Latest Posts

Inside Modern Supply Chain Intrusions: From CI/CD Abuse to Ecosystem-Wide Compromise

02 Jun 2026

DarkAtlas Squad
Investigation

Inside Modern Supply Chain Intrusions: From CI/CD Abuse to Ecosystem-Wide Compromise

Modern supply chain intrusions are attacks that compromise trusted software development systems, including CI/CD pipelines, package registries, GitHub repositories, developer tools, and cloud environments. Instead of attacking one organization directly, threat actors abuse trusted dependencies, automation workflows, and stolen developer credentials to spread across entire software ecosystems. TeamPcP History TeamPCP (also tracked as PCPcat, DeadCatx3, […]

Behind .payload: In-Depth Technical Analysis of Payload Ransomware

25 May 2026

Dark Atlas
DarkAtlas Squad

Behind .payload: In-Depth Technical Analysis of Payload Ransomware

Payload ransomware is a Windows ransomware family that appends the .payload extension to encrypted files, drops RECOVER_payload.txt ransom notes, and uses ChaCha20 encryption with per-file Curve25519 ECDH key exchange. The sample also includes anti-forensics features such as ETW patching, VSS deletion, Windows Event Log clearing, and process/service termination. Key Takeaways Overview On 15 February 2026, […]

PlugX DLL Sideloading via MSI Installer: Complete Malware Analysis of a KorPlug Campaign

18 May 2026

backdoor
Dark Atlas

PlugX DLL Sideloading via MSI Installer: Complete Malware Analysis of a KorPlug Campaign

PlugX (KorPlug) is a modular remote access trojan delivered in this campaign through an MSI-based DLL sideloading chain. In this sample,The installer drops a legitimate G DATA executable, a malicious AVK.dll sideloader, and an XOR-encrypted AVKTray.dat payload that ultimately loads a reflective PlugX DLL and establishes persistence. Key Takeaways Introduction A PlugX DLL sideloading campaign […]

Categories

Discover the latest articles and insights on Dark Atlas

All
Threat Intelligence
Malware Analysis
Threat Profile
Infrastructure adversary hunting
Supply Chain
Uncategorized
Image placeholder

Image placeholder

Image placeholder

Image placeholder

Image placeholder

Image placeholder

Image placeholder

Image placeholder

Image placeholder

Contact Us

Experience the power of #1 AI-Powered eXtended Cyber Intelligence Platform

Subscribe

New Security Updates Weekly!