Login
Sign Up
Toggle navigation
Knowledge on Demand
Threat Research
More
Blogs and News
Events
Threat Research
FortiBleed 2026 Credential Abuse Threat Hunt
FortiBleed refers to the exposure and abuse of leaked credentials associated with approximately 74,000 internet-facing Fortinet devices, including FortiGate firewalls and SSL VPN gateways....
6/19/2026
0
Read More »
AI-Generated Fake Instruction Video Lure Phishing Campaign
Threat actors are leveraging AI-generated deepfake audio videos hosted on legitimate SaaS and content delivery platforms to conduct phishing campaigns targeting social media users....
6/19/2026
0
Read More »
From Package to Postinstall Payload: Inside the Mastra npm Supply Chain Compromise
Analysis of the Mastra npm supply chain compromise revealed that attackers abused a trusted package ecosystem by introducing a malicious postinstall payload through a typosquatted dependency named easy-day-js....
6/19/2026
0
Read More »
Killing Me Gently: Inside Gentlemen’s EDR Killer Framework
Researchers analyzed the robust EDR-killing toolset of the prominent ransomware gang Gentlemen. Since early 2026, the group has become one of the most active threats in the ecosystem. They stand out by maintaining sophisticated tools designed to disrupt security software. Unlike peers, Gentlemen targets Southeast Asia, South America, and Western Europe over the US....
6/19/2026
0
Read More »
ClickFix Campaign Generated via AI Delivers SmartRAT
In March 2026, ThreatLabz detected multiple malicious typosquatting domains built using AI website generators. Cybercriminals are using these tools to rapidly scale convincing lures, ranging from simple credential harvesting to ClickFix campaigns delivering Remote Access Trojans (RATs)....
6/18/2026
0
Read More »
Crypto Clipper Uses Tor and Worm-like Propagation for Persistence and Control
Researchers identified a cryptocurrency clipper malware that spreads through malicious .LNK shortcut files and propagates like a worm via removable drives. It launches a bundled Tor client and communicates with hidden .onion C2 servers through a local SOCKS5 proxy (localhost:9050) to evade detection....
6/18/2026
0
Read More »
Titan Infostealer Embedded in AI Assistant PyPI Package
A malicious PyPI package masquerading as an AI assistant, myra-ai-assistant, was found to contain TITAN, a Python-based infostealer that uses OCR-driven screen monitoring to capture sensitive information such as login pages, emails, IDE sessions, and financial transactions....
6/18/2026
0
Read More »
Unveiling ErrTraffic: Inside a Growing ClickFix Malware Distribution Framework
ErrTraffic is a Malware-as-a-Service (MaaS) framework used to distribute malware through ClickFix social engineering lures embedded in compromised WordPress websites. The framework incorporates a Traffic Distribution System (TDS) and uses EtherHiding to conceal its command-and-control infrastructure within the blockchain....
6/17/2026
0
Read More »
FishMonger’s Arsenal Upgraded: SprySOCKS for Windows
Researchers found two new Windows variants of the SprySOCKS backdoor, previously known only on Linux. Linked to the Chinese group FishMonger (I-SOON), it active targeted government entities between 2023 and 2024. Telemetry confirmed victims across Honduras, Taiwan, Thailand, and Pakistan....
6/17/2026
0
Read More »
Dozens of Malicious Wallpapers Found on Steam Workshop: Gamers Accounts at Risk
Researchers discovered dozens of malicious wallpapers on Steam Workshop that abused Wallpaper Engine's Application Wallpaper feature to execute malware on users' PCs. The campaign distributed threats such as DarkKomet backdoors, Lumma and Vidar infostealers, crypto miners, and other credential-stealing malware....
6/17/2026
0
Read More »
China-Nexus Actor Targets US Defense, AI, and Medical Research
A PRC-nexus threat actor, UNC6508, targeted North American academic, medical, and military research institutions. The sophisticated campaign remained entirely undetected within target networks for over a year. Attackers initially breached networks by compromising externally facing web applications....
6/16/2026
0
Read More »
OceanLotus: From External Espionage to Domestic Targeting
OceanLotus (APT32) has shifted its focus from broader regional operations to a more targeted government within Vietnam. Between 2024 and 2026, the group used its SPECTRALVIPER backdoor in a supply-chain attack targeting stock investors and a long-term intrusion against a Vietnamese infrastructure and transport company....
6/16/2026
0
Read More »
Attackers Exploiting AI Brand Hype
A threat actor is leveraging AI brand impersonation by registering lookalike .ru domains that mimic DeepSeek, MiniMax, and ChatGPT, complete with cloned branding, AI chat interfaces, and the DeepSeek whale mascot to target Russian-speaking users....
6/16/2026
0
Read More »
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
ShinyHunters exploited the critical zero-day vulnerability CVE-2026-35273 in Oracle PeopleSoft's Environment Management component to compromise organizations, with a strong focus on the higher education sector....
6/15/2026
0
Read More »
Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion
Since November 2025, the Shai-Hulud V2 campaign has evolved significantly beyond typical software supply chain attacks. Over the last six months, the threat expanded from npm into PyPI and shifted focus from compromised maintainers to CI/CD abuse. The attackers undermined trust in SLSA provenance and OIDC-based publishing workflows without breaking cryptographic guarantees....
6/15/2026
0
Read More »
Looking for Something?
Threat Research Categories:
Threat Research
1041
Tags
Subscription
Please enter a valid email address.
Info