
Jean-Marc Albert
23.6K posts



From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel By routing gRPC streaming traffic over the Tor network and delivering malicious modules only after a successful C2 connection, the threat actors are able to obfuscate their infrastructure and evade static analysis. yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid[.]onion:50051 netskope.com/blog/from-clic…



HEADS UP. Popular JSON formatter extension has started injecting geolocation tracking and donation UI into websites Reddit thread seems to think they are also swapping tracking IDs for affiliates (a-la honey) Uninstall and switch to another one


@mthcht2 pull request done!














🔥 Weaponizing Windows Toast Notifications ✅ Enumeration paths: Start Menu, AppX, Registry ✅ .NET + PowerShell Snippets to craft spoofed toasts ✅ Detection via wpnapps.dll / msxml6.dll image loads ✅ SIGMA + MDE for correlation ✅ Purple Team playbook 🔗 ipurple.team/2026/03/25/toa… #ipurple #purpleteam #threathunting





📢🍏 macOS is now part of the EDR Telemetry Project. After three months of focused work, we’re excited to share a new framework and generator for endpoint visibility on macOS! Huge thank you to everyone who contributed and helped shape this release. Looking forward to what comes next. Read more: edr-telemetry.com/blog/macOS-EDR…


LOLFSAAS Living off Free SaaS Hundreds of SaaS platforms with free tiers, documenting abuse surface, opsec risks, authent methods, C2 framework mappings, and operational limits. lolfsaas.github.io








