News · Threat Research

Research notes, threat write-ups, and product updates from the whack.sh team.

Nine files, two payloads: a Silver Fox sideloader in an open directory

2026-09-29 · Threat Research

An open HFS server was serving a Silver Fox DLL-sideloading kit: a Microsoft-signed SPDDUMP.EXE loads a malicious mspdb140.dll, which starts a downloader and a keylogging, clipboard-stealing implant. Nine payload files reduce to two, and one 2 KB loader stub marks both stages.

Brevo delivered KongTuke ClickFix to 51 customer sites

2026-09-17 · Threat Research

Brevo served malicious JavaScript from its own delivery infrastructure on September 14, reaching 51 customer domains. Kirk of ADAMnetworks published the analysis; Whack.sh took part in the shared investigation.

PasteSwitch: 108 crypto-theft ads on a hijacked HBO Max Reddit account

2026-09-14 · Threat Research

Attackers hijacked the official verified u/hbomax Reddit account and ran 108 ClickFix ads in 48 hours, delivering fake Ledger, Trezor and Exodus wallet apps on macOS and clipboard hijackers driven by Binance Smart Chain dead drops. Hudson Rock led the research with ADAMnetworks.

The malware that shows scanners a clean page

2026-09-11 · Threat Research

A cloaked link serves a clean page to scanners and malware to real visitors. Every reputation engine that checked one recent Carnival Cruise Line case rated it safe for months, because each engine looked from a single datacenter IP. Why a scan verdict describes one observation rather than a URL, why the hop domains are disposable by design, and what multi-vantage checking still cannot catch.