[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwp0-pKqWQoPLRCd04OJNEmha1VvoFxHPCgmnBk-FyMw":3},{"article":4,"iocs":37,"watch_terms":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"c880dfa6-7d57-4f92-9844-8f521cf02fec","As usually, @smica83 uploaded a related sample to Bazaar: https:\u002F\u002Ft.co\u002Fjt9HqNOAtA\nActive source u...","as-usually-smica83-uploaded-a-related-sample-to-bazaar-https-t-co-jt9hqnoata-act","As usually, @smica83 uploaded a related sample to Bazaar: https:\u002F\u002Ft.co\u002Fjt9HqNOAtA\nActive source url: https:\u002F\u002Fnebraskatigers.s3.us-east-005.backblazeb2[.]com\u002Fbluebeam\u002FBlueBeam_Revu_0295-latest-x64.exe\n\"Xiamen Yufeng Tiantai Network Co., Ltd.\" (Sectigo given cert) signed...\n🤷‍♂️ https:\u002F\u002Ft.co\u002FlqVrXrwJMs","A malicious executable masquerading as BlueBeam Revu 0295 was discovered hosted on a Backblaze S3 bucket and uploaded to the Bazaar malware repository. The malware is signed with a certificate issued to 'Xiamen Yufeng Tiantai Network Co., Ltd.' by Sectigo, suggesting a supply-chain or certificate abuse vector.","Malware sample disguised as BlueBeam Revu installer uploaded to Bazaar.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2039266584745722142","2026-04-01T09:00:16+00:00","2026-04-01T10:00:10.042632+00:00",7,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":17,"icon":11,"name":19,"slug":20},"Malware","malware",[22,27,32],{"category":23},{"id":24,"icon":11,"name":25,"slug":26},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":28},{"id":29,"icon":11,"name":30,"slug":31},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[38,42,46],{"type":39,"value":40,"context":41},"url","https:\u002F\u002Fnebraskatigers.s3.us-east-005.backblazeb2.com\u002Fbluebeam\u002FBlueBeam_Revu_0295-latest-x64.exe","Malicious BlueBeam Revu installer hosted on Backblaze S3",{"type":43,"value":44,"context":45},"domain","backblazeb2.com","S3-like storage service hosting malware payload",{"type":20,"value":47,"context":48},"BlueBeam_Revu_0295-latest-x64.exe (trojanized)","Fake BlueBeam Revu executable with Sectigo certificate abuse",[]]