GigaWiper combines three known malware families (Crucio, FlockWiper) in a modular backdoor with 20 commands to delete or encrypt data after reconnaissance objectives are achieved.
Malware can extract data from isolated systems through electromagnetic radiation emitted by monitor cables, partially undermining traditional air-gapping approaches.
TrojPix enables data exfiltration from air-gapped systems through subtle pixel manipulation, but requires malware to already be installed on the target machine.
Eight manipulated Pyrogram packages on PyPI allow attackers to execute Python code and shell commands on production Telegram bot servers and exfiltrate credentials and database connections.