Login
Sign Up
Toggle navigation
Knowledge on Demand
Threat Research
More
Blogs and News
Events
Threat Research
ClickFix Campaign Generated via AI Delivers SmartRAT
In March 2026, ThreatLabz detected multiple malicious typosquatting domains built using AI website generators. Cybercriminals are using these tools to rapidly scale convincing lures, ranging from simple credential harvesting to ClickFix campaigns delivering Remote Access Trojans (RATs)....
6/18/2026
0
Read More »
Crypto Clipper Uses Tor and Worm-like Propagation for Persistence and Control
Researchers identified a cryptocurrency clipper malware that spreads through malicious .LNK shortcut files and propagates like a worm via removable drives. It launches a bundled Tor client and communicates with hidden .onion C2 servers through a local SOCKS5 proxy (localhost:9050) to evade detection....
6/18/2026
0
Read More »
Titan Infostealer Embedded in AI Assistant PyPI Package
A malicious PyPI package masquerading as an AI assistant, myra-ai-assistant, was found to contain TITAN, a Python-based infostealer that uses OCR-driven screen monitoring to capture sensitive information such as login pages, emails, IDE sessions, and financial transactions....
6/18/2026
0
Read More »
Unveiling ErrTraffic: Inside a Growing ClickFix Malware Distribution Framework
ErrTraffic is a Malware-as-a-Service (MaaS) framework used to distribute malware through ClickFix social engineering lures embedded in compromised WordPress websites. The framework incorporates a Traffic Distribution System (TDS) and uses EtherHiding to conceal its command-and-control infrastructure within the blockchain....
6/17/2026
0
Read More »
FishMonger’s Arsenal Upgraded: SprySOCKS for Windows
Researchers found two new Windows variants of the SprySOCKS backdoor, previously known only on Linux. Linked to the Chinese group FishMonger (I-SOON), it active targeted government entities between 2023 and 2024. Telemetry confirmed victims across Honduras, Taiwan, Thailand, and Pakistan....
6/17/2026
0
Read More »
Dozens of Malicious Wallpapers Found on Steam Workshop: Gamers Accounts at Risk
Researchers discovered dozens of malicious wallpapers on Steam Workshop that abused Wallpaper Engine's Application Wallpaper feature to execute malware on users' PCs. The campaign distributed threats such as DarkKomet backdoors, Lumma and Vidar infostealers, crypto miners, and other credential-stealing malware....
6/17/2026
0
Read More »
China-Nexus Actor Targets US Defense, AI, and Medical Research
A PRC-nexus threat actor, UNC6508, targeted North American academic, medical, and military research institutions. The sophisticated campaign remained entirely undetected within target networks for over a year. Attackers initially breached networks by compromising externally facing web applications....
6/16/2026
0
Read More »
OceanLotus: From External Espionage to Domestic Targeting
OceanLotus (APT32) has shifted its focus from broader regional operations to a more targeted government within Vietnam. Between 2024 and 2026, the group used its SPECTRALVIPER backdoor in a supply-chain attack targeting stock investors and a long-term intrusion against a Vietnamese infrastructure and transport company....
6/16/2026
0
Read More »
Attackers Exploiting AI Brand Hype
A threat actor is leveraging AI brand impersonation by registering lookalike .ru domains that mimic DeepSeek, MiniMax, and ChatGPT, complete with cloned branding, AI chat interfaces, and the DeepSeek whale mascot to target Russian-speaking users....
6/16/2026
0
Read More »
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
ShinyHunters exploited the critical zero-day vulnerability CVE-2026-35273 in Oracle PeopleSoft's Environment Management component to compromise organizations, with a strong focus on the higher education sector....
6/15/2026
0
Read More »
Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion
Since November 2025, the Shai-Hulud V2 campaign has evolved significantly beyond typical software supply chain attacks. Over the last six months, the threat expanded from npm into PyPI and shifted focus from compromised maintainers to CI/CD abuse. The attackers undermined trust in SLSA provenance and OIDC-based publishing workflows without breaking cryptographic guarantees....
6/15/2026
0
Read More »
Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to Serve Thai Gambling SEO Content
A large-scale SEO poisoning campaign is exploiting Azure DNS zone takeovers through abandoned cloud NS delegations. The threat actor hijacked orphaned DNS zones and hosted Thai-language gambling content under the trusted domains of 163 organizations across 30+ countries, including government agencies, healthcare providers, financial institutions, and more....
6/15/2026
0
Read More »
Threat Actors Weaponize AI Hype to Deliver AsyncRAT
Threat actors are exploiting growing interest in artificial intelligence by distributing malicious files disguised as AI-related guides and learning materials. The attack uses a complex, multi-stage infection chain with heavily obfuscated scripts and AutoHotkey-based loaders to deploy a .NET RAT and AsyncRAT directly into memory, enabling remote access....
6/12/2026
0
Read More »
Dissecting OnionDrop: Commoditized Loader with Nation-State-Grade Evasion
OnionDrop is a sophisticated multi-stage malware loader designed to deliver InfoStealers such as LegionLoader (CurlyGate), CGrabber, and Vidar Stealer at scale....
6/12/2026
0
Read More »
ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512
OP-512 is a newly identified, likely China-linked cyberespionage cluster that targeted a compromised IIS web server to conduct long-term intelligence-gathering operations....
6/11/2026
0
Read More »
Looking for Something?
Threat Research Categories:
Threat Research
1038
Tags
Subscription
Please enter a valid email address.
Info