Preview image for a blog post

Lua Loader Phishing: TrueType Font Deception Unleashes RATs and Infostealers

Global phishing campaign uses TrueType Font files to conceal Lua loaders, deploying advanced RATs and infostealers. Deep dive into evasion tactics and defense.
Preview image for a blog post

GlassWorm Unleashed: Solana Dead Drops Fuel Multi-Stage RAT and Comprehensive Crypto Exfiltration

GlassWorm malware now uses Solana dead drops to deliver a RAT, steal browser/crypto data, and deploy a malicious Chrome extension.