Skip to main content

TrendAI™
資安部落格

TrendAI 資安部落格

熱門文章

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
Malware

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

Read article
Targeted attacks
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.

Read Article
AI 堆疊根金鑰外洩警訊:LiteLLM PyPI 供應鏈事件深度解析

LiteLLM PyPI 資料外洩事件說明:惡意版本如何竊取雲端登入憑證、SSH 金鑰以及 Kubernetes 機密,了解衝擊與緊急防範步驟。

Read Article
Malware
Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries

We look into a stealthy multi‑stage attack campaign that delivers PureLog Stealer entirely in memory using encrypted, fileless techniques.

Read Article
Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.

Read Article
CISOs in a Pinch: A Security Analysis of OpenClaw

Learn about OpenClaw (a sovereign agent) and how this can be viable for enterprises.

Read Article
TrendAI™ 、Europol、Microsoft 以及合作夥伴聯手瓦解 Tycoon 2FA 釣魚平台

Tycoon 2FA 本週遭執法機關以及包含 TrendAI™ 在內的產業合作夥伴瓦解。這個網路釣魚服務平台利用「不肖中間人」(AitM) 代理器 (proxy) 來提供迴避多重認證 (MFA) 的服務。

Read Article
AI
駭客濫用惡意 OpenClaw Skills,散布 Atomic macOS Stealer 竊密軟體

惡意的 OpenClaw 技能會誘騙 AI 代理和使用者安裝新的 AMOS 變種來竊取大量資料。

Read Article
U.S. Public Sector Under Siege

Discover why Government and Education must prioritize Cyber Risk Management.

Read Article
AIResearch features
爆紅 AI 的隱性威脅:OpenClaw 透露了代理式 AI 助理的哪些風險?

OpenClaw (亦稱 Clawdbot 或 Moltbot) 象徵著代理式 AI 的全新疆土:強大、高度自主,而且令人訝異的是非常容易使用。本文比較它與前輩們的能力差異,並點出代理式 AI 典範固有的資安風險。

Read Article
APTsTargeted attacks
PeckBirdy:親中駭客集團在 LOLBin 攻擊手法中使用的多功能腳本框架

PeckBirdy 是一個精密的 JScript 幕後操縱 (C&C) 框架,親中 APT 集團利用它在各種環境發動就地取材二進位檔案 (LOLBin) 的攻擊,散播進階後門程式到博弈產業和亞洲政府機關。

Read Article