BTMOB Is No Longer One Android Malware Service
Flare found that BTMOB's official operation now sits among resellers, source-code buyers, private servers, and offers of uncertain authenticity, weakening infrastructure-only detection.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
Flare found that BTMOB's official operation now sits among resellers, source-code buyers, private servers, and offers of uncertain authenticity, weakening infrastructure-only detection.
Read article →The service preloads a payload-bearing PNG, copies a browser-specific command, and keys the final in-memory stage to the victim's public IP address.
Read article →A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Read article →Gitea 1.22.1 through 1.27.0 can let an anonymous request read files as the service account, expose the internal token, and plant a Git hook that executes during a clone.
Read article →INC ransomware activity raises the cost of treating an SMA 1000 hotfix as closure: affected appliances need log and configuration triage before defenders can trust them again.
Read article →An integration error routed wallet entropy through MicroPython's deterministic Yasmarang fallback. Updating prevents new weak seeds, but existing ones still require migration.
Read article →A compromised Adform tracking file used browser events, DOM observers and form-field hooks to keep substituting Bitcoin, Ethereum and Tron addresses.
Read article →A ServiceWorker and SharedWorker combine a clean Bun runtime, delivered PE sections, and locally generated bytes before a same-origin download.
Read article →A poisoned build can start a memory-resident loader, re-arm through macOS preferences, and seed more projects, Git hooks, and archives.
Read article →A crafted AD CS chase sent the CA to rogue directory services. July updates add a real-DC check, but defenders still need issuance and replication evidence.
Read article →IPMI's RAKP exchange exposes material for offline password cracking, leaving defenders with a management-plane incident that host telemetry may miss.
Read article →One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Read article →Actors changed controller IP addresses and passwords across at least seven states. Operators need known-good logic and connected-device evidence before closing an incident.
Read article →