<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>malware — LowEndSpirit</title>
        <link>https://lowendspirit.com/index.php?p=/</link>
        <pubDate>Thu, 04 Jun 2026 06:07:17 +0000</pubDate>
        <language>en</language>
            <description>malware — LowEndSpirit</description>
    <atom:link href="https://lowendspirit.com/index.php?p=/discussions/tagged/malware/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attack</title>
        <link>https://lowendspirit.com/index.php?p=/discussion/10852/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack</link>
        <pubDate>Thu, 07 May 2026 07:25:26 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>mikho</dc:creator>
        <guid isPermaLink="false">10852@/index.php?p=/discussions</guid>
        <description><![CDATA[<blockquote><div>
  <p>Security researchers at Kaspersky say they have identified a malicious backdoor planted in the popular and long-running Windows disc imaging software, Daemon Tools.</p>
  
  <p>The Russian cybersecurity company said on Tuesday that data collected from computers around the world running the Kaspersky antivirus software shows a “widespread” attack is under way, targeting thousands of Windows computers running Daemon Tools.</p>
</div></blockquote>

<p><a href="https://techcrunch.com/2026/05/05/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack/" rel="nofollow">https://techcrunch.com/2026/05/05/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack/</a></p>
]]>
        </description>
    </item>
    <item>
        <title>‘Frebniis’ Malware Hijacks Microsoft IIS Function to Deploy Backdoor</title>
        <link>https://lowendspirit.com/index.php?p=/discussion/5514/frebniis-malware-hijacks-microsoft-iis-function-to-deploy-backdoor</link>
        <pubDate>Sun, 19 Feb 2023 18:09:36 +0000</pubDate>
        <category>Industry News</category>
        <dc:creator>AuroraZero</dc:creator>
        <guid isPermaLink="false">5514@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>This is interesting to me anyways.</p>

<p>it seems the malware injects code into a DLL that an IIS feature called Failed Request Event Buffering (FREB) uses when troubleshooting failed requests.</p>

<p><a rel="nofollow" href="https://bwlf.us/WrathfulKhakiPiranha" title="https://bwlf.us/WrathfulKhakiPiranha">‘Frebniis’ Malware Hijacks Microsoft IIS Function to Deploy Backdoor</a></p>
]]>
        </description>
    </item>
   </channel>
</rss>
