Skip to main content

TrendAI™
資安部落格

TrendAI 資安部落格

熱門文章

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
Malware

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

Read article
MalwarePhishing & BEC
收到熟人傳來的 ZIP 壓縮檔?小心 WhatsApp 新病毒「SORVEPOTEL」正在竊資料!

TrendAI™ Research 發現了一個正在利用 ZIP 附件檔案並經由 WhatsApp 散布的惡意程式攻擊行動。惡意程式一旦執行,就會建立常駐機制,然後經由被駭入的 WhatsApp 帳號將自己複製並傳送給受害者的聯絡人。

Read Article
Ransomware & extortion
最新 LockBit 5.0 瞄準 Windows、Linux、ESXi 系統

TrendAI™ Research 分析了知名 LockBit 勒索病毒最新活動的二進位檔案,其 5.0 版本展現了進階的加密編碼、反制分析技巧,以及無縫的 Windows、Linux 和 ESXi 跨平台支援。

Read Article
Cyber crime
我們對 NPM 供應鏈攻擊的了解

TrendAI™ Research 分析了持續中的 NPM 供應鏈攻擊背後的關鍵細節,並提供一些防範其潛在入侵的必要步驟。

Read Article
AI
EvilAI 駭客集團利用 AI 生成的程式碼與假應用程式來發動大範圍的攻擊

EvilAI 集團結合了 AI 生成的程式碼與社交工程技巧,正在發動一波迅速擴大的攻擊行動,將其惡意程式偽裝成正常應用程式來躲避資安防護、竊取登入憑證,持續入侵全球企業。

Read Article
Ransomware & extortion
揭開 Gentlemen 勒索病毒的面具:攻擊手法、技巧與程序曝光

本文分析 Gentlemen 勒索病毒集團在攻擊全球各地關鍵產業時所採用的適應性進階手法、技巧與程序。

Read Article
MalwareSocial engineering
An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps

Trend™ Research analyzed a campaign distributing Atomic macOS Stealer (AMOS), a malware family targeting macOS users. Attackers disguise the malware as “cracked” versions of legitimate apps, luring users into installation.

Read Article
Ransomware & extortion
Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware

Warlock ransomware exploits unpatched Microsoft SharePoint vulnerabilities to gain access, escalate privileges, steal credentials, move laterally, and deploy ransomware with data exfiltration across enterprise environments.

Read Article
Ransomware & extortion
Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks

Crypto24 is a ransomware group that stealthily blends legitimate tools with custom malware, using advanced evasion techniques to bypass security and EDR technologies.

Read Article
Exploits & Zero-Days
Proactive Security Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)

CVE-2025-53770 and CVE-2025-53771 are vulnerabilities in on-premise Microsoft SharePoint Servers that evolved from previously patched flaws, allowing unauthenticated remote code execution through advanced deserialization and ViewState abuse.

Read Article
Malware
Back to Business: Lumma Stealer Returns with Stealthier Methods

Lumma Stealer has re-emerged shortly after its takedown. This time, the cybergroup behind this malware appears to be intent on employing more covert tactics while steadily expanding its reach. This article shares the latest methods used to propagate this threat.

Read Article