Capstone Technologies Group

@CapTechGroup
11 Followers
27 Following
234 Posts
Veteran-owned managed IT & cybersecurity for Ohio's medical, legal, and financial firms. Springfield-based, serving the Dayton–Columbus–Cincinnati corridor since 2002. Layered protection: SentinelOne, SonicWall managed firewalls, Adlumin SOC/SIEM, immutable backups, plus security awareness and HIPAA training. SonicWall Certified · N-able Partner. We post threat patterns and practical security guidance for professional practices—what we're actually seeing.
LocationSpringfield, Ohio
Since2002 · Veteran Owned
FocusLegal · Medical · Financial
CertifiedSonicWall · N-able Partner

Malicious npm packages (aes-decode-runner-pro, postcss-minify-selector) impersonating PostCSS tools deliver multi-stage Windows RAT with Python native extension modules. The infection chain: JavaScript dropper → PowerShell downloader...

https://captechgroup.com/threat-intelligence-center/malicious-npm-packages-pose-as-postcss-tools-to-de-2336d4?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=malicious-npm-packages-pose-as-postcss-tools-to-deliver-windows-rat

Law enforcement disrupted Amadey and StealC malware operations across eight countries, recovering 27M credentials and taking down 326 servers. Both operated as MaaS—Amadey as a loader deploying secondary payloads (Lumma, Vidar,...

https://captechgroup.com/threat-intelligence-center/amadey-and-stealc-malware-network-disrupted-27m-cr-17d1b2?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=amadey-and-stealc-malware-network-disrupted-27m-credentials-recovered

macOS.Gaslight demonstrates a tactical shift: instead of obfuscation, this Rust backdoor embeds 38 fabricated system messages wrapped in Markdown and {{DATA}} tokens to confuse LLM-assisted triage. The implant uses...

https://captechgroup.com/threat-intelligence-center/macosgaslight-rust-backdoor-exploits-prompt-inject-d31f84?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=macos-gaslight-rust-backdoor-exploits-prompt-injection-against-security-analysts

Storm-2603 exploited SharePoint servers to deploy Velociraptor with SYSTEM privileges, establishing redundant access via Cloudflare tunneling, Zoho Assist, and SSH through VS Code. Meanwhile, a second threat actor used...

https://captechgroup.com/threat-intelligence-center/storm-2603-and-velociraptor-exploit-single-intrusi-5b339a?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=storm-2603-and-velociraptor-exploit-single-intrusion-for-parallel-attack-operati

Analysis of 20M SSH brute force attempts reveals sophisticated botnet coordination: identical HASSH fingerprints (03a80b21afa810682a776a7d42e5e6fb) across 702K events, synchronized attacks from US and Ukraine within 53...

https://captechgroup.com/threat-intelligence-center/chinese-botnets-execute-coordinated-ssh-brute-forc-05ea03?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=chinese-botnets-execute-coordinated-ssh-brute-force-attacks-across-honeypots

Supply chain attack on Mastra AI: threat actors gained control of npm maintainer account and published malicious updates across 140+ packages. The malware disabled TLS certificate verification, hunted for 166...

https://captechgroup.com/threat-intelligence-center/north-korean-bluenoroff-hackers-hit-crypto-firms-v-1328ff?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=north-korean-bluenoroff-hackers-hit-crypto-firms-via-mastra-ai-supply-chain-atta

Evil MSI demonstrates sophisticated evasion: attackers manipulate BASE64 encoding to defeat statistical analysis tools by replacing 'A' with '#', reversing strings, and creating payloads that appear corrupted to automated...

https://captechgroup.com/threat-intelligence-center/evil-msi-background-malware-uses-base64-statistica-dc5a2c?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=evil-msi-background-malware-uses-base64-statistical-analysis-to-evade-detection

The Klue OAuth compromise demonstrates OAuth refresh token risk at scale. Attackers exploited a legacy credential to access integration service infrastructure, then weaponized stolen refresh tokens for persistent Salesforce API access. Python...

https://captechgroup.com/threat-intelligence-center/klue-oauth-breach-expands-as-icarus-hackers-claim-528ffc?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=klue-oauth-breach-expands-as-icarus-hackers-claim-attack

Professional services under fire: attackers using VHDX files to deliver Remcos RAT through a sophisticated chain—ZIP → VHDX → obfuscated JavaScript → WMI-based PowerShell → .NET reflection shellcode injection. Detection rates below...

https://captechgroup.com/about-us/threat-intelligence-center/vhdx-file-delivers-remcos-rat-to-professional-serv-2b898d?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=vhdx-file-delivers-remcos-rat-to-professional-service-firms

Operation Endgame disrupted SocGholish's multi-layered JavaScript framework that weaponized 14,971 WordPress sites through domain shadowing and fake update lures. Attackers injected malicious JS directly into webpage...

https://captechgroup.com/about-us/threat-intelligence-center/operation-endgame-disrupts-socgholish-servers-clea-275ade?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=operation-endgame-disrupts-socgholish-servers-cleans-14-971-wordpress-sites