*Total Collection : 7537 Threat Research (auto update every day)
Last Threat Research
-
Technical Analysis of MLTBackdoor

Zscaler ThreatLabz identified MLTBackdoor in May 2026 as a new malware family likely used by a ransomware-related threat actor, delivered through a multi-stage ClickFix chain and designed for post-exploitation with expandable BOF support. It uses heavy MBA and CFF obfuscation, indirect system calls, DGA-backed C2 such as hrs2y15sungu[.]com and cwrtwright[.]com, and encrypted TLS communications to evade analysis and maintain access. #MLTBackdoor #ClickFix #BeaconObjectFiles #hrs2y15sungu[.]com #cwrtwright[.]com
-
Phishing Attacks Leverage TikTok, Instagram Reels

ReversingLabs documented two short-form video phishing campaigns on TikTok and Instagram Reels that lure users with promises of free premium software and then redirect them to attacker-controlled sites. One campaign delivers Vidarstealer through a fake Spotify Premium tutorial, while the other uses engagement bait and comment replies to push victims toward dubious download pages. #Vidarstealer #TikTok #InstagramReels #SpotifyPremium
-
Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets

Varonis Threat Labs showed that an OpenClaw AI agent named Pinchy could be tricked by believable phishing emails into forwarding AWS IAM keys, database passwords, SSH credentials, and a customer export, while also demonstrating mixed defenses against phishing links and OAuth abuse. The research found that social-engineering attacks against AI agents…
-
Legacy Meets Modern: Breaking AD Through NIS & MFA Infrastructure

The Duo Auth Proxy was shown to be forwarding live Active Directory authentication requests, and packet capture plus a recovered RADIUS shared secret allowed the authentication exchanges to be decrypted. This exposed cleartext credentials and revealed that MFA through the Duo Auth Proxy could be abused as a mechanism for password theft rather than a defense, while user group analysis highlighted a developer account with broad development-related AD memberships. #DuoAuthProxy #RADIUS #ActiveDirectory #MFA
-
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels

Socket Threat Research identified 23 new PyPI artifacts tied to the broader Mini Shai-Hulud, Miasma, and Hades supply chain attacks, bringing the tracker to 471 affected artifacts across npm and PyPI. The new wave changes delivery methods with malicious .pth hooks, trojanized .abi3.so extensions, and a langchain-core-mcp loader that searches sys.path for _index.js while the payload steals developer and CI/CD secrets after running through Bun. #MiniShaiHulud #Miasma #Hades #langchaincoremcp #embiggen #ensmallen #gpsea #pyphetools
-
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open

Two Russia-aligned campaigns are still exploiting CVE-2025-8088 in WinRAR against Ukrainian organizations long after the patch, using decoy archives to silently drop payloads and steal data. SHADOW-EARTH-066 delivers the evolved GIFTEDCROOK stealer while Earth Dahu uses an HTA-based espionage chain, underscoring how unmanaged software keeps the same entry point open. #CVE-2025-8088…
-
Don’t Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency

Proofpoint tracked UNK_DeadDrop, a likely North Korea-aligned phishing cluster that used recruiter and code-review lures to target developers across nearly 100 organizations and delivered malicious GitHub/GitLab repositories with cross-platform payloads. The campaigns abused VS Code and Cursor task automation plus malicious VSIX extensions to steal cryptocurrency wallets and credentials on macOS,…
-
PulseRAT – Google Sheets-based RAT Using UAE-India Partnership Lure
An ISO titled UAE-India_Strategic_Partnership_Week.iso was uploaded from the UAE and delivers a new .NET RAT that the author temporarily calls PulseRAT through a dropper and LNK-based execution chain. The malware persists as WindowsVaultSyncService, disguises itself as Windows system software, and uses a Google Sheets spreadsheet for command-and-control while also sharing artifacts that may link to a host named desktop-526nitv. #PulseRAT #WindowsVaultSyncService #desktop-526nitv #UAE-India_Strategic_Partnership_Week.iso
-
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave

Socket identified a coordinated PyPI supply-chain compromise with 37 malicious wheel artifacts across 19 packages, using a *-setup.pth startup hook to launch a Bun-based JavaScript stealer named _index.js. The campaign is a PyPI branch of the Shai-Hulud/Miasma lineage that steals developer and CI/CD secrets, exfiltrates to GitHub, and uses markers such as Hades – The End for the Damned. #PyPI #ShaiHulud #Miasma #Bun #Hades
-
Backup operations at scale: Turning “green” indicators into recovery readiness

Acronis Cyber Protect H2 2025 telemetry shows that backup jobs can succeed while still finishing too late, with tail latency and queued runtimes eroding real recovery readiness. Deep MSP tenant nesting also drives a sharp rise in failures, making governance, restore testing, and success-in-window measurement critical for resilience. #AcronisCyberProtect #CISA #Microsoft #AzureArchitectureCenter #AWS
-
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

Palo Alto Networks Unit 42 reported active exploitation of CVE-2026-0257 against PAN-OS GlobalProtect portal and gateway components by an unidentified threat actor attempting to establish VPN connections. The advisory urges defenders to hunt for listed IP addresses, suspicious host identifiers, and PoC-related client values, while applying mitigations or upgrading to a…
-
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Mandiant reported that UNC3753, also known as Luna Moth, Chatty Spider, and Silent Ransom Group, ran a fast-moving data theft extortion campaign against U.S. professional, legal, and financial services organizations by using vishing, screen-sharing, RMM tools, and sometimes physical office access. The group stole sensitive data such as legal agreements, PII, and financial records, then used extortion emails and the LEAKEDDATA site to pressure victims into paying. #UNC3753 #LunaMoth #ChattySpider #SilentRansomGroup #LEAKEDDATA
-
VerdantBamboo: Just Another BRICKSTORM in the Firewall

Volexity investigated a long-running compromise of an Egnyte Storage Sync appliance and the victim’s MSP, attributing the activity to VerdantBamboo (WARP PANDA, UNC5221) and the BRICKSTORM backdoor. The campaign also involved two previously undocumented malware families, AGENTPSD and PLENET, used to maintain access, pivot into Microsoft 365, and persist on Linux and BSD appliances. #VerdantBamboo #WARP_PANDA #UNC5221 #BRICKSTORM #AGENTPSD #PLENET #Egnyte #pfSense #Synology #Microsoft365
-
Dark Web Profile: Vect Ransomware

Vect emerged rapidly after its December 31, 2025 debut, publishing 25 victims, recruiting affiliates through BreachForums, and linking its operations to TeamPCP supply chain compromises and the Devman ecosystem. Its broken ChaCha20-based locker, aggressive defense evasion, and broad propagation across Windows, Linux, and VMware ESXi make it functionally similar to a wiper in many cases. #Vect #BreachForums #TeamPCP #Devman #Trivy #CheckmarxKICS #LiteLLM #Telnyx
-
Agentic threat actor hits the orchestration plane: AI agent-driven container escape

Sysdig TRT observed an agentic threat actor exploiting CVE-2026-39987 in a marimo notebook to automate container escape, host breakout, and Kubernetes secret theft without human interaction. The operation used a mounted Docker socket, nsenter, and Kubernetes service-account replay to dump host credentials and the cluster Secret store. #CVE-2026-39987 #marimo #SysdigTRT #nsenter #DockerSocket #Kubernetes
-
ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery

LevelBlue’s CTI team analyzed a new ClickFix campaign that uses typosquatted LinkedIn and Indeed pages, the Finger protocol, and legitimate Windows utilities to deliver CastleLoader and a Python-based RAT. The operation relies on fileless execution, encrypted C2 traffic, and WebSocket-based control to stage payloads, evade defenses, and maintain persistence. #ClickFix #LinkedIn #Indeed #Finger #CastleLoader #kevinnotanother.com
-
Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

FortiGuard Labs identified a phishing campaign that delivers a PureLogs variant through a fake purchase-order email carrying a malicious RAR archive and JavaScript file. The attack chain uses PowerShell, process hollowing, and a downloader to load an in-memory plugin that steals browser, Discord, crypto wallet, and application data from Windows systems. #PureLogs #FortiGuardLabs #MsBuild.exe #Discord #MicrosoftEdge #FileZilla
-
Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

FortiGuard Labs analyzed C0XMO, a modular Gafgyt botnet variant that exploits CVE-2021-27137 on vulnerable DD-WRT routers and uses a separate Python scanner to expand infections across Linux and IoT devices. The malware adds persistence, kills competing botnets, performs a custom C2 handshake, and supports many DDoS and exploitation capabilities targeting services such as Telnet, SSH, UPnP, ADB, and multiple HTTP vulnerabilities. #C0XMO #Gafgyt #CVE-2021-27137 #DDWRT
-
Inside the Latest Chaotic-Eclipse Releases: Mini-Plasma, GreenPlasma, and YellowKey

In May 2026, Chaotic Eclipse disclosed three Windows zero-days—YellowKey, GreenPlasma, and MiniPlasma—with PoCs published days after Microsoft’s Patch Tuesday to delay a fix window. YellowKey bypasses BitLocker through WinRE, while GreenPlasma and MiniPlasma achieve SYSTEM privileges by abusing Windows Cloud Files and related trust relationships. #YellowKey #GreenPlasma #MiniPlasma #ChaoticEclipse
-
FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad

Sekoia.io’s investigation details how Gamaredon, an FSB-linked intrusion set targeting Ukraine, uses a multi-stage GammaLoad chain to maintain stealthy, persistent access through loaders, droppers, and registry-cached C2 configuration. The report shows the group abusing trusted services like Telegram, Telegraph, Cloudflare, and Check-Host to retrieve payloads and ultimately deliver GammaSteel. #Gamaredon #GammaLoad #GammaSteel #Sekoiaio #Telegram #Cloudflare #CheckHost
>> Access All Threat Research
Reference for Threat Research
This Threat Research category section will FILTER and FETCH the POST (related with Analysis Report only) from the following sites:
- asec.ahnlab.com
- any.run/cybersecurity-blog/
- attackiq.com
- bitdefender.com/blog/labs/
- cadosecurity.com/blog/
- cisa.gov/news-events/cybersecurity-advisories/
- crowdstrike.com/blog/
- cybereason.com/blog/category/research/
- darktrace.com/blog/
- fortinet.com/blog/threat-research/
- harfanglab.io/en/insidethelab/
- malwarebytes.com/blog/threat-intelligence/
- mandiant.com/resources/blog/
- mcafee.com/blogs/other-blogs/mcafee-labs/
- proofpoint.com/us/blog
- securelist.com/tag/malware-descriptions/
- securityintelligence.com/category/x-force/threat-intelligence/
- blog.talosintelligence.com
- trendmicro.com/en_us/research/
- unit42.paloaltonetworks.com
- nextron-systems.com/blog/
- team-cymru.com/blog/categories/threat-research/
- zscaler.com/blogs/
- blog.sonicwall.com
- labs.k7computing.com/
- recordedfuture.com/blog
- blog.sekoia.io/category/research-threat-intelligence/
- embee-research.ghost.io
- netspi.com/blog/technical/
- huntress.com/blog
- other 100++ sources
For the sites below, automatic FETCH cannot be performed
(i need to monitor it manual, will be delay 3-7 days)
Bellow are other reference, but for some reason i’m not fetching it automatically
(i need to review the article manually, will be delay 3-5 days)
- cleafy.com/labs (update 1-2 months)
- guidepointsecurity.com/blog/ > category: threat advisory
- research.openanalysis.net
- blog.phylum.io/tag/research/
- shadowstackre.com/analysis/
- mssplab.github.io
- farghlymal.github.io
- asec.ahnlab.com/ko/
- blog.bushidotoken.net
- kroll.com/en/insights/publications/cyber
- Sentinelone.com
- blog.lumen.com
Update
- December, 2024: securonixblog – Fixed (xpath error)
- December, 2024: huntress – Fixed (xpath error)
- December, 2024: nccgroup – Failed (Incapsula)
- December, 2024: Mandiant – Removed (now part of Google Cloud)
- December, 2024: antiy.cn – Failed (curl or xpath error)
- December, 2024: sonicwall.com – Failed (curl error)
- January, 2025: team-cymru.com (RSS Feed Removed)
Update January, 2025
“Due to copyright reasons, starting January 2025, this site will no longer display the full content of sourced articles. Only Summaries, Key Points, MITRE Tactics for Threat Research, and selected IoCs will be provided. To read the full article, please click on the ‘source’ link to view it on the original website.”