<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Windows on karmine&#39;s notes</title>
    <link>https://karmine05.github.io/dirtyfrag-blog/tags/windows/</link>
    <description>Recent content in Windows on karmine&#39;s notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>dhruv@fleetdm.com (Dhruv Majumdar)</managingEditor>
    <webMaster>dhruv@fleetdm.com (Dhruv Majumdar)</webMaster>
    <copyright>© 2026 karmine&#39;s notes</copyright>
    <lastBuildDate>Tue, 26 May 2026 13:00:00 -0400</lastBuildDate><atom:link href="https://karmine05.github.io/dirtyfrag-blog/tags/windows/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>ClickFix — Copy/Paste Social Engineering: Threat Brief and Fleet Detection Pack</title>
      <link>https://karmine05.github.io/dirtyfrag-blog/posts/clickfix-copypaste-fleet-detections/</link>
      <pubDate>Tue, 26 May 2026 13:00:00 -0400</pubDate>
      <author>dhruv@fleetdm.com (Dhruv Majumdar)</author>
      <guid>https://karmine05.github.io/dirtyfrag-blog/posts/clickfix-copypaste-fleet-detections/</guid>
      <description>ClickFix is the most active cross-platform initial-access technique of 2026 — fake CAPTCHAs and support prompts that silently copy a malicious command to the clipboard, instruct the user to paste it into the Windows Run dialog or macOS Terminal, and deliver infostealers (Lumma, AMOS), remote-access tools (NetSupport RAT), and AppleScript keychain stealers. No code-execution vulnerability is exploited — the victim is the delivery mechanism. This brief walks the five-stage attack flow, lists atomic indicators, and ships a Fleet/osquery detection pack with every query validated against the current Fleet table schema.</description>
      
    </item>
    
    <item>
      <title>SHADOW-EARTH-053 — Threat Brief, Kill Chain, and Validated Fleet Queries</title>
      <link>https://karmine05.github.io/dirtyfrag-blog/posts/shadow-earth-053-fleet-detections/</link>
      <pubDate>Tue, 26 May 2026 11:00:00 -0400</pubDate>
      <author>dhruv@fleetdm.com (Dhruv Majumdar)</author>
      <guid>https://karmine05.github.io/dirtyfrag-blog/posts/shadow-earth-053-fleet-detections/</guid>
      <description>Trend Micro disclosed SHADOW-EARTH-053 on 30 April 2026 — a China-aligned cyberespionage campaign exploiting ProxyLogon against unpatched Microsoft Exchange and IIS to deploy GODZILLA web shells and ShadowPad across South, East, and Southeast Asia plus one NATO target. This brief documents the campaign through Lockheed&amp;rsquo;s seven kill-chain stages with a Diamond Model rendered for each stage, consolidates the atomic indicators, and ships a vetted Fleet/osquery detection pack. Every query in the pack has been audited against fleetdm.com/tables before publication — schema bugs in the publicly circulating versions are called out and corrected inline.</description>
      
    </item>
    
  </channel>
</rss>
