Threat Research

    The Gentlemen ransomware-as-a-service (RaaS) operation, attributed to GOLD SHERWOOD, which uses stolen VPN credentials, vulnerable firewalls, and rapid privilege escalation to compromise organizations....
    BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, designed to support Initial Access Broker (IAB) operations....
    BREEZE COMET (UNC5669) is a financially motivated threat actor targeting Brazilian banks, fintechs, retailers, exchanges, and payment providers to manipulate banking software, APIs, and payment systems such as Pix, STR, and Boleto for fraudulent transfers....
    Between January and April 2026, researchers uncovered a social engineering campaign called Spring Ring that impersonated IT help desk staff through external Microsoft Teams accounts. The campaign targeted more than 150 employees across at least 10 organizations in multiple industries using voice phishing (vishing) techniques....
    The ValleyRAT campaign disguises a backdoor as signed adware, abusing the legitimate QN Wallpaper application and DLL sideloading via a malicious libcef.dll to load AES-encrypted payloads in memory....
    The TerminalFix campaign is a sophisticated ClickFix variant that uses compromised websites and fake Cloudflare CAPTCHA lures to trick victims into executing malicious PowerShell commands through Windows Terminal....
    A recent ClickFix campaign cluster used three different infection approaches to gain initial access, combining DLL sideloading, consistent file-naming patterns, and C2 dead drops. Attackers also used aggressive phone-based social engineering, directing victims to compromised WordPress websites hosting ClickFix lures....
    Researchers identified PackClient, a modular command-and-control (C2) framework actively being sold on Telegram. The framework has been linked to at least one Chinese-speaking threat actor, TA4922. PackClient expands TA4922’s arsenal of malware used for gaining initial access to targeted systems....
    A recently identified domain, passkeyconnect[.]com, is likely linked to Com-affiliated threat actors, including Bling Libra and CL-CRI-1116, based on known infrastructure fingerprints. Analysis identified 20+ organizations across 11 industries that could be targeted in vishing campaigns based on previously observed activity....
    The Aurora ransomware group has been observed targeting VMware ESXi environments with a Linux-based encryptor that uses ChaCha20 encryption and RSA-4096 key wrapping. Attackers also abused Cursor Agent with Claude Sonnet to automate hands-on-keyboard exploitation, including internal reconnaissance, credential abuse, NTLM relay, and certificate attacks across multiple victims....
    Tortoiseshell (Mirage Kitten/UNC1549) is an Iranian-linked threat actor affiliated with the IRGC, targeting defense, aerospace, IT, and military organizations....
    Suspected Chinese cyber actors have increasingly targeted Philippine government, defense, and critical infrastructure amid South China Sea tensions. Digital Defense Report 2025 ranked the Philippines 20th globally among countries most affected by cyber activity in H1 2025....
    QTFY, a China-linked hacking group attributed to Nanjing Xinjiuwei Network Technology Co. (XJW), has conducted cyber operations targeting U.S. critical infrastructure, including the defense industrial base, telecommunications, local governments, and higher education....
    Researchers highlight attacks targeting exposed AI infrastructure, including LiteLLM, RAGFlow, and Kestra, where adversaries exploited AI gateways and orchestration platforms for credential theft, remote code execution, persistence, container discovery, and cryptomining....
    A ValleyRAT campaign targeting organizations in India impersonates the Indian Income Tax Department through bilingual Hindi-English phishing emails and fake tax notices. Victims are directed to download a ZIP archive containing a legitimately signed Overwolf executable, which sideloads a malicious DLL and encrypted payload to deploy ValleyRAT....
    Looking for Something?
    Threat Research Categories:
    Tags