Skip to content

Derp | Security Research

Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.

Security News

Lazarusholic Bluesky

Kimsuky Uses LNK Phishing and GitHub Repositories for C2 While Testing AI Tradecraft

Researchers linked a North Korean Kimsuky intrusion cluster to spearphishing campaigns that deliver ZIP archives containing malicious .lnk files, which launch obfuscated PowerShell, open decoy PDF documents, and create persistence through scheduled tasks. The activity, tracked by Genians as Operation GitPower, also used public GitHub and GitLab repositories as command-and-control channels and malware staging infrastructure, including encrypted .NET AsyncRAT payloads disguised as image files. Fortinet separately reported DPRK-linked campaigns using the same combination of LNK-based infection chains and GitHub-backed C2, reinforcing the pattern across related operations. Investigators said the operators appear to be expanding beyond conventional malware delivery and are actively experimenting with AI-enabled tradecraft. Artifacts showed local LLM environments built with tools including Ollama, GPT4All, and Msty, along with RAG-style document handling, AI agent development libraries, and Whisper speech-to-text components, suggesting a research-and-integration phase focused on malware development, document analysis, and attack automation rather than training original models. Attribution was supported by overlaps with prior Kimsuky techniques, Korean-language artifacts, North Korean lexical patterns, Arirang manufacturer strings, and use of Astrill VPN.

opens in a new tab
  1. Multi-Stage PowerShell Loader Used Vercel-Hosted Payloads and Obfuscated Executionopens in a new tab

    Reddit Netsec

  2. RovoBlast Prompt Injection Flaw Let Atlassian Rovo Exfiltrate Sensitive Dataopens in a new tab

    Cysecurity

  3. Kata Containers Flaw Enables Host Root Code Execution via Config Path Annotationopens in a new tab

    Cvefeed High Severity

  4. Ransomware Attack Disrupts City of Coweta Systems While Emergency Services Stay Onlineopens in a new tab

    malware.news

  5. Metabase SQLi Zero-Day Exposed Customer Data at Framework and Tallyopens in a new tab

    BleepingComputer

  6. Suspicious macOS Coding-Agent Activity Used Tunnels and LaunchAgent Persistenceopens in a new tab

    Elastic Security Labs

  7. Levi Strauss Breach Exfiltrated Corporate Data via Social Engineeringopens in a new tab

    BleepingComputer

  8. Patchwork used fake PDFs and trojanized chat apps to spy on Windows and Android targetsopens in a new tab

    Cyber Security

  9. 22 Vulnerabilities in TeamDavid Expose Mailboxes, Files, and Server Secretsopens in a new tab

    Cvefeed High Severity

  10. Deepfake Scammers Impersonate OnlyFans Creators to Steal Money From Fansopens in a new tab

    Security Affairs

  11. Microsoft 365 Phishing Campaign Hijacks Identities for Stealthy BEC and Mail Accessopens in a new tab

    malware.news

  12. Nx Self-Hosted Remote Cache Flaw Enables Arbitrary File Write and RCEopens in a new tab

    Cvefeed High Severity

  13. UNC6671 Expands Vishing Extortion Under Redact, Pink, Helix, and Falcon Brandsopens in a new tab

    Techcrunch Com Security

  14. Orova ransomware campaign expands across SMBs and exposes U.S. healthcare dataopens in a new tab

    malware.news

  15. Apple Patches macOS Screen Sharing Authentication Bypass and CUPS Root Write Flawopens in a new tab

    Tidbits

  16. Pre-authentication Root RCE Flaws Expose Xeams Mail Serversopens in a new tab

    Fulldisclosure Mailing List

  17. Pre-authentication SYSTEM RCE Disclosed in Vicon Valerus ViconNet Gatewayopens in a new tab

    Fulldisclosure Mailing List

  18. Pre-authentication RCE in Unity Version Control On-Prem via Plastic SCM defaultsopens in a new tab

    Fulldisclosure Mailing List

  19. Pre-authentication Root RCE Chain and Default Admin Password Exposed in CatDV Serveropens in a new tab

    Fulldisclosure Mailing List

  20. Linux Safe RET Flaw on AMD Zen CPUs Enables Interrupt Injection Data Leaksopens in a new tab

    BleepingComputer

  21. Vanta Stealer Harvests Browser Credentials, Crypto Wallets, and Gaming Accountsopens in a new tab

    Cyber Security

  22. Ransomware Campaign Targeted Managers to Gain Business Access and Boost Extortionopens in a new tab

    malware.news

  23. Larva-26005 Links Xctdoor Campaign to Earlier CRAT Intrusions in South Koreaopens in a new tab

    Lazarusholic Bluesky

  24. CISA Flags Actively Exploited JetBrains TeamCity RCEopens in a new tab

    Cyber Security

  25. Cisco IMC RCE and Widespread BMC Flaws Expose Server Management Controllersopens in a new tab

    Arstechnica Security

  26. Canadian Hacker Pleads Guilty in Snowflake-Linked Breach and Extortion Spreeopens in a new tab

    malware.news

  27. Nuxt Server Island Template Injection Flaw Enables Server-Side RCEopens in a new tab

    Cvefeed High Severity

  28. Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages via keyv Compromiseopens in a new tab

    Elastic Security Labs

  29. Flooding Dropper Campaign Seeds 850 Malicious npm Packagesopens in a new tab

    malware.news

  30. Bixby exploit chain enabled remote system compromise on Samsung phonesopens in a new tab

    SecurityWeek

  31. macOS ClickFix Campaign Hid AMOS and MacSync Behind Fingerprinting Gatesopens in a new tab

    The Hacker News

  32. Poison Claude Resold Anthropic Access Through Fraudulent Cloud Accountsopens in a new tab

    Cyber Security

  33. Apache Answer Flaw Enables Account Takeover via OAuth Email-Binding Flowopens in a new tab

    Oss Security Mailing List

  34. PhaaS Kits Bypass MFA to Hijack Microsoft 365 Accounts at U.S. Organizationsopens in a new tab

    Cyber Security

  35. Root-Level ENDLESSDOORS Implant Found in Zbtlink Routersopens in a new tab

    Decipher Sc

  36. Windows Hello Key Abuse Enables Entra ID Token Theft and Persistenceopens in a new tab

    Dirkjanm

  37. Frontier AI agents crossed test boundaries and triggered UK and US scrutinyopens in a new tab

    Decipher Sc

  38. CISA Adds Exploited Langflow, Tomcat, and N-central Flaws to KEVopens in a new tab

    SecurityWeek

  39. Privilege Escalation in Red Hat ClusterCurator Grants Full Kubernetes Cluster Controlopens in a new tab

    Cvefeed High Severity

  40. Qilin Ransomware Drives UK Victim Surge and Hits Intertrust Australiaopens in a new tab

    malware.news

  41. One-Click RCE in VS Code, Cursor, and Google Antigravityopens in a new tab

    Cyber Security

  42. Odysseus Flaw Let Non-Admins Hijack Embedding Endpoint and Exfiltrate Dataopens in a new tab

    Cvefeed High Severity

  43. Greatness PhaaS Adds Device-Code Phishing to Hijack Microsoft 365 Accountsopens in a new tab

    BleepingComputer

  44. Google::Auth for Perl Flaw Enables SSRF and Credential Exfiltration via Credentials JSONopens in a new tab

    Oss Security Mailing List

  45. Microsoft Defender Automatically Isolated a QNET Device to Stop Ransomwareopens in a new tab

    malware.news

  46. Smoke#Screen Campaign Abuses ScreenConnect for Stealthy Cross-Platform Accessopens in a new tab

    Dark Reading

  47. OpenAI Moves Codex Into Persistent Cloud Workspaces Through Ona Acquisitionopens in a new tab

    The New Stack

  48. Email AI Assistants Abused to Hijack CEO Accounts and Redirect Wire Transfersopens in a new tab

    Cyber Security

  49. Malicious Keyv npm Releases Used Trusted Publishing to Steal Developer Secretsopens in a new tab

    SC World

  50. OWASP Launches Subtractive Security Top 10 to Eliminate Attack Pathsopens in a new tab

    Cyber Security

  51. Swiss Federal IT Office Breach Compromised 200 SharePoint Accountsopens in a new tab

    malware.news

  52. Direct-to-IP Malware Traffic Bypasses DNS Defenses at Scaleopens in a new tab

    Unit 42

  53. Deepfakes and Agentic AI Raise Fraud and Control Risks in Digital Paymentsopens in a new tab

    Bluescreen Kz

  54. Phishers Abuse Cloudflare, Vercel, GitHub Pages, and IPFS to Host AiTM Campaignsopens in a new tab

    malware.news

  55. Google Withdraws Google Earth AI Imagery Tool After Deepfake Abuse Concernsopens in a new tab

    malware.news

  56. ChainDrop npm Worm Compromises Packages via Preinstall Credential Harvesteropens in a new tab

    Cryptika

  57. Fake IRS Letters Lure Crypto Holders to Phishing Compliance Portalopens in a new tab

    Bitdefender

  58. Microsoft Excel Use-After-Free Flaw Enables Remote Code Executionopens in a new tab

    ThreatAft

  59. New York Expands Cybersecurity Mandates and Grants for Water Utilitiesopens in a new tab

    SecurityWeek

  60. Microsoft Adds Teams Reporting Tools to Counter AI Deepfake and Meeting Fraudopens in a new tab

    Windowslatest

  61. Trusted Coding Projects Can Trigger Code Execution Before User Interactionopens in a new tab

    Reddit Netsec

  62. Fake Xeno Roblox Executor Spreads Java Stealer and RAT via Discordopens in a new tab

    BleepingComputer

  63. Public RefluXFS PoC Targets Linux Kernel XFS Reflink Privilege Escalationopens in a new tab

    Oss Security Mailing List

  64. Qilin ransomware claims string of victims across U.S. and Europeopens in a new tab

    malware.news

  65. Critical OpenEMR RCE Lets Database Payloads Trigger PHP Code Executionopens in a new tab

    Cvefeed High Severity

  66. Critical Krayin CRM Flaw Lets Unauthenticated Attackers Take Over Admin Accountsopens in a new tab

    Cvefeed High Severity

  67. River Bank Says Stolen Data Was Deleted After June Ransomware Attackopens in a new tab

    Security Affairs

  68. Brazilian Schools Hit by Ransomware, Valid Account Abuse, and Insider Keyloggingopens in a new tab

    Securelist

  69. CTI-Transmute PDF Rendering Flaw Enabled SSRF and Local File Disclosureopens in a new tab

    Cvefeed High Severity

  70. Novel Malware Attacks Hijack Google-Synced Passkeys on Chromeopens in a new tab

    Unit 42

  71. Larva-24009 Phishing Campaign Delivers Malware to South Korean and Global Targetsopens in a new tab

    malware.news

  72. Elastic Defend Expands BYOVD Detection to 800+ Vulnerable Windows Driversopens in a new tab

    Help Net Security

  73. AI-Enabled Threat Actors Accelerate Exploitation and Target AI Infrastructureopens in a new tab

    Cyberscoop

Trackers

Latest Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.