Threat Research

    Researchers uncovered a high-volume phishing campaign that repurposed ASCII smuggling may be induced to follow threat actor-controlled instructions, an AI prompt-injection evasion technique for email filter evasion....
    We analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations across Latin America. Attackers used AI to enhance their capabilities, alongside living-off-the-land techniques, custom RATs, and tunneling tools....
    A Chinese-speaking threat operator used AI agents powered by Claude, Qwen, and DeepSeek to automate reconnaissance, exploitation, credential collection, and reporting against government, education, and industrial targets across Asia....
    Threat Intelligence observed a human-operated intrusion campaign in which attackers impersonate IT support personnel through Microsoft Teams and use social engineering and remote support tools to gain interactive access....
    During an August investigation into an Adversary-in-the-Middle (AiTM) attack, researchers discovered the control panel of a phishing kit known as Knight Office. The attack began with a DocuSign-themed email lure, followed by multiple redirects through the Monday work management platform and a compromised Joomla website....
    Operation QUICSILVER is a China-nexus cyberespionage campaign targeting Myanmar, using a Burmese-language graduation ceremony invitation impersonating Myanmar’s Information Technology and Cyber Security Department as a lure....
    The Gentlemen ransomware-as-a-service (RaaS) operation, attributed to GOLD SHERWOOD, which uses stolen VPN credentials, vulnerable firewalls, and rapid privilege escalation to compromise organizations....
    BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, designed to support Initial Access Broker (IAB) operations....
    BREEZE COMET (UNC5669) is a financially motivated threat actor targeting Brazilian banks, fintechs, retailers, exchanges, and payment providers to manipulate banking software, APIs, and payment systems such as Pix, STR, and Boleto for fraudulent transfers....
    Between January and April 2026, researchers uncovered a social engineering campaign called Spring Ring that impersonated IT help desk staff through external Microsoft Teams accounts. The campaign targeted more than 150 employees across at least 10 organizations in multiple industries using voice phishing (vishing) techniques....
    The ValleyRAT campaign disguises a backdoor as signed adware, abusing the legitimate QN Wallpaper application and DLL sideloading via a malicious libcef.dll to load AES-encrypted payloads in memory....
    The TerminalFix campaign is a sophisticated ClickFix variant that uses compromised websites and fake Cloudflare CAPTCHA lures to trick victims into executing malicious PowerShell commands through Windows Terminal....
    A recent ClickFix campaign cluster used three different infection approaches to gain initial access, combining DLL sideloading, consistent file-naming patterns, and C2 dead drops. Attackers also used aggressive phone-based social engineering, directing victims to compromised WordPress websites hosting ClickFix lures....
    Researchers identified PackClient, a modular command-and-control (C2) framework actively being sold on Telegram. The framework has been linked to at least one Chinese-speaking threat actor, TA4922. PackClient expands TA4922’s arsenal of malware used for gaining initial access to targeted systems....
    A recently identified domain, passkeyconnect[.]com, is likely linked to Com-affiliated threat actors, including Bling Libra and CL-CRI-1116, based on known infrastructure fingerprints. Analysis identified 20+ organizations across 11 industries that could be targeted in vishing campaigns based on previously observed activity....
    Looking for Something?
    Threat Research Categories:
    Tags