CYFIRMA
CYFIRMA Research
Cyber defenders, listen up! The CYFIRMA Research podcast has some juicy intel on the latest cyber threats that are lurking in the shadows. Tune in to this security briefing to stay on top of emerging threats and be ready to tackle digital risk like never before.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
CYFIRMA Research- Fake Telegram Premium Site Distributes New Lumma Stealer Variant 11.09.2025 5:21
CYFIRMA researchers have uncovered a malware campaign exploiting a spoofed Telegram Premium site—telegrampremium[.]app—to distribute a new variant of Lumma Stealer . Key Findings : • Drive-by download delivers malicious start.exe without user interaction • Targets browser credentials, crypto wallets, system info • Employs obfuscation, DGA-based domains, public DNS evasion • Uses legitimate platfor...
CYFIRMA Research- CVE-2025-8671 – HTTP/2 MadeYouReset Vulnerability DDoS Attacks 10.09.2025 4:08
Critical Alert: CVE-2025-8671 – HTTP/2 “MadeYouReset” DoS Vulnerability Organizations operating HTTP/2-enabled infrastructure—such as Apache Tomcat, Netty, F5 BIG-IP, Jetty, and other affected stacks—must act swiftly. This newly uncovered flaw enables attackers to bypass HTTP/2 stream-concurrency protections and trigger unbounded backend processing by exploiting mismatched stream reset handling, l...
CYFIRMA Research- Tracking Ransomware – July 2025 09.09.2025 4:21
Stay ahead with CYFIRMA’s Monthly Ransomware Report – July 2025. CYFIRMA’s July 2025 Ransomware Report recorded 504 global victims, a 7.5% rise from June, reflecting sustained threat levels. Qilin remained the most active, while Incransom and SafePay surged. Interlock introduced FileFix, a stealthy Windows UI-based delivery method; GLOBAL GROUP launched an AI-powered RaaS; and Gunra expanded to Li...
CYFIRMA Research- Infos3c Grabber Stealer 09.09.2025 4:48
CYFIRMA’s latest report explores Infos3c Grabber Stealer, a Python-based grabber malware that steals passwords, wallets, gaming accounts & Discord/Telegram data, captures screenshots, and exfiltrates via Discord. Use endpoint security + traffic monitoring to stay safe. Link to the Research Report: https://www.cyfirma.com/research/unveiling-a-python-stealer-inf0s3c-stealer/ #CyberSecurity #Thr...
CYFIRMA Research- REVENANT: Executionless, Self-Assembling Threat Hidden in System Entropy 08.09.2025 6:29
New Threat Model: Executionless Persistence Across Endpoints & AI Layers REVENANT introduces a forward-looking multi-stage attack framework that chains stealthy, executionless techniques to persist not just on systems, but in the operational memory of AI assistants. Key Highlights: Executionless delivery via fonts, clipboard state, and localization strings, no exploits, macros, or dropped bina...
CYFIRMA Research- Salat Stealer 08.09.2025 8:31
CYFIRMA has uncovered Salat Stealer (WEB_RAT) — a Go-based infostealer targeting Windows. It exfiltrates browser credentials, cryptocurrency wallets, and Telegram session data while evading detection through advanced persistence. Attributed to Russian-speaking actors, it operates under a MaaS model. Explore our in-depth analysis and mitigation strategies in the full report. Link to the Research Re...
CYFIRMA Research- Typhoon in the Fifth Domain: China's Evolving Cyber Strategy 05.09.2025 6:24
China's Cyber Shift: From espionage to sabotage, Targeting Global Infrastructure – check out, the newest CYFIRMA blog on Beijing's ambitions in the Fifth Domain. Link to the Research Report : https://www.cyfirma.com/blogs/typhoon-in-the-fifth-domain-chinas-evolving-cyber-strategy/ #Geopolitics #CYFIRMAresearch #ThreatIntelligence #cybersecurity #ETLM #currentaffairs #MilitaryAffairs #S...
CYFIRMA Research- TinkyWinkey Keylogger 02.09.2025 8:22
CYFIRMA identified TinkyWinkey, a stealthy Windows keylogger, capable of capturing keystrokes, system info, and active windows. It leverages DLL injection and persistent services to evade detection and maintain long-term presence. Link to the Research Report: https://www.cyfirma.com/research/tinkywinkey-keylogger/ #CyberSecurity #ThreatIntelligence #Keylogger #MalwareAnalysis #CYFIRMA ...
CYFIRMA Research- APT36 Campaign Targets Indian Defense BOSS Linux system 29.08.2025 3:41
CYFIRMA has uncovered an ongoing cyber-espionage campaign orchestrated by APT36 , a Pakistan-linked threat actor, targeting Indian Government entities . Key Highlights: Initial Access: Spear-phishing emails delivering weaponized .desktop files disguised as PDFs. Target Platforms: Windows & Linux BOSS OS. Malware Behavior: Downloads & executes ELF payloads, establishes persistence via cron/...
CYFIRMA Research- Lazarus Stealer 29.08.2025 4:17
CYFIRMA research exposes Lazarus Stealer — a stealthy Android banking malware targeting Russian financial institutions. Key Attack Vectors: Overlay Attack: Displays fake banking login screens to steal card details & account credentials. Silent SMS Notification Blocking: Obtains default SMS handler rights to suppress OTP alerts from the victim’s view. Real-Time OTP Harvesting: Captures verifi...
CYFIRMA Research- Android Malware Posing as Indian Bank Apps 28.08.2025 8:44
Posing as Indian banking apps, this Android malware deploys a hidden main payload that silently installs, maintains stealthy persistence, and facilitates credential theft. It harvests SMS, steals debit card details, and hijacks call forwarding all while leveraging Firebase Cloud Messaging (FCM) as its Command & Control (C2) channel. Link to the Research Report: https://www.cyfirma.com/research...
CYFIRMA Research- Raven Stealer 18.08.2025 4:00
CYFIRMA research explores the Raven Stealer, a stealthy info-stealing malware written in Delphi & C++, designed to harvest passwords, cookies, payment info and autofill data from Chromium-based browsers like Chrome & Edge. Link to the Research Report: https://www.cyfirma.com/research/raven-stealer-unmasked-telegram-based-data-exfiltration/ #CyberSecurity #InfoStealer #RavenStealer #Threat...
CYFIRMA Research: EdskManager RAT- Multi-Stage Malware with HVNC and Evasion Capabilities 25.07.2025 5:15
CYFIRMA research provides an analysis of a newly identified Remote Access Trojan, EdskManager RAT, which exhibits stealthy infection mechanisms and covert control using HVNC. Key Capabilities: · Multi-stage infection using signed binaries and encrypted config · HVNC-based hidden window interaction · Browser extension profiling (Chrome, Edge, Brave) · Dynamic C2 switching with z...
CYFIRMA Research: CVE-2025-5777– Pre-Auth Memory Leak in Citrix NetScaler (CitrixBleed 2) 21.07.2025 5:00
Critical Alert: CVE-2025-5777 – Pre-Auth Memory Leak in Citrix NetScaler (CitrixBleed 2)! Organizations relying on Citrix NetScaler ADC and Gateway for secure remote access must act immediately. This newly uncovered vulnerability allows unauthenticated attackers to leak sensitive memory—including session tokens—by sending malformed authentication requests. Exploited in the wild and backed by publi...
CYFIRMA Research- Octalyn Stealer Unmasked 18.07.2025 4:58
CYFIRMA exposes Octalyn Forensic Toolkit, a malicious GitHub-hosted tool masquerading as a legitimate forensic utility. In reality, it functions as a credential stealer with Telegram-based C2, targeting browser data, crypto wallets, Discord, and VPN configs. Built with Delphi and C++, Octalyn enables even low-skilled actors to exfiltrate sensitive data using Telegram bots. It uses PowerShell scr...
CYFIRMA Research- Tracking Ransomware- June 2025 16.07.2025 4:54
Stay ahead with CYFIRMA’s Monthly Ransomware Report – June 2025. June saw 463 ransomware victims globally, a 15% decline from May. Qilin led the threat landscape, exploiting Fortinet flaws and adding legal pressure tactics. New players like Fog and Anubis adopted stealthy, modular toolkits and file-wipers for maximum damage. Emerging groups Teamxxx, Warlock, and kawa4096 are gaining traction,...
CYFIRMA Research- RENDERSHOCK- Weaponizing Trust in File Rendering Pipelines 15.07.2025 5:58
New Threat Model: Zero-Click Compromise via File Rendering Automation RenderShock introduces a powerful new attack framework that leverages trusted file previewing, indexing, and sync mechanisms to trigger payloads — without exploits, macros, or even opening the file. Key Highlights: Zero-click execution using passive system features. Payloads delivered via LNKs, polyglots, CHMs, EXIF beacons...
CYFIRMA Research- GitHub Abused to Spread Malware Disguised as Free VPN 14.07.2025 5:19
CYFIRMA Research's latest report explores a fake "Free VPN for PC" app hosted on GitHub, delivering a packed DLL payload using obfuscated Base64 hidden in junk strings. It uses P/Invoke to load a hidden DLL, executes GetGameData, and injects into legit processes like MSBuild.exe. Packed, evasive, and anti-debug. Link to the Research Report: https://www.cyfirma.com/research/github-ab...
CYFIRMA Research- Phishing Attack: Deploying Malware on Indian Defense BOSS Linux 08.07.2025 3:20
CYFIRMA uncovers a sophisticated phishing campaign by APT36 (Transparent Tribe) leveraging Linux-specific malware on BOSS Linux systems (widely used by Indian government agencies). Attackers use malicious .desktop files to deploy stealthy ELF binaries while distracting users with fake PowerPoint files. Stay vigilant and safeguard critical infrastructure! Link to the Research Report: https://www....
CYFIRMA Research - 12-Day War update 02.07.2025 7:40
12-Day War update: Israel and Iran agree to a fragile ceasefire after America's bombing run on Tehran's nuclear facilities. Link to the Research Report: https://www.cyfirma.com/research/12-day-war-update/ #OperationRisingLion #MidnightHammer #IsraelIran #Geopolitics #CYFIRMAResearch #ThreatIntelligence #cybersecurity #ETLM #currentaffairs #MiddleEastWar #MilitaryAffairs #CYFIRMA #Externa...
CYFIRMA Research- Odyssey Stealer 26.06.2025 5:26
Odyssey Stealer, a rebranded version of Poseidon Stealer, targets macOS users through the Clickfix technique—tricking victims into copy-pasting malicious scripts into their terminal. With capabilities to steal hardware details, keychains, browser cookies, crypto wallets, and plugins, the stolen data is sent to the stealer's hosted infrastructure. During our analysis, we observed it creating...
CYFIRMA Research- APT36 Phishing Campaign Targets Indian Defense Using Credential-Stealing Malware 24.06.2025 6:36
Cyber Threat Alert: APT36 Targets Indian Defense with a Sophisticated Phishing Campaign! CYFIRMA has uncovered a targeted cyber-espionage operation by APT36 (Transparent Tribe), a Pakistan-based threat actor. This group is exploiting phishing emails embedded with malicious PDFs mimicking official NIC documents to infiltrate Indian defense systems. What’s Happening: · Victims receive a fake “p...
CYFIRMA Research- Tracking Ransomware: May 2025 18.06.2025 4:04
Stay ahead of evolving ransomware threats with CYFIRMA’s May 2025 Ransomware Report. May witnessed a 15.95% spike in ransomware attacks compared to April, with 545 incidents logged globally. New actors like SafePay and SilentRansomGroup rapidly gained ground, while established groups like Qilin deployed advanced loaders like NETXLOADER and SmokeLoader. Attackers leveraged tools such as Kickidler f...
CYFIRMA Research: Understanding CyberEye RAT Builder- Capabilities and Implications 16.06.2025 5:30
CYFIRMA’s latest research report analyses a stealthy Windows-based malware known as CyberEye, which is posing a significant threat across systems by offering attackers full remote control through a Telegram Bot API. Once executed, it silently harvests browser-stored passwords, cookies, credit card details, Wi-Fi credentials, and session tokens from apps like Telegram, Discord, and Steam. It monito...
CYFIRMA Research: Ukraine's Attack on Russia's Strategic Air Force- Live Feed from Revolution in Military Affairs 13.06.2025 8:35
Ukraine’s daring drone strike reshapes warfare! CYFIRMA’s research team examines how cheap tech took on Russia’s nuclear air force and what it means for global militaries. Link to the Reseach Report : https://www.cyfirma.com/blogs/ukraines-attack-on-russias-strategic-air-force-live-feed-from-a-revolution-in-military-affairs/ #Geopolitics #ThreatIntelligence #cybersecurity #ETLM #currentaffai...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.