[Op Report] PackClient: Hands-on-Keyboard with a new C2 Framework
MalBeacon MalBeacon

[Op Report] PackClient: Hands-on-Keyboard with a new C2 Framework

Over a 48-hour Deception.Pro operation, we watched a PackClient operator use a tax-themed RAT as a doorman: after hours of quiet beaconing, a hands-on-keyboard task chain suppressed UAC and silently enrolled the victim into a ManageEngine Endpoint Central server the attacker controlled. From there the intrusion looked like routine endpoint management, including AD enumeration, vulnerability scanning, and remote control, with every second-stage binary legitimately signed by Zoho.

Read More
[Op Report] From PDF Phish to XLoader: A ScreenConnect Hands-on-Keyboard Intrusion
MalBeacon MalBeacon

[Op Report] From PDF Phish to XLoader: A ScreenConnect Hands-on-Keyboard Intrusion

A phishing lure drops a batch script that silently installs ScreenConnect, giving an operator hands-on-keyboard control of a Deception.Pro honeynet before XLoader/FormBook is injected into a signed Windows binary to grab banking credentials and exfiltrate to Sendspace. A full walkthrough of the kill chain, why the ScreenConnect-plus-XLoader pairing is one we hadn't seen in our collection or in public reporting.

Read More
[Op Report] From Award Scam to Domain Recon & Exfiltration
MalBeacon MalBeacon

[Op Report] From Award Scam to Domain Recon & Exfiltration

A Deception.Pro honeynet captured a complete hands-on-keyboard intrusion that started with an "award receipt" phishing email linking to a GitHub-hosted download and ended with Active Directory reconnaissance and browser-credential theft. What makes it stand out is the actor's environment-aware payload logic — delivering different follow-on stages depending on whether the host was domain-joined — and the chaining of three separate C2 frameworks (Cobalt Strike, ScreenConnect, and Havoc) on a single machine for redundancy. We walk through the full attack chain and share defanged IOCs, Suricata signatures, hunting queries, and ATT&CK mappings.

Read More
[Update] New Home, Faster Backend, New Network View
MalBeacon MalBeacon

[Update] New Home, Faster Backend, New Network View

Deception.Pro has a new home at app.deception.pro — old demo.deception.pro links still work and redirect automatically. A backend database migration to faster, more reliable infrastructure means filtering detections and network data is now quicker and more stable. The rebuilt network view brings per-column filtering, more detail on every connection type, visible stats and timeline, and sessions that stay authenticated for two weeks.

Read More
[Update] File Manager, Interactive PowerShell, and Smarter Timelines
MalBeacon MalBeacon

[Update] File Manager, Interactive PowerShell, and Smarter Timelines

Deception.Pro now ships a full file manager on every running host—upload, download, move, rename, delete, and add files straight to your artifacts—plus an interactive PowerShell terminal for live, on-host command execution in your deception environment. We've also reworked timeline generation so every detection that fires is properly captured, giving you the complete, ordered picture of an engagement. All three updates are live now and came straight from the top of your request list.

Read More
[Update] Deception.Pro May 2026
MalBeacon MalBeacon

[Update] Deception.Pro May 2026

Deception.Pro just shipped AI-generated reports for paying customers, timeline-correlated EDR and network telemetry in artifact downloads, and a deeper, more believable Active Directory environment. Backend upgrades cut environment spin-up time, randomize replica file timestamps, and auto-configure timezones based on VPN egress — all in service of higher-fidelity adversary engagement.

Read More
[Op Report] Trojanized CPU-Z Delivers STXRAT, Steals Credentials, and Exfils Data Through a Hidden QEMU VM
MalBeacon MalBeacon

[Op Report] Trojanized CPU-Z Delivers STXRAT, Steals Credentials, and Exfils Data Through a Hidden QEMU VM

A trojanized CPU-Z installer dropped STXRAT via DLL side-loading, quietly deploying PureLogs Stealer to harvest browser credentials and PureHVNC for remote access — all while routing 54 hours of continuous data exfiltration through a locally-hosted QEMU Alpine Linux VM to evade detection. Deception.Pro captured the first documented full post-exploitation chain for this campaign, delivering ground-truth adversary telemetry that no sandbox or threat feed could replicate.

Read More
[Update] Deception.Pro April 2026
MalBeacon MalBeacon

[Update] Deception.Pro April 2026

TLS introspection is now live on Deception.Pro — decrypted PCAPs are automatically generated and available in the Artifact section of every operation. For the first time, you have full plaintext visibility into encrypted adversary traffic, correlated alongside your EDR telemetry, Suricata EVE logs, and raw captures. This release also ships meaningful improvements to artifact delivery speed, platform stability, and internal architecture.

Read More
[Update] Deception.Pro March 2026
MalBeacon MalBeacon

[Update] Deception.Pro March 2026

This release brings a new Timeline View for unified process and event history across detonations, expanded YARA detection coverage for executables in memory and on disk, and a round of frontend stability improvements. Free researcher accounts will also see a new telemetry consent flow for anonymized data used in AI model training — paid and PoV accounts are unaffected. Attackers bet heavily on encryption to blind defenders — that's about to get harder, with TLS introspection and several other major capabilities coming to the platform soon.

Read More
[Op Report] Velvet Tempest linked to ClickFix campaigns for Termite Ransomware, HoK Activity Observed
MalBeacon MalBeacon

[Op Report] Velvet Tempest linked to ClickFix campaigns for Termite Ransomware, HoK Activity Observed

A recent deception operation shows Velvet Tempest leaning on a “ClickFix”-style lure to move fast from initial access into hands-on-keyboard activity consistent with Termite ransomware operations. In this post, we break down the timeline, highlight the most actionable indicators of compromise, and translate the tradecraft into practical defender takeaways—including where deception can turn attacker momentum into instant signal.

Read More
[Op Report] Hands-on-Keyboard Intrusion Abusing Multiple RMMs
MalBeacon MalBeacon

[Op Report] Hands-on-Keyboard Intrusion Abusing Multiple RMMs

Proofpoint observed a hands-on-keyboard intrusion where an operator abused multiple RMM platforms—including Bluetrait, Fleetdeck, Level, and MSP360—after initial access via a malicious PDF “missing Adobe plugin” lure. The activity underscores a growing reality: attackers are increasingly using legitimate IT tooling as a resilient intrusion framework.

Read More
[Update] Deception.Pro Jan 2026
MalBeacon MalBeacon

[Update] Deception.Pro Jan 2026

The January 2026 Deception.Pro update introduces industry based replica browsing for Premium users, expanded and more reliable malware auto detonation across common delivery formats, improved artifact handling with VirusTotal linking, and broad stability enhancements, while laying the groundwork for dedicated KVM infrastructure, TLS inspection, and memory dump support.

Read More