Skip to main content

Threats Tagged 'yara'

View all threats tagged with 'yara'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: yara

Threats Tagged 'yara'

Click on any threat for detailed analysis and mitigation recommendations

ICMP-Ghost is an open-source tunnelling framework that uses ICMP and DNS protocols for command and control (C2) communication. It is designed in x64 assembly and claims to evade endpoint detection and network intrusion detection systems. The framework supports dual-channel C2 with the ability to switch between ICMPv4 and DNS tunnelling on the fly. Detection rules using PacketSmith Yara-X modules have been developed to identify traffic generated by this framework.

Join the discussion

This content is a walkthrough and educational lab setup for hunting the Zeus Banking Trojan using tools like Suricata, Splunk, Volatility, and YARA. It details a hands-on malware analysis and detection engineering pipeline involving a Windows victim VM with Sysmon and an Ubuntu VM running Splunk Enterprise and Suricata IDS. The write-up is intended for defensive security study and SOC portfolio development.

Join the discussion

A newly discovered Rust-based DDoS botnet exploits exposed Docker APIs on port 2375 to recruit compromised hosts. The malware uses asynchronous Rust libraries and obfuscation techniques to evade detection, with no antivirus engines initially detecting it. Its command-and-control (C2) protocol is weakly secured, lacking encryption and using predictable nonces and hardcoded credentials. The botnet infrastructure is centralized on a single server, which serves both malware distribution and C2 functions. The researcher developed a honeypot that impersonates infected bots to monitor ongoing DDoS targets in real time. This threat highlights the risks of exposed Docker APIs and the challenges traditional detection tools face with modern Rust-based malware. European organizations running Docker with exposed APIs are at risk of compromise and subsequent participation in DDoS attacks. Mitigation requires immediate restriction of Docker API exposure, network segmentation, and deployment of custom detection rules based on provided YARA and Snort signatures. Countries with high Docker adoption and significant internet infrastructure are most likely affected. The threat is assessed as medium severity due to moderate impact and exploitation complexity but notable evasion capabilities.

Join the discussion

Operation PCPcat is a large-scale credential theft campaign that compromised approximately 59,000 Next.js servers within 48 hours by exploiting two remote code execution vulnerabilities (CVE-2025-29927 and CVE-2025-66478). Attackers extracted sensitive files such as . env files, SSH keys, and cloud credentials, installed persistent backdoors, and operated a publicly exposed command and control infrastructure. The campaign involves exploitation, data exfiltration, and backdoor installation. Organizations running Next.js in production are advised to patch vulnerable systems immediately and rotate all potentially compromised credentials. The threat is assessed as medium severity with potentially widespread impact due to the scale and sensitivity of data targeted. European organizations using Next.js may be particularly at risk.

Join the discussion

RondoDox v2 is a significantly evolved botnet variant that has expanded its exploit capabilities by 650%, now leveraging over 75 CVEs across 16 different architectures. Originally targeting DVRs and routers, it has broadened its scope to include enterprise systems, indicating a shift towards more valuable targets. The botnet employs new command and control (C&C) infrastructure hosted on compromised residential IP addresses, complicating detection and takedown efforts. Although no known exploits are currently observed in the wild, the botnet's increased sophistication and scale pose a high risk. The threat actor is identifiable by an open signature email, and detailed technical analysis including dropper behavior, binary decoding, and detection rules are available. European organizations face heightened risk due to the targeting of enterprise systems and the widespread use of vulnerable devices. Mitigation requires targeted patch management, network segmentation, deployment of YARA and IDS/IPS rules, and enhanced monitoring of residential IP traffic. Countries with large enterprise sectors and significant IoT device usage, such as Germany, France, Italy, and the UK, are most likely to be affected. Given the high impact on confidentiality, integrity, and availability, ease of exploitation, and broad scope, this threat is assessed as high severity.

Join the discussion

RondoDox v2 is an advanced IoT botnet that has significantly expanded its attack surface, now supporting over 15 exploitation vectors and targeting enterprise environments beyond consumer devices. It supports 16 different CPU architectures and uses XOR obfuscation to evade detection. Command and control infrastructure is hosted on compromised residential IPs and multiple AWS EC2 instances, indicating a sophisticated and distributed setup. This evolution from a simple DDoS botnet to an enterprise-ready threat raises concerns about its potential impact on critical infrastructure and business networks. Detection rules and IOCs are available, including YARA and Snort/Suricata signatures. Although no known exploits in the wild have been reported yet, the high number of exploit vectors and expanded target scope make it a high-severity threat. European organizations, especially those with extensive IoT deployments and cloud infrastructure, should be vigilant. Countries with large enterprise sectors and significant AWS usage are particularly at risk. Immediate mitigation steps include deploying updated detection signatures, network segmentation, and enhanced monitoring of IoT devices and cloud assets.

Join the discussion

FlipSwitch introduces a new syscall hooking technique for Linux kernel 6.9+, bypassing traditional methods rendered obsolete by changes in the syscall dispatch mechanism. The technique locates the original syscall function, scans the x64_sys_call function's machine code for a specific call instruction, and modifies its offset to redirect to a malicious function. This precise method leaves minimal traces and can be fully reverted. FlipSwitch demonstrates the ongoing evolution of attack techniques in response to kernel hardening efforts, highlighting the cat-and-mouse game between attackers and defenders in cybersecurity.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: yara
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses