LIVE · cybersecurity feed
Live wire

powershell

malwarehigh

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

A sophisticated cyber campaign dubbed TerminalFix, a variant of ClickFix, is targeting organizations by tricking users into executing malicious PowerShell commands via a fake Cloudflare CAPTCHA. This campaign deploys a multi-stage attack involving DLL sideloading, steganographic payload extraction from images, and extensive Active Directory reconnaissance. The ultimate goal is to establish a persistent reverse tunnel, granting attackers network-level proxy access to internal systems for further exploitation.

banking trojanhigh

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.

phishinghigh

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

A recent phishing campaign has been identified that utilizes sophisticated techniques including obfuscated JavaScript and PowerShell. The attackers employ process hollowing and a variant of the PureLogs malware to exfiltrate sensitive user data.