Blog

EtherRAT Blockchain C2 Infrastructure Attributed to Lazarus

EtherRAT Blockchain C2 Infrastructure Attributed to Lazarus

Blockchain technology was built for trustless, decentralized finance. Threat actors found another use for it.EtherRAT is a JavaScript-based remote access trojan that stores its command and control…

Muhammad Sawood · Sarah JawaidMay 22, 2026
ROGUE SIGNAL: INSIDE THE CALCULATED US–ISRAELI CYBER AND MILITARY WAR ON IRAN

ROGUE SIGNAL: INSIDE THE CALCULATED US–ISRAELI CYBER AND MILITARY WAR ON IRAN

This analysis examines the full spectrum of operations behind the American-Israeli strike on Iran beginning February 28, 2026, from long-term cyber infiltration and network compromise to coordinated…

Sarah Jawaid · Muhammad SawoodMarch 09, 2026
The Exploit Theater: Nation-State Cyber Clashes in South Asia

The Exploit Theater: Nation-State Cyber Clashes in South Asia

Executive Summary In May 2025, cyberspace emerged as the battleground for a high-stakes digital conflict between India and Pakistan. This report provides a structured threat intelligence analysis of…

Muhammad SawoodJune 03, 2025
CVE-2025 Exploitation by the Five Elders in Their Global Cyber Campaigns

CVE-2025 Exploitation by the Five Elders in Their Global Cyber Campaigns

Executive Summary: This report documents confirmed exploitation of 2025 CVEs by nation-state APT groups and cybercriminal collectives. Only incidents with publicly verifiable sources are included…

Muhammad SawoodJune 03, 2025
🐎 Lasso Trail: Tracking Chinese ZuoRat-Style ORB Proxy Infrastructure Supporting Phishing and Malware Campaigns

🐎 Lasso Trail: Tracking Chinese ZuoRat-Style ORB Proxy Infrastructure Supporting Phishing and Malware Campaigns

✨ Executive Summary ZuoRAT is a Chinese-linked Remote Access Trojan (RAT) targeting SOHO routers for internal surveillance and device compromise. It leverages an ORB-style proxy C2 network where…

Muhammad SawoodApril 13, 2025
Rinnegan Awakening Unlocking Kimsuk’s-APT43 Hidden Shadow Network

Rinnegan Awakening Unlocking Kimsuk’s-APT43 Hidden Shadow Network

Alias: Mystery Baby,Baby Coin,Smoke Screen,Black Banshee,Velvet Chollima,Thallium,Emerald Sleet,THALLIUM,Sparkling Pisces Kimsuky was first disclosed and named by Kaspersky in 2013, with attack…

Muhammad SawoodDecember 21, 2024
CHASING SHADOWS THE HUNT FOR APT BITTER AND ITS HIDDEN INFRASTRUCTURE

CHASING SHADOWS THE HUNT FOR APT BITTER AND ITS HIDDEN INFRASTRUCTURE

Alias: Apt-c-08, Apt-k-47, Manlinghua, Turtlepower, NixBackdoor, Nimbo-C2, ORPCBackdoor Recently, I discovered that Mysterious Elephant, also known as APT-K-47, operates under the umbrella of APT-C…

Muhammad SawoodDecember 02, 2024
"Guarding against the Unknown, Just Like a Hokage"

© 2026 Hokage Vanguard — All rights reserved.