Threat Research

    Researchers report that Russian Star Blizzard (SEABORGIUM) has expanded its phishing operations in 2026, using large-scale phishing campaigns, compromised websites, and social engineering to target organizations, particularly those connected to Ukraine....
    Detects potential arbitrary file downloads initiated through Microsoft Office applications....
    The AgtaBackup RAT campaign uses fake Microsoft Store/video-conferencing pages to deliver legitimate RMM tools such as LogMeIn Resolve and ConnectWise ScreenConnect, giving attackers remote access to victim systems. Attackers then use PowerShell to download and silently install the .NET-based AgtaBackup RAT as a hidden SYSTEM service....
    Researchers identified a coordinated Malicious Browser Extension campaign in which Chrome extensions disguised as browser games impersonate legitimate Crypto Wallets such as TronLink, Trust Wallet, and Ledger Wallet Extension....
    NeedyMantis is a modular post-compromise malware family used in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, it is typically deployed after initial access to maintain long-term persistence and support follow-on operations....
    Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate products and redirect victims to malicious backup sites. The team identified two Custom GPTs linked to the same campaign and used to facilitate the attacks. A ClickFix lure tricks victims into executing PowerShell, which downloads a malicious MSI and launches a multi-stage infection chain....
    Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), with expanded targeting across multiple sectors. In June 2026, the threat actor primarily exploited the vulnerability as a zero-day against academic institutions....
    Threat actors used fraudulent Google Ads to target Ledger hardware wallet users with a phishing campaign. The ads redirected victims through Google Cloud Storage and frequently changing Vercel domains to a fake Ledger page hosted through Google Sites....
    Researchers highlight a Social Engineering campaign using attractive shipping-rebate offers to lure users into deceptive subscription programs with recurring monthly charges. The Phishing-style offers can obscure billing terms and lead victims to unknowingly enroll in paid memberships, making this an Online Fraud and Financial Scam....
    Vidar is an information-stealing malware first observed in 2018 that has continued to evolve its string obfuscation techniques. Its developers have modified deobfuscation algorithms, constants, and primitives to make detection and analysis more difficult. From May to early September 2026, ThreatLabz tracked Vidar’s progression from basic XOR-based obfuscation to ChaCha20....
    Researchers uncovered a SectopRAT (ArechClient2) variant hidden inside a legitimate Italian audio workstation application. Attackers tampered with FrameworkBase.dll to sideload sdkcra.dll, while the encrypted SectopRAT payload was embedded in legitimate-looking database files and launched through a scheduled task....
    The new MacSync macOS infostealer uses revamped binary-based delivery, with Objective-C/Swift payloads and DMG-based infection chains, including abuse of iCloud Calendar for payload delivery. The malware employs AES encryption, ECDH Curve25519, anti-debugging, and in-memory execution while establishing persistence through LaunchAgents, ZSHRC, and Git hooks....
    DarkMe malware was observed in two separate incidents targeting different organizations on August 31, 2026. DarkMe is a VB6-based spy-RAT previously linked to the financially motivated Water Hydra and Operation DarkCasino. The samples were identified through their command set, VB6 loader chain, and a modified RC4 routine that produces a single-byte XOR payload....
    Researcher details a malicious Firefox extension masquerading as a PDF identity-verification utility that fetches its malicious payload only after installation to evade detection. The extension targets Google accounts, injecting an account-takeover script into legitimate accounts.google.com pages to automate authentication flows and capture Google OAuth session cookies....
    RemControl is a previously undocumented Android banking trojan targeting retail banking customers across Western Europe, the Middle East, and Canada. It abuses Android Accessibility Services to display fake banking overlays, capture PINs and keystrokes, stream screens, and provide attackers with full remote control....
    Looking for Something?
    Threat Research Categories:
    Tags