Threat Research

    Storm-3121, Storm-3032, and other threat actors performed a Passkey-themed social engineering campaign that tricks users into fraudulent authentication workflows, leading to identity and cloud compromise....
    Casbaneiro is a banking trojan targeting Latin American users, delivered through phishing emails containing fake invoices and legal notices. The campaign uses a multi-stage infection chain involving an HTA downloader and AutoIt loader, which injects the final payload into a Windows process....
    We continue tracking infrastructure potentially linked to Com-affiliated threat actors, including Bling Libra and CL-CRI-1116, using known infrastructure fingerprints. Since August 28, 2026, we identified 17 newly created FQDNs, including domains designed to impersonate known brands....
    GoldFactory has weaponized Vwork, a modified version of the open-source Android cloning app Shelter, as an add-on to the Gigabud Android banking trojan. Vwork uses the Android Work Profile to clone banking applications into an isolated space, helping hide Gigabud from security detection while maintaining remote control of victims’ devices....
    Active exploitation of Cisco Secure Firewall Management Center (FMC) vulnerabilities CVE-2026-20079 and CVE-2026-20316, enabling authentication bypass, unauthorized access, and privilege escalation. Threat clusters deployed web shells, reverse shells, proxy tools, Cyclops Blink, and credential-harvesting capabilities....
    An investigation uncovered CL-CRI-1171, a large-scale cybercrime campaign that operated under the radar for at least two years and primarily targeted young gamers. The group runs a pay-per-install service, using YouTube channels and SEO-poisoning campaigns to distribute malware through a custom loader....
    Analysis of the operator’s campaign logs identified 3,562 compromised Redis servers across two runs, with 22–26% of targets breached and most remaining hosts blocked by authentication....
    BlueDelta (APT28/Fancy Bear), a Russian state-sponsored GRU-linked threat actor, targeted government, diplomatic, and defense organizations in Romania, Spain, and Türkiye between September 2025 and April 2026....
    This report details a ClearFake infection chain using ClickFix social engineering, malicious Cloudflare Workers, and EtherHiding to deliver the Amatera stealer. The malware abuses WebDAV and rundll32.exe ordinal execution, followed by payloads including ZigCryptoStealer, a Go-based reverse proxy, or NetSupport Manager....
    Toy Ghouls group that has been targeting Russian organizations since 2025 and also using Lockbit and Babuk Ransomware. This group developed two custom backdoors, mqtt-bird-agent and matrix-bird-agent, using HiveMQ MQTT and Element/Matrix as command-and-control (C2) channels....
    Gambling Goblin, a Chinese-speaking cybercrime cluster linked to Earth Berberoka, has targeted Brazilian government and educational organizations since mid-2025, compromising Linux servers and installing malicious Apache modules to proxy visitors to attacker-controlled phishing pages....
    The abuse of Node.js has resurfaced, with multiple threat actors targeting government departments, technology companies, and hotels since February 2026. Attackers use the legitimate, signed node.exe runtime to execute malicious scripts, evade signature-based detection, and maintain persistence through registry Run keys....
    VoidShadow is a modular, cross-platform post-exploitation framework targeting both Windows and Linux systems, providing attackers with full remote control and credential theft capabilities. It uses layered userland and kernel-mode rootkits for stealth and persistence, while its C2 traffic is sent over TLS and disguised as legitimate Microsoft Graph, WordPress, and Google Cloud....
    Researchers details a DPRK-linked cyber-espionage campaign targeting South Korean media and automotive sectors, involving two malware families: Ted backdoor and curlRAT. The campaign uses social engineering and malicious files to establish access and deploy malware capable of command execution, system reconnaissance, and data theft....
    Researchers uncovered a high-volume phishing campaign that repurposed ASCII smuggling may be induced to follow threat actor-controlled instructions, an AI prompt-injection evasion technique for email filter evasion....
    Looking for Something?
    Threat Research Categories:
    Tags