Threat Research

    Cyberespionage campaign (CL-STA-1114), linked to the Russian threat actor tracked as Void Blizzard/LAUNDRY BEAR, targeting Zimbra webmail used by government, defense, transportation, and financial organizations across NATO countries, Ukraine, CIS, and Africa....
    SVG (Scalable Vector Graphics) files can embed JavaScript and other active content, making them an effective vehicle for phishing, malware delivery, and browser-based attacks while appearing to be harmless images....
    Researchers recently identified TrickBot variants that communicate with command-and-control (C2) servers using DNS tunneling instead of the HTTP protocol seen in earlier versions. The malware sends malformed DNS queries to conceal its network communications and evade detection....
    Kali365 is a phishing-as-a-service (PhaaS) kit targeting U.S. organizations through Microsoft device code phishing. Instead of stealing passwords via fake login pages, it tricks victims into authorizing an attacker-controlled device on a legitimate Microsoft authentication page, allowing attackers to obtain OAuth access and refresh tokens....
    Researchers first exposed this campaign on May 22, 2026, identifying fake Chrome VPN extensions that redirected user traffic through attacker-controlled SOCKS5 proxy servers. Nearly two months later, the operation has expanded significantly, with 350+ new malicious extensions and at least 32 new Chrome Web Store accounts hosting cloned VPN apps....
    JADEPUFFER is the first documented agentic ransomware campaign where a large language model (LLM) autonomously executed the entire attack chain from initial compromise and credential theft to lateral movement and database extortion....
    Researchers are tracking Cruciferra, a crypter service used by multiple unrelated threat actors to conceal malware and improve delivery success. Built on Mono, it includes advanced evasion techniques such as indirect system calls, API/IAT unhooking, BYOVD-based EDR tampering, privilege escalation, persistence, and Process Ghosting....
    A suspected East Asia-linked threat actor conducted a multi-stage cyberespionage campaign targeting government entities in the Middle East, deploying the previously undocumented malware TELESHIM, MIXEDKEY, and BINDCLOAK....
    HOLLOWGRAPH is a sophisticated malware that abuses the Microsoft Graph API for covert command-and-control and uses DNS tunneling to refresh cloud authentication tokens, enabling it to blend into legitimate Microsoft 365 and network traffic....
    ClickLock Stealer is a newly discovered macOS malware that likely spreads through ClickFix phishing pages using compromised WordPress sites and Telegram infrastructure. It steals browser credentials, macOS Keychain data, password manager information, cryptocurrency wallet data, FTP credentials, and shell history, while using a modified GSocket backdoor for persistence....
    Security Labs identified a new Contagious Interview campaign, tracked as REF9403, that hides malware inside SVG image files using steganography. The infection chain appears to be previously undocumented. The campaign was uncovered after a DPRK-linked threat actor targeted the team's Slack workspace with a fake job posting and a malicious coding challenge....
    Researchers uncovered Spirals, a previously unseen Rust-based ransomware that compromised an IT services company in South Asia, progressing from initial access to data theft and network-wide encryption in less than 24 hours....
    UAT-11795 is a Russian-speaking, financially motivated threat actor targeting users primarily in the United States, with additional victims observed in Germany, Romania, and Venezuela....
    Since late March 2026, researchers have observed large-scale phishing campaigns that use fileless techniques and Lua-based loaders with low detection rates to deliver malware such as Agent Tesla, Remcos, XWorm, and Best Private LOGGER. The attackers impersonate well-known companies and pose as potential business partners to trick victims into opening malicious files....
    This campaign highlights the continued evolution of phishing attacks through the use of malicious VHDX images, DLL sideloading, in-memory shellcode execution, and layered anti-analysis techniques to evade traditional detection....
    Looking for Something?
    Threat Research Categories:
    Tags