What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)

2026-06-27T19:23:51Za4a07ec31d8801d7030fb0c099067069db99b1c71245c6597c70536d4346cbaa
CVE-2024-40766MITRESANS-ISCT1036Velvet Antipv4-mapped-ipv6ipv6linuxmalware-obfuscationphishingprocess-masqueradingrootkitssh-bruteforcevulnerability-managementwebshells

What happened

Collection of ISC SANS diary entries (June 2026) covering: Linux process name masquerading (malicious processes replacing their visible names to evade detection — mapped to MITRE ATT&CK T1036; example actor: Velvet Ant); continued prevalence of webshells with a newly observed GitHub-published variant; an eBanking phishing campaign that delivered via IPv4-mapped IPv6 addresses (novel addressing/evasion detail); analysis of coordinated SSH brute-force activity over three months; and a note about CVE-2024-40766 where the patch fixed the bug but a configuration issue remained. Also includes daily

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
a4a07ec31d8801d7030fb0c099067069db99b1c71245c6597c70536d4346cbaa
Enrichment time
2026-06-27T19:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th) · Baitaphish