Skip to main content

TrendAI™
資安部落格

TrendAI 資安部落格

熱門文章

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
Malware

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

Read article
Phishing & BEC
Unraveling Water Saci's New Multi-Format, AI-Enhanced Attacks Propagated via WhatsApp

Through AI-driven code conversion and a layered infection chain involving different file formats and scripting languages, the threat actors behind Water Saci are quickly upgrading their malware delivery and propagation methods across WhatsApp in Brazil.

Read Article
Cloud security
Shai-hulud 2.0 蠕蟲攻擊鎖定雲端與開發環境

Shai-hulud 2.0 攻擊行動使用了一個精密的變種來竊取主要雲端平台及開發人員服務的登入憑證和機密,並透過自動化方式在受害者維護的 NPM 套件內植入後門。其進階手法使得它能在軟體供應鏈內部迅速擴散,造成無數的下游使用者陷入風險險。

Read Article
Ransomware & extortion
Breaking Down S3 Ransomware: Variants, Attack Paths and Trend Vision One™ Defenses

In this blog entry, Trend™ Research explores how ransomware actors are shifting their focus to cloud-based assets, including the tactics used to compromise business-critical data in AWS environments.

Read Article
Information technology
AI Security: NVIDIA BlueField Now with Vision One™

Launching at NVIDIA GTC 2025 - Transforming AI Security with Trend Vision One™ on NVIDIA BlueField

Read Article
Agenda 勒索軟體利用遠端管理工具和 BYOVD 技術,在 Windows 上執行 Linux 版本

Trend™ Research 發現了一起 Agenda 勒索病毒在 Windows 系統上植入 Linux 變種的精密攻擊,這種跨平台的執行方式,可能讓企業更加難以偵測。

Read Article
Targeted attacks
中國陣營網路間諜行動:協同式攻擊策略正快速崛起

Trend™ Research 檢視了一些親中國的進階持續性滲透攻擊 (APT) 集團如何經由一種名為「高級通關服務」(Premier Pass-as-a-Service) 的最新網路犯罪經營模式來從事複雜的協同行動,Earth Estries 和 Earth Naga 集團近期的活動正是最好的示範。

Read Article
LLMs
When Tokenizers Drift: Hidden Costs and Security Risks in LLM Deployments

A tokenizer lies at the core of every large language model. When it drifts, whether from unseen flaws or adversarial interference, costs rise and performance drops. We explore this emerging risk, its implications, and the measures to prevent it.

Read Article
Cyber crimeMalware
快速、廣泛、難以偵測:Vidar Stealer 2.0 資訊竊取程式做了哪些升級

TrendAI™ Research 研究了最新版的 Vidar 資訊竊取程式之後發現它包含以下幾項升級:使用 C 語言全部重寫、採用多執行緒架構,以及多項值得注意的強化功能。而新版本的發表時機似乎也意謂著 Vidar 正準備繼承 Lumma Stealer 沒落之後所騰出來的龍頭寶座。

Read Article
Shifts in the Underground: The Impact of Water Kurita’s (Lumma Stealer) Doxxing

A targeted underground doxxing campaign exposed alleged core members of Lumma Stealer (Water Kurita), resulting in a sharp decline in its activity and a migration of customers to rival infostealer platforms.

Read Article
Zero Disco 攻擊行動:駭客利用 Cisco SNMP 漏洞部署 rootkit

Trend™ Research 發現了一起利用 Cisco SNMP 漏洞 CVE-2025-20352 的攻擊行動,駭客可從遠端在未受保護的裝置上執行程式碼並部署 Rootkit,受影響的裝置包括 Cisco 9400、9300 和老舊的 3750G 系列。

Read Article