Security researchers reported multiple malware campaigns emphasizing stealth and automation. K7 Lab analyzed a Python-based RAT packaged inside an apparently benign ELF executable, effectively embedding a Python runtime and scripts to evade simple file-type controls and complicate static inspection; the RAT also uses adaptive beaconing to reduce network noise by polling C2 rapidly when active (e.g., sub-second intervals) and sleeping longer when idle (e.g., config.HELLO_INTERVAL), lowering the chance of detection by behavior-based monitoring.
Separately, threat reporting described a Vietnamese actor (“Huna”) targeting job seekers with phishing lures (often via Dropbox-hosted archives/links) to deliver PureRAT and related payloads, with tooling that shows strong indicators of generative-AI-assisted development (unusually detailed comments, numbered steps, and even operator instructions embedded in scripts). An Iran-aligned espionage operation attributed to RedKitten targeted Iranian human-rights NGOs and activists using malicious Microsoft Excel lures and multi-stage malware, including AI-generated/obfuscated macros, cloud and messaging platforms for C2 (e.g., GitHub, Google Drive, Telegram), and TTP overlap with known Iranian groups (e.g., Charming Kitten/Nemesis Kitten patterns), indicating continued evolution toward AI-enabled tradecraft and resilient infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
K7 Labs analyzed a Python-based RAT after discovering a suspicious sample on VirusTotal and unpacking its embedded Python runtime. The malware was designed to masquerade as a benign ELF binary, using adaptive beaconing and anti-forensics cleanup features to evade detection and reduce traces on infected systems.
Researchers reported a financially motivated campaign targeting job seekers worldwide with fake employment lures that delivered PureRAT and related malware. The Vietnam-linked actor used trusted cloud services such as Dropbox, DLL sideloading, and Python-based payload retrieval, with artifacts repeatedly referencing "Huna" and the password string "huna@dev.vn."
During the campaign, RedKitten used spearphishing with Farsi-labeled 7-Zip archives containing macro-enabled Excel decoys about protester deaths. Opening the lure triggered an AI-obfuscated VBA dropper that installed the modular SloppyMIO implant, which used AppDomainManager injection, scheduled-task persistence, and a GitHub-to-Google-Drive-to-Telegram cloud C2 chain.
An Iran-linked, Farsi-speaking threat actor dubbed RedKitten began a targeted cyber-espionage campaign in late 2025 against Iranian human rights NGOs, activists, academics, journalists, officials, and business leaders. The operation particularly emphasized Kurdish community targets and reportedly directly impacted at least 50 individuals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcerescana.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.