Threat Research

  • Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC

    Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC

    Elastic Security 9.5 introduces Alert Zero tools that help SOC teams reduce alert fatigue by automating triage, correlating related alerts, and embedding investigations into existing workflows while keeping analysts in control. The update centers on Security alert analysis, Attack Discovery, and Elastic Workflows, with support for custom models, inspectable agent reasoning, and approved detection-gap remediation. #ElasticSecurity #AttackDiscovery #ElasticWorkflows #ESQL #VirusTotal

  • The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

    The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

    XCSSET v40 is a heavily updated macOS malware family that uses memory-resident execution, polymorphism, and supply-chain infection through poisoned Xcode projects to target developers. It also adds browser hijacking, Telegram trojanizing, defense evasion, and a rotating C2 infrastructure across domains, IPs, and endpoints. #XCSSET #Xcode #GoogleChrome #Telegram #Apple…

  • Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

    Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

    Google Threat Intelligence Group (GTIG) reports a sharp rise in open source software supply chain compromise in 2025 and early 2026, including major campaigns tied to UNC6780, MIDNIGHT NEPTUNE, and UNC4899. The article also outlines detailed mitigation guidance for protecting ecosystems such as PyPI, npm, Docker Hub, GitHub Actions, and developer pipelines from package poisoning, credential theft, and workflow abuse. #UNC6780 #MIDNIGHTNEPTUNE #UNC4899 #axios #PyPI #npm #DockerHub #GitHubActions

  • Network Anomaly Detection in KATA

    Network Anomaly Detection in KATA

    The article explains how Kaspersky Anti Targeted Attack (KATA) uses Network Anomaly Detection to identify Kerberoasting and DNS tunneling by spotting deviations from normal Kerberos and DNS behavior rather than relying on signatures. It also shows how prebuilt NAD rules, variables, and SQL-based logic help reduce false positives and surface actionable alerts for attacks that blend into legitimate network traffic. #KATA #Kerberoasting #DNStunneling #Kerberos #DNS

  • A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network

    A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network

    Sekoia researchers analyzed a new ErrTraffic ClickFix campaign that targeted WordPress servers, used fake AI tool lures, and hid C&C infrastructure in blockchain-based networks. Their DNS and WHOIS investigation uncovered 71 domains, multiple malicious IPs, typosquatting clusters, and possible links to the LenAI MaaS operator and the Aeternum botnet. #ErrTraffic #ClickFix #LenAI #Aeternum

  • Phishing Scam Targeting Drivers: Il Portale dell’Automobilista Ranked Among Google’s Top Results

    Phishing Scam Targeting Drivers: Il Portale dell’Automobilista Ranked Among Google’s Top Results

    CERT-AGID identified a phishing campaign that impersonates “Il Portale dell’Automobilista” through the typosquatted domain illportaledelautomobilista[.]org, which appears prominently in Google search results. The fake site steals personal and driver-license data such as codice fiscale, numero patente, and expiration date, while CERT-AGID has requested takedown actions and alerted Google and the Ministry of Infrastructure and Transport. #CERTAGID #IlPortaledellAutomobilista #MinisterodelleInfrastruttureeDeiTrasporti #illportaledelautomobilistaorg

  • Two ways to scale your scripts

    Two ways to scale your scripts

    The article explains that operational scripts on customer endpoints should be governed like production software, whether they are cloned, hand-written, or AI-generated. It highlights two scaling models—template reuse and AI-assisted authoring—showing that Acronis built-in scripts are heavily cloned while AI-generated scripts are increasingly common in some markets, requiring different governance controls for each. #Acronis #NISTSP800-53 #CISControlsv8 #OWASP #ENISA

  • OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

    OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

    The article describes OctLurk, SilkLurk, and LurkProxy, three closely related implants used since January 2025 against government and other organizations across Central Asia and the Syrian Arab Republic, with victim-specific loaders and heavy obfuscation. The same campaign also included credential theft, keylogging, browser password theft, network scanning, remote access, and the later deployment of PlugX, while infrastructure overlap and shared artifacts suggest a Chinese-speaking threat actor. #OctLurk #SilkLurk #LurkProxy #PlugX

  • Not Every Fox is Silver: Inside an AtlasRAT loader chain

    Not Every Fox is Silver: Inside an AtlasRAT loader chain

    AtlasRAT is a modular Windows RAT delivered through a four-stage in-memory loader chain, beginning with a Delphi executable disguised as AGE Flash Player and ending in TLS-based, ChaCha20-encrypted command-and-control with plugin execution, offline keylogging, and DLL injection into WeChat processes. Analysis suggests a builder-based malware framework with multiple versions and branches,…

  • Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers

    Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers

    Attackers are spreading fake Income Tax Department penalty notices and refund lures through WhatsApp, SMS, email, and lookalike websites to trick taxpayers into opening malicious files or entering credentials. The campaigns deliver malware such as ITD_Tax_Notice.exe and use disposable domains, fake Office Memorandums, and cloud-hosted second-stage payloads to steal data and enable remote access. #IncomeTaxDepartment #ITD_Tax_Notice.exe #ipwho.is #AlibabaCloud

  • Toy Ghouls’ new toy: the GenieLocker ransomware

    Toy Ghouls’ new toy: the GenieLocker ransomware

    GenieLocker is a custom ransomware family used by Toy Ghouls against Russian organizations, especially in manufacturing, with Windows, Linux, and ESXi variants active since March 2026. The group used stolen OpenVPN credentials for entry, deployed tools like Mimikatz and PsExec, and encrypted systems without evidence of data theft or double extortion. #GenieLocker #ToyGhouls #Bearlyfy #Labubu #Laboo.boo #Mimikatz #PsExec #OpenVPN

  • Inside Astaroth’s New Spambot Component

    Inside Astaroth’s New Spambot Component

    Astaroth (aka Guildma) operators added a WhatsApp Web spambot in Q4 2025, shifting from email-based distribution to automated messaging that turns infected victims into unwilling propagators of the malware. The analysis shows strong code overlap with the Vareg (aka WATER SACI, Eternidade) spambot and confirms Brazil-focused targeting through contact filtering, Portuguese…

  • [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)

    [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)

    AhnLab reports that a state-sponsored group abused vulnerabilities in Korean financial security software from 2025 through the first half of 2026 to deliver backdoors via watering hole and spear-phishing attacks, while many compromised Korean websites were used as infection points. The analysis also finds overlap with Gunra ransomware incidents and names…

  • False Sextortion ShinyHunters: Emails Arrive in Italy for the First Time

    False Sextortion ShinyHunters: Emails Arrive in Italy for the First Time

    CERT-AGID identified a new sextortion campaign circulating internationally since April 2026 and observed for the first time in Italy, with scammers impersonating ShinyHunters. The emails claim to have compromising material and demand $2,000 in Bitcoin within 48 hours, but ShinyHunters denied any involvement. #ShinyHunters #CERTAGID

  • Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

    Not Every Fox is Silver: Inside an AtlasRAT loader chain

    Two beta npm releases in the @joyfill namespace were found to contain an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to resolve hidden payloads, with one branch leading to a 77 KB Node.js remote-access trojan. The compromised packages were @joyfill/layouts and @joyfill/components, and the recovered code overlaps with the PolinRider loader and DEV#POPPER family while also dropping related infrastructure for a Python infostealer linked to OmniStealer. #Joyfill #PolinRider #DEVPOPPER #OmniStealer

  • Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

    Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

    TA488 launched a July 2026 campaign exploiting CVE-2026-42897 in Outlook Web Access to deliver the browser-based implant OWAReaper against government, telecommunications, finance, hospitality, and aerospace targets. OWAReaper provides stealthy persistence, credential theft, command execution, and exfiltration through HTTPS or DNS, using infrastructure such as acocdn[.]com, asecdns[.]com, dnsrecursive[.]eu, and tdndns[.]com. #TA488 #OWAReaper…

  • Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN

    Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN

    ASEC found Larva-26009 targeting MS-SQL servers to deploy VShell, GotoHTTP, SoftEther, and XMRig, using remote control and proxy tools to maintain access and mine cryptocurrency. The attack also involved web shells, credential theft attempts, privilege escalation utilities, and cloud-based infrastructure to obscure command-and-control activity. #Larva26009 #VShell #GotoHTTP #SoftEther #XMRig…

  • Advanced Search & YARA Improvements

    Advanced Search & YARA Improvements

    The Advanced Search update adds network filters, letting users query CIDR blocks in IP-related fields and constrain results by ASN or CIDR with the new WITH network option. The YARA interface now emphasizes newly observed indicators and total indicator counts, replacing the old total-matches-per-day chart to give analysts better visibility into rule impact. #CIDR #ASN #YARA

  • Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

    Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

    Unknown threat actors used a multi-package npm campaign to impersonate Alibaba private packages and deliver a staged downloader that ultimately deployed a targeted RAT against developers using Alibaba Group tools. The final payload enabled data theft, remote command execution, lateral movement through DingTalk, and platform-specific persistence across macOS, Windows, and Linux. #lib-mtop #aone-cli #DingTalk #AlibabaGroup

  • Notes from Underground: Adversarial Prompt Injection

    Notes from Underground: Adversarial Prompt Injection

    Threat actors are increasingly discussing and selling indirect prompt injection (IDPI) tools on underground forums, with generators for email, PDF, calendar invite, and webpage attack content. The activity suggests near-future abuse of hidden prompts in mail, documents, calendar invites, and malvertising to manipulate AI agents and exfiltrate data. #IndirectPromptInjection #TycoonPhaaS #OWASP…

For the sites below, automatic FETCH cannot be performed
(i need to monitor it manual, will be delay 3-7 days)

Bellow are other reference, but for some reason i’m not fetching it automatically
(i need to review the article manually, will be delay 3-5 days)

  • cleafy.com/labs (update 1-2 months)
  • guidepointsecurity.com/blog/ > category: threat advisory
  • research.openanalysis.net
  • blog.phylum.io/tag/research/
  • shadowstackre.com/analysis/
  • mssplab.github.io
  • farghlymal.github.io
  • asec.ahnlab.com/ko/
  • blog.bushidotoken.net
  • kroll.com/en/insights/publications/cyber
  • Sentinelone.com
  • blog.lumen.com

Update

Update January, 2025

“Due to copyright reasons, starting January 2025, this site will no longer display the full content of sourced articles. Only Summaries, Key Points, MITRE Tactics for Threat Research, and selected IoCs will be provided. To read the full article, please click on the ‘source’ link to view it on the original website.”