Advertisement · 728 × 90
#
Hashtag
#Emmenhtal
Advertisement · 728 × 90
Post image

Campagna MaaS usa Emmenhtal e Amadey per colpire entità ucraine via GitHub. Talos rivela tattiche e IOC per la mitigazione.

#Amadey #CiscoTalos #Emmenhtal #github #MaaS #SmokeLoader #ucraina
www.matricedigitale.it/2025/07/17/o...

1 0 0 0

In early 2025, the ClearFake framework widely spread #Emmenhtal Loader as the initial stage, aiming to download #Lumma or #Rhadamanthys, or PowerShell scripts installing #Vidar.

We identified thousands of sites compromised with ClearFake distributing these malware.

1 0 1 0
Post image

🆕New version of #Emmenhtal loader actively distributed worldwide since early March, leading to #Lumma or #Rhadamanthys stealers.
Very low AV detection on VT for now.
Similarly to V2, Emmenhtal V3 masquerades as #mp3 or #mp4 files, including relaxation songs.🧘‍♀️

3 1 1 0
Post image

#ClearFake variant is now spreading #Rhadamanthys Stealer via #Emmenhtal Loader.

cc @plebourhis.bsky.social @sekoia.io

1. ClearFake framework is injected on compromised WordPress and relies on EtherHiding

2. The #ClickFix lure uses a fake Cloudflare Turnstile with unusual web traffic

⬇️

3 2 2 0
Preview
Compromised store spread Lumma Stealer using a fake CAPTCHA In a shift in tactics the fake CAPTCHA was added to an existing site, instead of using malvertizing or SEO poisoning

In this post I take a deep dive into a fake CAPTCHA on a compromised website, and the multistage fileless loader that delivered the Lumma Stealer malware if visitors followed its instructions.

#Google #reCAPTCHA #WordPress #PowerShell #Malware #Emmenhtal #Infostealer #LummaStealer

2 0 2 1
Post image

Tracking #Lumma & #Emmenhtal #loader through weeks targeting LATAM - #threat #malware

📍🏴
💥🇨🇴🇲🇽🇦🇷🌎

⛓️ #Link | Mal domain > Fake CAPTCHA | ZIP/RAR > Encoded PS | mshta (HTA) > download next > Obfuscated script exec > File | ZIP dropped > Injection over file > #LummaStealer

0 0 1 0
Preview
GitHub - cert-orangecyberdefense/edam: Edam dropper Edam dropper. Contribute to cert-orangecyberdefense/edam development by creating an account on GitHub.

While monitoring recent #Emmenhtal iterations, we observed a distinct politically-aligned cluster 🇪🇺, strongly differing from usual financially motivated Emmenhtal distribs.
This cluster drops another malware we dubbed #Edam Dropper🧀
github.com/cert-orangec...

Targets: European #energy sector🔋

2 0 1 0