Threat Research

    On July 31, Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch, attributed to Storm-2945, a sub-group of Russia-linked Midnight Blizzard (APT29). The campaign abuses captive portal networks at hotels, conference centers, and similar venues to redirect victims to attacker-controlled infrastructure....
    The APT36 (Transparent Tribe)-linked PATCHCORD campaign is an evolving cyber espionage operation targeting telecommunications, government, defense, and critical infrastructure organizations across South Asia....
    Recent weeks have seen a rise in ClickFix social engineering campaigns delivering the KongTuke malware through DLL sideloading. The campaign abuses legitimate, digitally signed Mozilla Firefox binaries, while attackers rotate lure domains but reuse the same payload infrastructure and tools. The malicious DLLs are written in Rust and disguised as legitimate Firefox components....
    ClickFix campaign that used compromised WordPress websites and Cloudflare-themed social engineering lures to trick users into executing a malicious PowerShell command. The attack abused the legitimate Deno JavaScript runtime and winget to install Deno, execute remote JavaScript, and deliver a Python-based infostealer through an MSI staging chain....
    Head Mare, now assessed as an APT group, exploited two vulnerabilities in unpatched TrueConf video conferencing servers to achieve SYSTEM-level code execution and deploy a web shell. The attackers used the compromised server to collect infrastructure data, access the TrueConf database, and replace legitimate TrueConf Client installers with trojanized versions....
    A new Kimwolf v7 Android/IoT botnet variant has been identified with enhanced DDoS capabilities and stronger C2 resilience. The botnet mainly targets Android TV boxes and set-top boxes, adding an HTTP/2-based flood that mimics complete browser fingerprints....
    Lazarus Group / DPRK-linked Operation Dream Job campaign targeting the defense, aerospace, and aviation sectors through spear-phishing, job-offer lures, impersonation websites, SEO poisoning, and trojanized PDF viewers....
    Aeternum is a newly discovered C++ botnet loader that uses the Polygon blockchain as its command-and-control (C2) infrastructure. Instead of traditional servers or domains, attackers store encrypted and plaintext commands directly within blockchain smart contracts....
    Abyssos is a newly identified C++-based modular Remote Access Trojan (RAT) that supports credential theft, file exfiltration, and VNC-based remote access. The malware uses LLVM-based code obfuscation, anti-analysis techniques, and a custom TCP protocol for C2 communication....
    Gunra is a ransomware-as-a-service (RaaS) operation used by affiliates to target government, critical infrastructure, and other organizations through data encryption, data exfiltration, and double-extortion tactics. CVE-2024-55591 and CVE-2025-24472 allow threat actors to exploit scheduled tasks on vulnerable FortiOS firewall devices....
    The macOS malware infection originated from a ClickFix social engineering scam.The attack delivered a shell script that collected basic system and device information. It then downloaded a macOS malware payload tailored to the computer’s CPU architecture. The malware can steal stored passwords and other sensitive information from the victim....
    FakeAgent is a malvertising campaign that targeted at least 29 organizations by using a malicious Claude Artifact hosted on the legitimate Claude.ai domain to distribute a fake Claude Desktop application. The disguised executable ultimately delivered SectopRAT, which can steal passwords, credit card data, personal information, and files....
    The Head Mare hacktivist group exploited two TrueConf Server vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to gain SYSTEM-level access and deploy a web shell. Attackers then replaced legitimate TrueConf Client installers with trojanized versions containing the PhantomCore and PhantomGraph backdoors, turning the compromise into a supply-chain attack....
    Researchers investigated the exploitation of the zero-day vulnerability CVE-2026-18577 in N-able N-central, where attackers gained initial access and deployed legitimate Remote Monitoring and Management (RMM) tools to establish persistent remote access....
    Analysis revealed 10 NPM packages published from July 18–22, 2026, that download an obfuscated crypto-stealing malware and RAT from a remote server, with the payload concealed inside a JSON object to mask its malicious nature....
    Looking for Something?
    Threat Research Categories:
    Tags