CyberOSINT Blog
Deep analysis, threat research, and technical deep dives from our intelligence team
NightEagle (APT-Q-95): GhostContainer, Microsoft Dev Tunnels, and the Expansion to Russia
How a Chinese-linked APT group uses compromised VPN credentials, Cloudflare WARP, and Microsoft dev tunnels to breach Russian enterprises — GhostContainer backdoor on Exchange, VIEWSTATE injection, and AMSI/ETW bypass in a full technical deep-dive.
AI Agents as Cyber Weapons: How OpenAI, Claude, and Cursor Are Being Weaponized in Real-World Attacks
Three independent campaigns in one week prove AI agents are autonomously executing supply chain compromises, rebuilding state-sponsored malware, and generating 1M+ phishing emails — a detailed analysis of the AI weaponization era.
ClickFix 2.0: 5,400+ Hacked Sites Use Blockchain Smart Contracts to Deliver Malware
How the EtherHiding technique turned the BNB Smart Chain into an unstoppable malware delivery platform — from fake CAPTCHAs to WebRTC data channels, with a full IOC appendix including 12 payload families.
When Ransomware Meets AI: Aurora's Use of Cursor in Attacks Against 33 Organizations
Aurora ransomware operators used Cursor AI to plan attacks in Russian, generate cross-platform Zig encryptors, exploit AD CS, and automate the full kill chain — the first documented AI-augmented ransomware campaign.
Gitea RCE (CVE-2026-60004, CVSS 9.8): The diffpatch Attack Chain
How attackers weaponize Gitea's diffpatch endpoint to plant Git hooks, execute arbitrary commands as the Gitea OS user, and deploy cryptominer payloads — now on CISA's KEV with a mandatory patch deadline.
BTR Reforged: Weaponizing Microsoft Defender's Boot-Time Driver for Kernel-Level Defense Evasion
How a built-in Windows component — present on every system since Windows 7 — can be used to delete security software at boot, bypassing blocklists, WDAC, and tamper protection.