Threat Reports


Astroposia RAT

The Stealthy Atroposia RAT
This report discusses Atroposia, a new Remote Access Trojan (RAT) that has gained attention in underground forums. The malware is promoted as a multi-functional platform for remote control, data exfiltration, and stealth operations. It features advanced persistence and evasion tactics, along with a full C2 console for data exfiltration.

ShinySp1d3r

ShinySp1d3r Analysis
Overview ShinySp1d3r is a newly observed Ransomware-as-a-Service (RaaS) operation linked to the continued evolution of the ShinyHunters ecosystem and its collaboration with Scattered Spider/COM. While ShinyHunters first emerged in 2020 as a high-volume data theft and extortion group, recent campaigns show a clear progression toward

SILENTCONNECT

SILENTCONNECT Malware Analysis: Stealth Loader Installing ScreenConnect RMM
Overview In this report I discuss SILENTCONNECT, a newly discovered multi-stage malware loader that has targeted Windows machines since early March 2025. It has been observed actively in the wild. Its primary objective is to silently download and install ConnectWise ScreenConnect on the victim’s system, giving threat actors

NightSpire

NightSpire Ransomware Analysis
Overview of the NightSpire Ransomware Group NightSpire is a ransomware group first discovered in the wild in March 2025. Within just 6 months, the group has captured the attention of global cybersecurity analysts and claimed over 73 victims worldwide. The group blends traditional ransomware tactics with aggressive public shaming and

Myth Stealer

Myth Stealer Analysis
What is Myth Stealer Security researchers at Trellix identified a fully undetected information stealer called Myth Stealer. Written in Rust, this malware has been marketed on Telegram since late December 2024. It was initially offered as a free trial for users to test its functionality and capabilities, before evolving into

Vultur

Vultur Analysis
Target: Financial Sector Observations The Android banking trojan known as Vultur has resurfaced with a suite of new features and improved anti-analysis and evasion techniques. First identified in early 2021, Vultur leverages Android’s accessibility services APIs to execute malicious actions. Security researchers recently discovered a new version of

Amatera Stealer

Amatera Stealer Analysis
What is the Amatera Stealer Proofpoint has identified a new threat called the Amatera Stealer, a rebranded version of ACR stealer. While Amatera shares significant code overlap, features, and capabilities with ACR stealer, it has undergone substantial development and enhancement to emerge as a distinct potential threat in the cyber

Inside XWorm 6.0

Inside XWorm 6.0: How the Backdoor Spreads, Persists, and Evades Detection
New versions of the XWorm backdoor are being distributed in phishing campaigns after the original developer, XCoder, abandoned the project in 2024. The latest variants—6.0, 6.4, and 6.5—are used by various threat actors and support plugins that enable a wide range of malicious activity. This

Mini Shai-Hulud

The Worm in the Workflow: Mini Shai-Hulud and the CI/CD Supply-Chain Takeover
Mini Shai-Hulud is a highly active, self-propagating software supply chain attack campaign attributed to a financially motivated threat actor known as TeamPCP. Named after the colossal sandworms of Frank Herbert’s Dune universe, the campaign reflects both the actor’s thematic branding and the malware’s worm-like,