Threat Research

    Toy Ghouls group that has been targeting Russian organizations since 2025 and also using Lockbit and Babuk Ransomware. This group developed two custom backdoors, mqtt-bird-agent and matrix-bird-agent, using HiveMQ MQTT and Element/Matrix as command-and-control (C2) channels....
    Gambling Goblin, a Chinese-speaking cybercrime cluster linked to Earth Berberoka, has targeted Brazilian government and educational organizations since mid-2025, compromising Linux servers and installing malicious Apache modules to proxy visitors to attacker-controlled phishing pages....
    The abuse of Node.js has resurfaced, with multiple threat actors targeting government departments, technology companies, and hotels since February 2026. Attackers use the legitimate, signed node.exe runtime to execute malicious scripts, evade signature-based detection, and maintain persistence through registry Run keys....
    VoidShadow is a modular, cross-platform post-exploitation framework targeting both Windows and Linux systems, providing attackers with full remote control and credential theft capabilities. It uses layered userland and kernel-mode rootkits for stealth and persistence, while its C2 traffic is sent over TLS and disguised as legitimate Microsoft Graph, WordPress, and Google Cloud....
    Researchers details a DPRK-linked cyber-espionage campaign targeting South Korean media and automotive sectors, involving two malware families: Ted backdoor and curlRAT. The campaign uses social engineering and malicious files to establish access and deploy malware capable of command execution, system reconnaissance, and data theft....
    Researchers uncovered a high-volume phishing campaign that repurposed ASCII smuggling may be induced to follow threat actor-controlled instructions, an AI prompt-injection evasion technique for email filter evasion....
    We analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations across Latin America. Attackers used AI to enhance their capabilities, alongside living-off-the-land techniques, custom RATs, and tunneling tools....
    A Chinese-speaking threat operator used AI agents powered by Claude, Qwen, and DeepSeek to automate reconnaissance, exploitation, credential collection, and reporting against government, education, and industrial targets across Asia....
    Threat Intelligence observed a human-operated intrusion campaign in which attackers impersonate IT support personnel through Microsoft Teams and use social engineering and remote support tools to gain interactive access....
    During an August investigation into an Adversary-in-the-Middle (AiTM) attack, researchers discovered the control panel of a phishing kit known as Knight Office. The attack began with a DocuSign-themed email lure, followed by multiple redirects through the Monday work management platform and a compromised Joomla website....
    Operation QUICSILVER is a China-nexus cyberespionage campaign targeting Myanmar, using a Burmese-language graduation ceremony invitation impersonating Myanmar’s Information Technology and Cyber Security Department as a lure....
    The Gentlemen ransomware-as-a-service (RaaS) operation, attributed to GOLD SHERWOOD, which uses stolen VPN credentials, vulnerable firewalls, and rapid privilege escalation to compromise organizations....
    BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, designed to support Initial Access Broker (IAB) operations....
    BREEZE COMET (UNC5669) is a financially motivated threat actor targeting Brazilian banks, fintechs, retailers, exchanges, and payment providers to manipulate banking software, APIs, and payment systems such as Pix, STR, and Boleto for fraudulent transfers....
    Between January and April 2026, researchers uncovered a social engineering campaign called Spring Ring that impersonated IT help desk staff through external Microsoft Teams accounts. The campaign targeted more than 150 employees across at least 10 organizations in multiple industries using voice phishing (vishing) techniques....
    Looking for Something?
    Threat Research Categories:
    Tags