Threat Research

    Threat actors used SEO poisoning to distribute a trojanized ManageEngine OpManager installer that deployed BumbleBee malware for initial access. The intrusion progressed with AdaptixC2, credential theft from the domain controller, SSH-based lateral movement, and data exfiltration via FileZilla and SFTP....
    The Gentlemen emerged as a prominent Ransomware-as-a-Service (RaaS) group, significantly expanding its operations in early 2026 and ranking among the top ransomware actors by victim disclosures on its Data Leak Site (DLS)....
    Attackers are targeting Booking.com partner hotels in Japan using phishing emails. Phishing lures impersonate guest complaints and review requests to trick staff. Delivery methods include bulk phishing and interactive, trust-building Gmail chats. Victims are tricked into executing a malicious file containing "TONResolver" malware....
    Suspicious Bitsadmin File Download via Untrusted Domain....
    Researchers actively track and analyze threat actors and their campaigns, with a focus on attribution, infrastructure analysis, and adversary tradecraft. During our latest investigation, we identified a campaign exhibiting operational and technical characteristics consistent with a China-nexus threat cluster....
    Backdoor.Mistic is a stealthy backdoor observed in cybercrime intrusions since April 2026 and is suspected to be linked to the Woodgnat (KongTuke) initial access broker. Using DLL sideloading, fileless in-memory execution, and self-deletion capabilities, it establishes long-term covert access while evading detection....
    Throughout 2025, Chinese-speaking threat group CL-STA-1062 targeted Southeast Asian government entities and critical energy infrastructure. The attackers have been active since at least March 2022, demonstrating a long-term regional focus. High-confidence assessments link this group to UAT-7237, which attacked Taiwanese web hosting infrastructure in mid-2025....
    Russia-aligned APT group Gamaredon maintained an aggressive cyberespionage campaign throughout 2025, targeting Ukrainian government and military organizations with large-scale spearphishing attacks and new PowerShell-based malware....
    Software supply-chain attacks have evolved from isolated package compromises into sophisticated campaigns targeting developer ecosystems through credential theft, repository compromise, and CI/CD abuse. The Shai-Hulud activity cluster and its evolution into Mini Shai-Hulud demonstrate this shift, culminating in the modular Miasma framework for multi-ecosystem propagation....
    In early 2026, the team uncovered a threat actor targeting a service provider's SD-WAN infrastructure. After securing initial access, the actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN—specifically leveraging an unfiltered file upload feature to escalate privileges from an administrative account to root level....
    Researchers discovered a previously undocumented malware loader named SharkLoader while investigating activity targeting a diplomatic organization in Indonesia....
    A threat actor associated with Payouts King ransomware is using Edgecution, a malicious Microsoft Edge extension, to gain initial access through social engineering. The malware abuses the Chrome Native Messaging protocol to bypass browser sandbox restrictions, enabling a Python-based backdoor to execute arbitrary code, access the file system, and collect system information....
    Researchers identified multiple malicious skills on OpenClaw’s ClawHub marketplace that abused the AI agent ecosystem to deliver macOS infostealers, evade security scanning, and conduct novel agentic attacks such as runtime affiliate injection and agentic front-running for financial gain....
    We detected a cryptocurrency-mining campaign exploiting CVE-2026-33017, an unauthenticated RCE vulnerability in Langflow. The attack marks a shift in delivery vectors, specifically targeting exposed AI application endpoints. The malware disables host-level security controls, deploys a custom miner, and establishes persistence....
    Social engineering–driven malware campaign that impersonates the Indian Income Tax Department to lure victims into downloading a malicious archive from a fraudulent website....
    Looking for Something?
    Threat Research Categories:
    Tags