Maristel Policarpio
7 articles
-
BlogWeb Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.
March 16th, 2026 13 minMaristel Policarpio, Junestherry Dela Cruz, Sarah Pearl Camiling, Jacob Santos…
Read article -
BlogPureRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
Job seekers looking out for opportunities might instead find their personal devices compromised, as a PureRAT campaign propagated through email leverages Foxit PDF Reader for concealment and DLL side-loading for initial entry.
December 3rd, 2025 5 minSarah Pearl Camiling, Junestherry Dela Cruz, Jacob Santos, Sophia Nilette Robles…
Read article -
BlogAgenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques
Trend™ Research identified a sophisticated Agenda ransomware attack that deployed a Linux variant on Windows systems. This cross-platform execution can make detection challenging for enterprises.
October 23rd, 2025 13 minJacob Santos, Junestherry Dela Cruz, Sarah Pearl Camiling, Sophia Nilette Robles…
Read article -
BlogMalware Autopropagável se Espalha Via WhatsApp, Alvo: Usuários Brasileiros
A TrendAI™ Research identificou uma campanha ativa se espalhando via WhatsApp através de um anexo de arquivo ZIP. Quando executado, o malware estabelece persistência e sequestra a conta do WhatsApp comprometida para enviar cópias de si mesmo para os contatos da vítima.
October 3rd, 2025 15 minJeffrey Francis Bonaobra, Maristel Policarpio, Sophia Nilette Robles, Cj Arsley Mateo…
Read article -
BlogUnmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed
An analysis of the Gentlemen ransomware group, which employs advanced, adaptive tactics, techniques, and procedure to target critical industries worldwide.
September 9th, 2025 12 minJacob Santos, Maristel Policarpio, Don Ovid Ladores, Junestherry Dela Cruz
Read article -
BlogCrypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks
Crypto24 is a ransomware group that stealthily blends legitimate tools with custom malware, using advanced evasion techniques to bypass security and EDR technologies.
August 14th, 2025 13 minMaristel Policarpio, Sarah Pearl Camiling, Don Ovid Ladores, Jacob Santos…
Read article -
BlogAnubis: A Closer Look at an Emerging Ransomware with Built-in Wiper
Anubis is an emerging ransomware-as-a-service (RaaS) group that adds a destructive edge to the typical double-extortion model with its file-wiping feature. We explore its origins and examine the tactics behind its dual-threat approach.
June 13th, 2025 8 minMaristel Policarpio, Sarah Pearl Camiling, Sophia Nilette Robles
Read article