stealth

Winsage
June 17, 2026
The Windows variant of SprySOCKS malware, developed by the Chinese threat group Earth Lusca, targets government entities globally and features advanced capabilities such as rootkit-level stealth and extensive command-and-control (C2) functionalities. It operates on Windows systems, utilizing two main variants: WINDRV, which includes kernel drivers for stealth operations, and WINPLUS, a streamlined backdoor. The malware can communicate over TCP, UDP, and WebSocket, offering over 30 C2 commands for various operations, including system information gathering and keystroke logging. WINDRV loads a driver named ‘RawWNPF’ into memory using another signed kernel driver, allowing it to conceal processes and achieve persistence. The malware's design incorporates open-source elements and exploits vulnerabilities in the software supply chain, notably using a leaked certificate for driver signing. To combat SprySOCKS, organizations are advised to implement advanced endpoint detection and response (EDR) solutions, maintain regular patching, and manage supply chain risks vigilantly. The malware's adaptability and reliance on legitimate certificates complicate detection efforts, necessitating continuous refinement of security practices.
Winsage
June 16, 2026
Cybersecurity researchers have identified two new Windows variants of the SprySOCKS backdoor, named WINDRV and WINPLUS, which were previously thought to be exclusive to Linux systems. Both variants feature hard-coded command-and-control configurations and can communicate via TCP, UDP, and WebSocket protocols. They support over 30 commands for operations such as system information collection and file management. WINDRV employs kernel drivers for stealth, obscuring network connections and allowing TCP traffic diversion. SprySOCKS was first documented by Trend Micro in September 2023, linked to the Chinese state-sponsored threat actor Earth Lusca, also known as FishMonger. The Windows variants belong to version 1.8 of SprySOCKS and utilize a kernel driver named RawWNPF for enhanced stealth. The attack chain begins with an initial access method that drops a batch script, leading to the installation of the backdoor. Evidence suggests these variants may have been used in attacks against government organizations in Honduras, Taiwan, Thailand, and Pakistan between 2023 and 2024. The WINPLUS variant was first detected in July 2024 in Pakistan. There are indications of a potential UEFI bootkit involvement exploiting CVE-2023-24932, a vulnerability in the Windows Boot Manager.
AppWizard
June 11, 2026
DMZ is a mode in Call of Duty's Warzone that offers a player-versus-environment (PvE) experience, contrasting with the typical player-versus-player (PvP) focus of extraction shooters. The map Al Mazrah features locked buildings, loot rooms, and dynamic events, promoting exploration. DMZ 2.0 is set to launch alongside Modern Warfare 4, promising enhancements based on player feedback, including a revamped stealth system, dynamic weather effects, vehicle integration, and improved matchmaking for shared objectives. Story missions will become more engaging, and a new "star system" will increase difficulty by attracting tougher enemies as players engage in combat. The developers aim to maintain the core elements of the original DMZ while expanding its features, appealing to both PvE and PvP players. DMZ 2.0 is scheduled for release in October.
AppWizard
June 10, 2026
Two years ago, Sega and Creative Assembly announced a sequel to Alien: Isolation, which won game of the year in 2014. The original game has maintained a strong reputation in the stealth genre, known for its unique enemy AI that enhances the horror experience. As the game nears its 10th anniversary, it continues to attract new fans. The sequel's development team includes veterans from the original game and new members, fostering innovative gameplay design. The team aims to create a "survival sandbox" that offers players multiple choices and paths, enhancing player-driven narratives. They are also addressing pacing issues from the original game and integrating mechanics from the start for a cohesive design. The team is committed to delivering an authentic Alien experience while exploring the franchise's lore and connecting the game to broader narratives.
AppWizard
June 8, 2026
The PC Gaming Show 2026 featured over 60 new game announcements in a two-hour event. Key titles include: - Wielders of the Essence: Launching on November 5, demo available on Steam. - Warhammer 40,000: Darktide – Skitarii Class: Debuting on June 23, wishlist on Steam. - Spellsided: Unique RPG with a demo on Steam. - Star Trek: Outposts Unknown: Demo available on Steam. - Hack '95: Demo available on Steam. - Company of Heroes: Definitive Edition: Wishlist on Steam. - Red Kiss: Wishlist on Steam. - Arcane Eats: Demo available on Steam. - Serious Sam: Shatterverse: Sign up for playtest on Steam. - Control Resonant: Pre-orders available for September 24 release on Steam. - Sated: Wishlist on Steam. - Gone Feral: Wishlist and sign up for playtest on Steam. - Abiotic Factor – Entropic Break DLC: Coming this autumn, wishlist on Steam. - There Are No Ghosts at the Grand: Demo available on Steam. - Ssarseeker: Astroneer Expeditions: Early access begins June 11, wishlist on Steam. - Virtue and a Sledgehammer: Demo available on Steam. - Happy Bastards: Combat demo available on Steam. - Another Door: Demo available on Steam. - AfterQuest: Wishlist on Steam. - SlashZero: Wishlist and sign up for playtest on Steam. - Cassette Beasts 2002: Wishlist on Steam. - VOID/BREAKER: Major update available on Steam. - 2 Fights 2 Tight Spaces: Available now on Steam. - Stronghold 4: Demo available on June 23, wishlist on Steam. - Wind Runners: Demo available on Steam. - Wardens of Avalon: Sign up for playtest on Steam. - Planet Zoo 2: Pre-orders available on Steam. - Empulse: Early access on June 24, available during Steam Next Feast on June 15. - Arkheron: Sign up for playtest on the game's website. - ReVamp: Sign up for playtest via the trailer's QR code. - Wardogs: Wishlist on Steam and sign up for playtests via the trailer's QR code. - Shroom and Gloom: New demo available. - Maximum Thunderness: Coming later this year, wishlist on Steam. - Rivage: Demo available. - Time Strike: Wishlist on Steam. - Signet City: Wishlist on Steam. - Mr. Magpie's Harmless Card Game: Available now on Steam. - Ascenders: Beyond the Peak: Demo available on Steam. - Outward 2: Beta available now. - Thief: The Dark Project Remastered: Remastering classic stealth game. - Exo Rally Championship: Off-road racing game. - Duskers 2.0: Available on Steam. - El Paso, Elsewhere 2: Wishlist on Steam. - Beast of Reincarnation: Launching on August 3, pre-order on Steam. - Terrinoth: Heroes of Descent: Available now on Steam. - To Kill a God: Demo available now. - Pipes.exe: Wishlist on Steam. - Sunset Summit: Available now on Steam. - Clowntown: Available for wishlist on Steam. - Armatus: Launching this winter, wishlist on Steam. - Dave The Diver – In the Jungle DLC: Wishlist on Steam. - Carcass Clad: Wishlist on Steam. - Total War: Warhammer 40,000: Beta opportunities to be announced. - About Fishing: Demo available on Steam. - Vampire: The Masquerade – Eternal Whispers: Emphasizes meaningful choices. - Valheim 1.0: Launching on September 9, 2026, download on Steam now. - P.O.N.: Wishlist on Steam. - Locator: The Search for Abigail Lidari: Wishlist on Steam. - Exodus: Features combat and exploration. - Remothered: Red Nun's Legacy: Third installment in the horror series. - Into the Wind: Wishlist on Steam.
Tech Optimizer
June 6, 2026
Researchers have identified a new malware called JS.MonoGlyphRAT, which disguises itself as business documents to infiltrate corporate networks. It is primarily spread through phishing emails targeting various sectors in the U.S. and has been reported in countries like Germany, Sweden, and Australia. The malware is classified as "Unknown malware" on threat intelligence platforms, making traditional antivirus solutions ineffective. It establishes a persistent presence in the network by executing a JavaScript file and communicating with command-and-control (C2) servers over HTTP. Key indicators of compromise include unusual HTTP traffic, registry changes, and the execution of specific JavaScript files. The malware can download additional payloads and execute commands without leaving traces on disk. Indicators of compromise include specific IP addresses, URLs, file hashes, and registry keys associated with the malware's operation.
Search