Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@infosecbot.bsky.socialOct 6, 2026, 3:21 PM

#xworm #opendir at:

http://107.173.143\.44/60

c2: 151.241.154\.23:7007

— from @James_inthe_box (https://x.com/James_inthe_box/status/2107491399730073763)

@james-inthe-box.infosec.exchange.ap.brid.gyOct 6, 2026, 3:21 PM

#xworm #opendir at:

http://107.173.143\\.44/60

c2: 151.241.154\\.23:7007

@securityonline.bsky.socialOct 5, 2026, 7:14 AM

2CLoader malware dodges sandboxes and security tools to deliver Vidar and Remus infostealers. See how it works and how to detect it.

#2CLoader #Vidar #Remus #XWorm #Infostealer #MalwareLoader #ThreatLabz #CyberSecurity

@hendryadrian.bsky.socialSep 30, 2026, 10:45 PM

ThreatLabz tracked 2CLoader, a Windows loader using anti-analysis and HTTP C2 to deliver Vidar, Remus, and XWorm via XOR-encrypted JSON. #2CLoader #Vidar #XWorm

@threadlinqs.bsky.socialSep 30, 2026, 2:47 PM

2CLoader binds its AES key to its own .text hash, then drops Vidar, Remus and XWorm. https://intel.threadlinqs.com/threat/TL-2026-2819 #ThreatIntel #XWorm #Vidar #Remus

2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
@malware-traffic-analysis.netSep 10, 2026, 10:19 PM

Two new posts with #pcap, #malware, other files and #indicators for #XWorm (Tuesday, 2026-09-08) and #AMOS #Stealer (Thursday, 2026-09-10).

www.malware-traffic-analysis.net/2026/index.h...

Screenshot of my blog page with the two most recent posts.
@threadlinqs.bsky.socialSep 8, 2026, 10:52 PM

Lua loader hides in fake .ttf font files - fileless RATs via VEH-encrypted shellcode. https://intel.threadlinqs.com/threat/TL-2026-2402 #ThreatIntel #Rakhni #Agent #XWorm

The TTF Trap - Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers