Thursday , August 20 2026
Flow chart

Hacker to use fake Palo Alto GlobalProtect Tool in cyber attack

Trend Micro researchers identified a sophisticated malware campaign that aims at Middle East organizations. The campaign tricks victims into infecting their devices by pretending to be a real Palo Alto GlobalProtect VPN client.

The attack begins with the distribution of a malicious file named “setup.exe,” which masquerades as a legitimate installation package for Palo Alto Networks’ GlobalProtect VPN. Once executed, this file deploys “GlobalProtect.exe” along with configuration files “RTime.conf” and “ApProcessId.conf” into the victim’s system directory, specifically within the path C:\Users\ UserName)\AppData\Local\Programs\PaloAlto\.

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems...
Read More
Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

500+ critical infrastructure hit by Medusa ransomware

Medusa ransomware hit over 500 critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) said on Tuesday that the Medusa...
Read More
500+ critical infrastructure hit by Medusa ransomware

Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload harmful PHP files. This could...
Read More
Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 problems that could let users...
Read More
Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

DoNot (APT-C-35) Targeting Bangladesh Military Personnel

Bangladesh's military and defense system is actively under targeted attack linked to DoNot Team, or APT-C-35, as stated in a...
Read More
DoNot (APT-C-35) Targeting Bangladesh Military Personnel

McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Millions of Records

A large Azure data theft campaign is surfacing on the dark web. A hacker is offering employee lists taken from...
Read More
McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Millions of Records

NIST to Modernize NVD in the Age of Artificial Intelligence

National Institute of Standards and Technology (NIST) demands feedback from industry and the government on how to update the National...
Read More
NIST to Modernize NVD in the Age of Artificial Intelligence

ALERT
Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

TP-Link has revealed several serious security flaws in Aginet networking products managed by ISPs. This includes mesh systems, routers, PON...
Read More
ALERT  Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

LiteLLM supply chain attack reveals 153GB of stolen credentials online

153GB record surface online stolen during the LiteLLM supply chain attack linked to thousands of corporate domains, including AWS, Samsung,...
Read More
LiteLLM supply chain attack reveals 153GB of stolen credentials online

PATCHCORD Backdoor Targets Telecom and CII In South Asia

A previously undocumented backdoor called PATCHCORD actively target telecom and critical information infrastructure (CII) in South Asia. According to Acronis...
Read More
PATCHCORD Backdoor Targets Telecom and CII In South Asia

The malware deceives by using a command-and-control infrastructure with a new URL named “sharjahconnect.” The URL is designed to look like a legitimate company VPN portal, helping the malware to infiltrate and maintain access to compromised networks without being detected.

A particularly notable aspect of this malware is its use of the Interactsh project, a tool typically used by penetration testers to verify exploit success, for beaconing purposes. By leveraging Interactsh, the malware sends DNS requests to domains within the oast[.]fun domain, such as step[1-6]-{dsktoProcessId}.tdyfbwxngpmixjiqtjjote3k9qwc31dsx.oast.fun. These beaconing requests correspond to various stages of the infection process, from collecting machine information to executing commands received from the C&C server.

This method helps threat actors track their malware’s progress as it spreads, giving them real-time information about which targets have been compromised.

This malware, created in C#, can perform remote PowerShell commands, download and run more payloads, and steal specific files from the infected machine. Its command structure is flexible, enabling it to carry out various tasks.

Executing PowerShell Scripts:
The malware can run PowerShell commands and send the results back to the C&C server.
Process Management:
It can start new processes, download files from a specified URL, and upload stolen files to a remote server.
Data Encryption:
To secure its communications, the malware employs AES encryption, ensuring that data sent to the C&C server is protected from interception.

These capabilities make the malware a powerful tool for spying and stealing data, with the potential to cause serious harm to targeted organizations.

The malware uses smart techniques to avoid being detected by security tools. It checks file paths and specific files before running its main code, making it hard to find in controlled analysis environments. It also uses newly registered domains for its activities, which makes it difficult to detect and attribute the attack to a specific threat actor.

Companies in the Middle East and around the world need to stay alert and take action to improve their defenses against these threats. This means using strong endpoint protection, keeping security protocols up to date, and focusing on educating and raising awareness among employees.

Check Also

US defense

Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link …