Secplicity Blog - Research

Ethereum Malware Loader Targets Portuguese-Speaking Users

TL;DR Cristóbal Tárraga García, a member of the WatchGuard Threat Lab, uncovered a malware loader targeting Portuguese-speaking users that uses an Ethereum smart contract to dynamically locate attacker infrastructure and distribute additional payloads. The multi-stage infection chain combines…

ErrTraffic Malware Campaign: ClickFix and EtherHiding

TL;DR Euler Neto, a member of the WatchGuard Threat Lab identified an active malware campaign using the ErrTraffic Malware-as-a-Service framework to distribute multiple threats through compromised WordPress websites, ClickFix social engineering, and EtherHiding. The campaign uses Polygon blockchain…

Ransomware Tracker (Entry #356): JADEPUFFER

JADEPUFFER is the name of the agentic threat actor (ATA) that exploited a vulnerability in an Internet-facing Langflow instance ( CVE-2025-3248) and, without human intervention, gained persistence, enumerated a victim's systems, and deployed ransomware across the network. It was first reported on…

DeadLock Ransomware Group Embeds Data Leak Site Within Ransom Note

The DeadLock ransomware operation has existed since mid-2025, with most of the first reported sightings in mid-July, according to ThreatScene. Their report mentioned the group “now conducts double extortion” following a subsequent analysis in September 2025, which revealed newer DeadLock payloads…

Grandoreiro Malware Campaign Targets Europe and Latin America

WatchGuard telemetry identified a campaign associated to Grandoreiro that uses the DLL Side-Loading technique abusing four different softwares, targeting banks in Portugal. Also, it was identified cases of a known campaign that uses a malicious VBS to deliver the malware, targeting companies in…