Threat Research

    Researchers investigated the exploitation of the zero-day vulnerability CVE-2026-18577 in N-able N-central, where attackers gained initial access and deployed legitimate Remote Monitoring and Management (RMM) tools to establish persistent remote access....
    Analysis revealed 10 NPM packages published from July 18–22, 2026, that download an obfuscated crypto-stealing malware and RAT from a remote server, with the payload concealed inside a JSON object to mask its malicious nature....
    UNC6671 continues its data theft extortion operations under multiple brands, including Redact, Pink, Helix, and Falcon, despite the reported retirement of the BlackFile brand. The group uses IT helpdesk voice phishing (vishing), Adversary-in-the-Middle (AiTM) credential harvesting, and MFA token interception to compromise Microsoft 365 and Okta accounts....
    SMOKE#SCREEN is a multi-wave campaign that uses trusted software lures—including Zoom updates, Adobe updates, business documents, and system maintenance tools—to silently install the legitimate ScreenConnect RMM agent for persistent remote access....
    A newly observed ClickFix variant abuses the legitimate Windows binary pcalua.exe to evade parent-process detection and launch malicious activity. Victims are tricked into executing a crafted command that initiates PowerShell, spawns cmd.exe via WMI, and mounts a remote WebDAV share....
    ChainDrop is a large-scale npm supply chain compromise that leveraged compromised maintainer accounts to infect over 1,300 npm packages with a self-propagating worm, enabling rapid spread across developer environments and CI/CD pipelines....
    The Gentlemen ransomware affiliate used LOLBAS techniques, scheduled tasks, and MSI payloads to deploy EtherRAT across Windows networks for persistent access, credential theft, privilege escalation, and lateral movement....
    ThreatLabz is tracking a long-running supply chain attack involving the QuickFox application, a VPN proxy and game accelerator popular among Chinese users. The campaign has been active since at least August 2025 and relies on a trojanized version of the software. Attackers modified an Electron renderer HTML file to download and execute a JavaScript-based loader....
    The research highlights malware that bypasses traditional DNS-based detection by communicating directly with hardcoded IP addresses instead of resolving domain names. This technique reduces reliance on DNS infrastructure, making network-based monitoring and domain-blocking less effective....
    DOUBLECUP is a new Russian Loader-as-a-Service (LaaS) for ClickFix campaigns operating since early June 2026. It demonstrates the growing sophistication of ClickFix campaigns by using steganography and environmental keying to deliver payloads while evading detection....
    Part 2 of this analysis focuses on new tools used by an East Asia-linked threat actor targeting government organizations in the Middle East. Following ThreatLabz’s Part 1 coverage of the TELESHIM backdoor and MIXEDKEY loader, Kaspersky reported a related campaign....
    Threat actors are distributing a fake "undetected" Xeno Roblox script executor through gaming forums and Discord to deliver a multi-stage Java-based stealer and RAT. The malware disguises itself as legitimate Xeno and Windows components, stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency wallets, and payment data....
    Azalea is a sophisticated modular Remote Access Trojan (RAT) that uses a stealthy multi-stage loader, in-memory execution, and anti-analysis techniques to establish persistent access while evading detection. Its plugin-based architecture enables attackers to dynamically extend functionality, including reconnaissance, privilege escalation, keylogging, credential theft, and HVNC....
    Attackers compromised legitimate Joyfill packages and inserted malware that deploys a remote access trojan (RAT) on developer systems. Researchers linked the activity to the DPRK-associated PolinRider campaign based on indicators such as Tron, Aptos, and BNB Smart Chain transactions....
    XCSSET v40 is an advanced macOS malware targeting Apple developers through Xcode supply chain attacks, infecting legitimate projects and propagating across all existing Xcode projects on compromised systems....
    Looking for Something?
    Threat Research Categories:
    Tags