Junestherry Dela Cruz
9 articles
-
BlogWeb Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.
March 16th, 2026 13 minMaristel Policarpio, Junestherry Dela Cruz, Sarah Pearl Camiling, Jacob Santos…
Read article -
BlogPureRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
Job seekers looking out for opportunities might instead find their personal devices compromised, as a PureRAT campaign propagated through email leverages Foxit PDF Reader for concealment and DLL side-loading for initial entry.
December 3rd, 2025 5 minSarah Pearl Camiling, Junestherry Dela Cruz, Jacob Santos, Sophia Nilette Robles…
Read article -
BlogIncrease in Lumma Stealer Activity Coincides with Use of Adaptive Browser Fingerprinting Tactics
In this blog entry, Trend™ Research analyses the layered command-and-control approaches that Lumma Stealer uses to maintain its ongoing operations while enhancing collection of victim-environment data.
November 13th, 2025 7 minJunestherry Dela Cruz, Sarah Pearl Camiling
Read article -
BlogAgenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques
Trend™ Research identified a sophisticated Agenda ransomware attack that deployed a Linux variant on Windows systems. This cross-platform execution can make detection challenging for enterprises.
October 23rd, 2025 13 minJacob Santos, Junestherry Dela Cruz, Sarah Pearl Camiling, Sophia Nilette Robles…
Read article -
BlogFast, Broad, and Elusive: How Vidar Stealer 2.0 Upgrades Infostealer Capabilities
TrendAI™ Research examines the latest version of the Vidar stealer, which features a full rewrite in C, a multithreaded architecture, and several enhancements that warrant attention. Its timely evolution suggests that Vidar is positioning itself to occupy the space left after Lumma Stealer’s decline.
October 21st, 2025 7 minJunestherry Dela Cruz
Read article -
BlogShifts in the Underground: The Impact of Water Kurita’s (Lumma Stealer) Doxxing
A targeted underground doxxing campaign exposed alleged core members of Lumma Stealer (Water Kurita), resulting in a sharp decline in its activity and a migration of customers to rival infostealer platforms.
October 16th, 2025 5 minJunestherry Dela Cruz
Read article -
BlogUnmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed
An analysis of the Gentlemen ransomware group, which employs advanced, adaptive tactics, techniques, and procedure to target critical industries worldwide.
September 9th, 2025 12 minJacob Santos, Maristel Policarpio, Don Ovid Ladores, Junestherry Dela Cruz
Read article -
BlogBack to Business: Lumma Stealer Returns with Stealthier Methods
Lumma Stealer has re-emerged shortly after its takedown. This time, the cybergroup behind this malware appears to be intent on employing more covert tactics while steadily expanding its reach. This article shares the latest methods used to propagate this threat.
July 22nd, 2025 9 minJunestherry Dela Cruz
Read article -
BlogTikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead
Trend™ Research uncovered a campaign on TikTok that uses videos to lure victims into downloading information stealers, a tactic that can be automated using AI tools.
May 21st, 2025 8 minJunestherry Dela Cruz
Read article