

ClickFix Meets AI: How Attackers Use AI-Generated Obfuscated JavaScript to Deliver Malware via Fake CAPTCHA
Introduction ClickFix campaigns have historically relied on user-driven execution techniques, tricking victims into executing malicious commands through seemingly legitimate verification workflows. In recent campaigns, however, attackers have significantly evolved their tradecraft by combining compromised WordPress infrastructure, AI-generated JavaScript payloads, heavy obfuscation, and staged PowerShell delivery mechanisms. During our investigation, we observed a campaign wh
Mar 2332 min read


New Phishing Attack mimics Google AppSheet to deliver malware - Abusing WinWord.EXE local DLL Side-Loading
-- Praj Shete Summary A new, sophisticated phishing campaign is impersonating Google AppSheet to push a multi-stage, file-based malware...
Sep 15, 20256 min read


Detecting Process Injection using a debugger (x64bdg)
Praj Shete What is Process Injection? Process Injection is a technique used by attackers to run malicious code within the address space...
Aug 29, 20255 min read


Spoofed “icegate.gov.in” emails delivering JAR-based RAT/Stealer
Praj Shete Executive Summary Email remains one of the most exploited attack vectors for cybercriminals, who often leverage domain...
Aug 25, 20253 min read
Colonial Pipeline Cyber Attack
The Colonial Pipeline cyber attack was a ransomware attack that occurred in May 2021. The attack was aimed at Colonial Pipeline, which...
Feb 3, 20234 min read
Windows Zero-day MOTW bypass
What is MOTW? Mark-of-the-Web is a security feature in Windows that flags files which are downloaded from the internet as the file is...
Nov 3, 20222 min read
