2025 State of the Internet: Malware Investigations
ID: 8a5af947-9a56-5f3d-af9e-ea168792c90c
STIX ID: report--8a5af947-9a56-5f3d-af9e-ea168792c90c
Feed Name: Censys Blog
Date Published: 2025-07-30
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; Silas Cutler; Principal Security Researcher
This Censys State of the Internet report details two investigations: Wainscot, a variant used by or against Storm-0156 that exfiltrated data from a suspected Indian Territorial Army host and was sinkholed, and BeaverTail, a Python-based infostealer/backdoor linked to DPRK-associated operators targeting developers; the report contains infrastructure indicators (domains, ports, hosting providers), observed behaviors, maps of control servers, and notes on remediation and ongoing operational use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
