Jeffrey Francis Bonaobra
7 articles
-
BlogWeaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads
A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponized the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks.
April 3rd, 2026 18 minJacob Santos, Sophia Nilette Robles, Jeffrey Francis Bonaobra
Read article -
BlogUnraveling Water Saci's New Multi-Format, AI-Enhanced Attacks Propagated via WhatsApp
Through AI-driven code conversion and a layered infection chain involving different file formats and scripting languages, the threat actors behind Water Saci are quickly upgrading their malware delivery and propagation methods across WhatsApp in Brazil.
December 2nd, 2025 16 minJeffrey Francis Bonaobra, Sarah Pearl Camiling, Joe Soares, Byron Gelera…
Read article -
BlogShai-hulud 2.0 Campaign Targets Cloud and Developer Ecosystems
Shai-hulud 2.0 campaign features a sophisticated variant capable of stealing credentials and secrets from major cloud platforms and developer services, while automating the backdooring of NPM packages maintained by victims. Its advanced tactics enable rapid, stealthy propagation across the software supply chain, putting countless downstream users at risk.
November 27th, 2025 23 minJeffrey Francis Bonaobra
Read article -
BlogSelf-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users
TrendAI™ Research has identified an active campaign spreading via WhatsApp through a ZIP file attachment. When executed, the malware establishes persistence and hijacks the compromised WhatsApp account to send copies of itself to the victim’s contacts.
October 3rd, 2025 15 minJeffrey Francis Bonaobra, Maristel Policarpio, Sophia Nilette Robles, Cj Arsley Mateo…
Read article -
BlogWhat We Know About the NPM Supply Chain Attack
TrendAI™ Research outlines the critical details behind the ongoing NPM supply chain attack and offers essential steps to stay protected against potential compromise.
September 18th, 2025 9 minJeffrey Francis Bonaobra, Joshua Aquino
Read article -
BlogEvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks
Combining AI-generated code and social engineering, EvilAI operators are executing a rapidly expanding campaign, disguising their malware as legitimate applications to bypass security, steal credentials, and persistently compromise organizations worldwide.
September 11th, 2025 18 minJeffrey Francis Bonaobra, Joshua Aquino, Emmanuel Panopio, Emmanuel Roll…
Read article -
BlogWarlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware
Warlock ransomware exploits unpatched Microsoft SharePoint vulnerabilities to gain access, escalate privileges, steal credentials, move laterally, and deploy ransomware with data exfiltration across enterprise environments.
August 20th, 2025 14 minJeffrey Francis Bonaobra, Joshua Aquino, Mohammed Malubay, John Paul Lim…
Read article