
PolySwarm ๐บ๐ธ
@polyswarm
A threat intelligence & detection community helping security teams detect new & emerging malware.
Ticker: $NCT
Join our Discord: discord.gg/uzvBVvWwR5
ID: 893570035486150656
https://polyswarm.network 04-08-2017 20:31:12
2,2K Tweet
13,13K Followers
1,1K Following

#StealC V2 upgrades its #infostealer game with #RC4 encryption, improved payload delivery, & redesigned control panel. Recently reported by Zscaler, this #malware poses a serious risk to organizations. Check out our blog for more info & related samples. blog.polyswarm.io/stealc-evolves

Coinbase Global CEO Brian Armstrong says being added to the S&P 500 Index proves crypto "is here to stay." He speaks to Sonali Basak bloom.bg/4jdXgec

#PupkinStealer, a .NET-based #infostealer that targets sensitive data such as browser credentials and desktop files, exfiltrating it via Telegramโs Bot API. @CYFIRMA recently reported on it. Check out our blog for more info and PolySwarmโs samples. blog.polyswarm.io/pupkinstealer-โฆ

Russian #APT #StarBlizzard is back with #LOSTKEYS, a #malware family stealing sensitive files & system info across West & Eastern Europe. Googleโs Threat Intelligence Group initially reported on it. Check out our blog for info & our LOSTKEYS samples. blog.polyswarm.io/star-blizzardsโฆ


Nitrogen Ransomware, first identified in September 2024, poses a significant threat to organizations, particularly in the financial sector. Hackread.com recently covered it due to increased activity. #NitrogenRansomware #Ransomware #CyberSecurity blog.polyswarm.io/nitrogen-ransoโฆ

๐จ #FancyBear is back with #SpyPress, a stealthy JavaScript malware used in Operation #RoundPress to breach global webmail servers. It exploits XSS in RoundCube, Zimbra, and others to silently steal inbox data. ๐ฝ๏ธ Watch our latest short for more: blog.polyswarm.io/fancy-bears-spโฆ

Chinese-speaking threat actor UAT-6382 is exploiting a Cityworks zero-day (CVE-2025-0994) to target US local govt networks. Per Cisco Talos Intelligence Group, the attackers have been active since January 2025. #CyberSecurity #ZeroDay #CVE20250994 #InfoSec #ChinaCyber blog.polyswarm.io/chinese-threatโฆ


#WickedPanda, a Chinese state-backed threat actor, deployed #TOUGHPROGRESS malware using Google Calendar for stealthy C2 targeting government entities. Google Cloud reported the activity. Check out our blog for context and PolySwarm's related samples. blog.polyswarm.io/wicked-panda-tโฆ

#EDDIESTEALER is a Rust-based infostealer spread via fake CAPTCHA pages. It steals credentials & crypto wallet details using ChromeKatz & obfuscation. Elastic Security Labs reported on the campaign. #Infostealer #RustMalware #CyberSecurity #ThreatIntel blog.polyswarm.io/eddiestealer




