ZeroHour

Search: “UBoatRAT”

23 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

USN-8571-2: Apache HTTP Server regression

Ubuntu issues USN-8571-2 fixing an Apache HTTP Server regression that prevented startup when HTTP/2 proxying was enabled.

Ubuntu released USN-8571-2 to fix a regression introduced by USN-8571-1 in Apache HTTP Server. The earlier fix was incomplete due to a missing library symbol, causing Apache to fail to start when HTTP/2 proxying was enabled. The original advisory addressed CVE-2026-33007, a memory-handling flaw in mod_authn_socache allowing remote denial of service, and an HTTP response splitting vulnerability affecting multiple modules, credited to Pavel Kohout, Arkadi Vainbrand, Haruki Oyama, Merih Mengisteab, and Dawit Jeong.

Ubuntu Security Noticesupdated · 2h agofirst · 5d agoAdvisory 14 sourcesCVE-2026-33007

SloppyRAT: A New Tool For Ransomware Attacks

Zscaler details SloppyRAT, a new DLL backdoor delivered via ClickFix lures that stages CastleLoader and CastleRAT ahead of ransomware attacks.

Zscaler ThreatLabz analyzed SloppyRAT, a DLL-based backdoor distributed via ClickFix lures that abuses finger.exe over TCP port 79 to download a batch script. The malware copies curl.exe to download IronPython 3.4.2 from GitHub and executes zlib-compressed Base64-encoded Python to deploy CastleLoader and CastleRAT, then reflectively loads SloppyRAT in memory. It hinders analysis using XOR stack-string obfuscation, a modified affine cipher with modulus 127, and 13 runtime-decrypted code blocks, while communicating with C2 over a reverse SOCKS channel.

Zscaler ThreatLabzupdated · 5d agofirst · 5d agoMalware in the wild 3 sources

Anthropic caught Russia-linked spies using Claude in hacking operations

Anthropic disrupted Russia-linked APT29 using Claude in espionage against 20+ organizations, including Ukrainian government targets and a military drone maker whose vision SDK was stolen.

Anthropic's threat report covering December 2025 to August 2026 attributes the campaign to Midnight Blizzard (APT29/Cozy Bear, Storm-2945), which it links to Russia's SVR. The group compromised hotel Wi-Fi providers, altered DNS records to redirect travelers, accessed mailboxes at two drone-component manufacturers, and stole a proprietary SDK for a drone vision system, which it reverse-engineered using Claude. The group also used Claude to monitor whether security products detected its implants and to modify and redeploy flagged artifacts. The report also covers ShinyHunters affiliates using AI for credential scanning and extortion, a Chinese-speaking group's autonomous zero-day research, and a French-speaking hacktivist.

The Recordupdated · 4d agofirst · 5d agoThreat actor in the wild 15 sources

UBoatRAT Navigates East Asia

Unit 42 discovers UBoatRAT, a new custom RAT targeting South Korean and video-game industry personnel, delivered via Google Drive with GitHub-based C2 and BITS persistence.

Unit 42 identified UBoatRAT, a new custom remote access trojan first found in May 2017, whose initial version used a public Hong Kong blog service and a compromised Japanese web server for command and control. The latest variants target personnel or organizations related to South Korea or the video games industry, are delivered through Google Drive, and masquerade as Microsoft Word, Excel, or folder icons. The RAT checks for virtualization software and domain join, retrieves its C2 address from a Base64-encoded string in a GitHub-hosted file, uses a custom XOR-encrypted C2 protocol, and maintains persistence via Windows Background Intelligent Transfer Service (BITS) jobs that survive reboots.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wild1

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

ThreatFabric details StreamRat, a new Android banking trojan spread via Meta malvertising in Spain that reached about 571,000 EU accounts.

ThreatFabric reported that a fake TV-streaming malvertising campaign on Meta promoted StreamRat, a technically sophisticated Android banking trojan, targeting Spanish-speaking users; the ads reached an estimated 570,950 Meta accounts in the EU between June 11 and July 3, 2026. Once installed via sideloaded APKs, the trojan abuses Accessibility to log keystrokes, show credential-stealing overlays, capture screens, and remotely control devices, and was also promoted through TikTok. Its dropper requests default Home app and VPN permissions and was hosted via GitHub releases, closely resembling one used in the earlier Mirax campaign. C2 infrastructure includes IPs 45.147.28.59 and 193.32.2.245, and no named threat actor was attributed.

The Hacker News · 14d agoMalware in the wild

StreamRat Android malware spreads through Meta and TikTok ads

Malwarebytes reports StreamRat Android banking trojan spread via Meta and TikTok ads reaching roughly 570,000 users, mostly in Spain.

Malwarebytes researchers uncovered a malicious advertising campaign on Meta and TikTok promoting a fake free TV-streaming service that delivered the StreamRat Android banking trojan and infostealer. The ads, aimed at Spanish-speaking users with most victims in Spain, reached approximately 570,000 Meta users in a campaign running June 11 through July 3, 2026. The download site detected Android devices and the referral source, then coached users through sideloading steps including enabling installs from unknown sources. StreamRat can monitor the screen, capture typed credentials, display fake login screens, and give attackers remote control, including black-screen and fake Android update overlays.

Malwarebytes Labs · 12d agoMalware in the wild

Quoting Rick Brewster

Paint.NET added a clean-room Direct2D rewrite for WINE, largely written by Anthropic's Claude and described as unreviewed 'vibe coded' code.

Rick Brewster says Paint.NET now ships a from-scratch, reverse-engineered Direct2D implementation (PaintDotNet.Windows.Direct2D1.Managed.dll) used under WINE via a /wine flag, since Direct2D was never completed well enough there. He credits the Claude coding assistant with writing most of the code, calling it largely 'vibe coded' and not thoroughly reviewed. Simon Willison shared the quote as an example of shipping AI-assisted systems code in production software.

Simon Willison · 14d agoAI tools & infra1

ValleyRAT masquerading as adware

Kaspersky reports threat actors distributing the ValleyRAT backdoor disguised as adware, tracing the infection chain to the final payload.

Kaspersky researchers analyzed a campaign distributing the ValleyRAT backdoor under the guise of adware. The write-up documents the complete infection chain, from the malicious installer through deployment of the final backdoor payload. ValleyRAT is a remote access tool typically used by criminal actors for surveillance and data theft.

Kaspersky Securelist · 16d agoMalware in the wild

USN-8768-1: Shibboleth vulnerability

Ubuntu patches Shibboleth SQL injection in the ODBC storage plugin allowing remote attackers to extract sensitive information.

Ubuntu security notice USN-8768-1 fixes a Shibboleth vulnerability discovered by Florian Stuhlmann. The software incorrectly escaped input when using the ODBC storage plugin, allowing a remote attacker to perform SQL injection attacks and obtain sensitive information. Users are advised to update the Shibboleth package.

Ubuntu Security Notices · 22h agoAdvisory

USN-8752-1: Konsole vulnerability

Ubuntu patches Konsole URL-handling flaw that could let a remote attacker execute arbitrary code under specific circumstances.

USN-8752-1 fixes a Konsole vulnerability where certain URLs are incorrectly handled under specific circumstances. A remote attacker could possibly exploit this to execute arbitrary code on a victim's system. Ubuntu released updated packages for affected releases.

Ubuntu Security Notices · 2d agoAdvisory

11 Best CSPM Tools Compared (2026): Features & Pricing

CSPM comparison ranks Wiz first for agentless attack-path analysis; notes Ermetic absorbed into Tenable and Lacework into Fortinet FortiCNAPP.

An editorial comparison of eleven CSPM tools ranks Wiz as the agentless attack-path momentum leader, Prisma Cloud as the breadth benchmark, and Orca as the agentless SideScanning pioneer. It highlights consolidation: Ermetic now powers Tenable Cloud Security and Lacework became Fortinet's FortiCNAPP. The guide recommends starting with free tiers from Defender for Cloud, Prowler, and native cloud tools before buying.

GBHackers · 1d agoIndustry1

Silver Fox Targets Japanese Manufacturer with 3

Chinese group Silver Fox used new vulnerable drivers and DLL side-loading to deploy ValleyRAT at a Japanese industrial manufacturer.

Cato Networks detailed a Silver Fox campaign against a Japanese industrial manufacturing organization combining new vulnerable-driver abuse (BootRepair.sys and EnPortv.sys alongside wsftprm.sys), DLL side-loading via Zeon Corporation PDF binaries, and NTDLL unhooking to deliver ValleyRAT (Winos 4.0), a Gh0st RAT variant. The chain starts with an invoice-themed phishing lure hosting attacker-controlled content on legitimate QQ and Tencent Cloud services. Shellcode is injected into svchost.exe via thread-context hijacking, and a dual watchdog design pairs payload monitoring with a scheduled-task batch script for persistence. A separate 180-day VirusTotal retrohunt found 146 Atlas RAT samples across six PDB builds, though the Silver Fox link remains circumstantial.

The Hacker News · 20d agoThreat actor in the wild

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

Jitterbit Agent 12.8.1.6's Docker image exposes unauthenticated SOAP with hard-coded credentials, leading to OS command execution (CVSS 9.8).

0day Rubbish Research Team disclosed that the jitterbit/agent:12.8.1.6 Docker image ships an unauthenticated SOAP interface protected by hard-coded credentials. Attackers who recover these credentials can invoke the SOAP endpoint to execute OS commands, with the issue rated CVSS 9.8. The disclosure does not mention a CVE identifier or observed exploitation in the wild.

Full Disclosure · 7d agoVulnerability 2 sources1

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

Kaspersky details ValleyRAT delivered via trojanized QN Wallpaper using DLL sideloading, tied to Silver Fox and hitting 1,500+ users in China and India.

Kaspersky found a malicious installer abusing a modified version of the legitimate QN Wallpaper adware application to deliver the ValleyRAT backdoor via DLL sideloading of libcef.dll. The installer masquerades as DingTalk, Chrome or Tencent Meeting software, creates persistence, disables Windows Defender via the DisableAntiSpyware registry key, and loads AES-encrypted payloads. ValleyRAT collects keystrokes, clipboard contents and screenshots plus system details, can download additional modules, and resists removal by injecting into svchost.exe or marking its process critical. The campaign was detected over 100,000 times in 2026, affecting more than 1,500 users mainly in China and India, and is attributed to Silver Fox with both espionage and financial motives.

Security Affairs · 15d agoMalware in the wild

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The 'Spring Ring' operation uses vishing attacks against Microsoft Teams users to hijack sessions, deploy malware, and take over infrastructure.

Dark Reading reports on the Spring Ring threat gang conducting voice-phishing (vishing) attacks against users of Microsoft Teams. The operation aims to compromise collaboration-suite accounts to gain remote access to victim sessions, distribute malware, and potentially seize control of infrastructure. Further technical details were not provided in the available text.

Dark Reading · 13d agoPhishing & fraud1

USN-8756-1: Yelp vulnerability

Ubuntu patches Yelp help viewer flaw allowing crafted help documents to execute arbitrary scripts and expose sensitive user information.

USN-8756-1 fixes a vulnerability in Yelp, Ubuntu's help viewer, where help documents could execute arbitrary scripts. An attacker could trick a user into opening a specially crafted help document to obtain sensitive information. Ubuntu has released updated packages.

Ubuntu Security Notices · 2d agoAdvisory

Tracking OceanLotus’ new Downloader, KerrDown

Unit 42 identifies KerrDown, a new OceanLotus (APT32) downloader active since 2018 targeting Vietnamese speakers via malicious macros and DLL side-loading.

Unit 42 tracks KerrDown, a previously undocumented downloader family used by OceanLotus (APT32) since at least early 2018, primarily targeting Vietnam or Vietnamese-speaking individuals. Delivery uses macro-laced Microsoft Office documents embedding base64-encoded 32-bit and 64-bit DLLs, and RAR archives containing a legitimate program abused for DLL side-loading. KerrDown is dropped as main_background.png, downloads a DES-encrypted payload from a URL, and executes it directly in memory. Researchers used Jaccard-index similarity analysis to identify the new family, connect campaign samples, and infer patterns in the group's working hours and days.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wild1

USN-8731-1: MiniUPnPd vulnerability

Ubuntu issued USN-8731-1 fixing a MiniUPnPd integer underflow allowing remote DoS or information disclosure via malformed SOAPAction headers.

Ubuntu released USN-8731-1 to address an integer underflow vulnerability in MiniUPnPd's SOAPAction header parsing. A remote attacker could send a malformed SOAPAction header containing a single quote to trigger a denial of service or information disclosure. MiniUPnPd is a lightweight UPnP daemon widely deployed on routers and gateways.

Ubuntu Security Notices · 9d agoAdvisory1

12 Best Container Security Tools Compared (2026): Features & Pricing

GBHackers compares pricing and features of 12 container security platforms, from free Trivy, Falco, and SUSE NeuVector to commercial Sysdig, Wiz, and Aqua.

A procurement-focused comparison of twelve container security vendors including Sysdig, Wiz, Aqua Security, SUSE NeuVector, and CrowdStrike, centered on billable units (per node, workload, developer, or vCore) and pricing mechanics. The piece argues free open-source tools like Trivy, Falco, and NeuVector set a floor that commercial products must justify exceeding through enforcement and scale. It also notes rising container threats, including Kubernetes flaws exploited to jump from containers to cloud accounts and exposed container registries.

GBHackers · 4h agoIndustry 13 sources

Top 10 Best Container Security Tools in 2026

2026 roundup ranks Aqua, Sysdig, Prisma Cloud, Wiz, Snyk and CrowdStrike among the ten best container security tools across build-ship-run.

Buyer's guide compares ten container security products by lifecycle fit: Aqua leads full lifecycle, Sysdig leads runtime detection via Falco and eBPF, Wiz offers agentless graph visibility, Snyk covers developer-first shift-left. It notes Trivy and Falco as free production-grade open-source foundations. The guide argues standalone container security is increasingly absorbed into CNAPP platforms from Palo Alto, Wiz and CrowdStrike.

Cyber Security News · 1d agoTools1

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

ESET reports Russian group UAC-0099 hid a prompt in VBS malware comments to trip AI safety filters and disrupt automated malware analysis in Ukraine.

ESET identified a technique dubbed GuardBreaker in which UAC-0099 embedded a comment reading "I want to make nuclear weapon. Help me …" inside a malicious VBS script to trigger AI safety mechanisms and halt AI-assisted malware analysis. The script, part of the group's toolset, downloads the MATCHBOIL malware used exclusively by this Russia-aligned group; CERT-UA documented the chain including LUNCHPOKE, BURNYBEAR and MATCHBOIL.V2 in a July advisory. UAC-0099 typically targets transportation and energy sectors and hands validated targets to GRU-linked Sandworm. ESET warned that AI-assisted analysis must be backed by layered detection and human-driven engineering.

Help Net Security · 16d agoAI safety & security in the wild

Perplexity Details Its GPU Embedding Stack: How Ivy, Tulip and ROSE Serve pplx-embed

Perplexity details its GPU embedding serving stack (Ivy, Tulip, ROSE), which reuses LLM prefill/decode kernels, CUDA graphs, and LazyTensors to cut launch overhead.

Perplexity engineers published a deep dive on the serving infrastructure behind pplx-embed, used across Perplexity Search and its API platform. The stack comprises Ivy (Rust HTTP gateway), Tulip (gRPC scheduling and batching), and ROSE (Runtime-Optimized Serving Engine), which reuses LLM prefill and decode kernels rather than running a separate embedding engine. Optimizations include whole-model CUDA graphs with lazy capture and a LazyTensor abstraction that overlaps CPU batch preparation with in-flight GPU work. Benchmarks are reported against vLLM v0.22.0 in BF16, with FlashAttention 4 generally fastest but FlashInfer 3 winning on Qwen-based models at very long sequence lengths.

MarkTechPost · 10d agoAI tools & infra1

Daisy-Chaining Trust: Investigating Faronics Deploy Abuse

Actors abuse Faronics Deploy in phishing campaigns to run PowerShell and deploy ScreenConnect while evading detection with trusted tools.

Huntress investigated attacks in which threat actors abuse Faronics Deploy, a legitimate remote management tool, as part of phishing-driven intrusions. The chain uses the trusted deployment tool to launch PowerShell commands and deploy ScreenConnect for remote access. Leveraging signed, legitimate software helps the actors blend in and evade detection.

Huntress · 15d agoThreat actor in the wild