Jacob Santos
10 articles
-
BlogWeaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads
A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponized the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks.
April 3rd, 2026 18 minJacob Santos, Sophia Nilette Robles, Jeffrey Francis Bonaobra
Read article -
BlogAxios NPM 套件遭駭客入侵:供應鏈攻擊瞄準每週超過 1 億次下載的 JavaScript HTTP 用戶端
駭客對 Axios 發動供應鏈攻擊,利用偷來的 npm 登入憑證發布含有幽靈相依元件的惡意版本,然後在安裝過程中觸發一個跨平台遠端存取木馬程式 (RAT),隨後將其檔案更換成乾淨的誘餌檔案來誤導調查,使它難以被偵測。
March 31st, 2026 10 minPeter Girnus, Jacob Santos
Read article -
BlogWeb Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.
March 16th, 2026 13 minMaristel Policarpio, Junestherry Dela Cruz, Sarah Pearl Camiling, Jacob Santos…
Read article -
BlogPureRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
Job seekers looking out for opportunities might instead find their personal devices compromised, as a PureRAT campaign propagated through email leverages Foxit PDF Reader for concealment and DLL side-loading for initial entry.
December 3rd, 2025 5 minSarah Pearl Camiling, Junestherry Dela Cruz, Jacob Santos, Sophia Nilette Robles…
Read article -
BlogAgenda 勒索軟體利用遠端管理工具和 BYOVD 技術,在 Windows 上執行 Linux 版本
Trend™ Research 發現了一起 Agenda 勒索病毒在 Windows 系統上植入 Linux 變種的精密攻擊,這種跨平台的執行方式,可能讓企業更加難以偵測。
October 23rd, 2025 13 minJacob Santos, Junestherry Dela Cruz, Sarah Pearl Camiling, Sophia Nilette Robles…
Read article -
Blog收到熟人傳來的 ZIP 壓縮檔?小心 WhatsApp 新病毒「SORVEPOTEL」正在竊資料!
TrendAI™ Research 發現了一個正在利用 ZIP 附件檔案並經由 WhatsApp 散布的惡意程式攻擊行動。惡意程式一旦執行,就會建立常駐機制,然後經由被駭入的 WhatsApp 帳號將自己複製並傳送給受害者的聯絡人。
October 3rd, 2025 15 minJeffrey Francis Bonaobra, Maristel Policarpio, Sophia Nilette Robles, Cj Arsley Mateo…
Read article -
Blog最新 LockBit 5.0 瞄準 Windows、Linux、ESXi 系統
TrendAI™ Research 分析了知名 LockBit 勒索病毒最新活動的二進位檔案,其 5.0 版本展現了進階的加密編碼、反制分析技巧,以及無縫的 Windows、Linux 和 ESXi 跨平台支援。
September 25th, 2025 7 minSarah Pearl Camiling, Jacob Santos
Read article -
Blog揭開 Gentlemen 勒索病毒的面具:攻擊手法、技巧與程序曝光
本文分析 Gentlemen 勒索病毒集團在攻擊全球各地關鍵產業時所採用的適應性進階手法、技巧與程序。
September 9th, 2025 12 minJacob Santos, Maristel Policarpio, Don Ovid Ladores, Junestherry Dela Cruz
Read article -
BlogCrypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks
Crypto24 is a ransomware group that stealthily blends legitimate tools with custom malware, using advanced evasion techniques to bypass security and EDR technologies.
August 14th, 2025 13 minMaristel Policarpio, Sarah Pearl Camiling, Don Ovid Ladores, Jacob Santos…
Read article -
BlogSilent Threat: Red Team Tool EDRSilencer Disrupting Endpoint Security Solutions
Trend Micro's Threat Hunting Team has observed EDRSilencer, a red team tool that threat actors are attempting to abuse for its ability to block EDR traffic and conceal malicious activity.
October 15th, 2024 8 minJacob Santos, Cj Arsley Mateo, Sarah Pearl Camiling
Read article