Buddy Tancio
6 articles
-
BlogLiving Off Trusted Software: ScreenConnect Abuse Across Phishing, Search, and RMM Chains
In this blog entry, researchers at TrendAI Vision One™ Services – Managed Detection and Response (MDR) walk through how attackers deliver, install, and operate a reconfigured ScreenConnect client, and why it slips past defenses built to catch conventional malware.
August 17th, 2026 15 minBuddy Tancio, Allixon Kristoffer Francisco, Fe Cureg, Aira Marcelo…
Read article -
Blog駭客濫用惡意 OpenClaw Skills,散布 Atomic macOS Stealer 竊密軟體
惡意的 OpenClaw 技能會誘騙 AI 代理和使用者安裝新的 AMOS 變種來竊取大量資料。
February 23rd, 2026 8 minAlfredo Oliveira , Buddy Tancio, David Fiser, Philippe Lin…
Read article -
BlogAnalyzing a Multi-Stage AsyncRAT Campaign via Managed Detection and Response
Threat actors exploited Cloudflare's free-tier infrastructure and legitimate Python environments to deploy the AsyncRAT remote access trojan, demonstrating advanced evasion techniques that abuse trusted cloud services for malicious operations.
January 12th, 2026 13 minBuddy Tancio, Jed Valderama, Khristoffer Jocson, Franklynn Uy
Read article -
BlogAn MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps
Trend™ Research analyzed a campaign distributing Atomic macOS Stealer (AMOS), a malware family targeting macOS users. Attackers disguise the malware as “cracked” versions of legitimate apps, luring users into installation.
September 4th, 2025 16 minBuddy Tancio, Aldrin Ceriola, Khristoffer Jocson, Nusrath Iqra…
Read article -
BlogFake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain
We have detected a new tactic involving fake CAPTCHA pages that trick users into executing harmful commands in Windows. This scheme uses disguised files sent via phishing and other malicious methods.
May 19th, 2025 15 minBuddy Tancio, Khristoffer Jocson, Maylein Tom, Lisa Wu…
Read article -
ResearchUsing MITRE ATT&CK to Identify an APT Attack
We analyzed the tools, relationships, and behaviors used in a long-standing intrusion of a company after its security team observed malicious C&C traffic.
December 15th, 2020 4 minLenart Bermejo, Gilbert Sison, Buddy Tancio
Read article