Skip to main content

TrendAI™
Blog de Seguridad

Blog de Seguridad de TrendAI

Blogs destacados

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
Malware

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

Read article
MalwarePhishing & BEC
Malware auto-replicante se propaga a través de WhatsApp, apunta a usuarios brasileños

TrendAI™ Research ha identificado una campaña activa que se propaga a través de WhatsApp mediante un archivo adjunto ZIP. Al ejecutarse, el malware establece persistencia y secuestra la cuenta de WhatsApp comprometida para enviarse a los contactos de la víctima.

Read Article
Ransomware & extortion
Nuevo LockBit 5.0 apunta a Windows, Linux, ESXi

TrendAI™ Research analizó los binarios fuente de la última actividad del notorio ransomware LockBit con su versión 5.0, que exhibe técnicas avanzadas de ofuscación, anti-análisis y capacidades multiplataforma sin problemas para sistemas Windows, Linux y ESXi.

Read Article
Cyber crime
What We Know About the NPM Supply Chain Attack

TrendAI™ Research outlines the critical details behind the ongoing NPM supply chain attack and offers essential steps to stay protected against potential compromise.

Read Article
AI
Operadores de EvilAI utilizan código generado por IA y aplicaciones falsas para ataques de gran alcance

Combinando código generado por IA y ingeniería social, los operadores de EvilAI están ejecutando una campaña en rápida expansión, disfrazando su malware como aplicaciones legítimas para eludir la seguridad, robar credenciales y comprometer de manera persistente a organizaciones en todo el mundo.

Read Article
Ransomware & extortion
Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed

An analysis of the Gentlemen ransomware group, which employs advanced, adaptive tactics, techniques, and procedure to target critical industries worldwide.

Read Article
MalwareSocial engineering
An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps

Trend™ Research analyzed a campaign distributing Atomic macOS Stealer (AMOS), a malware family targeting macOS users. Attackers disguise the malware as “cracked” versions of legitimate apps, luring users into installation.

Read Article
Ransomware & extortion
Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware

Warlock ransomware exploits unpatched Microsoft SharePoint vulnerabilities to gain access, escalate privileges, steal credentials, move laterally, and deploy ransomware with data exfiltration across enterprise environments.

Read Article
Ransomware & extortion
Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks

Crypto24 is a ransomware group that stealthily blends legitimate tools with custom malware, using advanced evasion techniques to bypass security and EDR technologies.

Read Article
Exploits & Zero-Days
Proactive Security Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)

CVE-2025-53770 and CVE-2025-53771 are vulnerabilities in on-premise Microsoft SharePoint Servers that evolved from previously patched flaws, allowing unauthenticated remote code execution through advanced deserialization and ViewState abuse.

Read Article
Malware
Back to Business: Lumma Stealer Returns with Stealthier Methods

Lumma Stealer has re-emerged shortly after its takedown. This time, the cybergroup behind this malware appears to be intent on employing more covert tactics while steadily expanding its reach. This article shares the latest methods used to propagate this threat.

Read Article