<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ThreatChain Research</title>
    <link>https://threatchain.io/blog</link>
    <description>Malware analysis, CVE breakdowns, and threat intelligence from ThreatChain — decentralizing security.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 17 Apr 2026 08:05:01 +0000</lastBuildDate>
    <atom:link href="https://threatchain.io/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Vidar Sample Detected: file | ThreatChain</title>
      <link>https://threatchain.io/vidar-sample-detected-file-d6446f28</link>
      <guid isPermaLink="true">https://threatchain.io/vidar-sample-detected-file-d6446f28</guid>
      <pubDate>Thu, 16 Apr 2026 19:16:20 +0000</pubDate>
      <description>A new Vidar sample was identified by threat intelligence feeds on 2026-04-16 15:05:16. This post breaks down what we know about the specific sample, how to r...</description>
    </item>
    <item>
      <title>RemcosRAT Sample Detected: Preinterest.exe | ThreatChain</title>
      <link>https://threatchain.io/remcosrat-sample-detected-preinterest-exe-4a2bc726</link>
      <guid isPermaLink="true">https://threatchain.io/remcosrat-sample-detected-preinterest-exe-4a2bc726</guid>
      <pubDate>Thu, 16 Apr 2026 11:16:25 +0000</pubDate>
      <description>A new RemcosRAT sample was identified by threat intelligence feeds on 2026-04-16 09:06:52. This post breaks down what we know about the specific sample, how ...</description>
    </item>
    <item>
      <title>DattoRMM Sample Detected: TrueView.exe | ThreatChain</title>
      <link>https://threatchain.io/dattormm-sample-detected-trueview-exe-f58cb609</link>
      <guid isPermaLink="true">https://threatchain.io/dattormm-sample-detected-trueview-exe-f58cb609</guid>
      <pubDate>Wed, 15 Apr 2026 19:15:57 +0000</pubDate>
      <description>A new DattoRMM sample was identified by threat intelligence feeds on 2026-04-15 17:40:48. This post breaks down what we know about the specific sample, how t...</description>
    </item>
    <item>
      <title>SantaStealer Sample Detected: file | ThreatChain</title>
      <link>https://threatchain.io/santastealer-sample-detected-file-44bf32bd</link>
      <guid isPermaLink="true">https://threatchain.io/santastealer-sample-detected-file-44bf32bd</guid>
      <pubDate>Wed, 15 Apr 2026 11:15:26 +0000</pubDate>
      <description>A new SantaStealer sample was identified by threat intelligence feeds on 2026-04-15 10:05:11. This post breaks down what we know about the specific sample, h...</description>
    </item>
    <item>
      <title>DiscordRAT Sample Detected: RedTiger-Tools-main-2.0.exe | ThreatChain</title>
      <link>https://threatchain.io/discordrat-sample-detected-redtiger-tools-main-2-0-exe-dbdeed30</link>
      <guid isPermaLink="true">https://threatchain.io/discordrat-sample-detected-redtiger-tools-main-2-0-exe-dbdeed30</guid>
      <pubDate>Tue, 14 Apr 2026 19:15:55 +0000</pubDate>
      <description>A new DiscordRAT sample was identified by threat intelligence feeds on 2026-04-14 17:12:58. This post breaks down what we know about the specific sample, how...</description>
    </item>
    <item>
      <title>Smoke Loader Sample Detected: file | ThreatChain</title>
      <link>https://threatchain.io/smoke-loader-sample-detected-file-54731e0a</link>
      <guid isPermaLink="true">https://threatchain.io/smoke-loader-sample-detected-file-54731e0a</guid>
      <pubDate>Tue, 14 Apr 2026 11:15:25 +0000</pubDate>
      <description>A new Smoke Loader sample was identified by threat intelligence feeds on 2026-04-14 09:34:55. This post breaks down what we know about the specific sample, h...</description>
    </item>
    <item>
      <title>RatonRAT Sample Detected: xxx.exe | ThreatChain</title>
      <link>https://threatchain.io/ratonrat-sample-detected-xxx-exe-decadae3</link>
      <guid isPermaLink="true">https://threatchain.io/ratonrat-sample-detected-xxx-exe-decadae3</guid>
      <pubDate>Mon, 13 Apr 2026 19:16:07 +0000</pubDate>
      <description>A new RatonRAT sample was identified by threat intelligence feeds on 2026-04-13 18:36:53. This post breaks down what we know about the specific sample, how t...</description>
    </item>
    <item>
      <title>OffLoader Sample Detected: file | ThreatChain</title>
      <link>https://threatchain.io/offloader-sample-detected-file-6fb87b85</link>
      <guid isPermaLink="true">https://threatchain.io/offloader-sample-detected-file-6fb87b85</guid>
      <pubDate>Mon, 13 Apr 2026 11:16:09 +0000</pubDate>
      <description>A new OffLoader sample was identified by threat intelligence feeds on 2026-04-13 09:51:26. This post breaks down what we know about the specific sample, how ...</description>
    </item>
    <item>
      <title>SalatStealer Sample Detected: file | ThreatChain</title>
      <link>https://threatchain.io/salatstealer-sample-detected-file-bc0caae0</link>
      <guid isPermaLink="true">https://threatchain.io/salatstealer-sample-detected-file-bc0caae0</guid>
      <pubDate>Sun, 12 Apr 2026 19:15:44 +0000</pubDate>
      <description>A new SalatStealer sample was identified by threat intelligence feeds on 2026-04-12 17:11:02. This post breaks down what we know about the specific sample, h...</description>
    </item>
    <item>
      <title>RustyStealer Sample Detected: file | ThreatChain</title>
      <link>https://threatchain.io/rustystealer-sample-detected-file-f9ec3083</link>
      <guid isPermaLink="true">https://threatchain.io/rustystealer-sample-detected-file-f9ec3083</guid>
      <pubDate>Sun, 12 Apr 2026 11:15:51 +0000</pubDate>
      <description>A new RustyStealer sample was identified by threat intelligence feeds on 2026-04-12 05:47:37. This post breaks down what we know about the specific sample, h...</description>
    </item>
    <item>
      <title>Mirai Sample Detected: ciubuc_ppc | ThreatChain</title>
      <link>https://threatchain.io/mirai-sample-detected-ciubuc-ppc-251103e7</link>
      <guid isPermaLink="true">https://threatchain.io/mirai-sample-detected-ciubuc-ppc-251103e7</guid>
      <pubDate>Sat, 11 Apr 2026 19:15:17 +0000</pubDate>
      <description>A new Mirai sample was identified by threat intelligence feeds on 2026-04-11 17:39:16. This post breaks down what we know about the specific sample, how to r...</description>
    </item>
    <item>
      <title>Expiro Sample Detected: file | ThreatChain</title>
      <link>https://threatchain.io/expiro-sample-detected-file-496a17a7</link>
      <guid isPermaLink="true">https://threatchain.io/expiro-sample-detected-file-496a17a7</guid>
      <pubDate>Sat, 11 Apr 2026 11:16:05 +0000</pubDate>
      <description>A new Expiro sample was identified by threat intelligence feeds on 2026-04-11 09:17:40. This post breaks down what we know about the specific sample, how to ...</description>
    </item>
    <item>
      <title>CVE-2026-39337: Church Management Software Flaw Gives Attackers Complete Server Control | ThreatChain</title>
      <link>https://threatchain.io/cve-2026-39337-church-management-software-flaw-gives-attackers-complete-server-c-39435d2c</link>
      <guid isPermaLink="true">https://threatchain.io/cve-2026-39337-church-management-software-flaw-gives-attackers-complete-server-c-39435d2c</guid>
      <pubDate>Wed, 08 Apr 2026 00:41:04 +0000</pubDate>
      <description>If you're running ChurchCRM to manage your congregation's data, you need to act now. A critical vulnerability allows attackers to take complete control of yo...</description>
    </item>
    <item>
      <title>AsyncRAT: The Silent Spy That Gives Attackers Full Control of Your Computer | ThreatChain</title>
      <link>https://threatchain.io/asyncrat-the-silent-spy-that-gives-attackers-full-control-of-your-computer-4c3b97c1</link>
      <guid isPermaLink="true">https://threatchain.io/asyncrat-the-silent-spy-that-gives-attackers-full-control-of-your-computer-4c3b97c1</guid>
      <pubDate>Wed, 08 Apr 2026 00:40:17 +0000</pubDate>
      <description>Picture this: you download what looks like a normal program — maybe a cracked utility, a PDF someone emailed you, or an update that popped up at just the rig...</description>
    </item>
    <item>
      <title>Boatnet: The LZRD Mirai Variant Flooding IoT Devices Today | ThreatChain</title>
      <link>https://threatchain.io/boatnet-mirai-lzrd-botnet-2026</link>
      <guid isPermaLink="true">https://threatchain.io/boatnet-mirai-lzrd-botnet-2026</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Breaking: New Mirai botnet variant 'Boatnet' (LZRD) actively targeting IoT devices worldwide. Full technical analysis of CVE-2024-6047 and CVE-2024-11120 exploitation.</description>
    </item>
    <item>
      <title>How to Check If a File Is Malware: Free Methods That Actually Work (2026) | ThreatChain</title>
      <link>https://threatchain.io/how-to-check-if-file-is-malware</link>
      <guid isPermaLink="true">https://threatchain.io/how-to-check-if-file-is-malware</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Learn how to check if a file is malware using free hash-based detection, VirusTotal, and ThreatChain. Step-by-step guide for Windows, Mac, and Linux with SHA256 commands.</description>
    </item>
    <item>
      <title>That Fake Purchase Order in Your Inbox? It Might Be Formbook Stealing Every Keystroke You Type | ThreatChain</title>
      <link>https://threatchain.io/that-fake-purchase-order-in-your-inbox-it-might-be-formbook-stealing-every-keyst-af3f5610</link>
      <guid isPermaLink="true">https://threatchain.io/that-fake-purchase-order-in-your-inbox-it-might-be-formbook-stealing-every-keyst-af3f5610</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Imagine you work at a mid-sized company. It's a Tuesday morning. You open your email and see a message with the subject line &amp;quot;PO-000806758&amp;quot; — a purchase orde...</description>
    </item>
    <item>
      <title>Vidar: The Silent Thief Hiding Inside That Free Software Download | ThreatChain</title>
      <link>https://threatchain.io/vidar-the-silent-thief-hiding-inside-that-free-software-download-6d557467</link>
      <guid isPermaLink="true">https://threatchain.io/vidar-the-silent-thief-hiding-inside-that-free-software-download-6d557467</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Last Tuesday, a freelance graphic designer in Ohio downloaded what she thought was a cracked version of a popular video editing tool. Within 90 seconds — bef...</description>
    </item>
    <item>
      <title>The Biggest Crypto Hacks of 2026 (So Far): What Happened and How to Stay Safe | ThreatChain</title>
      <link>https://threatchain.io/biggest-crypto-hacks-2026</link>
      <guid isPermaLink="true">https://threatchain.io/biggest-crypto-hacks-2026</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>A breakdown of the biggest crypto hacks and DeFi exploits of 2025-2026. What happened, how each attack worked, and how to check if your funds were affected.</description>
    </item>
    <item>
      <title>ThreatChain Weekly: Chrome Zero-Day Hits KEV, WordPress Plugins Under Siege, and 4.4M Threats in 7 Days — Week of April 5, 2026 | ThreatChain Research</title>
      <link>https://threatchain.io/weekly-threat-report-2026-04-05</link>
      <guid isPermaLink="true">https://threatchain.io/weekly-threat-report-2026-04-05</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Weekly threat intelligence roundup from ThreatChain Research. Critical CVEs, malware trends, and actionable patches for the week.</description>
    </item>
    <item>
      <title>DCRat: The Cheap, Dangerous Malware That Lets Anyone Spy on Your Computer for $5 | ThreatChain</title>
      <link>https://threatchain.io/dcrat-the-cheap-dangerous-malware-that-lets-anyone-spy-on-your-computer-for-5-ecbbd254</link>
      <guid isPermaLink="true">https://threatchain.io/dcrat-the-cheap-dangerous-malware-that-lets-anyone-spy-on-your-computer-for-5-ecbbd254</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Picture this: you download what looks like a normal program — maybe a game crack, a free tool, or a file that came attached to a convincing email. Nothing se...</description>
    </item>
    <item>
      <title>RedLine Stealer: The Password Thief Hiding in a 98-Kilobyte File | ThreatChain</title>
      <link>https://threatchain.io/redline-stealer-the-password-thief-hiding-in-a-98-kilobyte-file-31c17f9d</link>
      <guid isPermaLink="true">https://threatchain.io/redline-stealer-the-password-thief-hiding-in-a-98-kilobyte-file-31c17f9d</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>In-depth threat intelligence analysis of RedLineStealer malware. Full IOCs, attack chain, and defensive recommendations.</description>
    </item>
    <item>
      <title>Inside OffLoader: A GCleaner-Dropped Payload Slipping Past 95% of AV Engines | ThreatChain</title>
      <link>https://threatchain.io/inside-offloader-a-gcleaner-dropped-payload-slipping-past-95-of-av-engines-9a5616c7</link>
      <guid isPermaLink="true">https://threatchain.io/inside-offloader-a-gcleaner-dropped-payload-slipping-past-95-of-av-engines-9a5616c7</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>In-depth threat intelligence analysis of OffLoader malware. Full IOCs, attack chain, and defensive recommendations.</description>
    </item>
    <item>
      <title>ACRStealer: The Hidden Threat Disguised as a Google Verification File | ThreatChain</title>
      <link>https://threatchain.io/acrstealer-the-hidden-threat-disguised-as-a-google-verification-file-de5691a0</link>
      <guid isPermaLink="true">https://threatchain.io/acrstealer-the-hidden-threat-disguised-as-a-google-verification-file-de5691a0</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Picture this: you're a freelance designer, and a client sends over what looks like a Google verification plugin. The file name even says &amp;quot;verificationgoogle....</description>
    </item>
    <item>
      <title>CVE-2026-34208: JavaScript Sandbox Library Can't Keep Attackers Out | ThreatChain</title>
      <link>https://threatchain.io/cve-2026-34208-javascript-sandbox-library-can-t-keep-attackers-out-81071546</link>
      <guid isPermaLink="true">https://threatchain.io/cve-2026-34208-javascript-sandbox-library-can-t-keep-attackers-out-81071546</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>CVSS Score: 10.0 (CRITICAL)  If your application uses SandboxJS to run untrusted JavaScript code safely, you need to patch immediately. A critical vulnerabil...</description>
    </item>
    <item>
      <title>Is This Crypto Wallet a Scam? How to Check Any Wallet Address (2026) | ThreatChain</title>
      <link>https://threatchain.io/is-this-crypto-wallet-a-scam</link>
      <guid isPermaLink="true">https://threatchain.io/is-this-crypto-wallet-a-scam</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Learn how to check if a crypto wallet address is a scam. Step-by-step guide using Etherscan, ScamSniffer, and ThreatChain's database of 2,530 known scam wallets.</description>
    </item>
    <item>
      <title>Claude Code Source Leak: How One Packaging Mistake Created a Hacker Feeding Frenzy | ThreatChain</title>
      <link>https://threatchain.io/claude-code-source-leak-how-one-packaging-mistake-created-a-hacker-feeding-frenz-claude-c</link>
      <guid isPermaLink="true">https://threatchain.io/claude-code-source-leak-how-one-packaging-mistake-created-a-hacker-feeding-frenz-claude-c</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Imagine accidentally dropping your house keys in a crowded mall – and within hours, those keys have been duplicated and distributed to every pickpocket in th...</description>
    </item>
    <item>
      <title>That &amp;quot;Payment Wire&amp;quot; Email Attachment? It's a Trojan Wearing Trusted Software as a Disguise | ThreatChain</title>
      <link>https://threatchain.io/that-payment-wire-email-attachment-it-s-a-trojan-wearing-trusted-software-as-a-d-5bbb1e4d</link>
      <guid isPermaLink="true">https://threatchain.io/that-payment-wire-email-attachment-it-s-a-trojan-wearing-trusted-software-as-a-d-5bbb1e4d</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>Picture this: It's a Monday morning. You're the office manager at a mid-size company in Stockholm, plowing through emails. One catches your eye — the subject...</description>
    </item>
    <item>
      <title>Your Computer Could Be Mining Cryptocurrency for Strangers Right Now — Here's How to Tell | ThreatChain</title>
      <link>https://threatchain.io/your-computer-could-be-mining-cryptocurrency-for-strangers-right-now-here-s-how--c26af9d1</link>
      <guid isPermaLink="true">https://threatchain.io/your-computer-could-be-mining-cryptocurrency-for-strangers-right-now-here-s-how--c26af9d1</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>In-depth threat intelligence analysis of CoinMiner malware. Full IOCs, attack chain, and defensive recommendations.</description>
    </item>
    <item>
      <title>Why Your Router Might Be Quietly Attacking Websites Right Now — And You'd Never Know | ThreatChain</title>
      <link>https://threatchain.io/why-your-router-might-be-quietly-attacking-websites-right-now-and-you-d-never-kn-e599ce2e</link>
      <guid isPermaLink="true">https://threatchain.io/why-your-router-might-be-quietly-attacking-websites-right-now-and-you-d-never-kn-e599ce2e</guid>
      <pubDate>Tue, 07 Apr 2026 22:54:13 +0000</pubDate>
      <description>In-depth threat intelligence analysis of Mirai malware. Full IOCs, attack chain, and defensive recommendations.</description>
    </item>
  </channel>
</rss>
