campaigns

Winsage
August 27, 2026
Researcher Dominik Reichel has identified a new malware implant called SLEEPWALKER, which is disguised as an agent from ESET. SLEEPWALKER is unique because it does not contain malicious code and remains dormant until it receives specific network signals to activate. It appears to be designed for targeted attacks, likely orchestrated by nation-states. Although it was submitted to VirusTotal last year, it has not been linked to any active campaigns or confirmed victims. The origins of SLEEPWALKER are unknown, and its code is described as somewhat "rough around the edges," indicating it may still be in development.
Winsage
August 27, 2026
Windows holds a 71 percent share of the desktop market, with over 1.6 billion active Windows PCs globally. In contrast, macOS accounts for just over seven percent of the market, rising to nearly 20 percent when combined with OS X. Windows users face a variety of threats, including trojans and riskware, and in 2025, Windows users encountered seven times more malware than macOS users. Surfshark's data indicates that macOS users are increasingly targeted by phishing attacks, which pose significant financial and personal risks.
Winsage
August 24, 2026
Microsoft has launched a referral program for its Edge browser, allowing users to earn 500 Microsoft Rewards points for each friend they invite to switch to Edge, with a maximum of 7,500 points per month. To qualify, the invited friend must be a new user, sign into Edge, and use the browser for at least two days within the first two weeks. Additionally, a new application called 'Microsoft Recommended Search' has been discovered, designed to change the default search engine to Bing across various browsers, raising concerns among users about Microsoft's promotional strategies.
AppWizard
August 23, 2026
Hearts of Iron IV is a grand strategy game set during World War II, where players control a nation and navigate warfare, diplomacy, and military strategy. It offers extensive gameplay options, including resource management and political maneuvering, and is known for its replayability. Phoenix Point is a turn-based tactical strategy game set in a post-apocalyptic world, where players lead customizable squads against alien threats, emphasizing tactical decision-making. War on the Sea is a real-time tactical strategy game focused on naval battles in the Pacific Theater during World War II, featuring historically accurate ships and aircraft. Terra Invicta is a grand strategy game in Early Access, where players manage factions in a near-future scenario while preparing for potential interstellar conflict. Command & Conquer: Generals is a real-time strategy game featuring three factions: the United States, China, and the Global Liberation Army, known for its engaging gameplay. Cold Waters allows players to command a Cold War-era nuclear submarine, focusing on stealth tactics and realistic naval simulation. Gears Tactics is a turn-based game set in the Gears of War universe, where players lead a squad against the Locust Horde. Warhammer 40,000: Battlesector involves commanding Primaris Space Marines in tactical battles against Tyranids, with expansions enhancing gameplay. Company of Heroes 2 is a real-time strategy game set on the Eastern Front during World War II, featuring squad-based tactics and dynamic campaigns. Total War: Shogun 2 is set in feudal Japan, allowing players to command clans during the Sengoku Jidai period, combining tactical battles with strategic management.
AppWizard
August 20, 2026
GeForce NOW has introduced support for Firefox, enabling gamers to play PC games directly from their browsers without downloads or installations. This integration allows access to high-performance gaming on various devices, with graphics powered by GeForce RTX at resolutions up to 1440p and frame rates of 120 fps for Ultimate members. Users can start gaming by downloading the latest version of Firefox and visiting play.geforcenow.com. The platform also offers cloud saves for seamless transitions across different devices. New game releases include Gallipoli, Stars Reach, The Sinking City 2, and more, with varying availability on GeForce NOW. Users can begin with a day pass, which can be credited toward a membership upgrade.
TrendTechie
August 19, 2026
Pirated digital copies of the film "Odyssey" are being used to spread the Lumma Stealer malware, which compromises viewers' computers. Bitdefender's internal data shows that users have attempted to download malicious executable files disguised as the film, which has not yet been released on online platforms. These counterfeit copies are circulating on illegal sites, and the Lumma Stealer malware can steal sensitive information from infected devices. Bitdefender identified several bait file names that are actually executable files designed to infect computers rather than play the film. This tactic follows a trend of using popular films to disseminate malware, with similar campaigns documented in the past. Cybercriminals exploit the gap between a film's theatrical release and its availability on legal streaming platforms. Users are advised to watch films only through verified services and to keep their cybersecurity software updated.
AppWizard
August 18, 2026
Napoleon Bonaparte was a Corsican general who became the ruler of France, known for his military strategies and ambition. His campaigns in Europe have influenced historical fiction, art, and video games, particularly in the genre of Napoleonic wargames. These games have evolved to include advanced AI, historical accuracy, and immersive gameplay. Total War: Napoleon is a notable entry in this genre, combining tactical battles with strategic campaigns, allowing players to command armies and manage empires. It was the first in the series to use buildings as tactical assets and is praised for its visual appeal and historical representation. Empire: Total War expands the timeline from 1700 to 1815, incorporating naval battles alongside land combat, enhancing the strategic experience with a diverse range of nations and historical events. Imperial Glory, released in 2003, focuses on turn-based grand strategy and diplomacy within the Napoleonic era. It features a robust diplomacy system and unique regional maps, making it a classic choice for retro gaming enthusiasts despite its age.
Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
Search