The Node.js loader that locks its own strings to the folder it lives in
A Node.js loader disguised as a dev tool: signed node.exe, extensionless script, folder-keyed string cipher, and an in-memory payload that never touches disk.
A Node.js loader disguised as a dev tool: signed node.exe, extensionless script, folder-keyed string cipher, and an in-memory payload that never touches disk.
A fake SysMon.py in C:\Windows\SystemHealth runs a Pyarmor-locked Python bundle: an XMRig Monero miner, a credential and wallet stealer, and a fake-wallet phisher.
A brand-new scheduled task on a two-year-old host launches a fileless PowerShell HTTP-RAT that listens on localhost only and waits for an operator's tunnel.
A WMI-launched PowerShell loader with reflection AMSI/ETW bypass and a payload that only decrypts if its own AMSI bypass succeeded first.
A PowerShell stager drops the legitimate Node.js runtime, runs a JavaScript RAT under it, and resolves its C2 domain from a TON blockchain smart contract.
A ClickFix lure drops a 145 MB Electron flomo app. The RAT runs a signed OneDriveLauncher that sideloads a trojanized DLL to decrypt a PNG-wrapped payload.
A ClickFix loader using finger.exe over TCP/79 to drop IronPython and an in-process x86 shellcode beacon.
A ClickFix campaign drops a 2.4 MB polyglot from prism-vertex[.]com that looks like an MSIX package but parses as an HTA when mshta opens it.
A 3.7 MB log-line file in System32\drivers\, a tiny PowerShell read-decode-execute, and an HTTP beacon that pulls its capability live.