Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIChina-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Cybersecurity researchers at ESET have discovered two previously undocumented Windows variants of the SprySOCKS backdoor, which was originally believed to target only Linux systems. The new variants, designated WIN_DRV and WIN_PLUS, feature hard-coded command-and-control configurations and support multiple communication protocols including TCP and UDP, representing a significant expansion of the C
AIFlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
Cybersecurity researchers have identified a macOS malvertising campaign called Operation FlutterBridge that distributes the FlutterShell backdoor through malicious Google and YouTube advertisements. Palo Alto Networks Unit 42 reports this represents an evolution of the JSCoreRunner (FileRipple) attack cluster previously documented in August 2025, indicating an ongoing and adapting threat campaign
