Threat Research

    The Gentlemen ransomware affiliate used LOLBAS techniques, scheduled tasks, and MSI payloads to deploy EtherRAT across Windows networks for persistent access, credential theft, privilege escalation, and lateral movement....
    ThreatLabz is tracking a long-running supply chain attack involving the QuickFox application, a VPN proxy and game accelerator popular among Chinese users. The campaign has been active since at least August 2025 and relies on a trojanized version of the software. Attackers modified an Electron renderer HTML file to download and execute a JavaScript-based loader....
    The research highlights malware that bypasses traditional DNS-based detection by communicating directly with hardcoded IP addresses instead of resolving domain names. This technique reduces reliance on DNS infrastructure, making network-based monitoring and domain-blocking less effective....
    DOUBLECUP is a new Russian Loader-as-a-Service (LaaS) for ClickFix campaigns operating since early June 2026. It demonstrates the growing sophistication of ClickFix campaigns by using steganography and environmental keying to deliver payloads while evading detection....
    Part 2 of this analysis focuses on new tools used by an East Asia-linked threat actor targeting government organizations in the Middle East. Following ThreatLabz’s Part 1 coverage of the TELESHIM backdoor and MIXEDKEY loader, Kaspersky reported a related campaign....
    Threat actors are distributing a fake "undetected" Xeno Roblox script executor through gaming forums and Discord to deliver a multi-stage Java-based stealer and RAT. The malware disguises itself as legitimate Xeno and Windows components, stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency wallets, and payment data....
    Azalea is a sophisticated modular Remote Access Trojan (RAT) that uses a stealthy multi-stage loader, in-memory execution, and anti-analysis techniques to establish persistent access while evading detection. Its plugin-based architecture enables attackers to dynamically extend functionality, including reconnaissance, privilege escalation, keylogging, credential theft, and HVNC....
    Attackers compromised legitimate Joyfill packages and inserted malware that deploys a remote access trojan (RAT) on developer systems. Researchers linked the activity to the DPRK-associated PolinRider campaign based on indicators such as Tron, Aptos, and BNB Smart Chain transactions....
    XCSSET v40 is an advanced macOS malware targeting Apple developers through Xcode supply chain attacks, infecting legitimate projects and propagating across all existing Xcode projects on compromised systems....
    A fake Public Security Bureau app distributed through attacker-controlled domains served as the primary infection vector for Flying Eagle malware. Chinese state media issued a warning in June 2026 about fraudulent apps masquerading as official government services....
    Remus Infostealer is being distributed through SEO-poisoned fake cracked software websites targeting primarily Turkish users. The malware injects into Chromium-based browsers to steal browser credentials, gaming platform data, and more files, while dynamically resolving its C2 from an Ethereum smart contract and disguising data exfiltration using spoofed Host headers....
    GenieLocker is a cross-platform ransomware family designed to target Windows, Linux, and VMware ESXi environments, enabling attackers to encrypt endpoints, servers, and virtual machines in a single operation....
    Threat actor STAC4749 conducted a Microsoft Teams voice phishing (vishing) campaign targeting North American organizations, impersonating IT support to gain remote access. After initial compromise, the attackers deployed a custom loader, backdoor, and modular post-exploitation tools to maintain persistence, enabling data exfiltration and the deployment of Chaos ransomware....
    TA488 (Void Blizzard/Laundry Bear) exploited CVE-2026-42897, an Outlook Web Access (OWA) XSS vulnerability, on 22 July 2026. The campaign targeted government, telecommunications, financial, hospitality, and aerospace organizations across the US and Europe....
    Researchers identified new malware used by the Iran-linked Mirage Kitten APT, including the NightLedger backdoor and ArcBridge/BridgeHead tunneling tools, to support long-term cyber-espionage operations. The malware provides remote access, command execution, file management, and covert communication to maintain persistence and evade detection....
    Looking for Something?
    Threat Research Categories:
    Tags