ZeroHour

Search: “Microsoft Security”

20,959 stories

Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign

Aggah campaign abuses Bit.ly, BlogSpot, and Pastebin as multi-hop C2 to deliver RevengeRAT across the Middle East, US, Europe, and Asia.

Unit 42 details the Aggah campaign, which began with spearphishing emails in March 2019 spoofing a large financial institution and targeting education, media/marketing, and government organizations in the Middle East, later expanding to the US, Europe, and Asia. Delivery documents use Template Injection to load a remote OLE file whose macro runs mshta against a Bit.ly link redirecting to a BlogSpot post, which then uses Pastebin pastes to download RevengeRAT configured with a duckdns[.]org C2 domain. The embedded script also deletes Microsoft Defender signatures and kills Defender and Office processes, and modifies registry keys to enable macros. High-level TTPs resemble the Gorgon Group, but Unit 42 could not confirm attribution.

Palo Alto Unit 42 · 29d agoThreat actor

​​​​​​What’s new in Microsoft Security: August 2026

Microsoft's August 2026 security update roundup adds agent-activity insights, expanded environment coverage, and enhanced security management capabilities.

Microsoft published its monthly 'What's new in Microsoft Security' roundup for August 2026. The updates add capabilities for gaining insights into agent activity, expand security coverage across supported environments, and enhance security management across customer environments. No specific product names, CVEs, or incident details were included in the available text.

Microsoft Security Blog · 19d agoTools