Threat Research

    Threat actor STAC4749 conducted a Microsoft Teams voice phishing (vishing) campaign targeting North American organizations, impersonating IT support to gain remote access. After initial compromise, the attackers deployed a custom loader, backdoor, and modular post-exploitation tools to maintain persistence, enabling data exfiltration and the deployment of Chaos ransomware....
    TA488 (Void Blizzard/Laundry Bear) exploited CVE-2026-42897, an Outlook Web Access (OWA) XSS vulnerability, on 22 July 2026. The campaign targeted government, telecommunications, financial, hospitality, and aerospace organizations across the US and Europe....
    Researchers identified new malware used by the Iran-linked Mirage Kitten APT, including the NightLedger backdoor and ArcBridge/BridgeHead tunneling tools, to support long-term cyber-espionage operations. The malware provides remote access, command execution, file management, and covert communication to maintain persistence and evade detection....
    Attackers used the fake corepack.org website to distribute malware disguised as the legitimate npm Corepack developer tool. The malicious installer deploys an infostealer to steal sensitive data and installs proxyware to abuse victims' internet bandwidth....
    TA458, the Russia-aligned group behind Operation RoundPress, continues targeting webmail platforms with half-click exploits that compromise users simply by opening a malicious email. The campaign relies on advanced XSS vulnerabilities to steal sensitive email data without requiring clicks or social engineering....
    Phantom Stealer is a .NET-based credential-harvesting malware designed to stealthily steal browser credentials, saved passwords, session cookies, cryptocurrency wallet data, clipboard contents, and system information while maintaining persistence and evading detection....
    An exposed Alibaba Cloud server revealed an active China-nexus cyberespionage campaign targeting organizations in Vietnam, Malaysia, Hong Kong, Honduras, and Venezuela. The operation used the newly identified TriBack Loader with DLL sideloading and Win32 callback APIs to evade detection, delivering AdaptixC2 and Beagle backdoors....
    Since January 2026, ThreatLabz has tracked a threat actor believed to operate as an initial access broker for ransomware campaigns. The actor primarily targets organizations through Microsoft Teams vishing attacks and deploys a Go-based backdoor named GoGRPC. Researchers identified four GoGRPC variants Lep, Giver, Pet, and Kind each with shared features and unique capabilities....
    A suspected cyberespionage campaign targeted Thailand's Ministry of Finance (MOF) using the autonomous Hermes AI agent running in unattended (YOLO) mode to automate network reconnaissance and post-compromise activities....
    Since at least July 2025, the Russian state-backed APT group LAUNDRY BEAR has targeted Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS). The group's primary objective is to covertly collect sensitive email data for the Russian Federation....
    Dolphin X is a stealer and RAT that targets 300+ applications, stealing browser credentials, cryptocurrency wallets, cloud tokens, SSH keys, and developer secrets. Its standout AI Profiler automatically analyzes infected systems to identify and prioritize high-value victims, helping attackers focus on the most valuable targets....
    Iranian-affiliated APT actors, including activity linked to CyberAv3ngers, are targeting internet-connected Programmable Logic Controllers (PLCs) across U.S. critical infrastructure sectors, including Government Services and Facilities, Water and Wastewater Systems, and Energy....
    Cyberespionage campaign (CL-STA-1114), linked to the Russian threat actor tracked as Void Blizzard/LAUNDRY BEAR, targeting Zimbra webmail used by government, defense, transportation, and financial organizations across NATO countries, Ukraine, CIS, and Africa....
    SVG (Scalable Vector Graphics) files can embed JavaScript and other active content, making them an effective vehicle for phishing, malware delivery, and browser-based attacks while appearing to be harmless images....
    Researchers recently identified TrickBot variants that communicate with command-and-control (C2) servers using DNS tunneling instead of the HTTP protocol seen in earlier versions. The malware sends malformed DNS queries to conceal its network communications and evade detection....
    Looking for Something?
    Threat Research Categories:
    Tags