Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Sandboxing Closes the Phishing Detection Visibility Gap
September 23, 2026
Critical cPanel Vulnerability Exposes User Accounts
September 23, 2026
Outerlimit Raises $16M to Secure AI Agents with Zero Trust
September 23, 2026
Home/Threats/Stealthy Tuoni C2 Malware Targets Major U.S. Real Estate Firm with AI-Enhanced Tactics
Threats

Stealthy Tuoni C2 Malware Targets Major U.S. Real Estate Firm with AI-Enhanced Tactics

Cybercriminals are refining their infiltration tactics. Instead of rapid, high-impact attacks, they now operate stealthily within target networks, exfiltrating critical information and maintaining...

Marcus Rodriguez
Marcus Rodriguez
January 6, 2026 2 Min Read
144 0

Cybercriminals are refining their infiltration tactics. Instead of rapid, high-impact attacks, they now operate stealthily within target networks, exfiltrating critical information and maintaining persistence for weeks or months before launching their final offensive.

This is exactly what happened in a recent attack discovered by Morphisec Threat Labs targeting a major U.S. real estate company.

This was not a common phishing campaign aimed at many people at once. Instead, it was a carefully planned attack using the Tuoni command-and-control malware framework, designed to hide and avoid detection using advanced techniques like AI-generated code, hidden images, and memory-only execution.

The attack marked a significant shift in how modern malware operates. Traditional attacks deposit files on a computer’s hard drive, leaving traces for security tools to find.

The Tuoni malware never touched the disk. It avoided signature detection, behavioral monitoring, and endpoint detection tools.

Without proper prevention-focused protection, this malware would have remained hidden inside the network indefinitely, stealing credentials and preparing the ground for ransomware deployment.

The sophistication of this attack demonstrates how threat actors now engineer malware specifically to evade all traditional security layers.

Morphisec analysts identified the malware through careful monitoring of advanced evasion techniques becoming increasingly common in sophisticated attacks.

The malware used steganography to hide harmful code inside image files that appeared innocent to security scanners. It also employed AI-enhanced loaders that generated code dynamically to mask how the malware ran and escape detection.

The modular Tuoni C2 framework was built to steal login credentials, maintain long-term access, and prepare systems for ransomware attacks on a large scale.

Understanding the Steganography Attack Vector

The infection mechanism reveals how Tuoni uses hidden images as delivery vehicles for its payload. Steganography hides malicious data inside normal-looking BMP image files, making them invisible to traditional scanning tools that look for known malware signatures.

When a target opens what appears to be a harmless image, the malware uses reflective memory loading to place itself directly into the computer’s memory without creating any files on disk.

This means no files appear in directories, no signatures are written to scan, and no behavioral alerts trigger. Security tools scanning for files on disk see nothing unusual.

The malware operates entirely in temporary memory, executing the loader and establishing communication with Tuoni infrastructure without leaving any trace.

This memory-only execution defeats antivirus software, EDR systems, and even advanced sandboxing because these tools rely on detecting files or unusual behaviors on disk.

The Tuoni framework then uses this silent position to steal user credentials, maintain persistence through multiple sessions, and prepare systems for ransomware deployment.

Without detection-focused tools detecting this activity, the attack remains unnoticed, giving attackers months to harvest sensitive data and expand their reach within the network.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingransomwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections

Next Post

Scattered Lapsus$ Hunters Resurface with New RaaS Platform ‘ShinySp1d3r’ and Aggressive Insider Recruitment

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical AWS Lambda Flaw Bypasses IAM, Exposes Cloud Services
September 23, 2026
Critical Next.js CVE-2024-XXXXX RCE Flaw Lets Attackers Use SVG Files
September 23, 2026
New Malware Uses Evasive Domain Tactics to Hide Infrastructure
September 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us