daily cyber × ai intelligence

index

tagged

[zigcryptostealer]

1 edition · 1 item

September 9, 2026

  • Talos traced a ClearFake WebDAV chain from a single odd rundll32 execution. A remote file named "verification.google" run through 32-bit rundll32.exe in a Ukrainian government organization's telemetry in April 2026 led to two delivery chains, two DLL loaders and ACR/Amatera stealer payloads, plus ZigCryptoStealer and NetSupport Manager; Talos tracks the actor as UAT-10820 (Cisco Talos). · Threat Activity

in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android