Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Introduction
A newly identified campaign dubbed TerminalFix uses PowerShell as its primary weapon in multistage attacks targeting enterprises, following tactics similar to the ClickFix campaign. The attack chain includes the establishment of reverse tunnels that grant threat actors access into compromised organizational networks, enabling potential lateral movement and persistence.
Read full article at Dark Reading ↗Introduction
A threat actor leveraged multiple infostealer malware variants to harvest session credentials and gain unauthorized access to Claude accounts across an unspecified number of Anthropic users. The campaign demonstrates the ongoing risk that infostealers pose to SaaS platform users, particularly when session tokens are compromised and can be weaponized for account takeover.
ValleyRAT leverages legitimate-looking adware and DLL sideloading techniques to evade detection while enabling the Silver Fox threat actor to steal data and maintain control over compromised systems. By disguising itself within seemingly ordinary applications rather than relying solely on cracked software or fake updates, the malware demonstrates an evolving approach to persistence and evasion on infected machines.
A new wave of ClickFix attacks employs a sophisticated multi-stage infection chain that conceals malware within PNG image files before deploying a custom reverse tunnel to compromised systems. The technique represents an escalation in complexity for ClickFix campaigns, moving beyond simple fake support scams to establish persistent remote access on victim machines.