Threat Research

    SideCopy has expanded its cyber operations beyond its traditional focus on government officials and high-ranking personnel to include academic institutions. The group typically uses spear-phishing campaigns to gain initial access and deliver malicious payloads....
    HEAVYGRAM is a Windows backdoor attributed with moderate confidence to Handala Hack, used since 2023 to target Iranian dissidents, journalists, and individuals opposing the Iranian government....
    Researcher details SparroWocky, a modular C++ backdoor deployed by the China-aligned FamousSparrow APT against governmental organizations across Latin America. The malware uses DLL sideloading, RC4-encrypted payloads, reflective code loading,...
    AMOS Stealer is a macOS information stealer advertised on Telegram as early as April 2024 and remains a growing threat. It steals system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications....
    Operation RapidRust, an APT36 campaign targeting government and defense organizations in India and Afghanistan, using new tools including RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. RUSTYSHADE is a Rust-based backdoor that uses private GitHub repositories for C2, while RUSTYMOVE enables propagation through removable media....
    A SpiceRAT C2 infrastructure cluster active from late 2025 through August 2026 was linked to SilkParasite-associated malware families, including NodeEdgeRAT and NomadRAT, through shared domains and TLS certificates....
    A malware campaign uses a fake Indian Income Tax Department assessment notice to distribute a RAT-like payload targeting Windows systems. The attackers operate ten malicious domains hosting a fraudulent tax assessment portal designed to mimic official government communications....
    HypeAgent is a multi-stage infostealer that uses JavaScript, PowerShell, .NET loaders, and PNG steganography to evade detection. It combines scheduled-task persistence, encrypted payloads, reflective loading, AMSI bypassing, and process hollowing to execute its payload....
    A compromised regional news outlet injected malicious JavaScript that triggers a ClickFix prompt, using a cookie check to control execution. The lure tricks users into running an obfuscated CMD/PowerShell command, which downloads and executes an encrypted, compressed payload....
    In June 2026, ThreatLabz identified SloppyRAT, a new malware family likely used in ransomware operations to establish an initial foothold and support lateral movement. The malware uses encrypted code blocks, runtime decryption, junk code, and indirect system calls to complicate analysis and detection....
    The team identified four espionage-focused threat actors using a new exploit kit, tracked as BlueMoon, targeting Chrome and Microsoft Windows vulnerabilities. The China-aligned actor TA412 was the first observed user of BlueMoon on August 28, 2026, followed by several other suspected China-linked groups....
    Storm-3121, Storm-3032, and other threat actors performed a Passkey-themed social engineering campaign that tricks users into fraudulent authentication workflows, leading to identity and cloud compromise....
    Casbaneiro is a banking trojan targeting Latin American users, delivered through phishing emails containing fake invoices and legal notices. The campaign uses a multi-stage infection chain involving an HTA downloader and AutoIt loader, which injects the final payload into a Windows process....
    We continue tracking infrastructure potentially linked to Com-affiliated threat actors, including Bling Libra and CL-CRI-1116, using known infrastructure fingerprints. Since August 28, 2026, we identified 17 newly created FQDNs, including domains designed to impersonate known brands....
    GoldFactory has weaponized Vwork, a modified version of the open-source Android cloning app Shelter, as an add-on to the Gigabud Android banking trojan. Vwork uses the Android Work Profile to clone banking applications into an isolated space, helping hide Gigabud from security detection while maintaining remote control of victims’ devices....
    Looking for Something?
    Threat Research Categories:
    Tags