Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft has identified a cyberattack operation called CaptiveCrunch, attributed to Storm-2945 (a sub-cluster of Midnight Blizzard), that compromises hotel Wi-Fi networks to deliver fake browser updates. The malicious updates install CornFlake, a remote access trojan capable of capturing webcam footage, audio recordings, and keystrokes from infected devices. This attack vector specifically target
AITwo Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Two beta release versions of npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) from the DEV#POPPER malware family. The malicious packages execute encrypted JavaScript code automatically when imported into Node.js applications, creating a supply chain security risk for developers using these components.
AIGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
A new malspam campaign is exploiting Google's DoubleClick domain to bypass security detection systems and deliver the DesckVB remote access trojan (RAT). The attack leverages the trusted reputation of Google-owned infrastructure to route malicious traffic before redirecting victims to attacker-controlled servers. This technique exploits the fact that many enterprise security tools whitelist or dep
AIPakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
The Pakistan-aligned threat actor SideCopy has launched a targeted spear-phishing campaign against Afghanistan's Ministry of Finance, deploying the open-source Xeno RAT malware. The attack vector involves a ZIP archive containing a malicious LNK file with a Pashto-language filename designed to deceive targets into execution.
