
Read all Blogs from this Author
A fileless AsyncRAT campaign is targeting German-speaking users via a fake “I’m not a robot” prompt that executes malicious PowerShell code. Delivered through Clickfix-themed sites, it abuses system utilities to load obfuscated C# code in memory, enabling full remote access and credential theft. It persists via registry keys and communicates with a C2 server on port 4444. Organizations should block suspicious PowerShell activity and scan memory for threats.
CloudSEK researchers have uncovered a sophisticated campaign leveraging typo-squatted “Spectrum” domains to spread a new Atomic macOS Stealer (AMOS) variant. Disguised as a CAPTCHA verification, the attack uses dynamic payloads tailored to the victim's OS—stealing passwords, bypassing macOS security, and executing malware. With Russian-language comments found in the code and flawed delivery logic, the campaign reflects both growing cross-platform ambitions and rushed execution. Dive into how this multi-platform threat operates—and why your organization should stay alert.
Read all Whitepapers and reports from this Author
.png)
CloudSEK’s Middle East Threat Landscape Report 2025 reveals a sharp surge in cyber attacks led by state-aligned hacktivists, ransomware groups, and dark-web marketplaces. Finance, Government, and Telecom emerged as top targets, with 748+ coordinated incidents and escalating data leaks, extortion, and sector-specific breaches. A concise, high-impact report that leaders must read to understand 2025’s evolving threats
Read MoreRead all knowledge base articles from this Author