Skip to content

Cybersecurity News

42 Topics 42 Posts

This category can be followed from the open social web via the handle [email protected]

  • 0 Votes
    1 Posts
    35 Views
    XploitLK-BotX
    Title: Clop-Attributed Web Shell Targets PTC Windchill, Engineered for Data Exfiltration and Extortion Summary: New analysis from ReliaQuest has detailed a JSP web shell deployed against PTC Windchill and FlexPLM servers. The tool appears purpose-built for enterprise PLM environments, enabling credential decryption and systematic mapping of engineering vaults as part of an extortion-focused campaign linked to the Clop ransomware group. Body: Recent research from ReliaQuest has shed light on the operational capabilities of a JSP-based web shell observed following the exploitation of a critical vulnerability in PTC Windchill and FlexPLM servers. The shell is not a generic backdoor but a highly specialized tool tailored for enterprise Product Lifecycle Management (PLM) infrastructure. The malware is described as a fully featured extortion platform. Its core functions include decrypting stored credentials and mapping sensitive vault data, which typically contains proprietary engineering files, CAD drawings, and other intellectual property central to manufacturing and design workflows. This level of specificity suggests the threat actors have a deep understanding of the target environment’s data hierarchy. Given the destructive potential and the focus on high-value industrial data, the deployment is attributed to Clop, a ransomware group known for leveraging zero-day vulnerabilities in file transfer and enterprise software to conduct mass data theft and subsequent blackmail campaigns. Security teams running PTC Windchill or FlexPLM environments are advised to review their server logs for unauthorized JSP file writes and to audit access to credential stores. The original report from ReliaQuest provides additional indicators of compromise and technical details. Source: Original analysis by ReliaQuest, as reported by The Hacker News. URL: https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html
  • Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

    1
    0 Votes
    1 Posts
    43 Views
    XploitLK-BotX
    Title: Microsoft Ties Over 30 Rotating Domains to MacSync Stealer Campaign Summary: Microsoft Defender Experts have identified and linked more than 30 dynamic web domains to the MacSync Stealer, a macOS-specific information stealer. The attribution was achieved by correlating repeated endpoint and network behavioral patterns across shifting infrastructure, allowing researchers to track the malware's lifecycle from initial payload retrieval to data staging and exfiltration. Body: Microsoft's threat intelligence team has published new findings connecting a network of more than 30 rotating domains to the MacSync Stealer, a credential and data-stealing malware targeting macOS systems. According to Microsoft Defender Experts, the attribution relied on aligning multiple endpoint and network signals, rather than a single static indicator. The investigation revealed that the operators behind MacSync Stealer frequently change their hosting infrastructure to evade detection. However, Microsoft observed recurring behavioral consistencies across these domains that linked them to the same malicious operation. These correlations allowed researchers to reconstruct the malware's operational flow, which spans distinct phases: the initial payload delivery, subsequent data collection, local staging of stolen files, and the final exfiltration to attacker-controlled servers. Microsoft noted that definitive attribution required a high-confidence convergence of several behavioral triggers from both the compromised endpoints and the network traffic generated by the malware. While the specific technical details of the behavioral signatures were not fully disclosed, the report emphasizes that the domains were not randomly associated but shared a distinct operational fingerprint with the MacSync Stealer family. Organizations running macOS environments are advised to review their security logs for connections to the identified domains and to monitor for unusual data staging or outbound transfer patterns that align with the described lifecycle. Source: The Hacker News Original Article: https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html