VNVũ Nhật Lâminblog.fiscybersec.com·2d ago · 22 min readHoneyMyte Takes CoolClient Into the Kernel: When a Rootkit Changes What Windows Lets You SeeSummary CoolClient was already a fully capable espionage backdoor: keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and a plugin-based extension architecture00
VNVũ Nhật Lâminblog.fiscybersec.com·2d ago · 27 min readHoneyMyte đưa CoolClient xuống kernel: khi rootkit thay đổi thứ Windows cho phép bạn nhìn thấyTóm tắt CoolClient vốn đã là một backdoor gián điệp đầy đủ chức năng: keylogging, đánh cắp clipboard, thu thập thông tin xác thực, quản lý file, trinh sát hệ thống, và kiến trúc mở rộng bằng plugin. B00
VNVũ Nhật Lâminblog.fiscybersec.com·2d ago · 21 min readEvooo1Bot: When an Infected Router Stops Being Disposable Ammunition and Becomes Rentable InfrastructureSummary Evooo1Bot reuses the DDoS engine from the publicly leaked Mirai source code verbatim. That part is nothing new after ten years. What is new is everything bolted onto it: encrypted C2 communica00
VNVũ Nhật Lâminblog.fiscybersec.com·2d ago · 25 min readEvooo1Bot: khi router bị nhiễm không còn là đạn dùng một lần mà trở thành hạ tầng cho thuêTóm tắt Evooo1Bot dùng lại nguyên engine DDoS từ mã nguồn Mirai bị rò rỉ công khai. Phần đó không có gì mới sau mười năm. Cái mới nằm ở những thứ được gắn thêm vào: giao tiếp C2 mã hóa, scanner brute-00
VNVũ Nhật Lâminblog.fiscybersec.com·6d ago · 17 min readBdThemes: A WordPress Supply Chain Attack That Changed No Code At AllSummary Not a single source code file in the WordPress.org repository was modified. No plugin update was released. No file on disk changed. Yet rogue administrator accounts were created on victim site00