Skip to main content

Author

Tanium Cyber Threat Intelligence Team

Desktop featured image: CTI blog 1

SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

Desktop featured image: CTI blog 2

Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

Desktop featured image: CTI blog 4 - wide

Hybrid 2FA phishing threatens enterprises, RomCom uses SocGholish to deploy Mythic Agent malware, and MuddyWater targets critical infrastructure with evolving tactics

Desktop featured image: CTI blog 3 - wide

Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

Desktop featured image: CTI blog 1 - wide

Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

Desktop featured image: CTI blog 2 - wide

Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

Desktop featured image: CTI blog 4 - wide

Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities

Desktop featured image: CTI blog 3 - wide

Astaroth trojan uses GitHub to host malware configurations, TA585 delivers MonsterV2 malware in phishing campaigns, and threat actors exploit Microsoft’s logo in tech support scams

Desktop featured image: CTI blog 1 - wide

XWorm malware reemerges with ransomware, Microsoft disrupts multiple threats targeting Teams, and Storm-1175 exploits a critical GoAnywhere MFT vulnerability

Desktop featured image: CTI blog 2 - wide

Check out the latest insights on DarkCloud malware, the “Trinity of Chaos” alliance, and WARMCOOKIE updates.

Desktop featured image: CTI blog 4 - wide

SystemBC botnet targets VPS infrastructure, ShinyHunters targets enterprise cloud applications, and a phishing campaign uses AI-generated code to avoid detection

Desktop featured image: CTI blog 3

AMOS Stealer campaign targets macOS, TAG-150 deploys new CastleRAT malware, and GPUGate targets IT firms in Western Europe

Desktop featured image: CTI blog 1 - wide

The latest on HexStrike AI, TinkyWinkey’s keylogging, and Silver Fox APT’s driver abuse bypassing endpoint defenses.

Desktop featured image: CTI blog 2 - wide

New Linux malware evades antivirus detection, UNC5518 deploys CORNFLAKE.V3 using ClickFix and fake CAPTCHA pages, and a PRC-Nexus campaign hijacks web traffic.

Desktop featured image: CTI blog 4 - wide

Researchers uncover malicious Python packages, PipeMagic masquerades as a ChatGPT desktop app, and Noodlophile Stealer targets enterprises through social media

Desktop featured image: CTI blog 3 - wide

Ransomware groups adopt shared EDR-killing tool, PS1Bot spreads via malvertising, and Charon ransomware uses APT-style tactics to target critical sectors

Desktop featured image: CTI blog 1 - wide

Discover how attackers hijack CAPTCHAs, why CVE activity spikes matter, and global PXA threats.

Desktop featured image: CTI blog 2 - wide

Katz Stealer seeks credentials and crypto assets, Lumma Stealer returns after a disruption, NailaoLocker ransomware targets Windows

Desktop featured image: CTI blog 4 - wide

BlackSuit ransomware combines data exfiltration and encryption, AsyncRAT spawns multiple forks, and HazyBeacon abuses AWS Lambda for command and control

Desktop featured image: CTI blog 3 - wide

Get the latest on BERT ransomware, TGR-CRI-0045 exploits, and XWorm’s stealthy evolution in this week’s CTI roundup.

Desktop featured image: CTI blog 1 - wide

Get the latest on GIFTEDCROOK’s evolution, Jasper Sleet’s infiltration tactics, and rising cyber threats in ESET’s H1 2025 report.

Desktop featured image: CTI blog 2 - wide

Cyber attackers exploit legitimate tools, ClickFix attacks accelerate, and BlueNoroff targets macOS devices

CTI Roundup: UNC6032, APT41, Void Blizzard

The latest on UNC6032 fake AI websites, APT41’s use of Google Calendar, and Void Blizzard targeting critical sectors.

CTI Roundup: Hazy Hawk, Remcos RAT, and npm Phishing

Recent news on Hazy Hawk using DNS records, a fileless Remcos RAT campaign, and the use of AES encryption with malicious npm packages in phishing attack.

CTI Roundup: Marbled Dust, Horabot, and TA406

Learn about Marbled Dust exploiting a zero-day vulnerability in Output Messenger, a new phishing campaign using Horabot malware, and TA406 changing targets.

CTI Roundup: Luna Moth, Venom Spider, StealC V2

Updates on Luna Moth threatening U.S. legal and financial firms, Venom Spider targeting hiring managers and recruiters, and StealC malware getting upgrades.

CTI Roundup: Infostealers, Zero-Day Attacks, and Gremlin Stealer

The latest news on infostealers, Google observing 75 zero-day exploits in 2024, and new threat Gremlin Stealer.

CTI Roundup: Deepfakes, ToyMaker IAB, and ClickFix

Recent news about threat actors using real-time deepfakes to land remote work, ToyMaker initial access broker, and state-sponsored hackers using ClickFix.

CTI Roundup: SMS Phishing, Node.js, and Fake PDF Converters

The latest news about threat actors exploiting SMS with social engineering, misusing Node.js for malware, and fake PDF converters delivering malware.

CTI Roundup: Email Attacks, Hunters International, and New Ransomware Data

Read the latest news about attacks combining credential phishing and malware, Hunters International pivoting to data extortion, and ransomware trends.

CTI Roundup: QR Code Phishing, Babuk Locker 2.0, and Qilin

QR code phishing accelerates, LockBit 3.0 rebrands, and Qilin affiliates target downstream customers of an MSP.

CTI Roundup: StilachiRAT, Reddit Infostealers, and New Password Reuse Data

The latest information about StilachiRAT malware, AMOS and Lumma stealers spreading via Reddit, and research on how many logins use compromised passwords.

CTI Roundup: Malvertising, XCSSET Variant, and GitHub Abuse

The latest news about a malvertising campaign threatening devices, XCSSET variant, and an ongoing campaign using fake GitHub repositories to spread malware.

CTI Roundup: Silk Typhoon, Fake Ransom Notes, and ClickFix

The latest cyber threat news on Silk Typhoon shifting tactics, threat actors targeting executives with physical ransom notes, and the ClickFix trick.

CTI Roundup: Auto-Color Malware, Vulnerable Windows Driver, and Lotus Blossom

Latest news about Auto-color Linux malware, attackers exploiting Truesight.sys, and Lotus Blossom.

CTI Roundup: Ferret Malware, macOS Stealers, and MS Power BI

Learn about North Korean hackers targeting job seekers, growing macOS infostealers, and MS Power BI phishing.

CTI Roundup: New TorNet Backdoor, Lynx Ransomware, and Q4 Trends

The latest on an ongoing TorNet backdoor campaign, Lynx ransomware group's advanced affiliate program, and Cisco Talos' Q4 incident response trends report.

CTI Roundup: 2024 Ransomware Recap, Breached Passwords, and O365 Exploits

Learn what researchers have to say about ransomware trends from 2024, as well as new insights on stolen passwords and two recent O365 attacks.

CTI Roundup: FunkSec, Malvertising, and Fake Software

News about FunkSec ransomware, a recent malvertising scam targeting Google Ads users, and threat actors using fake software and installers to push malware.

CTI Roundup: PayPal Phishing, PLAYFULGHOST, and NonEuclid

The latest on a PayPal impersonation phishing campaign, PLAYFULGHOST malware, and the new NonEuclid RAT.

CTI Roundup: Earth Koshchei, RiseLoader, and a New Ransomware Advisory

Earth Koshchei executes rogue RDP attacks, Zscaler releases technical details about RiseLoader malware, and Corvus issues a ransomware advisory.

CTI Roundup: Seasonal Phishing, Zloader, and Secret Blizzard

The latest news around threat actors impersonating HR in a seasonal phishing campaign, Zloader's new features and capabilities, and Secret Blizzard.

CTI Roundup: Rockstar 2FA, RevC2 and Venom Loader, and SmokeLoader Malware

Rockstar 2FA targets M365 users, new RevC2and Venom Loader malware, and SmokeLoader reappears.

CTI Roundup: Sophos vs. Chinese Threat Actors, CRON#TRAP Linux VM, Bing Phishing Campaign

Learn about ongoing battles between Sophos and multiple Chinese threat actors, CRON#TRAP infecting Windows with Linux VMs, and Bing being used for phishing.

CTI Roundup: Scattered Spider and RansomHub Partner, Infostealer Malware Bypasses Chrome Patches, Evasive Panda Back in the News

Latest news on Scattered Spider and RansomHub, infostealers evading Chrome defenses, and Evasive Panda.

CTI Roundup: Gophish Toolkit Phishing, Malicious Virtual Hard Drive Files, Return of Bumblebee Malware

Learn about the Gophish toolkit for phishing, attackers bypassing secure email gateways and antivirus scanners, and the return of Bumblebee malware.

CTI Roundup: Callback Phishing, Time-to-Exploit Trends, and PureLogs Infostealer

Learn about threat actors spreading malware via callback phishing, Mandiant's analysis of time-to-exploit trends, and PureLogs targeting Chrome browsers.

CTI Roundup: Rise in File Hosting Services Misuse, Mamba 2FA, and Dark Angels Ransomware Attacks

News around Microsoft attacks using file hosting services, phishing campaigns mimicking Microsoft 365 login pages, and Dark Angels ransomware group updates.

CTI Roundup: Sniper Dz, Elastic 2024 Global Threat Report Insights, and Andariel Financial Attacks

Latest news around Sniper Dz, insights from Elastic Security Labs 2024 Global Threat Report, and Andariel financial attacks against U.S. organizations.

CTI Roundup: North Korean-Sponsored Remote IT Workers, Legitimate Sites Sending Spam, and Political Deepfakes

North Korea exploiting remote roles, third-party infrastructure used to send spam, and insights from new deepfakes report.

CTI Roundup: HTTP Headers Phishing Technique, Scattered Spider Back in the News, and UNC2970 Targets Job Seekers

Learn about a phishing campaign using HTTP headers, Scattered Spider, and UNC2970 exploiting job seekers.

CTI Roundup: Emansrepo Infostealer and Earth Lusca Multiplatform Backdoor

Emansrepo Stealer spreads via email, Palo Alto sheds light on top-level domains, and Earth Lusca deploys a new multiplatform backdoor.

CTI Roundup: Xeon Sender Targets Cloud APIs and MoonPeak Malware Updates

Xeon Sender targets cloud APIs, Cisco Talos reveals UAT-5394 infrastructure, and attackers leverage public .env files to extort victims.

CTI Roundup: Mad Liberator Ransomware Targets AnyDesk Users

New tools appear in ongoing social engineering campaign, Mad Liberator ransomware targets AnyDesk users, and Bitdefender explores the evolving cybercriminal underground.

CTI Roundup: SharpRhino RAT Threatens IT Admins, Phishers Leverage Google Drawings and WhatsApp Links

SharpRhino RAT threatens IT admins, ransomware gangs ramp up pressure on targets, and a new phishing scam leverages Google Drawings and WhatsApp links.

CTI Roundup: Cisco Talos Q2 IR Trends Report, New GenAI Scams on the Horizon

Cisco Talos releases its Q2 IR trends report, ransomware groups target ESXi flaw, and scammers exploit GenAI in domain registration and network attacks.

CTI Roundup: Evasive Panda Deploys New Malware, Macma Backdoor and Nightdoor

Evasive Panda deploys new versions of Macma backdoor and Nightdoor, cybercriminals work independently after RaaS takedowns, and a new Linux Play variant targets VMware ESXi systems.

CTI Roundup: MuddyWater Deploys BugSleep Malware, New Attack From Void Banshee

MuddyWater deploys BugSleep malware, researchers discover malicious files on the npm registry, and Void Banshee exploits a Microsoft MHTML flaw.

CTI Roundup: Threat Actor Updates. APT40, CloudSorcerer, Eldorado

APT40 rapidly exploits network vulnerabilities, CloudSorcerer APT targets Russian organizations, and Eldorado threatens Windows and Linux systems.

CTI Roundup: FakeBat Loader-as-a-Service, ESET H1 2024 Threat Report

FakeBat loader spreads via multiple infection chains, and ESET releases its threat report from the first half of 2024.

CTI Roundup: Busy Days for Threat Actors ONNX Store, Boolka, & SneakyChef

ONNX Store targets the financial industry, Boolka delivers the BMANAGER trojan via SQLi attacks, and SneakyChef deploys SpiceRAT and SugarGh0st.

CTI Roundup: Vortax Spreads Infostealer Malware, Linux Malware Uses Emojis to Execute Commands

Vortax spreads infostealer malware, new malware campaign distributes fake error messages, and Linux malware uses emojis to execute commands.

CTI Roundup: Windows HTML Malware, Remcos RAT, & Black Basta Ransomware

CTI reports a malware campaign utilizing Windows search in HTML, Remcos RAT via UUE files, and a Black Basta ransomware exploit of a Windows vulnerability.

CTI Roundup: TargetCompany Ransomware, LilacSquid Cyber Espionage, & DarkGate Malware

TargetCompany’s Linux variant threatens ESXi environments, LilacSquid targets multiple sectors, and DarkGate malware switches from Autolt to AutoHotkey.

CTI Roundup: Social Engineering, DNS Tunneling, & Malvertising

Beware of an ongoing campaign targeting enterprises and other current cyber threat news to know.

CTI Roundup: Q1 Exploit Trends, HijackLoader, & the State of Pentesting

Kaspersky reveals the top exploit and vulnerability trends for the first quarter of 2024, HijackLoader evolves with new evasion techniques, and Cobalt releases its 2024 State of Pentesting report.

CTI Roundup: Cuttlefish Malware, Hackers Leverage Docker Hub

Cuttlefish malware targets SOHO routers, nation states and cybercriminals share compromised networks, and threat actors use Docker Hub to spread malware and phishing scams.

CTI Roundup: ToddyCat APT, GuptiMiner Malware, APT28 Exploits a Windows Print Spooler Flaw

ToddyCat deploys advanced tools for industrial scale data theft, hackers use eScan updates to spread GuptiMiner malware, and Russia’s APT28 exploits a Windows Print Spooler flaw.

CTI Roundup: A Malicious Notepad++ Plugin, “Junk Gun” Ransomware, and a Google Malvertising Campaign

Researchers discover modified Notepad++ plug-in, new junk gun ransomware appears on cybercrime forums, and a malvertising campaign targets IT teams.

CTI Roundup: LockBit Update, Earth Freybug Deploys UNAPIMON Malware

Law enforcement’s impact on LockBit, how unpatched vulnerabilities contribute to ransomware attacks, and Earth Freybug deploys UNAPIMON malware.

CTI Roundup: Tycoon Phishing-as-a-Service and TheMoon Malware Update

Researchers discover a new version of the Tycoon 2FA AiTM kit, a phishing attack disguises keylogger as bank payment notice, and TheMoon malware targets ASUS routers.

CTI Roundup: Fake Google Sites Pages, Hackers Target Global Governments

Hackers spread malware through fake Google Sites pages, cybercriminals exploit APIs, and an APT campaign targets global government entities.

CTI Roundup: 12 Million Secrets and Keys Leak on GitHub

BianLian threat actors exploit JetBrains TeamCity flaws, ransomware attacks continue to accelerate, and more than 12 million secrets and keys leak on GitHub.

CTI Roundup: Linux Servers Target of New Malware Campaign

New Linux malware campaign targets misconfigured servers, ransomware actors diversify their exfiltration tools, and Cado reveals its top cloud threat findings report for 2H23.

CTI Roundup: CVEs on the Rise, TimbreStealer Malware, and a New Phishing Report

Researchers predict a 25% rise in CVEs, TimbreStealer malware spreads through phishing, and Proofpoint releases its 2024 State of the Phish report.

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS

Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise

Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram

DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware

Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware

Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack

AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.

CTI Roundup: Remcos RAT Phishing Attacks, New Meduza Stealer Found on Dark Web

CISA adds two bugs to the KEV catalog, UAC-0050 distributes Remcos RAT with phishing tactics, and an updated version of Meduza Stealer launches on the dark web.

CTI Roundup – top 2023 stories: The latest on Chae$ 4, 3AM ransomware, DarkGate, and Andariel

Tanium’s Cyber Threat Intelligence (CTI) team looks at some of the top cybersecurity developments from 2023 that will continue to pose threats in 2024.

CTI Roundup: TA4557, OAuth Cryptomining, and the China-based KEYPLUG backdoor

TA4557 targets recruiters via email, threat actors use OAuth apps to automate BEC and cryptomining attacks, and researchers discover Sandman APT’s connection to the China-based KEYPLUG backdoor.

CTI Roundup: Russian threat actor APT28 exploits Outlook vulnerability

APT28 exploits a critical Outlook vulnerability, QR phishing campaigns grow more complex, and an SQL brute force attack results in BlueSky ransomware.

Tanium–Blog-2.3.22-Naveen Goela’s Mission to Mature Security with Science

North Korean hackers pose as job seekers and recruiters, the Telekopye Telegram bot enables large-scale phishing scams, and DPRK-aligned threat actors target macOS in two campaigns.

CTI Roundup: AlphaLock, a New Russian Hacking Group is Discovered

Researchers discover a new Russian hacking group, Rhysida ransomware threatens multiple sectors, and a new campaign targets public Docker Engine APIs.

CTI Roundup: ChatGPT-Powered Infostealer Targets Cloud Platforms

Google Cloud releases its Q3 Threat Horizons report, BlueNoroff hacks macOS machines with ObjCshellz malware, and a ChatGPT-powered infostealer targets cloud platforms.

CTI Roundup: Hackers Target Crypto Experts with KANDYKORN Malware

Lazarus Group targets a software vendor, a link shortening service abuses the .US top-level domain, and hackers target crypto experts with KANDYKORN malware.

CTI Roundup: Ransomware Spikes in September, Updates on Octo Tempest & Quasar RAT

Octo Tempest threatens global organizations, ransomware activity spikes in September, and Quasar RAT evades detection with DLL sideloading.

CTI Roundup: North Korean Lazarus Group Exploits JetBrains TeamCity Flaw

BlackCat operators introduce Munchkin utility, North Korean threat actors exploit JetBrains TeamCity flaw, and threat actors target macOS with evolving techniques.

Image for MITRE ATT&CK blog post

Threat actors attempt moving laterally from SQL server to the cloud, ShellBot avoids detection in attacks on Linux SSH servers, and Smart Links attacks target Microsoft accounts.

CTI Roundup: The FBI takes down Qakbot and Bumblebee returns from hiatus

A look at the FBI’s recent Qakbot takedown, the return of Bumblebee after a two-month hiatus, and other developing cyberthreats from 2023.

stock image: face in dark room lit by glow of a computer monitor

Threat actors repurpose old code in fake vulnerability PoC, the FBI and CISA issue a joint advisory for Snatch RaaS, and threat actors deploy new SprySOCKS Linux malware in cyberespionage attacks.

CTI Roundup: Go Infostealers, 3AM Ransomware, & RedLine/Vidar Malware

New family of Go infostealers spreads in targeted attacks, researchers discover 3AM ransomware in the wild, and RedLine/Vidar threat actors pivot to ransomware.

CTI Roundup: Hackers Target Microsoft Teams with DarkGate Loader Malware

Hackers target Microsoft Teams with DarkGate Loader malware, phishing campaign leverages the new Agent Tesla variant, and Chaes malware uses the Chrome DevTools protocol to steal data.

CTI Roundup: Stop Making These Four Common Password Mistakes Now

Threat actors use misleading dates in phishing subject lines, four common password mistakes to avoid, and Earth Estries targets global governments and tech companies.

Tanium–Blog-2.3.22-Naveen Goela’s Mission to Mature Security with Science

XLoader macOS variant poses as a productivity app, Lazarus Group uses new malware, and threat actors abuse Facebook promotions to spread malicious code.

CTI Roundup: Monti ransomware targets VMware ESXi servers with new Linux locker

Raccoon Stealer malware reappears, AI adoption remains low among threat actors, and Monti ransomware targets VMware ESXi servers with new Linux locker

CTI Roundup: Rhysida Ransomware Threatens the Healthcare Sector

Cloud takeover campaign targets top-level executives, Rhysida ransomware threatens the healthcare sector, and LOLKEK ransomware continues to evolve.

CTI Roundup: Google AMP & Salesforce Exploited for Phishing Attacks

Threat actors abuse Google AMP for evasive phishing attacks, hackers exploit Salesforce’s email services in targeted Facebook phishing campaign, and Russian actor BlueCharlie alters infrastructure in response to disclosures.

CTI Roundup: Realst Malware targets MacOS, Infostealer Malware Sees Exponential Growth

Realst malware targets macOS Sonoma ahead of public release, infostealer malware sees exponential growth, and new Nitrogen malware spreads via Google Ads for ransomware attacks.

Image for MITRE ATT&CK blog post

Ransomware impersonates Sophos, FIN8 group uses modified backdoor to deliver BlackCat ransomware, and Chinese espionage actors continue to evolve.

CTI Roundup: Attacks Spike in 2023, Ransomware Payments Skyrocket

USB-based malware attacks spike during the first half of 2023, ransomware payments skyrocket, and Big Head ransomware accelerates.

CTI Roundup: Truebot infects US & Canada networks

Truebot infects networks throughout the US and Canada, Charming Kitten targets new operating systems, and SmugX targets European government entities.

CTI Roundup: North Korean Andariel Group Strikes With EarlyRat Malware

8Base ransomware activity spikes, China-linked Volt Typhoon APT uses novel tradecraft to gain initial access to target networks, and North Korean hacker group Andariel strikes with new EarlyRat malware.

CTI Roundup: New DoJ Cyber Unit Pursues State-Sponsored Threats

The DoJ launches a cyber unit to prosecute nation-state threat actors, cybercriminals use expired AWS S3 buckets to distribute malicious code, and a new exfiltration malware targets RDP workloads.

CTI Roundup: Skuld Malware Steals Discord Data From Windows PCs

Chinese hackers use DNS-over-HTTPS for Linux malware communication, a new Golang-based Skuld malware strand steals Discord and browser data from Windows PCs, and a massive phishing campaign uses 6,000 sites to impersonate brands.

CTI Roundup: North Korea’s Kimsuky Cyber Spies at it Again

Washington and Seoul expose North Korea’s Kimsuky cyber spies, the Asylum Ambuscade crimeware group conducts cyberespionage, and the Cyclops ransomware and stealer combo poses a dual threat.

CTI Roundup: Microsoft Finds a macOS Bug That Lets Hackers Bypass SIP Root Restrictions

Improved BlackCat ransomware variant strikes with lightning speed in stealthier attacks, Microsoft finds a macOS bug that lets hackers bypass SIP root restrictions, and Dark Pink hackers continue to target government and military organizations.

CTI Roundup: Russia, Iran, & North Korea Target Global SMBs

State-aligned threat actors target global SMBs, new PowerExchange malware backdoors Microsoft Exchange servers, and an IT security employee attempts to impersonate a ransomware gang during an attack on his own company.

CTI Roundup: Hackers target macOS systems with Cobalt Strike

Hackers use Golang variant of Cobalt Strike to target macOS systems, Cybercriminals adapt to Microsoft’s macro-blocking feature, and cybercriminals target the Microsoft VSCode Marketplace.

Image for MITRE ATT&CK blog post

CISA issues a joint advisory on Russia’s Snake malware operation, hackers use ChatGPT lures to spread malware on Facebook, and a new phishing-as-a-service tool appears in the wild.

CTI Roundup: Google Ads pushes new BumbleBee malware

A new SLP bug potentially enables massive DDoS amplification attacks, Google Ads pushes new BumbleBee malware, and Chinese hackers use Linux malware variants for espionage .

CTI Roundup: CCP-Sponsored APT41 Deploys Google GC2 for Attacks

APT41 leverages Google GC2, ransomware gangs abuse Process Explorer driver to kill security software, and new details regarding 3CX’s software supply chain compromise emerge.

CTI Roundup: Microsoft Warns About Mercury and DEV-1084 Attacks on Hybrid Environments

Microsoft’s security advisory on Mercury and DEV-1084 and a report linking Russian hackers to attacks against NATO and the EU.

CTI Roundup: Threat Actors Use Self-Extracting (SFX) Archives for Backdoor Attacks

A new SFX exploit enables stealthy backdoor attacks, an ALPHV ransomware affiliate is targeting Veritas Backup Exec, and CTI tracks the emergence of Rorschach ransomware.

CTI Roundup: How Weak is Your Password?

Key findings from the Specops 2023 Weak Password Report, a look at the recently exposed APT43 hacking group, and a breakdown of the New AlienFox toolkit.

CTI Roundup: New CISA tool detects hacking activity in Microsoft cloud services

A joint advisory on LockBit 3.0 ransomware, CISA’s latest tool which detects hacking activity in Microsoft cloud services, and ScarCruft’s evolving arsenal.

CTI Roundup: US Federal Agency Hacked Using Telerik

Hackers used the Telerik bug to breach a US federal agency, a suspected Chinese actor used the Fortinet zero-day along with custom malware to engage in cyberespionage, and the Tick advanced persistent threat (APT) group targeted the customers of an East Asian data loss prevention (DLP) company.

CTI Roundup: FBI and CISA Issue Royal Ransomware Warning

A joint FBI and CISA advisory on Royal ransomware, Sharp Panda’s new malware variant, and an update on IceFire ransomware.

CTI Roundup: Threat Actors Exploiting ChatGPT

Hackers use fake ChatGPT apps to push Windows and Android malware, attackers flood NPM repository with over 15,000 spam packages containing phishing links, and New Stealc malware emerges with a wide set of stealing capabilities.

CTI Roundup: Business Email Compromise Groups Go Global

BEC groups target companies worldwide, RedEyes hackers use new malware to steal data, and Devs targeted by W4SP Stealer malware in malicious PyPI packages.

CTI Roundup: ESXiArgs Ransomware Attacks Target VMware

The latest on ESXiArgs ransomware attacks, new QakNote attacks pushing QBot malware via Microsoft OneNote files, and Biden’s attention to data privacy in the State of the Union.

CTI Roundup: Threat Actors Use Sliver C2 Framework

Sliver’s growing popularity as an open-source C2 framework, Emotet’s comeback and new evasion techniques, and how Chinese hackers exploited a Fortinet flaw using a 0-Day.

CTI Roundup: Ransomware Profits Drop as Attacks Remain High

Reporting revealed declining ransomware profits in 2022, a new backdoor based on the CIA’s Hive malware is discovered, and a new wave of BackdoorDiplomacy attacks are targeting Iranian government entities.

CTI Roundup: Malicious PyPI Packages Bypass Firewalls

PyPI packages use Cloudflare tunnels to bypass firewalls, new Raspberry Robin malware variant targets financial institutions in Portugal and Spain, and IcedID malware strikes again.

Rising Trend in APT Hackers Using Excel Add-ins as Intrusion Vector

APT hackers turn to malicious Excel add-ins as initial intrusion vector, PurpleUrchin bypasses CAPTCHA and steals cloud platform resources, and Russia’s Turla APT piggybacks on other hackers’ USB infections

Attackers Turn to SVG Files to Distribute QBot Malware

How hackers are using SVG files to smuggle QBot malware onto Windows systems, a new batch of ransomware families leading attacks on Windows systems, and this year’s spike in command-and-control servers.

Machine Learning. Security Friend or Foe?

Recent advancements in machine learning, the latest on Black Proxies, and the DHS Cyber Safety Board’s plan to review Lapsus$ gang’s hacking tactics.

Qakbot Malware Attacks on the Rise: Cyber Threat Intelligence Roundup

An aggressive Qakbot/Black Basta campaign that’s targeting US organizations, the US ban on Huawei, Hikvision, ZTE, and Dahua equipment, and a new report that links Chrome, Defender, and Firefox exploitation frameworks to a Spanish IT firm.

‘Tis the Season for a New Phishing Scam: Cyber Threat Intelligence Roundup

Organizations prioritize third-party risk management and gauge their own third-party security postures, Chinese hackers use Google Drive to drop malware, and a new phishing kit targets US shoppers this holiday season.

Australia Considers Ban on Ransomware Payments: Cyber Threat Intelligence Roundup

A new APT41 subgroup, Australia’s plan to ban ransomware payments, and Twitter’s mounting security woes.

Info-stealing Malware in Software Supply Chains: Cyber Threat Intelligence Roundup

Info-stealing malware in software supply chains and key findings from KELA’s latest cybercrime prevention report.

New Solutions for Addressing Software Supply Chain Attacks - Cyber Threat Intelligence Roundup

A pro-China disinformation campaign targeting US elections, Google’s new GUAC open-source project, and the ongoing debate about password expiration.

Zimbra Zero-Day Flaw: Cyber Threat Intelligence Roundup

Zimbra’s new zero-day flaw, a Ursnif malware variant focuses on ransomware and data theft, and a stealthy PowerShell backdoor disguises itself as a Windows update.

Emotet Malware Resurfaces: Cyber Threat Intelligence Roundup

The resurgence of Emotet, the evolution of IcedID, and the new Alchimist framework targeting Windows, macOS, and Linux

Business Email Compromise Attacks on the Rise: Cyber Threat Intelligence Roundup

The rising trend of business email compromise, the latest on the popular Bumblebee loader, and an overview of fake Microsoft Exchange ProxyNotShell exploits, which are now for sale on GitHub.

Hackers Use PowerPoint Files for “Mouseover” Malware: Cyber Threat Intelligence Roundup

Hackers use PowerPoint files for mouse-hover malware delivery, Russia plans “massive cyberattacks” on critical infrastructure, and researchers uncover a covert attack campaign targeting military contractors.

The Rise of Phishing-as-a-Service: Cyber Threat Intelligence Roundup

The minimal impact of offensive hacks in the Russia - Ukraine conflict, a new EvilProxy phishing toolkit and Monti ransomware emerges.

Kimsuky’s New Malware Attack Strategy: Cyber Threat Intelligence Roundup

Kimsuky’s new strategy for evading security researchers, Chinese hackers use ScanBox malware to target the Australian government, and new ransomware called Agenda that’s customized for each victim.

Nobelium's New ‘MagicWeb’ Malware: Cyber Threat Intelligence Roundup

The latest on APT29’s new post-exploitation strategy, an ongoing campaign against U.S. and NATO-affiliated organizations, and how hackers are using the Sliver toolkit as a Cobalt Strike alternative.

The State of Ransomware in 2022: Cyber Threat Intelligence Roundup

Investigating ransomware data from the first half of 2022, the latest on information-stealing malware deployed by Russia’s Shuckworm APT, and a look at UNC3890 activity observed actively targeting Israeli organizations.

BazarCall, Yanluowang, BumbleBee: Cyber Threat Intelligence Roundup

An advisory about BazarCall, the latest on the Yanluowang ransomware attack against Cisco, and more in our cyber threat intelligence roundup.

Malicious Macros, Dark Utilities, LockBit: Tanium Cyber Threat Intelligence Roundup

Ransomware gangs are exploiting macros, threat actors are leveraging the Dark Utilities platform, and more in the cyber threat intelligence roundup.

New Report Reveals Commodity Malware Surpasses Ransomware: Cyber Threat Intelligence Roundup

Top incident response trends from Q2, a new 'CosmicStrand' UEFI rootkit, and Censys discovers evidence of Russia-based ransomware network in the U.S.

Russian APT29 Hackers Use Google Drive and Dropbox to Evade Detection: Cyber Threat Intelligence Roundup

Russian APT29 hackers are using Google Drive and Dropbox to evade detection, new CloudMensis spyware is targeting Apple macOS users, and more in our cyber threat intelligence roundup.

Ransomware Gangs Make Stolen Data Searchable: Cyber Threat Intelligence Roundup

Ransomware groups are making stolen data searchable, Qakbot malware attacks are on the rise, and more in our cyber threat intelligence roundup.

FBI and MI5 Issue Warning of China Spying: Cyber Threat Intelligence Roundup

FBI and MI5 warn of massive China threat, a new red-teaming tool is being abused by threat actors, and an emerging supply-chain-style attack top our latest threat intelligence roundup

Tanium Cyber Threat Intelligence Roundup

The latest emerging threats, advancements in adversarial tactics, and trends observed across the cyber threat landscape.

What You Need to Know About Microsoft Office Zero-Day Vulnerability Follina

New Microsoft Office zero-day (CVE-2022-30190) named Follina is being exploited in attacks by cybercriminals and state-sponsored APT groups.