Threat Research

    Head Mare, now assessed as an APT group, exploited two vulnerabilities in unpatched TrueConf video conferencing servers to achieve SYSTEM-level code execution and deploy a web shell. The attackers used the compromised server to collect infrastructure data, access the TrueConf database, and replace legitimate TrueConf Client installers with trojanized versions....
    A new Kimwolf v7 Android/IoT botnet variant has been identified with enhanced DDoS capabilities and stronger C2 resilience. The botnet mainly targets Android TV boxes and set-top boxes, adding an HTTP/2-based flood that mimics complete browser fingerprints....
    Lazarus Group / DPRK-linked Operation Dream Job campaign targeting the defense, aerospace, and aviation sectors through spear-phishing, job-offer lures, impersonation websites, SEO poisoning, and trojanized PDF viewers....
    Aeternum is a newly discovered C++ botnet loader that uses the Polygon blockchain as its command-and-control (C2) infrastructure. Instead of traditional servers or domains, attackers store encrypted and plaintext commands directly within blockchain smart contracts....
    Abyssos is a newly identified C++-based modular Remote Access Trojan (RAT) that supports credential theft, file exfiltration, and VNC-based remote access. The malware uses LLVM-based code obfuscation, anti-analysis techniques, and a custom TCP protocol for C2 communication....
    Gunra is a ransomware-as-a-service (RaaS) operation used by affiliates to target government, critical infrastructure, and other organizations through data encryption, data exfiltration, and double-extortion tactics. CVE-2024-55591 and CVE-2025-24472 allow threat actors to exploit scheduled tasks on vulnerable FortiOS firewall devices....
    The macOS malware infection originated from a ClickFix social engineering scam.The attack delivered a shell script that collected basic system and device information. It then downloaded a macOS malware payload tailored to the computer’s CPU architecture. The malware can steal stored passwords and other sensitive information from the victim....
    FakeAgent is a malvertising campaign that targeted at least 29 organizations by using a malicious Claude Artifact hosted on the legitimate Claude.ai domain to distribute a fake Claude Desktop application. The disguised executable ultimately delivered SectopRAT, which can steal passwords, credit card data, personal information, and files....
    The Head Mare hacktivist group exploited two TrueConf Server vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to gain SYSTEM-level access and deploy a web shell. Attackers then replaced legitimate TrueConf Client installers with trojanized versions containing the PhantomCore and PhantomGraph backdoors, turning the compromise into a supply-chain attack....
    Researchers investigated the exploitation of the zero-day vulnerability CVE-2026-18577 in N-able N-central, where attackers gained initial access and deployed legitimate Remote Monitoring and Management (RMM) tools to establish persistent remote access....
    Analysis revealed 10 NPM packages published from July 18–22, 2026, that download an obfuscated crypto-stealing malware and RAT from a remote server, with the payload concealed inside a JSON object to mask its malicious nature....
    UNC6671 continues its data theft extortion operations under multiple brands, including Redact, Pink, Helix, and Falcon, despite the reported retirement of the BlackFile brand. The group uses IT helpdesk voice phishing (vishing), Adversary-in-the-Middle (AiTM) credential harvesting, and MFA token interception to compromise Microsoft 365 and Okta accounts....
    SMOKE#SCREEN is a multi-wave campaign that uses trusted software lures—including Zoom updates, Adobe updates, business documents, and system maintenance tools—to silently install the legitimate ScreenConnect RMM agent for persistent remote access....
    A newly observed ClickFix variant abuses the legitimate Windows binary pcalua.exe to evade parent-process detection and launch malicious activity. Victims are tricked into executing a crafted command that initiates PowerShell, spawns cmd.exe via WMI, and mounts a remote WebDAV share....
    ChainDrop is a large-scale npm supply chain compromise that leveraged compromised maintainer accounts to infect over 1,300 npm packages with a self-propagating worm, enabling rapid spread across developer environments and CI/CD pipelines....
    Looking for Something?
    Threat Research Categories:
    Tags