Threat Research

    Chinese government-linked cyber threat actors, enabled by Integrity Technology Group, combine automated scanning, large-scale botnets, and hands-on exploitation to compromise organizations worldwide, including U.S. critical infrastructure....
    Research documents the evolution of MATCHBOIL, a custom C# downloader used by the Russia-aligned UAC-0099 APT group to deliver payloads and establish persistence on compromised systems. Between 2024 and 2026, the malware evolved with advanced .NET obfuscation, sandbox and anti-analysis checks, and modified persistence mechanisms, including scheduled tasks and registry Run keys....
    In July 2026, ThreatLabz uncovered a supply-chain attack involving a malicious Terraform provider designed to run attacker-controlled code when initialized. The compromised provider retrieves a Bash loader from a Terraform-themed spoofed domain, which deploys tailored malware based on the victim’s operating system and CPU architecture....
    Researchers details a financially motivated threat actor targeting South Korean financial organizations using ARTEX, an open-source agentic penetration-testing tool, alongside LLMs. The campaign leveraged AI-assisted intrusion operations, Claude Code, proxy infrastructure, and attacker-controlled servers, resulting in data exfiltration from targeted organizations....
    A large-scale fake Android app adware campaign involved more than 1,900 malicious applications installed across 500,000+ devices in 190+ countries, with India, Russia, and the U.S. among the most affected....
    In September, threat actors abused legitimate Power BI domains to make phishing emails appear trustworthy and evade security controls. Victims were directed to fake reference documents that prompted them to click “Download Reference,” leading to attacker-controlled websites....
    Researchers identified 42 malicious RubyGems packages published by a threat actor known as Ghost Dev, targeting crypto and Web3 developers through typosquatting, brandjacking, and malicious utility packages. The packages deploy either a reverse shell or a cryptocurrency theft toolkit, with delayed execution and sandbox/CI environment detection....
    2CLoader is a newly identified malware loader observed in August 2026 delivering Vidar and Remus information stealers, as well as XWorm RAT. It uses multiple anti-analysis and evasion techniques, including anti-VM and anti-debug checks, user-activity detection, indirect system calls, and Windows API hooks to evade security tools....
    An Iranian state-aligned threat actor impersonated the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. The activity, tracked as CL-STA-1178, includes a campaign dubbed “Blinder Tunnel.” Blinder Tunnel targeted Iraqi critical infrastructure in March 2026, with infrastructure staging observed as early as November 2025....
    In August 2026, analysts investigated MDR cases involving ClickFix-style lures that deployed a Python-based tunneling implant. Unlike traditional ClickFix attacks, the lures instructed victims to open Windows Terminal, a technique known as TerminalFix....
    TIKTOUK, a WordPress credential-collection toolkit comprising Python components and a Go-based Linux crawler that probes websites and extract exposed secrets. The toolkit targets WordPress configuration, backup, environment, and log files, recovering database credentials, AWS keys, API tokens, and encrypted email credentials through configuration-key-based decryption....
    ClingSTUN is a Linux backdoor that exploits unpatched vulnerabilities in Internet-facing routers and IoT devices to establish persistent access and turn compromised systems into remotely controlled proxy nodes....
    In July 2026, China-aligned threat actor TA419 conducted multiple credential-phishing campaigns targeting AI experts. The campaigns impersonated prominent economists and AI policymakers to target experts at US think tanks, universities, and legal organizations....
    Researchers identified 70+ fake cryptocurrency websites impersonating legitimate projects such as xStocks and Pendle, using fake reward votes to lure crypto users. Clicking the voting option prompts victims to connect cryptocurrency wallets, including MetaMask and WalletConnect, potentially leading to malicious token approvals or transaction signatures....
    Researchers details active exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path, allowing attackers to execute commands on internet-facing servers without authentication....
    Looking for Something?
    Threat Research Categories:
    Tags