Tag: FortiGuard Labs Threat Research

Interlock Ransomware: New Techniques, Same Old Tricks

An in-depth analysis of an Interlock ransomware intrusion, detailing new malware tooling, defense evasion techniques, and high-ROI detection strategies.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: Interlock Ransomware: New Techniques, Same Old…

Unveiling the Weaponized Web Shell EncystPHP

FortiGuard Labs analyzes EncystPHP, a stealthy web shell exploiting CVE-2025-64328 in FreePBX environments to enable remote command execution, persistence, and long-term system compromise        This article has been indexed from FortiGuard Labs Threat Research Read the original article: Unveiling the…

Inside a Multi-Stage Windows Malware Campaign

FortiGuard Labs analysis of a multi-stage Windows malware campaign that abuses trusted platforms to disable defenses, deploy RATs, and deliver ransomware.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: Inside a Multi-Stage Windows…

New Remcos Campaign Distributed Through Fake Shipping Document

FortiGuard Labs analyzes a phishing campaign delivering a fileless Remcos RAT via malicious Word templates, CVE-2017-11882 exploitation, and in-memory execution.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: New Remcos Campaign Distributed Through…

UDPGangster Campaigns Target Multiple Countries

FortiGuard Labs uncovers UDPGangster campaigns linked to MuddyWater, using macro-laden phishing lures, evasion techniques, and UDP backdoors to target multiple countries        This article has been indexed from FortiGuard Labs Threat Research Read the original article: UDPGangster Campaigns Target Multiple…

New eBPF Filters for Symbiote and BPFdoor Malware

FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.        This article has been indexed from FortiGuard Labs Threat Research Read the…

ShadowV2 Casts a Shadow Over IoT Devices | FortiGuard Lab

ShadowV2, a new Mirai-based botnet targeting IoT devices, surfaced during the recent AWS outage. FortiGuard Labs examines its propagation, DDoS capabilities, and global footprint.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: ShadowV2…

Cloud Abuse at Scale

FortiGuard Labs analyzes TruffleNet, a large-scale campaign abusing AWS SES with stolen credentials and linked to Business Email Compromise (BEC).        This article has been indexed from FortiGuard Labs Threat Research Read the original article: Cloud Abuse at Scale