodes in the browser to render a fake login page and harvest credentials.   IoCs: Phishing page host hxxps://jbcarnedesol[.]com/wp-includes/images/xned26/.secured/ hxxps://jbcarnedesol[.]com/wp-includes/images/xned26/.secured/assets/js/afid.php?r=0   Your Portfolio Policy.html 18f90671643ff92f251e6729769235bb 3a5c626f163355ffb0714536bdaa36e3aebd7c71daa8d0831c2b8baa87ddaa2d
6
13
1,327
ClickFix now targets macOS users 🍎   ClickFix infostealer on bennysburger[.]co[.]nz (NZ).   Fake Cloudflare modal (iframe from superstarlog[.]click) writes malicious cmd to clipboard → Instructs user: open Terminal, and paste command → leads to macOS infostealer exfils via osascript to genomicsforge[.]com.   C2 URL stored on Polygon blockchain to evade DNS blocking.   IOCs:  - superstarlog[.]click (ClickFix overlay)  - genomicsforge[.]com (payload/exfil C2)  - Polygon contract: 0x08207B087F61d7e95E441E15fd6d40BEfd6eD308  - /tmp/hubs.ly/Q04mNnj20  - API key: 5190ef1733183a0dc63fb623357f56d6   hubs.ly/Q04mN5hX0
5
9
1,280