Ransomware threat actors tracked as Velvet Tempest are using the ClickFix technique and legitimate Windows utilities to deploy the DonutLoader malware and the CastleRAT backdoor.
The script has been used on OSX with V10, V11, V15, V16, V18 and V19 DDRs. Windows and DDRs V12-14 may or may not work. It's very fast. The longest run I have measured was 2 min. for a 420MB / 40 file ...
Using an AI coding assistant to migrate an application from one programming language to another wasn’t as easy as it looked. Here are three takeaways.