Skip to main content

Attack Demos

Attack Demo Library

Hands-on attack demonstrations mapped to OPSWAT MetaDefender capabilities.

Published: 109 Categories: 14
Date Title OS Type
2026-09-19 White Hats Breach OpenAI Through a libheif Image Chain (Hacktron AI, Claude Opus 5) — Deep CDR Rebuilds Image-Borne Hidden Payloads (2026-09-18 CISO Daily Digest)
Deep CDR
Linux
Steganography · Mid
2026-09-18 Kaspersky: NightEagle's GhostContainer Backdoor Takes Over Microsoft Exchange Servers — Sandbox Detonates the Exchange Implant's Network Stage (2026-09-17 CISO Daily Digest)
MetaDefender Sandbox
Linux
Malware · Mid
2026-09-17 FBI, NCSC and AIVD Expose Iran's HEAVYGRAM: Telegram-Controlled Spyware Built to Target Dissidents and Journalists — Sandbox Detonates the Screen-Capture Stage (2026-09-16 CISO Daily Digest)
MetaDefender Sandbox
Linux
Malware · Mid
2026-09-16 Vite CVE-2026-39364: Mass Scanners Harvest Cloud Credentials and Terraform State From Exposed Dev Servers (F5 Labs) — Proactive DLP Flags Secrets in Config Files Before They Cross the Boundary (2026-09-15 CISO Daily Digest)
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-09-15 E4del and PINHOLE RATs Ride FTP-Banner Dead Drops in a ZIP + Shortcut (LNK) Chain (SOCRadar) — Deep CDR Strips the Shortcut's Download-and-Execute Logic (2026-09-14 CISO Daily Digest)
Deep CDR
Linux
LNK Abuse · Mid
2026-09-14 DPRK-Linked 'ted' Backdoor Compiled Into HAProxy Load Balancers (Rapid7) — Trojanized Server Binaries Flagged by Metascan (2026-09-13 CISO Daily Digest)
Metascan
Linux
Malware · Mid
2026-09-13 OpenAI Agent Swarm Flooded RubyGems With 2,000+ Packages ('GemStuffer') — SBOM Inspects the Swarm-Published Gem That Reached RCE on RubyDoc.info via .yardopts (2026-09-12 CISO Daily Digest)
SBOM
Linux
SBOM · Mid
2026-09-12 Gitea diffpatch RCE (CVE-2026-60004, CISA KEV) — Sandbox Detonates the Hook Planted as the Gitea Service Account (2026-09-11 CISO Daily Digest)
MetaDefender Sandbox
Linux
Malware · Mid
2026-09-11 Fake Coding Tests, Real RATs: Mirage Kitten Hides NodeRabbit and PollCat in Trojanized npm Packages (Kaspersky, 2026-09-10 CISO Daily Digest)
SBOM
Linux
SBOM · Mid
2026-09-10 ChatGPT Hidden Channel: A Planted Prompt Quietly Exfiltrates Gmail via a Shared JFrog Artifactory (Check Point Research, 2026-09-09 CISO Daily Digest)
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Mid
2026-09-09 ValleyRAT in Signed QN Wallpaper Installers — Sandbox Flags the Keylogging Payload of a Silver Fox Campaign (2026-09-08 CISO Daily Digest)
MetaDefender Sandbox
Linux
Malware · Mid
2026-09-08 Nexus Driver's-License Trove: Exported National-ID Spreadsheet Flagged by Proactive DLP
Proactive DLP
Linux
Data Loss Prevention · Mid
2026-09-07 StyleSmuggler: Unpatched Magento Zero-Day Backdoor Implants Flagged by Metascan (2026-09-06 CISO Daily Digest)
Metascan
Linux
Malware · Mid
2026-09-06 ASCII Smuggling: Invisible Unicode Tag Characters Split 'Funding' Lures Past Content Filters (Microsoft, 2026-09-05 CISO Daily Digest)
OPSWAT AI Content Inspector
Linux
phishing · Mid
2026-09-05 GuardBreaker: Weaponized Script Comments That Blind LLM Malware Analysis (ESET / UAC-0099, 2026-09-04 CISO Daily Digest)
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Mid
2026-09-04 PaperCut NG/MF RCE Chain (CVE-2026-81578 + CVE-2026-82078, CISA KEV) — Sandbox Flags Post-Exploit Two-Stage Dropper
MetaDefender Sandbox
Linux
Malware · Mid
2026-09-03 ALPHV Rebrands as Lynx: Double-Extortion Ransomware Payloads Flagged by Metascan (2026-08-30 CISO Daily Digest)
Metascan
Linux
Malware · Mid
2026-08-31 Malicious npm Dependency Powering Wallet-Draining Browser Extensions (2026-08-29 CISO Daily Digest)
SBOM
Linux
SBOM · Mid
2026-08-30 Prompt-Injection Hijack of Claude Code Auto Mode via Untrusted Project Instructions (2026-08-29 CISO Daily Digest)
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Mid
2026-08-29 Password-Protected RAR Smuggling APT28's HOOKEDGE Stager Past Perimeter AV
Archive Engine
Linux
Archive Abuse · Mid
2026-08-28 Nested-ZIP Delivery of a Spark RAT Dropper — APT24's Supply-Chain Smuggling Trick
Archive Engine
Linux
Archive Abuse · Mid
2026-08-27 Supply-Chain Polyglot — RedC2 4.0 & the 24-Package npm Campaign Hide a Dropper That Is Both Script and ZIP
FileType Engine
Linux
Polyglot · Mid
2026-08-26 Extension-Mismatch Smuggle — ToxicPanda 2.0 & ShinyHunters Hide Loaders Behind a Benign .jpg
FileType Engine
Linux
Extension Mismatch · Beginner
2026-08-25 PNG Magic-Byte Spoof — Helix/Delek US & Gunra Payloads Hidden Behind a Forged Image Header
FileType Engine
Linux
Extension Mismatch · Mid
2026-08-22 Cloud Credential Exposure — 768 Leaked AWS Access Keys Still Active with Full Admin Privileges
Proactive DLP
Linux
Data Loss Prevention · Mid
2026-08-21 Skimmed at the Gateway: Magecart / FIN6 Card-Data Theft Meets CVE-2026-71290 TLS Trust Break — Caught by Proactive DLP
Proactive DLP
Linux
Data Loss Prevention · Mid
2026-08-20 Double-Extension Masquerade: invoice.pdf.sh Bypasses the Human Eye (Emotet / QakBot Malspam Tactic)
FileType Engine
Linux
Extension Mismatch · Beginner
2026-08-19 Cloud Credential Theft via MLflow SSRF — Adaptive Sandbox Flags Metadata-Service Credential Probing (CVE-2026-64849)
Adaptive Sandbox
Linux
Malware · Mid
2026-08-18 Invisible Prompt Injection: White-on-White Text Hidden in US Court Filings to Steer AI-Assisted Review (Matthew Elliott / 404 Media)
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Mid
2026-08-18 Weaponized 7z Archive Smuggling a Malicious Payload — Clop's Mass-Extortion Delivery Pattern (CVE-2026-12569 / PTC Windchill)
Archive Engine
LinuxWindows
Archive Abuse · Mid
2026-08-17 Web Shell / C2 Beacon After Citrix NetScaler CVE-2026-8452 Pre-Auth RCE (watchTowr PoC)
MetaDefender Sandbox
LinuxWindows
Malware · Mid
2026-08-16 APT Reverse-SSH Persistence After vCenter CVE-2026-59310 (CVSS 9.8) Exploitation
MetaDefender Sandbox
LinuxWindows
Malware · Mid
2026-08-13 Jewelbug APT: Watering-Hole Lure Masquerading as a JPG Photo (Extension Spoofing)
FileType Engine
LinuxmacOSWindows
Extension Mismatch · Beginner
2026-08-12 Lazarus Operation Dream Job: PDF Launch Action Dropping the Troy Backdoor (afd.sys Zero-Day CVE-2026-68820)
Deep CDR
LinuxWindows
PDF Abuse · Mid
2026-08-11 StormEncryptor Ransomware: China-linked Storm-1175's Rapid-Encryption Kit (N-able CVE-2026-18577)
Metascan
LinuxWindows
Malware · Mid
2026-08-10 Corrupted-Header Archive Weaponizing ClamAV Parser Flaws (CVE-2025-8088, CVE-2026-20337/38)
FileType Engine
LinuxWindows
Extension Mismatch · Mid
2026-08-09 Prompt-Injection File Hijacking AI Coding Agents (Anthropic Auto Mode / Trajectory Labs 0-of-720 Audit)
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Mid
2026-08-08 SBOM Analysis Flags Vulnerable npm Dependencies in the WEL1DROPPER Wave
SBOM
Linux
SBOM · Mid
2026-08-07 AI-Crafted M365 Sign-In Lure for AitM Session Hijacking (Arctic Wolf Storm-2755 Wave)
OPSWAT AI Content Inspector
LinuxWindows
AI Content Inspector · Mid
2026-08-06 ClickFix HTML Lure with Browser-Assembled Payload (Atomic Stealer Campaign Pattern)
Deep CDR
LinuxWindows
Script Injection · Mid
2026-08-05 Sandbox emulates macro-enabled DOCM attack chain
Adaptive Sandbox
LinuxWindows
Macro · Adv
2026-08-05 Employee PII in Spreadsheet Exports (Żabka Jira Breach Pattern)
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-08-04 AI-crafted fraudulent invoice targeting finance teams
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Beginner
2026-08-04 AI-Generated Microsoft 365 Device Code Phishing Lure (Storm-2945)
OPSWAT AI Content Inspector
LinuxWindows
phishing · Mid
2026-08-04 Hardcoded API Keys and DB Passwords in Config Files (Keyv npm Worm Pattern)
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-08-03 Multi-engine scan flags GHOSTBLADE-style iOS implant
Metascan
LinuxWindows
Malware · Adv
2026-08-02 Sandbox observes Run-key persistence installation
Adaptive Sandbox
LinuxmacOSWindows
Malware · Mid
2026-08-01 Sandbox flags screen-capture followed by data exfiltration
Adaptive Sandbox
LinuxmacOSWindows
Malware · Adv
2026-07-31 Region-specific document origin analysis for policy decisions
Country of Origin
Linux
Country of Origin · Beginner
2026-07-30 HTML Application file running embedded script when opened
Deep CDR
LinuxWindows
Script Injection · Beginner
2026-07-29 Keylogger sample detected by signature-based engines
Metascan
LinuxWindows
Malware · Beginner
2026-07-28 AI-generated identity documents for fraud onboarding
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Mid
2026-07-27 Sandbox detects credential-store probing behavior
Adaptive Sandbox
LinuxmacOSWindows
Malware · Mid
2026-07-26 Macro-enabled document delivered inside archive to bypass filters
Archive Engine
LinuxWindows
Archive Abuse · Beginner
2026-07-25 Archive locale metadata contradicting embedded document language
Country of Origin
Linux
Country of Origin · Beginner
2026-07-24 SVG image with script payload in onload handler
Deep CDR
LinuxWindows
Script Injection · Beginner
2026-07-23 Deliberately corrupted ZIP header evading simple scanners
FileType Engine
LinuxWindows
Extension Mismatch · Adv
2026-07-22 RLO Filename Spoofing Masquerades Executable as Text
FileType Engine
LinuxmacOSWindows
Extension Mismatch · Mid
2026-07-21 Firmware image shipping outdated libraries flagged via SBOM
SBOM
Linux
SBOM · Adv
2026-07-20 Tiny ZIP bomb expanding to enormous size on extraction
Archive Engine
LinuxWindows
Archive Abuse · Mid
2026-07-19 Self-extracting 7z archive auto-runs embedded payload on extract
Archive Engine
LinuxWindows
Archive Abuse · Mid
2026-07-18 Tar Path Traversal Escapes Extraction Directory
Archive Engine
LinuxWindows
Archive Abuse · Mid
2026-07-17 Payload Buried in Nested ZIP Layers
Archive Engine
LinuxWindows
Archive Abuse · Beginner
2026-07-16 PDF Launch Action Executes External Program
Deep CDR
LinuxWindows
PDF Abuse · Beginner
2026-07-15 Electron App Ships Outdated Chromium with CVEs
SBOM
Linux
SBOM · Adv
2026-07-14 Private Keys and Certificates Leak via Files
Proactive DLP
Linux
Data Loss Prevention · Adv
2026-07-13 AI-Generated Lures Impersonate Trusted Brands
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Beginner
2026-07-12 Double Extension Masquerade Hides Executable
FileType Engine
LinuxmacOSWindows
Extension Mismatch · Beginner
2026-07-11 Executable Disguised Behind Forged PNG Magic Bytes
FileType Engine
LinuxmacOSWindows
Extension Mismatch · Mid
2026-07-10 Wiper-Style Destructive Malware Caught by Metascan
Metascan
LinuxWindows
Malware · Mid
2026-07-09 Keylogger Keyboard Hook Detected by Behavioral Sandbox
Adaptive Sandbox
LinuxmacOSWindows
Malware · Mid
2026-07-08 Fileless PowerShell Execution Caught in Memory
Adaptive Sandbox
LinuxmacOSWindows
Script Injection · Adv
2026-07-07 Known Malware Caught by 30+ Engines Simultaneously
Metascan
LinuxWindows
Malware · Beginner
2026-07-06 Protected Health Information Detected in Medical Records
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-07-05 Remote Template Injection in DOCX Documents
Deep CDR
LinuxWindows
Macro · Adv
2026-07-04 OneNote Notebook Hides an Embedded Executable
Deep CDR
LinuxWindows
Script Injection · Beginner
2026-07-03 Polyglot File Valid as Both PDF and EXE
FileType Engine
LinuxmacOSWindows
Polyglot · Adv
2026-07-02 PDF carrying an embedded file object released on open
Deep CDR
LinuxWindows
PDF Abuse · Mid
2026-07-01 Payroll spreadsheet with PII flagged before sharing
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-06-30 API keys and passwords hardcoded in script files
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-06-29 Malware payload hidden inside ordinary image file (steganography)
Deep CDR
LinuxWindows
Steganography · Mid
2026-06-28 RTF document embedding OLE object that executes on open
Deep CDR
LinuxWindows
Macro · Mid
2026-06-27 Compiled HTML Help file executing script on open
Deep CDR
LinuxWindows
Script Injection · Mid
2026-06-26 Password-protected RAR hiding payload from static inspection
Archive Engine
LinuxWindows
Archive Abuse · Mid
2026-06-25 Malware sample whose metadata conflicts with claimed origin
Country of Origin
Linux
Country of Origin · Mid
2026-06-24 PDF produced by outdated engine with known CVEs
SBOM
Linux
SBOM · Mid
2026-06-23 Remcos-style RAT sample flagged by multi-engine scan
Metascan
LinuxWindows
Malware · Beginner
2026-06-22 HTML page assembling payload in browser and auto-downloading it
Deep CDR
LinuxWindows
Script Injection · Mid
2026-06-21 XOR-encrypted macro source defeating static inspection
Deep CDR
LinuxmacOSWindows
Macro · Adv
2026-06-20 Hidden prompt-injection instructions inside a document
OPSWAT AI Content Inspector
Linux
AI Content Inspector · Adv
2026-06-19 LNK invoking PowerShell download-and-execute chain
Deep CDR
LinuxWindows
LNK Abuse · Mid
2026-06-18 Shortcut file whose target string hides a command payload
Deep CDR
LinuxWindows
LNK Abuse · Beginner
2026-06-17 Credit card numbers flagged in plaintext export
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-06-16 Malicious PowerPoint presentation with embedded macro
Deep CDR
LinuxWindows
Macro · Beginner
2026-06-15 Sandbox captures periodic C2 beacon network behavior
Adaptive Sandbox
LinuxmacOSWindows
Malware · Mid
2026-06-14 Proprietary source code detected in outbound archive
Proactive DLP
Linux
Data Loss Prevention · Mid
2026-06-13 AI-generated lure document with no spelling errors
OPSWAT AI Content Inspector
LinuxWindows
AI Content Inspector · Beginner
2026-06-12 Sandbox replays multi-stage dropper execution chain
Adaptive Sandbox
LinuxmacOSWindows
Malware · Mid
2026-06-11 LockBit-style ransomware binary caught by signature engines
Metascan
LinuxWindows
Malware · Beginner
2026-06-10 PDF with embedded JavaScript auto-executing on open
Deep CDR
LinuxWindows
PDF Abuse · Mid
2026-06-09 RedLine-style infostealer sample flagged by Metascan engines
Metascan
LinuxWindows
Malware · Beginner
2026-06-08 National ID Numbers Detected in Exported Spreadsheet
Proactive DLP
Linux
Data Loss Prevention · Beginner
2026-06-07 Miasma Worm Spread Through Poisoned Developer Packages
Metascan
LinuxWindows
Malware · Mid
2026-06-06 Sandbox Observes Mass File Encryption and Ransom Note Behavior
Adaptive Sandbox
LinuxmacOSWindows
Malware · Beginner
2026-06-05 Emotet-Style Banking Trojan in Phishing Documents
Metascan
LinuxWindows
Malware · Beginner
2026-06-04 Executable Renamed to .jpg Bypasses Naive Filters
FileType Engine
LinuxmacOSWindows
Extension Mismatch · Beginner
2026-06-03 Excel DDE Field Launching External Command
Deep CDR
LinuxWindows
Macro · Beginner
2026-06-02 SBOM Analysis Surfaces Malicious npm Package in App Dependencies
SBOM
Linux
SBOM · Mid
2026-06-01 Malicious Word Document with AutoOpen VBA Macro
Deep CDR
LinuxmacOSWindows
Macro · Beginner
Page 1 of 1
---