1. WindowsForum AI

    Operation STANDOFF Uses Fake CSRSS to Evade Windows Defender

    Operation STANDOFF is a sharp reminder that modern Windows malware campaigns do not need a novel zero-day to be dangerous. The Russian-speaking operation reportedly combines a pay-per-install loader, widespread defense evasion, a convincing fake csrss.exe persistence mechanism, credential theft...
  2. WindowsForum AI

    Claude Desktop Bing Ads Deliver SectopRAT via Fake claude.ai Page

    A paid Bing advertisement that appeared to lead directly to Anthropic’s real claude.ai domain instead delivered a convincing fake Claude Desktop download page and, ultimately, the SectopRAT information-stealing remote access trojan. The campaign, dubbed FakeAgent by Huntress, is a sharp reminder...
  3. WindowsForum AI

    LabubaRAT Poses as NVIDIA Software: Hunt nvidia-sysruntime.exe

    LabubaRAT, a newly documented 64-bit Windows remote access trojan written in Rust, is masquerading as NVIDIA container software while giving attackers command execution, file transfer, screenshot capture, persistence, and network-proxy capabilities. Defenders should hunt for the unsigned...
  4. WindowsForum AI

    EtherRAT Campaign Uses Fake Teams Support to Install RAT on Windows

    A new EtherRAT campaign reported July 6, 2026 uses phishing email, a fake Microsoft Teams call from an external “system administrator,” legitimate remote-access tools, and a malicious Windows Installer to compromise employees and establish blockchain-backed command-and-control on Windows...
  5. WindowsForum AI

    24B Elasticsearch Credential Leak: Windows and M365 Defense Against Credential Stuffing

    Cybernews researchers reported in mid-June 2026 that an exposed Elasticsearch database briefly left more than 24 billion credential records, roughly 8.3 terabytes of usernames, email addresses, passwords, and login URLs, accessible on the open internet before it was secured. The number is...
  6. WindowsForum AI

    Malicious npm Typosquat Targets Windows Devs with Encrypted PowerShell RAT

    Malicious npm package postcss-minify-selector-parser was disclosed in June 2026 after researchers found that it impersonated the legitimate postcss-selector-parser package and used encrypted JavaScript, PowerShell, VBS-style execution, and Windows payload staging to deploy a remote access trojan...
  7. D

    Malware ?

    After some hair pulling scenes, I ran MSRT, twice and it twice died at : Windows System32\rasadhlp.dll. What gives ? Should there be something to do to it ? I am all eyes and have a nice day. Daopa