Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Claude Fable 5: il servizio riattivato a breve dal governo USA, ma attenzione a GLM 5.2

📌 Link all'articolo : redhotcyber.com/post/claude-fa…

A cura di Luigi Zullo

#redhotcyber #news #intelligenzaartificiale #cloudcomputing #geopolitica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Keynote su AI, democrazia e Decisioni Artificiali camisanicalzolari.it/keynote-s…

Review: The Tanmatsu, A Year On


The media in this post is not displayed to visitors. To view it, please log in.

About 18 months ago, we brought you a sneak peek at a handheld that started life in the Dutch conference badge scene. At the time it showed promise, but its software wasn’t ready for a fair review. Now it has both a stable operating system and a growing software library. It’s time to put it through its paces and see what it can do.

A Handheld Computer For Hackers

The Tanmatsu PCB, showing all the different parts.The bare PCB, with the expansion connector bottom centre.
The Tanmatsu (Japanese for “Terminal”), is a general putpose palmtop computer based around an ESP32-P4 application processor from Espressif. It takes the form of a PCB and PETG 3D printed sandwich, with the front face PCB sporting a silicone QWERTY keyboard and an 800×480 MIPI DSI display. The keyboard should be familiar to many readers, being the same moulding as the Solder Party KeebDeck which has appeared on other devices.

Under the hood that P4 has two 400MHz RISC-V cores and 32MB of PSRAM with 16MB of Flash, and there’s an ESP32-C6 for WiFi, BLE and IEEE 802.15.4 mesh networking. There’s an Ebyte LoRa module with an SMA antenna too, which can be had in 868, or 915MHz versions depending on where in the world you live.

For interfacing there are USB A and C ports, and SD card socket, a 3.5 mm jack for audio, and three expansion ports. On the right side a Qwiic compatible socket, on the left a socket with PMOD and SAO capabilities, and on the rear under the cover, a CSI camera connector the same as the Raspberry Pi, and a much larger expansion socket with all the various signals, planned for add-ons. It’s all powered by a chunky 2500 mAh LiPo which can be charged through the USB-C port.

Because I know the folks behind it I’ve watched it grow from its origins in a souped-up version of the MCH2022 badge into its current form, indeed I bought my Tanmatsu just over a year ago. Due to those origins in the Dutch badge team, this device is open-source. The Tanmatsu is a commercial version produced and sold by Renze Nicolai, its designer, while the Konsool is its community cousin. You can find its mechanical hardware here, its electronics here, and its firmware here.

An App Repository For Your Creations


Turning the Tanmatsu on, after a synthwave-inspired splash screen you find yourself in a graphical menu. The user interface is pretty intuitive to anyone used to a desktop GUI or a modern smartphone, along the top are status icons for SD card, Wi-Fi, and battery, the main body of the screen has a grid of icons, and along the bottom is a list of the various keyboard shortcuts. Navigation is via a set of arrow keys with the return key selecting an option, and a set of coloured function keys handle special functions.
The Tanmatsu handheld computer showing a screen from the Wadamesh Meshcore app.Meshcore is only a download from the repository away.
On first start-up the Tanmatsu has no apps installed, so the first order of business is to connect to a Wi-Fi network and update the firmware through the Settings. It takes a while to do this as it can update the firmware on the P4, the C6, and the microcontroller it uses for housekeeping. A feature I like is that this is the first device from the world of badges I’ve seen that can hold more than one set of Wi-Fi network details rather than requiring me to change the settings at each location.

With a freshly updated Tanmatsu you can open the repository, this device’s app store, and download some apps to get started. This is a long-standing badge.team feature, in that badges going back to their SHA 2017 offering have had downloadable apps. The apps are sorted into categories for easy navigation, and in my case there are immediately two apps I have installed, the Tamatype camera app for my Pi camera add-on, and from the choice of two different Meshcore apps, Wadamesh.

The apps themselves come in two forms, either ones written in an interpreted scripting language such as MicroPython, or those compiled directly for the P4. It doesn’t ship with a script engine installed, however MicroPython is downloadable as an app from the repository. This is not a multitasking device so the front-end is a launcher, and after running an app the screen will flash blue for a moment as it loads. Each app has a metadata file which instructs the Tanmatsu what to do with it, an icon file, and a folder containing its executable components. There’s a comprehensive online guide, should you wish to try developing your own apps.

In use the Tanmatsu is convenient to hold and type with using two hands. The display is clear and bright, and the keyboard while a little on the small side has a positive click action. Using the apps depends on the individual choices of the app developer, but the interface conventions are straightforward. I’ve been using it for Meshcore for a while now, and it makes a very handy terminal indeed.

In A Niche Of Its Own


The price of a fully assembled Tanmatsu is 99 Euros, plus Dutch sales tax if you live in the EU, and shipping. The good news for Americans in an age of uncertain tariffs is that I’m told they will be shipping from a US warehouse in the next few months. It’s worth considering for a moment where this places the device in the ecosystem of similar computers.

It’s relatively simple to make a handheld Linux cyberdeck using a Raspberry Pi board, however once the price of new peripherals and parts is taken into account it’s not necessarily a cheap project. There are quite a few similar-sized Linux devices on the market whose prices reflect this at about twice as much. Thus I think that the Tanmatsu fits in a middle zone between development boards that come without the screen, battery, and keyboard, and those Linux handhelds that are all-singing all-dancing.

In its favour it’s as far as I know the only P4 device on the market with a mature operating system and particuarly an app repository, but if only Linux will do, it’s unable to deliver. Where I think its niche lies is in being simple and low power enough to be a reliable and powerful hacker’s communicator and general purpose toolkit, but cheap enough to remain a reasonable purchase. For now it stands alone in that niche, and only time will tell whether it can successfully define it.


hackaday.com/2026/07/01/review…

Tyorgg reshared this.

Engineering Micro-Submarines to Replace Fish


The media in this post is not displayed to visitors. To view it, please log in.

Everybody loves aquariums. There’s something soothing about watching the lil’ critters inside them swimming, crawling and wriggling about. But at the same time few people are up to the task of ensuring that said critters stay alive and happy in said aquarium. This is where small robots may be able to steal some fishy jobs, like a modern take on the gaudy fake aquariums of the 1990s. Cue [CPSDrone]’s mini-drone aquarium with mostly maintenance-free robotic fish.

These pose a few interesting engineering challenges, such as the replacing of feeding fish by having them scuttle back to their charging station like an aquatic Roomba, and giving them some level of intelligence to the point that they at least appear to be doing something fish-like.

Rather than give each robot fish full autonomy, they are instead controlled by a central system. This then raised the problem of radio frequency communication while underwater. The theory was that 433 MHz transceivers would still work for something the size of an aquarium before attenuation spoils things, which a quick test confirmed to be true.

This enabled the construction of a small microcontroller-carrying submarine as a proof of concept before diving into the final version, involving resin 3D printed enclosures that are made water-tight using rubber O-ring seals and UV-cured resin. All that was left now was to add the big control system, which takes up much of the rest of the video.

Sadly they didn’t implement the boids algorithm, as this is pretty good at creating realistic life-like motion, as show with this demonstration by [Ben Eater]. This algorithm is pretty simple, with each ‘creature’ obeying rules on coherence, separation and alignment, creating a pattern that can be observed among schools of fish as well as flocks of birds. Due to its simplicity you could conceivably even omit the central control system and just give each ‘fish’ enough sensors to keep track of its buddies.

youtube.com/embed/M733JzO3LBE?…


hackaday.com/2026/07/01/engine…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Kali Linux 2026.2 è uscito con nove nuovi strumenti e aggiornamenti per NetHunter

📌 Link all'articolo : redhotcyber.com/post/kali-linu…

A cura di Carolina Vivianti

#redhotcyber #news #kali linux #linux #gnome #kdeplasma #nethunter #android #cybersecurity

Postcard from New Hampshire: The digital translation problem


The media in this post is not displayed to visitors. To view it, please log in.

Postcard from New Hampshire: The digital translation problem
WELCOME TO THE FREE MONTHLY EDITION of Digital Politics.I'm Mark Scott, and I have a confession: I have World Cup fever. And despite England's poor performances against Ghana and Panama, I can't help but whisper: It's coming home.

Happy early July 4th to all US readers.

— Regulators and companies are speaking past each other when it comes to the litany of new digital regulatory challenges that lie ahead.

— Europe has drunk the kool-aid on tech sovereignty. It risks putting its ambitions over the practicalities of implementing those proposals.

— Four out of every 10 Americans now use AI chatbots at work.

Let's get started:


YOU SAY ENFORCEMENT, I SAY COMPLIANCE


REGULATORS ARE FROM MARS, COMPANIES are from Venus. That's definitely how it felt after spending time with both groups in Portsmouth, New Hampshire last week at the annual Navigate digital policy conference. The three-day gathering — co-hosted by Harvard University's Berkman Klein Center for Internet & Society and the IAPP, an industry-focused non-profit — brought together policymakers, lawmakers and industry types from mostly Western countries to speak plainly about the current state-of-play on everything from cross-border data flows to platform governance enforcement.

That, and a fair share of lobster rolls.

While the event was held under the Chatham House Rule, it quickly became clear that those regulators and company executives present had radically different perspectives on what "good" looked like when complying with the growing list of national and regional rules related to artificial intelligence, data protection, digital competition and online safety. This divide — in which both sides fail to understand where the other is coming from — is a stark reminder that for digital legislation to truly take hold, more time needs to be spent on implementing the rules, and not just passing them.

In one conversation with a Western regulator, the official raised frustration that companies under his remit didn't take the time to make themselves known to his agency. From his perspective, the door was always open to company executives looking to build up a good rapport with a newly-empowered agency eager and willing to understand the problems that firms were facing. Better to make that investment from the get-go, he added, than come asking for advice/help when things inevitably went wrong. The regulator said his goal wasn't doling out the largest fines. Instead, it was about ensuring firms were compliant with what, he admitted, were complex rules.

So far, so good.

And yet, over lunch just a few hours later, I sat next to someone from a large tech company whose services fall directly under the remit of the regulator mentioned above. Great, I thought. Time to confirm what the official said: that regulatory compliance was proceeding, as envisioned, built on mutual trust and communication.

Thanks for reading the free monthly version of Digital Politics. Paid subscribers receive at least one newsletter a week. If that sounds like your jam, please sign up here.

Here's what paid subscribers read in June:
— In Digital Politics' first 100 editions, I made a lot of claims. Some were right, some less so. Here's how I did over the last two years. More here.
— How Western countries' AI plans are not keeping up with industry; Lessons from Australia's social media ban for kids; Where future data centers are likely to be built. More here.
— How the G7 summit shows the digital divide between the US and everyone else; Why digital competition rules are already overseeing AI; SpaceX's IPO versus X's DSA fine. More here.
— If social media bans for kids are coming, this is how they should work; How one of Europe's top courts just blew up platform liability protections; How digital industries are driving economic growth for the next decade. More here.

Not so fast. The company executive made clear that his local colleagues had received a much different perspective when they had tried to engage with the regulator's case team. Those officials' failure to return emails, provide clear guidance and demonstrate a willingness to cooperate to determine what "good" looked like had become a daily frustration. "I don't think that regulator understands what's going on within his agency," the individual commented after I explained how the official had explained his regulatory ethos to me.

This pattern repeated during the conference. Regulators — and, to a lesser extent, legislators who were present — outlined the complex structural implementation plans designed to support each country's newly-minted digital rulebooks. There were cross-agency task forces. There were lengthy public consultations to co-develop codes of practice. There were open-door policies to help companies navigate the intricacies of data protection, AI and competition rulebooks that often overlapped in unclear ways.

"We want companies to come to us before there's a problem," said another regulator. "We're not going to bite."

That contrasted with high levels of frustration from company executives attending the New Hampshire conference. Many of these individuals skewed toward larger, multinational firms. Their presence at what was essentially an informal digital policymaking gathering for regulators, industry types and civil society also indicated they were more likely to be engaged in these conversations than the average corporate type.

Yet, conversation after conversation revealed the structural asymmetry currently at play in how companies comply with the growing list of national and regional digital rules. One compliance-focused executive told me her global team kept an ever-growing excel spreadsheet of the legislative proposals that may eventually become law. In 2023, the list was around 30 (excluding US state legislation.) This year, the number had grown to more than 200 — and covered traditional staples like the European Union and United States, as well as more far-flung locations like Brazil and Indonesia.

"I don't need sympathy for having to deal with this complexity," the individual conceded. "It's just that for most regulators, they have to deal with one, maybe two, sets of rules. I'm dealing with at least 15."

In truth, the first half of that quote is doing a lot of heavy-lifting. At a time of sky-rocketing profits (at least for the world's largest tech companies), it's hard to have sympathy for companies' needs to comply with the global cavalcade of digital regulation. That is just the state of play in 2026.

But what I do have time for is the questioning of the effectiveness of so many different pieces of legislation — and across multiple digital policymaking topics — that are coming into force at a speed that even regulators and lawmakers admitted in New Hampshire was a lot to handle. That's especially true when many national efforts across different agencies and legislative agendas were not joined up, leaving companies to often comply with potential contradictory regulatory guidance.

This digital translation problem — in which regulators and companies speak past each other — is a worry. Effective oversight should not be viewed solely via the prism of blockbuster fines. Instead, it's the day-to-day wonkery of mundane compliance meetings, requests for information and annual submissions that is the bread and butter of good digital regulation.

Both regulators and (most) companies want that. But what the New Hampshire conference demonstrated was a fundamental gap between regulatory intent and corporate experience in complying with digital rules.

Yes, there is a communication failure in terms of how both sides approach these issues. But, more importantly, there is a structural mismatch — one that shows no signs of resolving — that will determine whether the current generation of digital legislation actually changes corporate behavior or simply generates compliance paperwork without fundamentally improving people's online experiences.


Chart of the week


IF YOU HAVE BECOME ADDICTED TO EITHER Chat-GPT or Claude to give yourself quick answers to complex problems, don't worry. You're not alone.

More than 40 percent of Americans polledby the Pew Research Center now use these AI chatbots to search for information on a regular basis. That's a worrying sign for Google whose own service, Gemini, is now outdone by Chat-GPT when it comes to such AI-powered search.

There's a growing number of US states passing AI chatbot legislation, in part to ward off harm to kids. But among adults, only four percent of those surveyed used these tools for "companionship."
Postcard from New Hampshire: The digital translation problemSource: Pew Research Center


THE FINE LINE BETWEEN TECH SOVEREIGNTY AND PROTECTIONISM


IN BRUSSELS AND OTHER EU CAPITALS, an awkward balancing act is underway. In the era of AI hype in which we currently live, policymakers are desperate to Make Europe Great Again via industrial policies that jumpstart AI-enabled growth. That often includes earmarking billions of euros in public funds for digital public infrastructure like data centers and even semiconductor facilities. The goal: to onshore technologies expected to dominate the economic agenda for the next decade.

Such policies are not much different to those promoted by the likes of Canada and Singapore. Sure, the 27-country bloc's economy is exponentially bigger than those so-called Middle Powers. But the combination of public investment, onshoring of critical technologies and the promotion of "tech sovereignty" has now become one of the critical digital policymaking trends for 2026.

But where the EU stands apart from others is the internal divide on what to do with its most important economic and diplomatic partner: the US.

To say that the winds have shifted against Washington would be an understatement. Donald Trump's administration has made its position toward Europe blatantly clear. Europe, too, has hardened its stance toward the US in the wake of the Greenland crisis, which — if you had forgotten — happened less than six months ago.

That stand-off, in which a NATO ally threatened to take over part of another NATO country's territory, led to a significant mind-shift for the US' staunchest allies in the bloc. It also reinvigorated a primarily French-led agenda to cut US tech firms off from parts of the European economy. That also included a renewed attempt to use the EU countries' national procurement rules and other industrial policy levers to back the creation of European champions amid the rush for technological sovereignty.

Yet with so much of European digital policymaking, things are never that easy. While there has been a growing call to pull the plug on American Big Tech giants — with the misguided specter of a "kill switch" repeatedly doing the rounds — many in Brussels are also aware of how unrealistic those ambitions currently are.

Let's leave aside the politics of the transatlantic relationship. Almost everyone understands they are in bad shape. But EU officials (especially those within the European Commission) have crunched the numbers and come to the conclusion that the bloc can't simply pull the plug on US tech overnight. There are too many dependencies, too much investment required and too little technical know-how across Europe to conduct a 'rip-and-replace' strategy promoted by Paris and its allies.

This realism was baked into the European Tech Sovereigntypackage announced earlier this month. Yes, there was the now must-have language about boosting EU economic output, onshoring critical technologies and urging member countries to determine which parts of their infrastructure needed to be "fully sovereign." But the proposals also didn't mention the need to pull back completely from long-standing allies — even if some of the plans certainly nudged the EU away from US tech.

Such pragmatism, in which EU officials acknowledge the inability to pull away from America, even while popular demand for such an approach grows, has left the bloc in a weakened position.

It would be one thing if Europe had gone "full protectionist" by blocking non-EU firms from bidding for lucrative government contracts and imposing export controls on critical technologies. Yes, before you ask, the EU does have some of those.

But policymakers have been insistent that Europe doesn't want to go down the protectionist route. This is about "right-sizing" the current relationship with the US, they tell me. Europe is open for business. But it also wants to build things more at home (via domestic companies) than rely on technologies from partners no longer seen as 100 percent trustworthy.

That nuance may play well in the corridors of the Berlaymont Building. But as an industrial policy, it leaves much to be desired.

Sign up for Digital Politics


Thanks for getting this far. Enjoyed what you've read? Why not receive weekly updates on how the worlds of technology and politics are colliding like never before. The first two weeks of any paid subscription are free.

Subscribe
Email sent! Check your inbox to complete your signup.


No spam. Unsubscribe anytime.

By attempting a "cake and eat it, too" policy of both promoting European tech solutions while also telling the world you're open for business, the EU may fail to keep pace with the US and China. Both are pursuing more binary digital policy options. I'm not saying that's a certainty. But the complexities of Europe's tech sovereignty pitch — borne from the different political objectives of its 27 member countries — appears to be too slow, too nuanced and too unwieldy to compete on the global stage.

I don't think this approach was done on purpose. Instead, EU policymakers are attempting to balance the demands from the 'rip-and-replace" brigade (led by France) and the market liberals (led by the so-called D9+ countries). It's also trying to navigate a transatlantic relationship with a White House administration whose own policy objectives can blow hot and cold, often within weeks.

It's not an easy balance. Many within the Brussels bubble would prefer a scorched-earth policy of an immediate pull-back from relations with Washington and US tech firms, many of which have sided with the White House on tech-related foreign policy topics. The EU should be given credit for not giving into such rhetoric — and recognizing that such policies would not be practical over the short-term.

But in trying to straddle the divide between the bloc's tech sovereignty ambitions, Brussels has fallen into a long-standing trap. It laid out sophisticated policy objectives, only for those proposals to potentially fail to meet the geopolitical reality — and binary tech sovereignty alternatives — promoted by China and the US.


What I'm reading


— The European Commission informed Microsoft and Amazon that their cloud computing services were likely to be so-called "gatekeepers" under the EU's antitrust rules. More here.

— The German government's independent commission on online child safety published 56 recommendations on how to keep kids better protected online. More here.

— The British government outlined five different scenarios for how artificial intelligence could develop between now and 2030. More here.

— Columbia University's Institute of Global Politics explains how so-called "AI slop" is infiltrating the online information ecosystem. More here.

— The Royal United Services Institute makes the case for why access to the latest AI models is increasingly viewed via the lens of national security. More here.



digitalpolitics.co/digital-reg…

UDP Broadcasting and Easily Finding Network Services


The media in this post is not displayed to visitors. To view it, please log in.

Local area networks (LANs) that use technologies like Ethernet and Wi-Fi are incredibly useful for letting devices talk with each other. Yet a core problem here is knowing which devices are where on the network, as anyone who has ever tried to add a network printer or network share to their system can probably attest to. Unless you happen to know the IP address of the LAN device, the port, and protocol, the target device may as well be located on the Moon without further help, such as automatic network discovery in lieu of waddling over to the device and reading the label listing its IP address.

Over the decades quite a few ways have been developed to enable such network discovery, with many of them using UDP broadcast as the first step. By broadcasting a global message on the entire LAN, any device that has an actively listening UDP socket on that particular port can parse said message and decide whether it’s feeling sociable enough to reply.

The topic of UDP broadcasting is however not as straightforward as it may sound if you’re just getting started, including the existence of many opinions on the ‘right way’. There is also a massive divide between a sprawling service discovery protocol like mDNS and a light-weight one like that one that I had to implement a few years ago for an open source project.

Network Broadcasting


The obvious advantage of a broadcast message is that a client device that seeks its protocol soul mate on the LAN doesn’t need to ping all possible IP address and subnets. Instead, a broadcast message is designed so that all connected networking devices know that it should be forwarded to all other known devices. Thus with a single message from the client, in theory, only a single message will then neatly land at every single other connected system.

Of course, this ignores happy joy fun things such as convoluted network configurations, such as those involving overlapping Wi-Fi repeaters and subsequent routing, but in general we can assume that this is how it works. Various edge cases and fascinating complications of these will be considered in a later section.

Much of this service auto-discovery is tossed under the header of ‘zero-configuration networking‘, or zeroconf for people who don’t like typing. The best part about zeroconf is probably that there are so many standards here, ranging from DNS-SD to mDNS, UPnP, SLP and others. Perhaps unsurprisingly, one of the major issues here is that platform support here is spotty, with mDNS – despite being one of the most universal – not having much support outside of MacOS/OS X with Bonjour and Linux/BSD with Avahi.

Thus while trying to add the auto-discovery of NymphCast receivers and media servers by NymphCast clients, I found myself asking the daunting question of whether I was at risk of being about to embark on reinventing the proverbial wheel. After all, nobody wants to become the subject of an xkcd comic.

UDP Discovery Basics


As it turns out, I ought not to have been too worried, as despite looking everywhere I could find nothing along the lines of the NyanSD network service discovery (NSD) protocol that I ended up implementing and integrating into NymphCast. What I wanted after all was the most no-frills NSD possible that could be easily integrated, while working the same across just about any desktop, server and embedded platform imaginable.

All that’s needed for this is a way to create an appropriate UDP socket, and a way to either broadcast a query and receive the response, or to listen for incoming UDP packets. Here you can figure out the platform-native method for each target platform, or not reinvent the wheel and use an existing networking library for C++ like Poco. This is what I used for NyanSD, along with my ByteBauble utility to handle endianness conversions.

For the UDP server — the listening side — the procedure is fairly standard, with a regular UDP listening socket. As UDP is a connectionless protocol, there is not a lot of preamble here, just a UDP socket instance (here Poco::Net::[url=https://docs.pocoproject.org/current/Poco.Net.DatagramSocket.html]DatagramSocket[/url]), which is bound to the target port and regularly polls for any fresh UDP packets to process. This can all be seen in the single source file for NyanSD which covers both the client and server side code.

Where things get spicy is with the client that sends the broadcast query and waits for any replies. If we were to just shove the query data into the socket along with the request to toss it over to a regular IP address, not a lot would happen. To make it into a broadcast request we need a few things:

  1. Let the network subsystem know that we want to do broadcast things.
  2. Create the special broadcast address for the target network interface.

With Poco the first point is easily handled by simply calling setBroadcast(true) on the UDP socket instance. For BSD sockets this sets the appropriate flag on the socket, which is essentially repeated across all OS implementations due to how prevalent the BSD socket library is.

The second point can be summarized for IPv4 as a curt ‘make it end with .255’. For example 192.168.0.255 when the client network interface’s IP address is 192.168.0.42. If there are multiple interfaces on the client system, you can go through the list one by one to broadcast on each of them before filtering out potential duplicate returns.

As for how to do broadcasting with IPv6: you don’t, as this protocol relies on multicast and special multicast receiver groups, which is another kettle of fish and of not much relevance for LANs.

Complications


If you look at the NyanSD API, it may give the impression that the query process is incredibly straightforward, with the sendQuery() function neatly returning a stack of remote systems that responded to our query. While these are definitely all the responses, it’s important to remember that NyanSD queries every single network interface. This means that the responses are likely to contain duplicates, which may even come from the loopback address when a service runs locally.

The filtering of this is captured in the NymphCast client library (libnymphcast) where the findServers() function in the main source file calls the isDuplicate() and isDuplicateName() functions, as well as the removeLoopback() function that nukes any responses that match a remote service found via a non-loopback interface. This last filtering is essential for NymphCast when e.g. using playback groups that would otherwise get confused by a stray loopback address.

Although one may think that such in-depth filtering is unnecessary if all you have is a single Wi-Fi or Ethernet interface in your system, one of the curveballs that I encountered during real-life testing was apparently related to Wi-Fi repeaters. For some reason it seems that the way that the repeaters did their broadcasting led to erroneous duplication of packets and thus multiple returns from a single system.

Depending on your exact use case and network configuration you may encounter any such issues and perhaps an exciting new one.

NyanSD Findings


Over the years that NyanSD has been used in the NymphCast project, it has proven to be one of the most reliable and probably nearly zero-fuss components. I have so far used it on Windows, various Linux distributions, FreeBSD, Haiku, Android, and the ESP32 via FreeRTOS and ESP-IDF. What this experience has proven to me most of all is that service discovery doesn’t have to be complicated.

The basic UDP protocol is simple and reliable enough that, barring a very sick LAN, there shouldn’t be any issues here. Assuming you get your filtering sorted of the responses, it’s probably the last part of a project to worry about.

One thing that I’m also very happy with in NyanSD is that there’s no set port in the protocol, like how mDNS always uses port 5353. What this means is that I can have NyanSD listen with a UDP socket on the same port as the NymphCast server’s TCP socket, which also means that different services with their own port can be targeted directly rather than every NyanSD-enabled service on the network getting blasted by every NyanSD query.

I did also do some work on a NyanSD daemon as a more central services database, but so far I have had no real need for it in a practical deployment. I guess that such a thing could be very useful if the port of a service is not set in stone, but generally that’s the one aspect of network services that tends to be boringly predictable.


hackaday.com/2026/07/01/udp-br…

Terminus is a Text Only Phone Because Telephony is Dead Anyway


The media in this post is not displayed to visitors. To view it, please log in.

This may say more about us than the current state of the telephone network, but unless your Grandma is still kicking, how many phone calls do you take that are actually worth picking up? Around here it’s one variety of scam or another, with the odd cold-calling salesperson to round it out.

So when we saw [Bolan Xu]’s texting-only TERMINUS cell phone project, it took but a minute to decide that, yeah, we wouldn’t miss the telephone part of the phone very much either.

The trade-offs are immense when compared to your smartphone; there’s no voice, no web browser, no social media, and no camera. But on the flip side there’s also no spyware and no annoying spam calls. Besides, he’s built a QWERTY keyboard onto this thing, and that does seem to be what most of us miss in this era of black rectangles.

In terms of electronics, its rocking a tiny OLED display for you to read your messages on, driven by an ESP8266. When WiFi is available the plan was to bridge over the internet in an SMS version of VOIP, but [Bolan Xu] ended up installing a cellular modem in it anyway.

As you can tell from the skeletal case, this is very much a prototype, but it is a promising project. We’ve seen ESP-based phones before, but they tend to be a bit smarter, and run on ESP32 instead of the more modest ESP8266.


hackaday.com/2026/07/01/termin…

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign


The media in this post is not displayed to visitors. To view it, please log in.


Introduction


To access compromised systems, threat actors frequently abuse legitimate remote monitoring tools. At first glance, these utilities rarely raise red flags: they are signed with valid digital certificates, often allowlisted under corporate IT policies, and fully supported by OS vendors. However, they grant attackers the ability to harvest data from target devices, drop malware, and move laterally across the network.

During a recent investigation engagement, the Kaspersky Managed Detection and Response (MDR) team discovered the ScreenConnect remote access tool being leveraged to deploy and execute an AsyncRAT payload.

A deep dive into this single incident unraveled a massive campaign distributing malicious installer archives hosted on spoofed websites. These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, Bandicam, and others. In total, we uncovered more than 90 domain names localized across 10 languages. The malicious archives bundle a legitimate, signed Microsoft install.exe binary alongside a rogue install.res.1033.dll library. It is loaded onto the device via DLL sideloading and deploys the ScreenConnect service, which awaits further instructions from the threat actors.

As a result, what initially appeared to be an isolated ScreenConnect incident served as the starting point for a full investigation into the threat actor’s C2 infrastructure. Every spoofed site we uncovered followed the exact same playbook: dropping a hidden ScreenConnect remote administration service under the guise of a legitimate software installer. This allowed the attackers to maintain control over compromised endpoints, with victims ranging from individual users to organizations.

We continue to break down complex, multi-stage incidents like this in our ongoing The SOC Files series. In this post, we take a deep dive into the technical execution of the ScreenConnect attack and analyze the broader infrastructure under the threat actor’s control.

Initial incident investigation


The investigation was triggered by an alert from Kaspersky MDR, which flagged the creation and execution of suspicious PowerShell and VBS scripts spawned by a ScreenConnect process.
About ScreenConnect
ScreenConnect is a legitimate remote management utility. Kaspersky solutions detect it as not-a-virus:HEUR:RemoteAdmin.MSIL.ConnectWise.gen.

ScreenConnect was running as an Access-type service — enabling direct remote connectivity — with the server explicitly passed via the command line:

ScreenConnect service execution event with suspicious parameters
ScreenConnect service execution event with suspicious parameters

Once running, ScreenConnect created and executed a PowerShell script named Fj5NmEsp9EuKrun.ps1:

Malicious PowerShell script creation
Malicious PowerShell script creation

Below is an excerpt from the contents of the script:

Snippet of Fj5NmEsp9EuKrun.ps1
Snippet of Fj5NmEsp9EuKrun.ps1

This script configures Microsoft Defender exclusions for the following objects:

  • All disks in the system: C:\, D:\, and others
  • All root directories on the C:\ drive, as well as the C:\Users\Public directory
  • RegAsm.exe process

Additionally, the script disables User Account Control (UAC) prompts by setting the ConsentPromptBehaviorAdmin registry parameter to 0.

Following this setup, the ScreenConnect service goes on to create a VBScript file:

Malicious VBScript creation
Malicious VBScript creation

The installer_method3_stream.vbs script creates five files in the C:\Users\Public directory (msgbox.txt, secret_bytes.txt, 1.vb, cap.ps1, and script.vbs) and immediately triggers their execution by launching script.vbs.

Contents of script.vbs
Contents of script.vbs

This script terminates all active powershell.exe processes to cover its tracks and executes cap.ps1 in a hidden window.

Contents of cap.ps1
Contents of cap.ps1

cap.ps1 reads the contents of the secret_bytes.txt file, extracts sequences matching the [SXX- pattern, and converts XX from hexadecimal representation to a byte. It then uses a 0xA7 XOR key to decrypt each byte and inverts the bit order. The resulting byte array yields a fully formed PE binary, which is then reflectively loaded into the CLR.

Within the loaded assembly, the ConsoleApp1.Module1 type contains a static method named Run. The script uses reflection (Reflection.BindingFlags) to resolve a reference to this method and invoke it.

The Run method executes a process hollowing technique (T1055.012), spawning a new RegAsm.exe process with the CREATE_SUSPENDED flag. The deobfuscated and decrypted PE image from secret_bytes.txt is then copied into its address space. As a result, the RegAsm.exe process no longer executes its original code, instead serving as a container for the injected .NET module — which, in this case, is the AsyncRAT remote access Trojan.

To establish persistence, the malware schedules a task named MasterPackager.Updater:
"schtasks" /Create /TN "MasterPackager.Updater" /TR "wscript.exe "C:\Users\Public\script.vbs" " /SC MINUTE /MO 2 /F
This task triggers every two minutes, ensuring that script.vbs — and consequently the entire loader chain — executes even after a system reboot.

Once the entire infection chain successfully executes, the RegAsm.exe process establishes a connection to the C2 domain mora1987[.]work[.]gd.

AsyncRAT infection and persistence chain via ScreenConnect
AsyncRAT infection and persistence chain via ScreenConnect

How ScreenConnect entered the system


A retrospective analysis of the incident allowed us to pinpoint the source of the ScreenConnect installation: a user-downloaded archive named obs-studio-windows-x64.zip.

The archive was downloaded from hxxps://www.studioobs[.]com/, a typosquatted domain mimicking the official site for OBS Studio, a popular open-source screen recording app. This site is present in search engine results; in this specific incident, the user landed on the malicious domain directly from a search query, a vector we analyze in more detail below.

Clicking the download button for the supposedly legitimate software triggers a request to the following URL, from which the archive is fetched:
hxxps://fileget.loseyourip[.]com/obs-studio-windows-full/gVOMs5VZ9BtlcaM

Site used to deliver ScreenConnect
Site used to deliver ScreenConnect

The archive contains a legitimate, Microsoft-signed executable named install.exe (87603EA025623B19954E460ADD532048), renamed to masquerade as the OBS Studio installer, along with a malicious library named install.res.1033.dll. Additionally, the archive includes an Assets folder containing both a copy of the actual software being impersonated and the ScreenConnect utility.

Contents of obs-studio-windows-x64.zip
Contents of obs-studio-windows-x64.zip

The complete file structure of the archive is organized as follows:

Detailed directory tree of obs-studio-windows-x64.zip
Detailed directory tree of obs-studio-windows-x64.zip

When OBS-Studio-Installer.exe is executed, it loads install.res.1033.dll via DLL sideloading. This library contains the instructions required to install both ScreenConnect and OBS Studio. The deployment relies on native Windows utilities (msiexec.exe), but the attackers renamed the standard MSI packages to look like DLL files:

  • Assets\x86\Data\vcredist_x64.dll: ScreenConnect installer
  • Assets\x86\Data\vcredist_x86.dll: OBS Studio installer

The contents of the vcredist_x64.dll MSI package are shown below:

ScreenConnect installation files
ScreenConnect installation files

The Windows Installer is launched to install ScreenConnect silently in the background without requiring a system reboot:
msiexec.exe /i "C:\Temp\OBS-Studio-Windows-x64\Assets\x86\vcredist_x64.dll" /qn /norestart
Once the installation wraps up, a new service named Microsoft Update Service is created. The command line for this service explicitly defines the connection server as r[.]servermanagemen[.]xyz.

Meanwhile, the MSI package for the actual OBS Studio software runs using a standard graphical user interface.

ScreenConnect and OBS Studio installation workflow
ScreenConnect and OBS Studio installation workflow

Expanding the investigation


The attackers’ reliance on the legitimate install.exe binary provided a crucial pivot point for our broader investigation. We discovered that this specific file was being deployed in the wild under a variety of suspicious aliases, including:

  • ds4windows.exe
  • crosshairx_installer.exe
  • obs-studio-installer.exe
  • dns jumper.exe
  • glary utilities pro.exe
  • processhacker-2.39-setup.exe

These file names indicate that the threat actor was disguising their ScreenConnect archives as popular utilities beyond OBS Studio. Among the fakes, we identified counterfeit installers for DS4Windows, DNS Jumper, Glary Utilities, and Process Hacker. Crucially, when we search for these utilities on major search engines, these fraudulent sites frequently appear at the very top of the organic search results. This indicates that the threat actor is actively leveraging SEO techniques to boost traffic to their landing pages.




Spoofed software portals appearing in search engine results

Spoofed software portals appearing in search engine results

For example, here is how the fraudulent download portal for DNS Jumper looks:

Fake website mimicking the official DNS Jumper resource
Fake website mimicking the official DNS Jumper resource

On this page, the download button directs users to the following address:
hxxps://direct-download.giize[.]com/dns-jumper/iopbsr4hymbo7nfa1q7j

Just like the OBS Studio variant, this drops an archive onto the victim’s device with an identical structure: a renamed legitimate install.exe file, a sideloaded library, and an Assets directory containing the promised software packaged alongside ScreenConnect.

Contents of the DNS Jumper and ScreenConnect archive
Contents of the DNS Jumper and ScreenConnect archive

Other fraudulent websites that appear in search engine results when querying the corresponding software are designed in a similar fashion.




Spoofed websites used to distribute ScreenConnect

Spoofed websites used to distribute ScreenConnect

Notably, the vast majority of the fraudulent sites we uncovered are localized into English, Russian, and Chinese. In several instances, the pages were also translated into German, French, Spanish, Arabic, and other languages. This multi-language support underscores the global footprint of the campaign, targeting a broad user base across multiple regions.

Language localization options on a ScreenConnect delivery site
Language localization options on a ScreenConnect delivery site

Fake domain infrastructure


To distribute ScreenConnect disguised as freeware, the threat actor spun up an extensive network of domain names mapped across three IP addresses. We have categorized these into two distinct infrastructure clusters.

Cluster 1: 162.216.241[.]242 and 198.23.185[.]81

```
162.216.241[.]242
Country: United States
Org name: Dynu Systems Incorporated
```
The connection graph below illustrates the campaign websites tied to IP address 162.216.241[.]242, which hosts the previously mentioned www[.]studioobs[.]com domain.

URL connection graph for IP 162.216.241[.]242
URL connection graph for IP 162.216.241[.]242

Looking into the registration dates for the domains on this IP, we found that the threat actor initially attempted to disguise their sites as various gaming portals:

Subsequently, starting in January 2026, they shifted strategy and began registering fake domains designed to mimic popular freeware:

In this specific branch of the ScreenConnect campaign, the malicious archives are hosted on fileget.loseyourip[.]com. Notably, the download resource is hosted on a completely separate provider:
```
198.23.185[.]81
Country: United States
Org name: NOHAVPS LLC
```
Our analysis of this second IP address revealed that it also hosts additional resources tied to the campaign, including fake gaming sites and supplementary download links:

URL connection graph for IP 198.23.185[.]81
URL connection graph for IP 198.23.185[.]81

Cluster 2: 2.59.134[.]97

```
2.59.134[.]97
Country: Germany
Org name: dataforest GmbH
```
Below is an infrastructure graph showing this IP address and its hosted domains. Notably, unlike the previous case, this address also hosts direct-download.giize[.]com, a resource used to store distributed malicious archives.

URL connection graph for IP 2.59.134[.]97
URL connection graph for IP 2.59.134[.]97

In this branch of the campaign, the threat actor skipped game-themed lures entirely, focusing exclusively on creating fraudulent freeware sites that bundled ScreenConnect with the requested application. The domains hosted on IP address 2.59.134[.]97 were registered between October 2025 and March 2026.
The chart below shows the volume of fraudulent websites created month by month:

Breakdown of ScreenConnect delivery sites by theme, August 2025 through March 2026 (download)

C2 infrastructure analysis


In total, we identified dozens of different archives distributed across this campaign. All of them share a uniform file structure, containing the malicious install.res.1033.dll library and the ScreenConnect MSI package located at Assets\x86\vcredist_x64.dll.

In some instances, the ScreenConnect installation package also bundles a CAB archive.

Contents of the CAB archive
Contents of the CAB archive

This archive contains a system.config XML file, which defines the connection address for the ScreenConnect C2 server:

Contents of system.config
Contents of system.config

By analyzing these ScreenConnect installations, we uncovered additional C2 addresses, which are mapped out in the following graph:

Connection graph of ScreenConnect C2 domains
Connection graph of ScreenConnect C2 domains

The next graph illustrates the AsyncRAT command-and-control infrastructure:

AsyncRAT C2 server infrastructure
AsyncRAT C2 server infrastructure

Based on the registration dates of the C2 domains, we can determine that the campaign was launched in October 2025 and paused at the end of March. However, at the time of publication, many of the landing pages remain accessible via search engine results.

Takeaways


Investigating a single case of AsyncRAT delivered via ScreenConnect allowed us to uncover a massive, multi-domain, multi-language infrastructure designed to distribute a hidden installer for this software and further advance the attack. The threat actor disguises ScreenConnect as popular utilities and distributes it through fraudulent websites that mimic official product pages. The attackers leverage search engine optimization techniques to push these sites to the top of search results in engines like Google and Bing.

This attack chain targets both everyday consumers downloading free software from the internet and corporate networks, where remote access tools are frequently allowlisted and granted elevated privileges.

The potential objective of the campaign is to steal credentials en masse and gain unauthorized access to systems for subsequent resale on dark web marketplaces.

To mitigate the risks associated with this threat, we recommend implementing the following security measures:

  • Enforce strict software installation controls: application allowlisting and blocking MSI package execution from untrusted sources
  • Continuously monitor for the creation of new remote administration services and scheduler tasks
  • Filter outbound traffic to unknown domains and IP addresses
  • Regularly train users on safe downloading practices
  • Verify the authenticity of all software sources

For enterprise users, credential monitoring is a critical mitigation strategy against the risks detailed in this article, as a leaked account or compromised system access frequently serves as a vector for subsequent attacks on the organization. Kaspersky Digital Footprint Intelligence provides continuous data monitoring across open and dark web sources, enabling security teams to respond proactively to potential threats.

Detection by Kaspersky solutions


Kaspersky Managed Detection and Response detects the malicious activity described in this post using the following indicators of attack:

  1. ScreenConnect service creation with suspicious parameters
    logsource:
    product: windows
    category: security
    detection:
    selection_access:
    EventID: 4697
    Service File Name|contains:
    - 'e=Access'
    - 'ClientService.exe'
    selection_support:
    EventID: 4697
    Service File Name|contains:
    - 'e=Support'
    - 'ClientService.exe'
    condition: selection_access or selection_support
  2. Anomalous child processes being spawned by the ScreenConnect service
    logsource:
    product: windows
    category: process_creation
    detection:
    selection:
    ParentImage|endswith:
    - '\\ScreenConnect.ClientService.exe'
    - '\\ScreenConnect.WindowsClient.exe'
    - '\\ScreenConnect.WindowsBackstageShell.exe'
    - '\\ScreenConnect.WindowsFileManager.exe'
    Image|endswith:
    - '\\powershell.exe'
    - '\\cmd.exe'
    - '\\net.exe'
    - '\\schtasks.exe'
    - '\\sc.exe'
    - '\\msiexec.exe'
    - '\\mshta.exe'
    - '\\rundll32.exe'
    condition: selection

Additionally, Kaspersky products detect the malware covered in this post under the following verdicts:

  • Trojan.Win64.DLLhijack.*
  • Trojan.VBS.Agent.*
  • Trojan.PowerShell.Agent.bav
  • Trojan.JS.SAgent.sb

Endpoint malicious activity can be monitored using Kaspersky EDR Expert. Specifically, security teams should look for the execution of commands and scripts containing suspicious patterns, such as XOR operations used for command and data obfuscation by malware operating on the host. This activity is flagged by the suspicious_assembly_loading_into_powershell_via_reflection_amsi and xored_powershell_command_amsi rules.

Additionally, persistence mechanisms involving the creation, modification, or utilization of scheduled tasks via the schtasks.exe utility are caught by the scheduled_task_create_from_public_directory_via_schtasks rule.

Malicious code injection into the RegAsm.exe process — leveraged by attackers to masquerade execution behind a trusted system component — is detected via the code_injection_to_unusual_process rule.

To visualize the stages of the attack, security teams can utilize Kaspersky Cloud Sandbox on the Threat Intelligence portal. For instance, this tool allows defenders to map out the entire deployment and payload execution chain originating from the initial VBS dropper.

Furthermore, the Kaspersky Threat Intelligence portal supports searching and graphing the connections between malicious domains and files involved in this campaign, as demonstrated in our adversary infrastructure analysis section.

Finally, the Similarity engine within Kaspersky Threat Analysis profiles file contents to hunt down samples resembling the original threat, helping organizations identify new or previously undetected malicious objects.


Indicators of compromise

Loaders


B32810973132D11AFD61CCEE222BBB79
5B7E1FE55BD7B5EA54BD4ED1677E5A26
9A9CCD8B0E5D05F4EE77667B024844DB
0EEE9BAD07E22415439E854657FA1366
8F4E8B680D3E8D3F5AC39BD72882F713

Malicious library: install.res.1033.dll


5F96C04E3AFAE97017B201BE112284D2
73BEAD922109A61E5F9F85771A7812C5
EDFF4F58722C93D7C09ED71899416396
83601C3D4ED28E8D2BE1B99BEB8EC18C
695E794631EF130583368770E7B81E98
83601C3D4ED28E8D2BE1B99BEB8EC18C
1E6A5C7B620D487D0CFC6874C3B77C90
54025CE2A9405039899FE99A1D77E0BB
BD05FCF80E493CF9AA71EC510319469D
999A63730C9634481D1D76955A2E76A8
479BD3BB617B39CD4A46D0768A2592D4
776DFD3DF9C04BB9FCDD6C1880C3761A
8E4C57358A66EB14D31ABB614DDC68DE
A40D3AEB0DAE5B00BDB3A517F3135BBB
A85A5BFDCB7C65AB93043B8CF9E20065
01325880EFFFEC546F59490089A3B415

AsyncRAT C2


mora1987[.]work[.]gd

Fake websites addresses


ds4windows[.]io
direct-download[.]giize[.]com
tmodloader[.]org
tmodloader[.]app
ds4windows[.]net
losslessscaling[.]app
processhacker[.]dev
steamtools[.]pro
dnsjumper[.]app
free-download[.]camdvr[.]org
defendercontrol[.]org
dns-jumper[.]com
cpuz[.]app
processhacker[.]org
processhacker[.]app
steamtools[.]cc
cpuz[.]pro
wallpaper-engine[.]app
processhacker[.]net
antimicrox[.]net
defendercontrol[.]app
tmodloader[.]pro
dnsjumper[.]io
bandicam[.]app
mgba[.]app
dnsjumper[.]pro
ferdium[.]app
ds4windows[.]pro
lossless-scaling[.]online
defender-control[.]com
gom-player[.]app
defendercontrol[.]pro
lossless-scaling[.]download
antimicrox[.]pro
mgba[.]pro
lossless-scaling[.]app
losslessscaling[.]pro
mgba[.]dev
tmodloader[.]download
tmod-loader[.]com
defendercontrol[.]download
ferdium[.]pro
deadreset[.]com
gom-player[.]net
crosshairx[.]pro
libreoffice[.]pro
studioobs[.]com
studio-obs[.]net
crosshairxv2[.]com
km-player[.]com
corel-draw[.]net
glary-utilities[.]com
download-full-version[.]ooguy[.]com
crosshair-x[.]com
kms-tools[.]com
studio-obs[.]com
crosshairx[.]net
clair-obscur-33[.]com
vlc-player[.]net
arksurvival-ascended[.]com
elden-ringnightreign[.]com
ready-ornot[.]com
arma-reforger[.]com
crusader-kings[.]com
crosshairx2[.]com
mediaplayerclassic[.]net
bandizip[.]pro
obs-studio[.]site
ovr-advanced-settings[.]com
studio-obs[.]pro
vlc-media[.]com
clair-obscur-33[.]town
ovr-toolkit[.]com
crusader-kings[.]church
bandizip[.]net
apexlegends[.]org
obs-studio[.]pro
vlc-media[.]net
crosshairx[.]site
monster-hunterwilds[.]com
km-player[.]pro
mediaplayerclassic[.]pro
kms-tools[.]net
fernbus-simulator[.]com
studioobs[.]pro
bandicam[.]cc
crystaldiskmark[.]cc
crystaldiskmark[.]io
crystaldiskmark[.]dev
crystaldiskmark[.]app
crystaldiskmark[.]pro
bandicam[.]io

Fake domain infrastructure


fileget.loseyourip[.]com
file-download-crosshairx.giize[.]com
all-toll-free.loseyourip[.]com
mpc-update.giize[.]com
all-toll-free.publicvm[.]com
198.23.185[.]81
direct-download.giize[.]com

ScreenConnect C2


servermanagemen[.]xyz
185.254.97[.]249
r.manage-server[.]xyz
45.145.41[.]205
winservec[.]net
manageserver[.]xyz
cloudsynn[.]com
pingserv[.]pro
ehostservers[.]xyz
serverdnsplan[.]net
pingpanl[.]pro
managedevice[.]xyz
edgeserv[.]ru


securelist.com/tr/the-soc-file…

OpenClaw: risks for agent users and how to mitigate them


The media in this post is not displayed to visitors. To view it, please log in.

OpenClaw, which was previously known as Clawdbot and Moltbot, is today one of the most successful and fast‑growing ecosystems for AI agents, recognized worldwide. The project quickly became popular with users because of its flexibility and ability to solve fairly complex tasks that previously required a lot of time for automation and execution. A dedicated marketplace appeared quickly after the project started gaining traction, where developers and users began publishing tools for working with it. Currently, employees all over the world use OpenClaw to automate their tasks, often unaware of risks this practice introduces to them and their employers.

In this article we will examine several security aspects of OpenClaw, look at how attackers can target this system, which vulnerabilities are already known, and how to protect against all of the listed issues.

OpenClaw skills


The project’s success was ensured by the fact that the agent accepts natural language instructions, does not require knowledge of programming languages, and allows the use of skills, which expand its capabilities. The overall architecture of OpenClaw can be seen below:

The OpenClaw overall architecture
The OpenClaw overall architecture

As shown in the scheme, the system is designed to be used along with agent skills. These skills can reside locally on a system where the agent is installed or can be obtained from external sources. At the time of writing this article, a dedicated hub named ClawHub is used for sharing skills among users.

One of the key features of OpenClaw skills is that they are easy to create and do not require coding. A skill is in essence a set of commands written in natural language, although it can contain code. Currently, there is a general description of the skill format: it is usually a text file named SKILL.md, although more complex variants can exist. The primary requirement for these files is that they use plain‑text formats. To illustrate what this looks like, here is a fragment of a skill:

Openclaw skill example
Openclaw skill example

The application areas for the OpenClaw skills are quite broad and can include everyday tasks such as checking email, performing routine operations and calculations on a computer, as well as more complex pipelines that handle testing, research, or software development. For most actions, the agent requires access to the operating system’s file system, as well as to the tokens and keys of the systems it will interact with. All necessary data are usually provided by users either through environment variables or in plain‑text files located alongside the agent.

Since many skills enable automation of work processes, employees worldwide actively use them. This fact, combined with the widespread adoption of the system and the overall popularity of artificial‑intelligence technologies, has attracted attackers to the project.

OpenClaw vulnerabilities


In less than two years, around 530 vulnerabilities have been discovered both in OpenClaw itself and in the underlying technologies. That said, the publication of OpenClaw vulnerabilities in the CVE database began only in February 2026. Below is a breakdown of these vulnerabilities by severity.

Registered vulnerabilities (download)
As shown in the chart, the number of high-severity vulnerabilities is quite large. Most of these vulnerabilities fundamentally involve issues with storing sensitive data and operating with excessively high privileges. Each of them can be exploited to hijack the agent or inject commands that it will execute.

Malicious skills


Besides exploiting vulnerabilities and deceiving users, there are more specific attack vectors against OpenClaw, namely, the skills.

Research logically draws a parallel between supply‑chain attacks and the distribution of malicious skills. However, unlike usual supply-chain attacks, creating malicious skills is trivial because there is no longer a need to develop custom malware.Despite this, until February 7, 2026, no skills underwent even a basic security check, which allowed malicious skills to appear immediately. Our scan of the skill hub in April, identified 24 accounts that were distributing more than 600 malicious skills. Overall, open‑source intelligence indicates that over 1,100 malicious accounts have been created since January.

Following the investigations and a lengthy effort to clean the skill repository of malicious entries, it was announced that files would undergo preliminary scanning with VirusTotal (VT) and NVIDIA’s SkillSpector. On the one hand, this is a more responsible approach to publishing skills; on the other, because OpenClaw is primarily an agent that executes a set of instructions, detecting malicious activity moves to a different level. Now it is necessary not only to analyze a file for dangerous commands that should be blocked, but also to examine all possible malicious behaviors that could be triggered by a harmful instruction within a skill. An example of a malicious command in natural language:

Example of a malicious command within a skill action
Example of a malicious command within a skill action

An example of a malicious command using a part of a bash command:

Malicious command inside a skill
Malicious command inside a skill

The example in the image and similar malicious skills are detected by Kaspersky products as HEUR:Trojan.ANSI.MalClaw.gen.

In addition, Kaspersky products monitor malicious OpenClaw skill activity on the system. Below are detection statistics from our systems that identified malicious OpenClaw client behavior. The data for June cover the first half of the month.

Statistics on Kaspersky product detections of OpenClaw malware (download)
As shown in the chart, even despite the measures taken to counter the publication of malicious skills, attacks continue. Therefore, it is important to employ layered protection that isolates the OpenClaw agent from critical data and infrastructure systems. We also recommend checking all skills that enter the organization’s perimeter. For this purpose, Kaspersky Scan Engine is suitable. This solution is designed to protect web applications, proxy servers, network attached storage and mail gateways. It can be integrated into almost any application, is easy to deploy and manage.

Malicious skill detected by Scan Engine
Malicious skill detected by Scan Engine

Additionally, monitor network accesses used by the agent. For this purpose, the project already provides a sandboxing subsystem and various wrappers for working with APIs and services. Last but not least, develop a comprehensive AI policy and make sure your employees never use third-party tools that are not explicitly allowed to use.


securelist.com/openclaw-securi…

Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk


The media in this post is not displayed to visitors. To view it, please log in.


About the vulnerability


The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. This software handles license management across various Schneider Electric products used for comprehensive industrial automation ranging from PLC programming to centralized control room implementation. Below, we break down how a single flaw can jeopardize an entire industrial facility, how to detect it on your workstations, and how to minimize the risks.

This vulnerability is a CWE-427: Uncontrolled Search Path Element issue. It stems from a system application referencing an OpenSSL configuration file at a hardcoded path without proper access controls.

This behavior allows a local non-administrator to craft a custom OpenSSL configuration file and force the lmadmin.exe system process – the core service that handles licensing – to load a third-party DLL. Consequently, the attacker’s code executes within the context of the service rather than a standard user account. Under specific conditions, this paves the way for further privilege escalation to the NT AUTHORITY\SYSTEM level.

Once NT AUTHORITY\SYSTEM access is achieved, the adversary can gain full control over local configuration files, sensitive system data, and secrets stored on the host. The potential for lateral movement to other nodes in the industrial network – such as engineering workstations – hinges on network connectivity, availability of stored credentials, and overall network architecture. Furthermore, the attacker can disrupt the operation of the license server itself, directly impacting the availability of engineering software and maintenance.

We will examine the role the FlexNet Publisher component plays within the Schneider Electric Floating License Manager (Schneider Electric FLM), why the hardcoded openssl.cnf path inside the application creates a critical hazard, what the exploit chain looks like, and the necessary mitigation steps to secure your environment.

The role of FlexNet Publisher in Schneider Electric FLM


FlexNet Publisher is a third-party commercial product by Flexera Software. The engineers behind Schneider Electric FLM, along with developers of numerous other industry solutions, integrate FlexNet Publisher as a library to manage product licensing. The underlying issue within FlexNet Publisher is that up to and including version 11.19.6.0, the library failed to restrict low-privileged users from modifying or replacing the openssl.cnf file. This is a textbook example of an Uncontrolled Search Path Element vulnerability (CWE-427).

Schneider Electric FLM relies on a combination of tightly integrated components:

  1. lmadmin.exe: a lightweight 32-bit daemon that services license requests coming from PLCs, HMIs, and SCADA modules. During installation, this component is automatically registered as a Windows service named lmadminSchneider. The service is configured to launch automatically and executes under the NT AUTHORITY\LOCAL SERVICE account.
    Properties of lmadminSchneider: the executable file and security context of the service
    Properties of lmadminSchneider: the executable file and security context of the service

    Properties of lmadminSchneider: the executable file and security context of the service

  2. The openssl.cnf configuration file located in the OpenSSL-contrib subdirectory. This configuration file can specify a path to engine-module, a custom DLL file that FlexNet can automatically load into the lmadmin.exe process space. The application references this configuration file via a hardcoded path built into the binary:C:\cygwin\home\nightly\LMADMI~1.4\tier1\lmadmin\contrib\openssl\_RELEA~1\openssl\openssl.cnf
    LMADMI~1.4 is the directory name in MS-DOS 8.3 filename format. Any user authorized to create directories in the root of C:\ can recreate this structure – by default, all authenticated users are allowed to do that. A clean, default installation of Schneider Electric FLM does not actually create that folder.
  3. The FlexNet Publisher component (historically known as FLEXlm): the license management library that reads openssl.cnf, specifically parsing the [engine] section. If a dynamic_path parameter is defined within that section, FlexNet Publisher will load the specified DLL module at the specified path without performing any checks.
  4. The Schneider Electric FLM web portal is a lightweight HTTP server embedded directly within the lmadmin.exe process. It provides access to two main areas: Dashboard (accessible without authentication) and Administration (password-protected). Because the web portal and lmadmin.exe share the same address space, any code loaded via FlexNet Publisher executes directly inside the lmadmin.exe process. This allows an attacker to easily intercept credentials for the Administration portal and leverage them to expand their attack surface across other systems.

SeImpersonatePrivilege assigned to the lmadmin.exe process
SeImpersonatePrivilege assigned to the lmadmin.exe process

The exploit path


To exploit this vulnerability, the attacker must first have the ability to execute arbitrary code locally on the machine hosting the vulnerable service. The primary weakness exploited here stems from standard Windows NTFS permissions: by default, the root directory of the system drive often allows the Authenticated Users group to create new folders. If these permissions (ACLs) have not been tightened, a non-privileged attacker can manually reconstruct the exact directory structure that lmadmin.exe checks for its OpenSSL configuration:
C:\cygwin\home\nightly\LMADMI~1.4\tier1\lmadmin\contrib\openssl\_RELEA~1\openssl\
Next, within this newly created openssl.cnf file, the attacker adds a parameter pointing to a malicious engine module hosted in a writeable directory, for example: dynamic_path = C:\\Users\\public\\malicious.dll. When FlexNet Publisher initializes OpenSSL, it parses this section. Upon finding the dynamic_path parameter, it uses it to load the attacker’s DLL. Because vulnerable versions of FlexNet are allowed to read an OpenSSL configuration from an initially non-existent, untrusted path, the lmadmin.exe process accepts the rogue configuration file as legitimate.

Example of a malicious openssl.cnf configuration file
Example of a malicious openssl.cnf configuration file

For lmadmin.exe to parse the openssl.cnf file and execute the malicious DLL, the lmadminSchneider service must be restarted. This can happen under any of the following conditions:

  • After a regular reboot of the host machine.
  • If the user possesses permissions to restart the service – by default, the Authenticated Users group is not allowed to do that.

Upon lmadmin.exe service startup, FlexNet Publisher initializes OpenSSL, opens the openssl.cnf configuration file, and parses the [engine] section. If a dynamic_path is specified, OpenSSL loads the corresponding DLL module directly into the lmadmin.exe process space. Once loaded, the code within the DLL executes in the context of lmadmin.exe. Because the service runs under NT AUTHORITY\LOCAL SERVICE, the malicious code inherits its privileges.

While the NT AUTHORITY\LOCAL SERVICE account is highly restricted by design, a significant risk for further privilege escalation remains. This exposure exists because, in a standard configuration, the service process is granted SeImpersonatePrivilege. This privilege allows the process to impersonate a client’s security context after authentication. Given an appropriate interaction scenario via RPC, COM, or named pipes, an attacker can exploit this to achieve local privilege escalation to NT AUTHORITY\SYSTEM. This is commonly done with tools from the Potato exploit family or similar impersonation abuse techniques. Consequently, while each individual step may appear unremarkable, their combination forms a complete exploit chain: moving from a low-privileged local user to executing code within a service context, and under the right conditions, to achieving a full escalation to NT AUTHORITY\SYSTEM privileges.

Mitigating CVE-2024-2658


  • If your organization does not rely on floating licenses, we recommend completely removing Schneider Electric FLM or avoiding its installation on workstations where it isn’t strictly required. Whenever feasible, use licenses tied to specific machines instead.
  • If still required, Schneider Electric FLM should be hosted on a dedicated server with strictly controlled user access.
  • Use an administrative account when creating the C:\cygwin directory and explicitly deny write permissions to the Authenticated Users group for this folder. This prevents staging a rogue OpenSSL configuration file along the hardcoded path.
  • Finally, update Schneider Electric FLM to version 3.0.0.0 or later.


Detection with Kaspersky solutions


Kaspersky Industrial CyberSecurity successfully detects exploitation attempts targeting this vulnerability. The KICS Vulnerability Manager module flags the presence of the vulnerable software version on endpoints, while the behavioral analysis engine tracks each stage of the attack chain – from the creation of the rogue configuration file on disk to the vulnerable service’s attempt to load the malicious library.

Detecting an exploitation attempt: an overview
Detecting an exploitation attempt: an overview

The KICS alert card consolidates details on the exploitation attempt alongside recommended defensive actions.
Description
The Exploit Prevention component of the EPP application detected attempts to exploit a vulnerability in a protected process. This type of attack may lead to malicious code execution, unauthorized access, or system integrity compromise.

EPP application data
● Object name: C:\Program Files (x86)\Schneider Electric\Floating License Manager\FLEXnet Publisher License Server Manager\lmadmin.exe.
● Status: Untreatable.
● MD5 hash: c3f57667d9e8e1b2375ba09cdf71cac8.
● SHA256 hash: 9dab845704d1999ec8ed089594cfd2173a08057f1caf9a2346c22c81039dbb7a.

Mitigations
● Analyze the event and identify the source of the startup or interaction with the process.
● Make sure that this vulnerability is relevant to your system (check the software version and installed updates).
● If a vulnerability exploit is confirmed, isolate the device and search for signs of compromise (suspicious files and their checksums, unknown processes/services, or queries to external IPs/FQDNs). Also, check for similar traces on other devices.
● Install security updates for the attacked software or operating system and run a full scan of the device if necessary.

Detecting an exploitation attempt: target process details
Detecting an exploitation attempt: target process details

Additionally, to proactively identify the presence of the vulnerability on a host as part of a continuous vulnerability management process, organizations can utilize the OVAL scanning task within KICS products. The following screenshot illustrates how KICS for Nodes highlights the presence of the vulnerable software version.

CVE-2024-2658 vulnerability details
CVE-2024-2658 vulnerability details

Conclusion


The CVE-2024-2658 vulnerability is a prime example of the consequences that dependency-loading mechanisms lacking proper validation can have. In the case of the Schneider Electric Floating License Manager, a local non-administrator can position a rogue openssl.cnf configuration file at the hardcoded path to inject a malicious DLL directly into the lmadmin.exe service context. Given a certain system configuration, this chain can be leveraged to escalate privileges to the NT AUTHORITY\SYSTEM level.

To remediate this vulnerability, organizations must immediately upgrade the affected component (FlexNet Publisher) to a patched version and restrict write permissions for non-privileged users to the C:\cygwin directory. Implementing these controls will significantly reduce exploitation risk, while Kaspersky Industrial CyberSecurity solutions can provide an added layer of defense by detecting anomalous behavior at the earliest stages of the attack.


securelist.com/tr/schneider-el…

From cause to cash: a cross-border look at hacktivist activity


The media in this post is not displayed to visitors. To view it, please log in.

While tracking the activities of 4BID we uncovered a new string of campaigns that appear to be the work of several interconnected actors. While politically motivated groups generally limit their scope to specific nations – for 4BID and its peers, primarily Russian and occasionally Belarusian organizations – our latest findings reveal a shift. The actual geographic footprint of these attacks became broader than expected, striking companies across Kazakhstan, the UAE, Syria, and Egypt.

What triggered our investigation was spotting a cluster of indicators of compromise within a breached Russian organization’s infrastructure. We used these footprints to successfully track down other environments hit by the same threat actors and piece together the bigger picture.

This article dives into the software deployed throughout these hacktivist campaigns:

  • New ransomware samples
  • Scripts used at various stages of the attacks
  • Commercially available IT remote monitoring and management (RMM) tools

These include both updated versions of known threat-actor tools and previously unseen software.

Overlapping activity streams


Within the initial organization’s infrastructure, we found numerous activity indicators linked to several interconnected hacktivist groups – which ultimately set the direction for our follow-up analysis. We can attribute the following findings to hacktivist activity with a medium level of confidence:

  • Several samples of BlackReaperRAT, which we attribute to the 4BID group, were found alongside scripts designed to download Panorama9 RMM, AnyDesk, and Dev Tunnels.
  • Besides the artifacts listed above, we discovered ClearWater ransomware in other compromised infrastructures. Interestingly, during this same window, public sources showed Hakerskii Kit claiming a successful attack on a Russian factory. Also detected in that facility’s infrastructure was ClearWater ransomware, with the attackers publicly thanking the С.A.S. group for their contribution.
  • We uncovered several samples of Warp RAT within the hit infrastructures, which we link to the Goffee threat group. A detailed report on this specific activity will be published at a later date.


Technical details

Vulnerable web servers and fd.aspx


Analysis of the compromised environments revealed that the attackers gained initial access in most cases by exploiting the ProxyShell vulnerability in Microsoft Exchange, which allows for full server compromise.

Once inside, the attackers deployed the fd.aspx web shell – a modular ASP.NET file designed for remote control, file transfers, and system reconnaissance. Communication with the web shell relied on a basic security check: if the key parameter in an incoming request failed to match the AUTH_KEY constant, fd.aspx simply returned “Access Denied”.

Access key verification
Access key verification

If the verification was successful, the command contained in the request’s scriptText parameter was passed directly to PowerShell, and the output returned to the operator in the body of the HTTP response. In environments where PowerShell execution was restricted, the web shell swapped it out for cmd.exe. The CreateNoWindow: true and UseShellExecute: false flags were used to keep the command execution hidden from the user.

Beyond running commands, the web shell features bidirectional Base64-encoded file transfers. This allows any binary data – like executables, archives, or certificates – to be passed right inside the body of an HTTP request. The UploadFile function writes files to any directory the web server process can access, which makes it easy to drop additional shells or swap out legitimate files. The DownloadFile function exfiltrates any accessible file from the compromised system back to the attackers’ C2 server.

The web shell also includes a system reconnaissance feature that grabs the following data points:

  • OSVersion: operating system version
  • MachineName: hostname
  • UserName: current username
  • UserDomainName: domain name
  • ProcessorCount: number of processors
  • SystemDirectory: system directory path
  • CurrentDirectory: current working directory
  • Version: .NET Framework version

Additionally, the reconnaissance feature uses the DriveInfo.GetDrives() function to enumerate running processes and map out connected drives – along with the amount of free space available on each. This file system reconnaissance is topped off with LastWriteTime metadata for each object, which helps the operator quickly spot recently modified files and get their bearings within the storage layout.

Alongside the web shells, we encountered a variety of scripts and C2 frameworks across all compromised infrastructures, which we break down below.

Scripts deployed


Once the attackers gained control over a target system, they moved on to the next phase: loading their required toolkit via custom scripts. Variations of these scripts were consistently found alongside fd.aspx on compromised hosts. Most of them interact with legitimate tools, which makes them look almost identical to routine administrative scripts at first glance. The only real giveaway is the code comments, written in Ukrainian. One such script is responsible for deploying AnyDesk on the compromised host.

The build quality of these scripts is worth discussing separately. Several of them show telltale signs of AI generation; inside some compromised systems, we found multiple iterations of the exact same script, a few of which were completely broken. AI-generated code typically fails to work out of the box and requires manual tweaking to run properly.

First, the script checks for admin privileges, as it cannot proceed without them. If that check passes, it looks for an active anydesk.exe process. If the process is missing, the script fetches and installs the application directly from the official website. Once AnyDesk is successfully installed, the script configures an unattended access password and pulls the unique AnyDesk ID. All the collected details are compiled into a report and exfiltrated to the attackers’ server at 185.221.153[.]121. Because we spotted simultaneous activity from multiple groups – 4BID, Hakerskii Kit, and C.A.S. – on the analyzed hosts, this IP address could potentially belong to any one of them.

Besides AnyDesk, the threat actors leverage other legitimate tools. One example is Microsoft Dev Tunnels, a Microsoft service that exposes a local server to the internet. It’s brought into the system by a separate script that, much like the one for AnyDesk, checks if the utility is already present before downloading it from the official site. In certain instances, the utility was fetched directly from the attackers’ server instead:


Once installed, the application runs, and the resulting connection details are saved to a file named login.txt. The contents of this file consist of standard instructions for using a provided code to authenticate on a Microsoft page through a web browser.
To sign in, use a web browser to open login.microsoft.com/device and enter the code

.
As a final step, the script opens up the required ports and creates the tunnel, giving the attackers a back door into the compromised host.

Another script we uncovered handles the installation of Panorama9, a legitimate remote monitoring and management utility. Immediately after downloading that application, the attackers configure it via the registry to hide both its system tray icon and its installation folder. To camouflage the Panorama9 services, the attackers rename them to Windows Update Helper and Windows Update Helper Cache and swap out their descriptions, making the utility look almost identical to standard system components. Once the utility finishes its job, the script clears its tracks.

The attackers used a dedicated script to establish persistence on the system. When executed, it used the net user command to spin up a local user account and then hid it via the registry. The script added this new user to every available local group; if the machine was domain-joined, it also attempted to inject the user into all Active Directory groups.

At the same time, the script tweaked RDP settings: it set the minimum encryption level through the registry, added a firewall rule to allow port 3389, and ran the relevant services.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/07125138/hacktivists-broaden-attack-geography-code-02.png][img=1200x169]https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/07125138/hacktivists-broaden-attack-geography-code-02.png[/img][/url]
After it wrapped up its main tasks, the script wiped the event logs, command history, temporary files, and finally itself. Once the attackers got what they wanted out of the infected host, they triggered another script that removed the previously created user account, cleaned out the registry keys generated during the earlier phases, and then deleted itself as well.

The scripts described here are just the most telling examples out of dozens of samples we found. An analysis of the attackers’ toolkit reveals a clear trend: they aren’t just fine-tuning the solutions they’ve used in the past (specifically, the AnyDesk deployment script), but are actively broadening their arsenal with new tools like Panorama9, Dev Tunnels, and others.
[h3]Publicly available utilities[/h3]
As previously mentioned, the attackers leverage a broad spectrum of dual-use public software, such as all kinds of remote monitoring and management utilities. While they use the scripts discussed above to drop some of the utilities onto systems, we didn’t encounter scripts for others, so we can’t confirm whether any exist. We observed the following tools deployed across the campaigns in question:
[ul]
[li]AnyDesk: a remote administration tool[/li]
[li]Advanced IP Scanner: a network scanning utility[/li]
[li]Dev Tunnels: a Microsoft service used for exposing a server to the internet[/li]
[li]Panorama9: an IT infrastructure management and monitoring service[/li]
[li]Nezha Monitoring: a server status monitoring utility[/li]
[li]Tactical RMM: a remote monitoring and management tool[/li]
[/ul][h3]C2 and communications[/h3]
To gain a foothold in the victim’s infrastructure, the attackers relied on several post-exploitation frameworks. Some of these are publicly available utilities, while others are custom-built.

Among the publicly available tools in the group’s arsenal are:
[ul]
[li]Sliver[/li]
[li]Havoc[/li]
[li]Apollo Mythic[/li]
[li]Adaptix[/li]
[/ul]
We also discovered a previously undocumented backdoor, dubbed [strong]BlackSalt[/strong], which contacts the C2 server to fetch commands and executes them via cmd.exe.
[h4]Sliver[/h4]
On several hosts, following the initial Microsoft Exchange server compromise, files named upd.exe, winhost.exe, update1.exe, update.exe, and akolo.exe were dropped alongside the previously mentioned fd.aspx files and scripts. All of them were located in the C:\Windows\System32\inetsrv\ directory and were configured as SFX archives with nearly identical payloads, which ran an install.bat script upon extraction.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05142954/hacktivists-broaden-attack-geography12.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05142954/hacktivists-broaden-attack-geography12.png]Contents of the SFX archive [/img][/url]
Contents of the SFX archive

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143056/hacktivists-broaden-attack-geography26.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143056/hacktivists-broaden-attack-geography26.png]The install.bat script contents[/img][/url]
The install.bat script contents

The script copies the malicious components into the Windows folder and installs servicechecker.bat as a system service. To do this, it leverages the legitimate [url=https://github.com/winsw/winsw/]Windows Service Wrapper [u](WinSW)[/u][/url] utility included in the archive under the filename backupsrv.exe. The archive also contains the WinSW configuration file, backupsrv.xml, which specifies exactly which script should be registered as a service. Once installed, servicechecker.bat is configured to run automatically on system boot.

The servicechecker.bat script, in turn, runs backupagnt.exe, a loader for the main malicious component housed in WindowsInternal.UpdateComponent.dll. This file was built with the help of the Donut utility and is encrypted with a simple single-byte XOR key (0x0F). Its primary job is to inject the Sliver code straight into the device’s memory.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143201/hacktivists-broaden-attack-geography2.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143201/hacktivists-broaden-attack-geography2.png]The backupagnt.exe loader code[/img][/url]
The backupagnt.exe loader code

All Sliver instances uncovered during this investigation were configured to communicate with the C2 server at 185.221.153[.]121 over mTLS.
[h4]Havoc[/h4]
Inside a similar SFX archive located in the user directory $user\desktop\ under the filename demon.x64.exe, we found another post-exploitation framework: Havoc. This instance was configured to communicate with the C2 server at 77.72.85[.]62.
[h4]Apollo[/h4]
Mythic Apollo is a cross-platform post-exploitation agent used within the Mythic framework to manage compromised systems. It provides a persistent connection to the C2 server, executes operator commands, handles file uploads/downloads, runs arbitrary code, and supports expansion via plugins. We previously provided a detailed breakdown of the Mythic framework in our post, [url=https://securelist.com/detecting-mythic-in-network-traffic/118291/]Hunting for Mythic in Network Traffic[/url].

Here is an example of the Mythic Apollo configuration we encountered in these hacktivist attacks:

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/07125225/hacktivists-broaden-attack-geography-code-03.png][img=1029x401]https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/07125225/hacktivists-broaden-attack-geography-code-03.png[/img][/url]
This specific sample of the .NET Mythic Apollo agent was compiled with an extensive suite of modules and supports multiple transport profiles that enable communication via HTTP, TCP, WebSocket, SMB, named pipes, and web shells. The C2 address 77.72.85[.]62 is hardcoded into its configuration.
[h4]Adaptix[/h4]
AdaptixC2 is another post-exploitation framework in the attackers’ arsenal. This is a relatively new open-source project, which we broke down in our post, [url=https://securelist.com/tr/adaptixc2-network-and-host-detection/119424/]Adapt or pay:an analysis of the AdaptixC2 framework[/url].

The agent samples discovered during our investigation into these hacktivist campaigns consist of a packed AdaptixC2 Beacon delivered via a custom x64 loader. Upon execution, the payload decrypts an embedded shellcode, allocates memory, and executes the malicious payload using the CreateThread WinAPI function. Packed inside the shellcode is the AdaptixC2 Beacon agent in DLL format, featuring a configuration encrypted using RC4.

According to the AdaptixC2 classification system, this agent falls under the BEACON_HTTP type. It is capable of executing commands, performing file operations, enumerating and killing processes, launching new programs, and exfiltrating data back to the C2. It also supports SOCKS port forwarding and BOF modules.

AdaptixC2 uses encryption to keep its configuration under wraps. The corresponding block contains the data size, the actual RC4-encrypted configuration, and a 16-byte key.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/07125354/hacktivists-broaden-attack-geography-code-04.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/07125354/hacktivists-broaden-attack-geography-code-04.png]Example agent configuration[/img][/url]
Example agent configuration

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143441/hacktivists-broaden-attack-geography7.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143441/hacktivists-broaden-attack-geography7.png]Example of agent requests pinging the C2 address, as flagged by Kaspersky solutions and displayed in Kaspersky Threat Lookup[/img][/url]
Example of agent requests pinging the C2 address, as flagged by Kaspersky solutions and displayed in Kaspersky Threat Lookup

[h4]BlackSalt Backdoor[/h4]
During the investigation, we also came across target infrastructures running vulnerable versions of Microsoft Exchange where – much like the Sliver cases – SFX archives named WindowsServiceHelper.exe were discovered in the C:\Windows\System32\inetsrv\ directory. Once extracted, the archive executed an install.bat file.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143530/hacktivists-broaden-attack-geography8.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143530/hacktivists-broaden-attack-geography8.png]SFX archive contents (09d0517a1f69feff8186655ae3b567e0)[/img][/url]
SFX archive contents (09d0517a1f69feff8186655ae3b567e0)

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143953/hacktivists-broaden-attack-geography10.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05143953/hacktivists-broaden-attack-geography10.png]The install.bat script contents[/img][/url]
The install.bat script contents

Similar to the other archives of this type, the script uses the WinSW utility to install the malicious components. In this specific case, however, the primary payload is a file named svc.exe, which turns out to be an obfuscated backdoor written in VBS. Much like the deployment scripts used for the remote management utilities, the code of this setup BAT script was clearly put together with AI tools and features comments in Ukrainian.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/08112721/hacktivists-broaden-attack-geography-00.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/08112721/hacktivists-broaden-attack-geography-00.png]Main backdoor loop[/img][/url]
Main backdoor loop

The backdoor is essentially a textbook reverse shell. Its capabilities boil down to fetching commands from the C2 server at 45.150.109[.]2, executing them via cmd.exe, and piping the output back to the C2.
[h4]EDR killers[/h4]
In their attacks, the threat actors deploy what are known as EDR killers: malicious tools designed to disable security software on the system. In the vast majority of cases, these utilities rely on the BYOVD technique.

On the hosts compromised during these hacktivist operations, we discovered samples named kil.exe and Killer.exe. These are modified versions of the public, Rust-based BYOVD project EDRKiller. The attackers streamlined the utility to act strictly as a client for the driver and expanded the hardcoded list of security processes to terminate. The sample targets the vulnerable Warsaw_PM driver, though it lacks the functionality to load the driver itself – the attackers drop it onto the system separately.

The general workflow plays out as follows:
[ol]
[li]In user mode, the program finds the PID of the target process.[/li]
[li]It opens a handle to \\.\Warsaw_PM.[/li]
[li]It constructs a buffer containing the target process’s PID.[/li]
[li]It calls DeviceIoControl.[/li]
[li]The driver executes the calls:[ul]
[li]ZwOpenProcess;[/li]
[li]ZwTerminateProcess.[/li]
[/ul][/li]
[/ol]
The EDR killer continuously enumerates processes, repeatedly sending the IOCTL and terminating the target processes every single time they pop up.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05144527/hacktivists-broaden-attack-geography24.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05144527/hacktivists-broaden-attack-geography24.png]Example of the process list storage inside the EDR killer[/img][/url]
Example of the process list storage inside the EDR killer

Both kil.exe and Killer.exe share the exact same list of processes targeted for termination:
MsMpEng.exe, SenseIR.exe, SenseNdr.exe, SenseCncProxy.exe, SenseSampleUploader.exe, NisSrv.exe, avp.exe, kavfs.exe, bdagent.exe, bdservicehost.exe, vsserv.exe, AvastSvc.exe, AvastUI.exe, aswidsagent.exe, avgsvc.exe, mfemms.exe, mfefire.exe, mfevtps.exe, dwengine.exe, dwservice.exe, elastic-agent.exe, elastic-endpoint.exe, Sysmon.exe, wazuh-agent.exe, ipban.exe
Another utility used to kill security software processes is ghostdriver.exe, an unmodified build of the open-source project GhostDriver. In this case, the attackers simply pulled a version straight from GitHub and didn’t modify any of its code.

[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05144818/hacktivists-broaden-attack-geography30.png][img=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05144818/hacktivists-broaden-attack-geography30.png]Example of output from the GhostDriver utility[/img][/url]
Example of output from the GhostDriver utility

The tool operates through the following stages:
[ol]
[li][strong]Identify target processes
[/strong]The program takes a list of process names (such as msmpeng.exe) via command-line arguments. If no list is specified, it falls back to a default set.[/li]
[li][strong]Enumerate system processes
[/strong]To locate PIDs, the tool relies on standard Windows APIs:[ul]
[li]CreateToolhelp32Snapshot[/li]
[li]Process32First[/li]
[li]Process32Next[/li]
[/ul][/li]
[li][strong]Generate a list of processes[/strong] to kill.[/li]
[li][strong]Load the vulnerable driver
[/strong]This is the core phase of the utility’s operation. During this step:[ul]
[li]The sys driver is written to disk.[/li]
[li]A SERVICE_KERNEL_DRIVER type service is created.[/li]
[li]The driver is kicked off via the Service Control Manager (SCM).[/li]
[/ul][/li]
[/ol]
[url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05145109/hacktivists-broaden-attack-geography31.png][img=680x263]https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/05145109/hacktivists-broaden-attack-geography31.png[/img][/url]

GhostDriver.sys is hardcoded inside the GhostDriver executable and is a binary driver known as [strong]RentDrv2 (BadRentdrv2)[/strong].

It contains the [strong]CVE-2023-44976[/strong] vulnerability, which allows it to:
[ul]
[li]Accept user-mode commands via DeviceIoControl.[/li]
[li]Perform operations on processes from kernel mode.[/li]
[li]Bypass security mechanisms, including Protected Process.[/li]
[/ul]
Upon execution, GhostDriver drops RentDrv2 to disk, loads it into the Windows kernel, and connects to it via the virtual device [code]\\.\rentdrv2
. The utility then issues command 0x22E010 to the driver, passing along the target process ID, and the driver terminates that process directly from kernel mode.

GhostDriver runs in a continuous loop. Every ~700 ms, it rescans for the target processes and sends out termination commands.

After the driver starts up, the utility attempts to delete the ghostdriver.sys file. To do this, it opens a file handle, uses the SetFileInformationByHandle WinAPI function to rename it to something like :GhostDriver, reopens the handle, and marks the file for deletion via FileDispositionInfo. Before wrapping up, it also tries to stop and remove the driver service, and delete the C:\rentdrv.log file where the driver writes its logs.

Example of the adversary command execution launching GhostDriver:

Current versions of Kaspersky products are resilient to these types of attacks: the utilities described in this post cannot terminate their processes.

Connection to the ClearWater ransomware


Alongside the previously described Mythic Apollo samples (C2: 77.72.85.62), backupagnt.exe loaders, and Panorama9 deployment scripts, we discovered a new ransomware strain named ClearWater across several compromised infrastructures. Written in C++ and compiled with GCC (MinGW), the sample is a 64-bit Windows executable. It features zero obfuscation; in fact, the binary wasn’t stripped of its DWARF debug information. This makes analyzing the sample significantly easier and points to either sloppiness or a lack of technical expertise on the developers’ part.

Original function names preserved within the Trojan's body
Original function names preserved within the Trojan’s body

When executed, ClearWater logs its progress in a separate console window.

The console window displayed upon launching the Trojan
The console window displayed upon launching the Trojan

File encryption


Like most ransomware strains, ClearWater is a Trojan designed to locate and encrypt the victim’s files. The Trojan executable contains a hardcoded RSA-2048 primary public key in PEM format.

For every file it processes, the ransomware generates a new 32-byte key and a 12-byte nonce – though only 8 of those 12 bytes are actually used – and encrypts the file’s contents via the ChaCha20 symmetric algorithm. The ChaCha key is then RSA-encrypted and appended to a specific data structure at the end of the file. To pull this off, the malware leverages cryptographic implementations from the open-source libsodium library.
struct
{
uint8_t label[4]; //'M', 'Y', 'E', 'K' marker
uint32_t rsa_encr_size; //size of RSA-encrypted data
uint8_t rsa_encr_data[256]; //RSA-encrypted ChaCha key
};
The Trojan processes all files except those with a .txt extension. This approach can easily break installed software, as it blindly encrypts both libraries and executables; however, it does explicitly skip the system directory during its search. Encrypted files are additionally appended with the .clear extension. The malware scans for targets on local drives as well as SMB network shares, which it maps out by using the net view command.

Additional functionality


Within every directory it processes, the Trojan drops the attackers’ demands into a file named CLEARWATER_README.txt.

Ransom note:
Ransom note:

Additionally, by modifying the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key, the malware sets up a persistence mechanism that automatically opens the ransom note with notepad.exe on startup.

ClearWater is distributed inside a self-extracting archive. The extraction script runs in silent mode (GUIMode=”2″), escalates privileges via a UAC prompt, drops the Trojan at C:\ProgramData\ClearWater_x64.exe, and kicks it off. Once the ransomware finishes running, the SFX archive cleans up after itself and wipes the original archive (SelfDelete=”1″).

Alongside this script and the Trojan executable, the archive includes a BMP image. The ransomware sets this image as both the desktop wallpaper (by tweaking the HKEY_USERS\<…>\Control Panel\Desktop\Wallpaper registry key and calling SystemParametersInfoA with the SPI_SETDESKWALLPAPER parameter) and the lock screen background (by modifying the LockScreenImagePath and LockScreenImageUrl values under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP).

Two variants of the desktop and lock screen image
Two variants of the desktop and lock screen image

To complicate system recovery after the attack, ClearWater performs several actions typical of ransomware:

  • Deletes shadow copies using the following commands:
  • Wipes the backup catalog and disables Windows Restore:
  • Removes restore points:
  • Disables the system startup recovery option:

ClearWater also features a kill_all_non_whitelisted_processes() function designed to terminate active tasks, though it doesn’t actually call it during execution. This function leverages PowerShell to look up and kill any process whose name isn’t included in a hardcoded allowlist within the Trojan’s body. It uses the following PowerShell code to do this:
Get-Process|Where-Object{$w -notcontains $_.Name.ToLower()}|Stop-Process -Force
The exclusion list contains various essential system processes and breaks down as follows:
system, idle, smss, csrss, wininit, services, lsass, winlogon, svchost, explorer, dwm, shellexperiencehost, runtimebroker, trustedinstaller, tiworker, textinputhost, taskhostw, mousocoreworker, fontdrvhost, audiodg, sihost, spoolsv, taskeng, taskhost, searchui, securityhealthservice, startmenuexperiencehost, searchindexer, backgroundtaskhost, sppsvc, wmiprvse, wudfhost, vboxservice, vboxtray, vmtoolsd, vmwaretray, vboxguest, vmsrvc, vgauthservice, vmacthlp, qemud, qemu-ga, msdtc, searchprotocolhost, wlanext, dllhost, conhost, comppkgsrv, msmpeng, mssecflt, systemsettings, securityhealthsystray, nvtray, nvvsvc, ravbg64, igfxtray, igfxem, igfxcuiservice, igfxhk, igfxext

Updated Blackout Locker


In a previously published report (link in Russian) on collaborations between several hacktivist groups, we highlighted a tool called Blackout Locker. In late January 2026, the 4BID group ran a series of attacks against organizations in Russia using an updated version of this malware. This section breaks down the new version of Blackout Locker and covers its key characteristics uncovered during our analysis.

Rust dropper


The attackers use a dropper written in Rust to distribute Blackout Locker. Depending on the specific sample, the dropper first carries out a series of staging actions. It then writes the payload executable to …\Users\[USERNAME]\AppData\Local\Microsoft\[REDACTED].dat and swaps its extension to EXE by calling the Windows command prompt:


After that, it launches the renamed executable.

Blackout Locker


The primary tool deployed in the attacks in question is an updated version of Blackout Locker.

Our analysis revealed that the key difference in this new version is the addition of a screen locker component, which it drops and executes in tandem with the ransomware’s main background payload.

During the initial phase, the screen locker file is created under the following paths:


To launch the screen locker, several tasks are created:


The screen locker is also written to the following registry keys:


After this, two LNK files, SystemHelper.lnk and WindowsHelper.lnk, are created via PowerShell for subsequent execution:

  • The first file is placed in the %PROFILEPATH%\All users\Start menu\Programs\Startup directory:
  • The second file is placed in the %USERPROFILE%\Start menu\Programs\Startup directory:

As a result, a shortcut is created in the startup folder pointing to WindowsSystemHelper.exe located on the desktop. This ensures the screen locker appears every time the user logs in. Even if the victim enters the correct password into the locker window, it will keep popping back up; while the window itself closes after password entry, the corresponding task is never actually deleted.

Screen locker


During execution, Blackout Locker generates a file named README.txt, which the screen locker later references to pull the text displayed to the user. Some Blackout Locker samples drop a ransom note written in English:

On the lock screen, it may look like this:

Other samples deploy a ransom note in Russian:

If the program fails to read README.txt, it falls back to a hardcoded ransom message. If this fallback message is in Russian but the victim’s operating system lacks support for Cyrillic encodings, the loader’s on-screen output renders as garbled text.


Attack geography


The majority of the compromised infrastructures belong to Russian and Belarusian organizations, which aligns with the stated agenda of these hacker groups. However, for the first time, we identified victims in other countries with no relation to this agenda: Kazakhstan, the UAE, Syria, and Egypt. Within the network of a Kazakh aviation company, we detected multiple post-exploitation frameworks pointing to C2 servers at 77.72.85[.]62 and 185.221.153[.]121, traces of the Panorama9 and Tactical RMM platforms, and backupagnt.exe loaders. A similar footprint was observed in the infrastructure of an Egyptian hospital, though the familiar toolkit was augmented by the fd.aspx web shell. The remaining international victims exhibited a nearly identical combination of artifacts, with only minor variations.

While the primary targeting vector previously centered on Russia and Belarus, the threat actors now appear to be pivoting their attention toward the wider CIS region and the Middle East. This strategic shift correlates with a statement from a member of the 4BID group, who claimed that attacking Russia is no longer profitable.


Takeaways


The hacktivist groups discussed in this report are steadily expanding the geographical footprint of their campaigns, pushing beyond Russia and the wider CIS region. Alongside this expansion, we observe the growing use of ransomware and other tooling consistent with financially motivated operations, which may further influence their choice of victims.

This shift underscores the critical need for continuous threat landscape monitoring. To stay ahead of threat actors, organizations must look beyond the immediate risks facing their perimeter and proactively track emerging threats, including the tactics of groups targeting specific industry verticals or geographic regions.

Detection by Kaspersky solutions


Kaspersky solutions reliably detect the malicious activity in question at every stage of the malware lifecycle. This section outlines potential detection scenarios.
Publicly available dual-use software leaves numerous artifacts on targeted hosts, which helps Kaspersky Endpoint Detection and Response Expert trace the activity of these utilities.

For instance, network connections established with Panorama9 servers both during the initial software launch and throughout the tool’s operation trigger the panorama9_dns_activity rule. The Hunt Hub section of our TI Portal features detection rules for other event types and specific operating systems, searchable with the keyword panorama9. Similar rules exist for the other utilities described in this post: Tactical RMM, Nezha, and Dev tunnels.

GhostDriver.exe relies on an embedded vulnerable driver, which it drops onto the target host. The creation of these drivers is detected by the vuln_driver_created_by_unsigned_process rule family.

Ransomware is inherently quite noisy and so can be detected at various execution phases. The execution graph within Kaspersky Cloud Sandbox on our Threat Intelligence Portal visualizes the entire ClearWater execution chain, capturing key behaviors such as modifying the desktop wallpaper and deleting shadow copies.

ClearWater execution graph in Kaspersky Cloud Sandbox
ClearWater execution graph in Kaspersky Cloud Sandbox

Additionally, the Threat Lookup and Research Graph sections of Kaspersky Threat Intelligence Portal allow you to visualize and analyze the connections between the malicious domains and files used by the adversaries.

Visualization via Research Graph on Kaspersky Threat Intelligence Portal
Visualization via Research Graph on Kaspersky Threat Intelligence Portal

Kaspersky Threat Lookup demonstrating the connection between malicious files and the attackers' IP address
Kaspersky Threat Lookup demonstrating the connection between malicious files and the attackers’ IP address

Monitoring network traffic is another highly effective method for detecting the malicious activity described here. Kaspersky Anti Targeted Attack (KATA) with the NDR module detects the network communications of all malware samples in question utilized throughout this campaign.

For instance, upon detecting HTTP network activity characteristic of the BlackSalt backdoor, the system triggers an alert for the Backdoor.BlackSalt.HTTP.C&C rule triggering.

Examples of using the Kaspersky Anti Targeted Attack (KATA) platform with the NDR module to detect other agents described here – along with their detailed technical analysis – are available in our dedicated reports on Adaptix and Mythic detection.

Indicators of compromise

Web shells
26100db3f56880110a92a2b4742d6eaffd.aspx
cf682a6fee80a78be578b1edd82627fafd.aspx
2d5533fb65ebb50a5a5fd53e62d73b9afd.aspx
fe04d230db612ea24af3826fda667131fd.aspx
Scripts
2db94ee3ec69988588702bd77999a5d4any_local.ps1
f88d2b5c3b885ad5a9c1c44551bccc60main.ps1
1e1edf879b2dc6c9892a22bfa5985db1main.ps1
78250fa890220821e2b91e31b965de59main.ps1
f2af797ac45b9f578c53cc49e5797397auto_dev.ps1
0c32bfdf83ecebe3a1399d261dc8ff57auto_dev_test.ps1
e14cc9a959bbe16c48b8dff063b311f3auto_dev_test_multimple_task.ps1
36b3be503c6e34613ff50cb28e0f3ddbauto_dev_test_multimple_task.ps1
c12ebe625737ed0908b045e811f14ecdtun.ps1, auto_dev_test_multimple_task.ps1
1c0924f5711a24821921de5ad822213bgrant.ps1
d78adab5e16c26d4cd14fe38f77e29e6pan.ps1, pam.ps1
6cf548445c39aff844be96d73c89e376test.ps1
911a21aa999c324dc960d3498eec528eradiant.ps1
68e310de44c3165ffffa25bc495d6fc5
4f41a22b3e7469fb6b45a42d71ec7087
80e5bde401d6b0ca96015ae9cfeb6535
1c82a94c362a9e98a66ae57d6ff37900
fa04aeedc0d2f5bb6ed357fdae1c1435
AdaptixC2
555a6722436d7cf7de396e0c57d32a27
b974141ff9ad1efb60dd9e16977266ca
7da855b2fd9b52f9088e64d656164637
d08056c2ac28933d6843658c2c8c574f
038cab0c60c53cf12f048272014024c0
c183033d86d2e052b8eb0deb2136ab29
bc0ebf67986eea803b4c9633ed3a4bb5
18618f4b468ba4e64c2e1072a6da2134
1742a9fa35e253614b76ac0f687ba02e
c7eb6da3aa216816079a1b785097552a
3ee38b944e5c83922f99641846f7db0c
d8ff7f417d56fa2a3baf3c8933013a25
1ff222457f5e0e32adfa8341f260dde7
ede8ce887dd9ab7add0f0fc872d51369
1344e6bc51cea35befb4adff7a25899b
2a09162d72aa416e18bab46070043a13
841b7d3863b49f62d4faa9949ff5df38
1bd1ca848b15530e39792b4fe6f31367
Mythic Apollo
b36968b98046d1b033d84f292e7ca1cb
663a479d6d24c767f1d3229a0a91554b
54a308f734095d54ae0e1c86c849a2d8
3137958eb830186826d486afd9222aee
1d09499cb2d7d70df903b60602a58887
d74262f968dc3f378c4021a89d16a292
3d9cbc944f9a9e127550ffb4e8394965
bcd3859f4ddd72c4690d76c3b4ef8955
3a9b0875fc692944c180b165a83a0d17
c558e6a9d0a697c757aa6d7782e269c9
61647db645f7cc221046999ef1dbe1d1
02493e1cb684be6a1a1fc6334a56c516
a3dba01c76571adc0797801ff30f2b90
3f4fbba101b209b00e70787fd5bab819
cd0c5b9e4e47df4231d02ed87ff49f26
b8a13e808b5b5f1836d3e559755139d0
60f8b115aec8a13b0069efc84fc645f5
da55b5612a80ef20ec75b68151e7ff4b
7d35b4961914ad83a57f8832d8e870d8
334abbdc99d359aab2ea371dd4eda5f2
389a1bbdbf5c91bd1c179227f5ae0923
87d48fbccb4aaee95222e215ecb7ebec
76c819185e3c8b8557a2c3986ab80a7c
6d19c8eea11d50c01d20f18382a964d1
Other C2 frameworks
8db0adf8fd6dc6195d7ae55e37e49f97
08f3a14a2337eb9936c38f5159be007c
717ab7624c192f6f8dd38994116c28dc
d1c51b92939aa168f0951a8368841373
5398b7eaa94f0ee570b1c5642b559047
d65a79ea9257637c77cab6e087468912
008cd423ca45134d3343f66cced1d104
9741672506f26813c71839aaa6aa3882
06bed0a0906e52c764b3b7016d6a4428
upd.exe (SFX archive)
08c069f133ac27cbc02a0ed79e4e87baupd.exe
a36082c998391a3ebaf05ba4f834172cbackupagnt.exe
9810ea6752112b3569ddc096e1a72e1dsliver
update1.exe (SFX archive)
10824d14c814524155f2b529cf5fee43update1.exe
a36082c998391a3ebaf05ba4f834172cbackupagnt.exe
9810ea6752112b3569ddc096e1a72e1dsliver
akolo.exe (SFX archive)
242038139842ec79ec1044c64eb0804aakolo.exe
53ba13cc6066adfd67f8098c0a5b8ddebackupagnt.exe
9810ea6752112b3569ddc096e1a72e1dsliver
update.exe (SFX archive)
84bb66a982710c5536143a07d84e8749update.exe
a36082c998391a3ebaf05ba4f834172cbackupagnt.exe
9810ea6752112b3569ddc096e1a72e1dsliver
akolo.exe (SFX archive)
fa3c222f6b53d6a2e35a54600f6aa011akolo.exe
0b1870d57221eec6f3bbef648e71a724backupagnt.exe
5e81f72614db42615489266be11b1d09sliver
akolo.exe (SFX archive)
4c8a0531653b5398a35c6b1b80ff1350akolo.exe
83f66862c0cc40da20236fd6b47138fdbackupagnt.exe
5e81f72614db42615489266be11b1d09sliver
[REDACTED].exe (SFX archive)
56be07e46fd452315008ed246ebbf52b[REDACTED].exe
579e8bbd6a5bcca89b5acd6fb5db32dbbackupagnt.exe
dd8fea244afc8223b961f1d9d6ac8c5dApollo
WindowsServiceHelper.exe (SFX archive)
09d0517a1f69feff8186655ae3b567e0WindowsServiceHelper.exe
62123c39477389d500e74e82782adea5BlackSalt Backdoor
winexe.exe (SFX archive)
6d365de5c5a13006b7cadd6bc6876e84winexe.exe
2f40bcee90abed0898e92521da17e52dBlackSalt Backdoor
WindowsServiceHelper.exe (SFX archive)
6dfef58ef68fb7965a23da8be3141af9WindowsServiceHelper.exe
56d1de3159adbfda20aca593c99901f9BlackSalt Backdoor
[REDACTED].exe (SFX archive)
96dbdc2651d829bf9ba35674dd4bfcae[REDACTED].exe
129225b3e93c17f131bcc2a982ffb09aBlackSalt Backdoor
test.exe (SFX archive)
9f37fff7e5d22f83fc1c0872ad5332f9test.exe
cf54f6cbdb4dbf1ce6fc2e5be4ca3b20BlackSalt Backdoor
1.exe (SFX archive)
e99efd77392e2b4fe4d9bf5728a12b981.exe
129225b3e93c17f131bcc2a982ffb09aBlackSalt Backdoor
WindowsServiceHelper.exe (SFX archive)
f2dc794bf93887e281ad89209493065aWindowsServiceHelper.exe
2f40bcee90abed0898e92521da17e52dBlackSalt Backdoor
EDR killers
d13997b1716e4c82ab454285202eafdckiller.exe, 2.exe
ecb57d8793514aa02314417265b1853fkil.exe, 3.exe
3b974ff986445e5944c51179d19bd6beGhostDriver.exe

Network indicators
212.46.12[.]182
185.221.153[.]121
77.72.85[.]62
45.150.109[.]2
130.49.155[.]112
45.112.194[.]82
138.226.236[.]52
85.137.253[.]186


securelist.com/tr/hacktivists-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs
securityaffairs.com/194588/unc…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

Inchiesta Equalize, prime tre condanne per gli “esecutori” della tentata estorsione aggravata dal metodo mafioso

Francesco Baldo, Nicolas e Michael Chiera sono stati condannati rispettivamente a 3 anni e 2 mesi e a 2 anni e 10 mesi. Ha patteggiato un anno e undici mesi Fulvio Cilisto. Tutti sono ritenuti concorrenti nel piano di costringere la famiglia Motterlini a pagare molto meno di quanto vantato dalla società di Lorenzo Sbraccia

ilfattoquotidiano.it/2026/06/2…

@news

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

LINUX NEWS ITALIA

Ricordo con piacere che il punto di riferimento italiano all'#opensource, #Linux e #Freesoftware, è parte del Feriverso.

  • Potete seguirlo da qui
  • Commentare sia nel sito che da un'istanza qualsiasi.

Ma c'è anche il Forum community (anch'esso open source) proprio come era Internet un tempo.

ziobudda.org
@news

@informatica
@gnulinuxitalia

Cybersecurity & cyberwarfare ha ricondiviso questo.

DevConf Italia 2026


Il 7 e l'8 luglio, a Pavia è DevConf Italia 2026, evento dedicato a open source, sviluppo e infrastrutture moderne. 
La conferenza riunisce community, developer e ricercatori per discutere tecnologie emergenti, cloud, security e tooling.Maggiori informazioni e registrazione: devconf.it/2026/

🔗 Leggi il post completo

Cybersecurity & cyberwarfare ha ricondiviso questo.

#CISA Warns #BlueHammer Flaw Is Now Exploited in #Ransomware Attacks
securityaffairs.com/194577/sec…
#securityaffairs #mobile
Cybersecurity & cyberwarfare ha ricondiviso questo.

Anthropic says US lifts export ban on Fable 5
L: bbc.com/news/articles/cdr42623…
C: news.ycombinator.com/item?id=4…
posted on 2026.07.01 at 00:47:38 (c=1, p=9)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Sensitive content

in reply to Elena Brescacin

SelfHosting journey stopped for a while, now continues...

I stopped for a while working on my personal website as I had to translate another big project from English to Italian; but now I took it in hands again, and guess what - the redirect from "/wp" to the domain does no longer work. Reachable just via domain . ext / wp / page-name. But I configured nginx differently.
I'll check what happens...again...

Selfhosted reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

Come sarebbe un comunicato onesto su Palantir?

Finalmente uno spot pubblicitario su Palantir, sorprendentemente onesto e informativo.

youtu.be/mBW9QCVDSjY

@privacypride

Cybersecurity & cyberwarfare ha ricondiviso questo.

#RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
securityaffairs.com/194556/mal…
#securityaffairs #mobile
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

FortiBleed: uno sniffing è stato progettato specificatamente per FortiGate

📌 Link all'articolo : redhotcyber.com/post/fortiblee…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #malware #fortinet #fortigate #fortibleed

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CVE-2026-8037: Critical Pre-Auth RCE in Progress Kemp LoadMaster Puts Enterprise Networks at Risk
#CyberSecurity
securebulletin.com/cve-2026-80…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Critical wolfSSL Vulnerabilities Expose Billions of Servers and IoT Devices to Certificate Forgery and RCE
#CyberSecurity
securebulletin.com/critical-wo…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

PoC Published for CVE-2026-24294: NTLM Reflection Bypass Grants SYSTEM Access on Windows Server 2025
#CyberSecurity
securebulletin.com/poc-publish…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

SEO-Poisoned Bing Search Delivers BumbleBee Loader and Akira Ransomware to Enterprise Network
#CyberSecurity
securebulletin.com/seo-poisone…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Gaslight: un attacco informatico in Rust che confonde i sistemi di analisi AI

📌 Link all'articolo : redhotcyber.com/post/gaslight-…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #gaslight #coreadelnord

Cybersecurity & cyberwarfare ha ricondiviso questo.

#GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents
securityaffairs.com/194546/hac…
#securityaffairs #hacking #cybercrime #AI

Watch a Steam Controller Skitter Itself To Its Charge Puck


The media in this post is not displayed to visitors. To view it, please log in.

Hacks don’t have to be practical but it helps if they are educational or clever or amusing, as [Ray Foss] demonstrates with his auto-docking Steam Controller.

It’s an open-source web application that combines a camera, a Steam Controller, and some clever software for the sole purpose of saving the user from the tyranny of having to manually set the controller onto its magnetic charging puck. Instead, one can simply lay the controller down nearby and let the computer do the rest of the work.

First one fires up the web interface, ensures a webcam has a good top-down view of both the charging puck and the controller, connects wirelessly to the controller, then clicks a few points on the camera view to tell the system where things are.

After that, the system buzzes the controller’s haptic feedback motors to make it skitter across the desktop until — guided by the camera and implementing obstacle avoidance — it docks successfully with its magnetic charging puck.

It may not be super practical and may even seem a bit Rube Goldberg-esque, but it’s fun and demonstrates a few interesting things. One is moving a controller via slip-stick friction by asymmetrically pulsing the feedback motors. Another is automatically reducing the pulse frequency to make smaller movements when it gets close to the charging puck, for finer control.

The computer vision part also ignores anything in expected cable locations, removing the need to deal with them algorithmically. WebHID via the browser takes care of talking to the controller, and confirming a successful docking by watching messages to detect when charging has begun.

If this seems a bit familiar, it’s because this project was inspired by the work of [Very Lazy Pixels] which we covered previously.


hackaday.com/2026/07/01/watch-…

Rinaldo Giorgetti reshared this.

In merito ai recenti data breach


@Informatica (Italy e non Italy)
Ci stiamo abituando male, anzi malissimo. Nelle ultime settimane sono usciti articoli che descrivevano alcuni data breach subiti da aziende italiane, due in particolare hanno destato curiosità e clamore: il […]
L'articolo In merito ai recenti data breach proviene da Edoardo Limone.

L'articolo proviene dal blog dell'esperto di

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

TIM Red Team Research scopre una RCE su Webmin con CVSSv4 da 9,4 su 10

📌 Link all'articolo : redhotcyber.com/post/tim-red-t…

A cura di Redazione RHC

#redhotcyber #news #cybersecurity #hacking #vulnerabilita #linux #webmin #sicurezzainformatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

357 – L’Intelligenza Artificiale inizia a uccidere le persone camisanicalzolari.it/357-linte…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

RHC Conference 2026 - Nuove Prospettive per la Cybersecurity Data-Driven

📍Guarda il video: youtube.com/watch?v=UycUgws7Hd…

#redhotcyber #rhcconference #conferenza #informationsecurity #ethicalhacking #dataprotection

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Cloud Atlas, Mirai e infostealer sotto lo stesso tetto: la mappa dell’infrastruttura del cybercrime

📌 Link all'articolo : redhotcyber.com/post/cloud-atl…

A cura di Luigi Zullo

#redhotcyber #news #sicurezzainformatica #hacking #malware #cybersecurity #server #datirubati

From Sugar to Ethanol Fuel With a Little Microbial Help


The media in this post is not displayed to visitors. To view it, please log in.

In these trying times it seems appropriate to work through some ‘what if ‘ scenarios, such as the local gas station suddenly not having any more gasoline to sell you, or said gas station ceasing to exist altogether. In that case it can be incredibly useful to be able to create your own gasoline alternative in the form of ethanol. As demonstrated by [Hyperspace Pirate] in a recent video this process is fairly straightforward once you have procured an appropriate feedstock, such as here sugar (sucrose).

Although baker’s yeast (Saccaromyces cerevisiae) is more commonly associated with the production of ethanol-laced drinks, there’s nothing that says that you cannot distill out the approximately 10-15% ethanol that results from a yeast feeding frenzy and resulting waste products.

How to do this distillation step is explained in the video, with the mixture heated and put through a self-made reflux column to deal with the fact that the water/ethanol mixture is an azeotropic mixture, meaning that a lot of water is expected to make its way out of the condenser along with ethanol without this measure to condense as much of the water vapor before it can make its way to the top of the column.

Ultimately the conversion rate of plain white sugar to ethanol is about 54%, with the rest turning into CO2. With an appropriately converted combustion engine for running on 100% ethanol, it runs pretty well, though the final cost per liter of ethanol will heavily depend on your feedstock.

With the full costs of the electric heater of the distillation column taken into account – at 2.57 kWh/L – as well as the cost of the off-the-shelf sugar, [Hyperspace Pirate] with his Florida kWh cost of $0.12 paid around $2.62/L, or $9.91 per gallon. Even with how much prices at the gas pump have shot up recently, you’d pretty much need to find a free source of feedstock and otherwise optimize the process for it to make much sense, even in this economy.

That said, it’s crazy that the world of Mad Max doesn’t run on ethanol. If tomorrow a certain bubble were to implode and the global economy fell apart as a result, producing bioethanol would seem to be a highly marketable skill.

youtube.com/embed/RvfuDIWNzGc?…


hackaday.com/2026/06/30/from-s…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Venti agentici: 8.000 candidature e nessun impiego. Quanto vale oggi una laurea in Informatica?

📌 Link all'articolo : redhotcyber.com/post/venti-age…

A cura di Carolina Vivianti

#redhotcyber #news #integrazionedellAI #settoreinformatico #barrieregiovani #laureatiinformatica

How to Remove Bounce When Bouncy Objects Encounter Bounciness


The media in this post is not displayed to visitors. To view it, please log in.

We all love a good bit of bounce now and then, with everything from trampolines to bouncy castles and bouncy balls forming the staple of a wholesome childhood for many. That said, most of our bouncy experiences in day to day life concern bouncy objects that meet immovable or rigid objects, including said child having a blast in a bouncy castle. Where the physics get arguably more interesting and less intuitive is when you combine two objects that are both bouncy, with [Steve Mould] recently taking a look at the tuning of said bounciness to even kill the bounce completely.

Understanding how to achieve this tuning means understanding how the kinetic energy is stored in each flexible material, and how to dissipate it in a way that doesn’t result in the aforementioned bounciness. In the simple physical demonstration setup the addition or removal of weights to the lower sprung platform tunes the response to the bouncy ball that is dropped on top of it.

After going through the science behind bounciness and springiness using the practical application of this science in the context of golf balls and clubs, [Steve] introduces the simulation tool that he created. This allows you to tweak the parameters of such a double spring system, which may bring back some high school physics lessons for some.

In a system like that of a golf club and the ball, having undesirable oscillations (bouncing) reduces the final kinetic energy transferred to the ball. Although ‘bouncy’ is perhaps not the first thought that comes to mind when handling a golf ball or a club, ultimately they are just as bouncy as a bouncy ball or an electric switch, just on their own scales, with their own opportunities for optimization and analysis.

youtube.com/embed/EP1mYq8hLIY?…


hackaday.com/2026/06/30/how-to…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Pentagon warns US unable to fight two ceasefires simultaneously

duffelblog.com/pentagon-warns-…

reshared this

Building a Fiber-Coupled Laser Source for Precision Optics


The media in this post is not displayed to visitors. To view it, please log in.

A rectangular black box is shown, connected to a coil of fiber-optic wire. Out of the end of the fiber, purple light is emitted. A label in the lower right corner says "405nm Singlemode Light Source".

Laser diodes are convenient light sources, but for precise optical work their often-elliptical beam profile leaves something to be desired. One way to get around this is to couple the beam into a single-mode optical fiber, which then emits a circular Gaussian beam from the other end. For more advanced experiments, therefore, [Diffraction Limited] built this fiber-coupled laser source.

The simplest approach is to place the fiber directly against a light source, but this results in most of the light missing the three-micron fiber core. Optical fibers have an acceptance cone, and only light approaching from within this cone is coupled into the fiber. The design therefore uses an aspheric lens to focus light from the laser diode down to a tiny point matching the diameter of the fiber core, creating a cone of incoming light narrower than the acceptance cone.

The body of the laser source was CNC machined out of brass, with the laser-diode press-fit in one end. The lens stands in front of the diode, and was glued in place so that its focal point was just above the end of a mounting pin for the glass fiber. Positioning and fixing the fiber in place was the biggest challenge; [Diffraction Limited] could use the micro-manipulator from a previous video to position the fiber, but the UV-set glue used to fix it in place shrinks during curing, pulling it out of position. To deal with this, two set screws under the mounting pin allowed its position to be adjusted slightly after gluing. As expected, adhesive shrinkage meant that the completed source initially produced no light, but after the set screws were adjusted, the beam appeared.

For more on fiber-coupled lasers, check out [Les Wright]’s work. If you don’t have access to an aspheric lens, an anti-bumping bead could be a reasonable alternative.

youtube.com/embed/l26sCJn0sB4?…


hackaday.com/2026/06/30/buildi…

Tyorgg reshared this.