Threat Research

    P2PInfect activity targeting internet-exposed and exploiting misconfigured Redis instances, with attackers abusing Redis replication and module-loading capabilities to achieve remote code execution. The campaign exploits CVE-2022-0543 and deploys ELF-based malware, establishes reverse shells, and uses mechanisms such as cron jobs and SSH authorized keys for persistence....
    Torrent trackers are frequently abused to distribute malware disguised as popular movies, games, and pirated software. Attackers use cracked software and malicious installers to infect large numbers of users. During the analysis, researchers discovered a new modular, multi-stage malware framework called MovieReaper....
    Chinese threat actors UTA0560 and JungleBamboo (APT31) exploited a Chrome patch-gap vulnerability, CVE-2026-85046, in targeted spear-phishing campaigns against NGOs. The exploit chain combined CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (V8 sandbox escape), and CVE-2026-85880 (Windows kernel LPE) to escape browser and OS security boundaries....
    SideCopy has expanded its cyber operations beyond its traditional focus on government officials and high-ranking personnel to include academic institutions. The group typically uses spear-phishing campaigns to gain initial access and deliver malicious payloads....
    HEAVYGRAM is a Windows backdoor attributed with moderate confidence to Handala Hack, used since 2023 to target Iranian dissidents, journalists, and individuals opposing the Iranian government....
    Researcher details SparroWocky, a modular C++ backdoor deployed by the China-aligned FamousSparrow APT against governmental organizations across Latin America. The malware uses DLL sideloading, RC4-encrypted payloads, reflective code loading,...
    AMOS Stealer is a macOS information stealer advertised on Telegram as early as April 2024 and remains a growing threat. It steals system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications....
    Operation RapidRust, an APT36 campaign targeting government and defense organizations in India and Afghanistan, using new tools including RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. RUSTYSHADE is a Rust-based backdoor that uses private GitHub repositories for C2, while RUSTYMOVE enables propagation through removable media....
    A SpiceRAT C2 infrastructure cluster active from late 2025 through August 2026 was linked to SilkParasite-associated malware families, including NodeEdgeRAT and NomadRAT, through shared domains and TLS certificates....
    A malware campaign uses a fake Indian Income Tax Department assessment notice to distribute a RAT-like payload targeting Windows systems. The attackers operate ten malicious domains hosting a fraudulent tax assessment portal designed to mimic official government communications....
    HypeAgent is a multi-stage infostealer that uses JavaScript, PowerShell, .NET loaders, and PNG steganography to evade detection. It combines scheduled-task persistence, encrypted payloads, reflective loading, AMSI bypassing, and process hollowing to execute its payload....
    A compromised regional news outlet injected malicious JavaScript that triggers a ClickFix prompt, using a cookie check to control execution. The lure tricks users into running an obfuscated CMD/PowerShell command, which downloads and executes an encrypted, compressed payload....
    In June 2026, ThreatLabz identified SloppyRAT, a new malware family likely used in ransomware operations to establish an initial foothold and support lateral movement. The malware uses encrypted code blocks, runtime decryption, junk code, and indirect system calls to complicate analysis and detection....
    The team identified four espionage-focused threat actors using a new exploit kit, tracked as BlueMoon, targeting Chrome and Microsoft Windows vulnerabilities. The China-aligned actor TA412 was the first observed user of BlueMoon on August 28, 2026, followed by several other suspected China-linked groups....
    Storm-3121, Storm-3032, and other threat actors performed a Passkey-themed social engineering campaign that tricks users into fraudulent authentication workflows, leading to identity and cloud compromise....
    Looking for Something?
    Threat Research Categories:
    Tags