Reports

contagious interview fleet

An Undocumented OtterCookie-Lineage Build and Its Invisible C2 Fleet

How one stage-3 payload led to nine OtterCookie-related hosts, three server fingerprints, and a Contagious Interview infrastructure fleet sitting at zero detections. Author: Yury Sergeev, RST Cloud Published: 15 August 2026 Summary A client shared a single stage-3 payload from a DPRK-nexus Contagious Interview delivery chain. Deobfuscating it yielded more than a capability list: it exposed the […]

An Undocumented OtterCookie-Lineage Build and Its Invisible C2 Fleet Read More »

MacSync

MacSync Stealer: C2 Infrastructure Rotation

On 5 May 2026, an RST Cloud customer’s Jamf Protect blocked a download from jacksonvillemma[.]com. Four days earlier, the operator’s prior MacSync C2 had been publicly disclosed. Twenty-four hours after that disclosure, the new C2’s TLS certificate had been issued. Three days later, the new C2 was attempting to deliver its loader to a managed

MacSync Stealer: C2 Infrastructure Rotation Read More »

Axios NPM Supply Chain Attack

RST CLOUD THREAT INTELLIGENCE _ TLP:CLEAR When the axios npm supply chain attack broke on 31 March 2026, twelve separate vendor reports followed within 48 hours. Elastic Security Labs, Google GTIG, Microsoft Threat Intelligence, Wiz, Snyk, StepSecurity, Tenable, and others each documented the campaign from a different vantage point: initial discovery, dropper mechanics, RAT architecture, attribution, remediation. Valuable, individually. But absorbing all twelve

Axios NPM Supply Chain Attack Read More »