Tech News
← Home  ·  All topics

Remote Access

6 GoKawiil briefs on this topic

SectopRAT Backdoor Found Hidden in Legitimate Italian Audio Software

Fortinet's FortiGuard Labs identified a new variant of the SectopRAT remote access Trojan concealed within legitimate digital-audio software from an Italian company. Researcher Xiaopeng Zhang said attackers modified the FrameworkBase.dll file after the software was already installed on victim machines, secretly loading the SectopRAT payload rather than compromising the vendor itself.

Fake mathjs npm package hides encrypted backdoor triggered by equation solving

Security researchers at SafeDep discovered that a malicious npm package called mathmain, disguised as a copy of the popular mathjs library, contains a hidden remote access implant. The malicious code stays encrypted and dormant until a specific equation is solved using the library's lusolve() solver function, which acts as a decryption key to unlock and execute the payload.

North Korea's WaterPlum hackers infect 30,000 devices via fake job coding tests, steal $10.7M

Cybersecurity agencies from Japan, the US, Australia and Germany issued a joint advisory identifying North Korea's WaterPlum group as the actor behind malware hidden in fake job application coding tests. The scheme has infected over 30,000 devices across 100 countries and compromised more than 7,000 crypto wallets, netting $10.71 million believed to fund the North Korean government.

VectraRAT Malware Kit Sold for $250 a Month Targets Windows Enterprises

A malware-as-a-service platform called VectraRAT is being sold on underground markets for roughly $250 monthly, giving buyers a Windows-based remote access implant, command-and-control infrastructure, and a management panel. The package effectively bundles everything needed to compromise and control enterprise Windows systems without requiring technical expertise from the attacker.

Phishing Campaign Chains Multiple Google Redirects to Evade Detection

Attackers are exploiting a chain of legitimate Google services, including redirect links, to disguise malicious URLs and slip past email security filters. Victims who follow the multi-hop links are directed either to credential-harvesting phishing pages or prompted to install ScreenConnect remote access software.

ConnectWise flags unpatched ScreenConnect file-transfer flaw, urges manual fix

ConnectWise disclosed a new security flaw in its ScreenConnect remote access platform affecting file transfer behavior in both cloud and on-premises deployments. The vulnerability has no CVE identifier yet and no official patch, though the company says a fix is coming later this week. In the meantime, ConnectWise published manual mitigation steps requiring administrators to disable file transfer permissions across user roles.