Wazuh detects AWS access key compromise by correlating CloudTrail and GuardDuty telemetry across validation, enumeration, persistence, and exfiltration stages. The article explains how attackers abuse exposed AWS access keys and how Wazuh rules can reconstruct the compromise chain to raise a high-confidence alert. #Wazuh #CloudTrail #GuardDuty #AWSCompromisedKeyQuarantineV2…
Category: Threat Research
Unit 42 uncovered CL-CRI-1171, a long-running pay-per-install campaign that used OfferLoader to distribute multiple payloads through YouTube gaming videos and SEO-poisoned download pages. The operation delivered Insomnia RAT, ARKTunnel, and Docro Hijacker while hiding behind rotational domains, trojanized installers, and gating checks that filtered out scanners and analysts. #OfferLoader #CL-CRI-1171 #InsomniaRAT…
Proofpoint reported that multiple espionage-oriented threat actors rapidly adopted the BlueMoon exploit kit, which chains Chrome V8 and Windows vulnerabilities to deliver different payloads and backdoors. The activity affected US NGOs, US aerospace and defense-related organizations, Vietnamese manufacturing, and targets in Singapore and Indonesia, with notable payloads including GemStone and ShadowPad….
Zimperium’s zLabs uncovered Mantax Otax v2, a highly aggressive Android threat linked to Indonesian actors that combines spyware, data theft, remote surveillance, and ransomware in one campaign. It uses phishing and sideloaded APKs, then steals credentials and personal data, records screens and photos, and encrypts files on older Android devices while coordinating extortion through Firebase and a dynamic C2 infrastructure. #MantaxOtax #Firebase #Android
NSA, CISA, and the FBI warn that China-based AI companies are running industrial-scale knowledge distillation campaigns to extract proprietary capabilities from U.S. frontier AI models, including Claude, GPT, Gemini, and Grok. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as major actors and describes evasive access methods such…
MacSync Stealer is a macOS information-stealing MaaS operation that uses ClickFix lures, malvertising, and multi-stage native Mach-O loaders to evade Apple defenses. It exfiltrates credentials, Keychain data, cookies, SSH keys, and crypto wallets through HTTPS C2 infrastructure and cleans up traces with self-deleting temporary files. #MacSync #ClickFix #drivinguber.com #newsinweb.com #com.utils.Launcher
The article analyzes network IoCs linked to five notorious ransomware families—LockBit, Cl0p, Akira, Medusa, and Qilin—using WHOIS, DNS, and traffic data to uncover additional infrastructure and related artifacts. It highlights 84 network IoCs, thousands of connected domains and IPs, and several potentially compromised or malicious assets, including answersite[.]com and Medusa-related subdomains. #LockBit #Cl0p #Akira #Medusa #Qilin #answersitecom
Google Threat Intelligence Group reports that adversaries in Q2 2026 rapidly advanced from basic AI prompting to agentic workflows, using AI for mass credential harvesting, supply chain compromise, and attacks on proprietary AI assets. The report also details UNC6780’s open source supply chain operations, multiple nation-state and cybercrime groups abusing Gemini across the attack lifecycle, and Google’s mitigations against misuse. #UNC6780 #DUSTMAKER #Gemini #UNC6508 #UNC5792 #SANDWORMRELIC #BASINCASTLE #CALANQUEION #RAVINECASTLE #MIDNIGHTNEPTUNE #UNC6240 #OutsiderEnterprise
Check Point Research found a covert cross-account command channel in ChatGPT that let an attacker run hidden tasks inside a victim’s session and receive the results across accounts. In a proof of concept, the technique was used to access data from a connected Gmail account and exfiltrate conversation content through shared internal Artifactory metadata. #ChatGPT #Gmail #JFrogArtifactory
Cisco Talos linked two WebDAV-based infection chains to the Amatera stealer, including a “verification.google” DLL execution seen at a Ukrainian government organization and a parallel “pf.ch” chain delivered through ClearFake, Cloudflare Workers, and EtherHiding. The campaign used Amatera to steal credentials and cryptocurrency data while delivering secondary payloads such as ZigCryptoStealer,…
Fake tax-document and DocuSign lures are being used to deliver a custom HVNC backdoor to banking and financial organizations across Latin America. The malware provides hidden remote access, keystroke and browser-data theft, and Startup-folder persistence while disguising itself as Windows Update Assistant and using infrastructure tied to GHOSTnet GmbH and Azure…
CloudSEK’s TRIAD uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service platform that targeted Microsoft 365 and enabled MFA bypass through AiTM session theft. The operation exfiltrated 5,137 credential records across 3,331 victim IPs in 40+ countries, used Telegram-driven credential delivery and geo-matched residential proxies, and remained active while evidence of counter-forensic cleanup was observed. #BigBear20 #Evilginx2 #GeneralBoss #Microsoft365 #Telegram
The article explains how the DPRK has built cyber operations into a core state instrument for espionage, sanctions evasion, and revenue generation, backed by institutions such as the GRIB, NIA, and KWP. It also details the role of DPRK threat clusters and fake IT workers in funding weapons programs, with activity spanning cryptocurrency theft, laundering networks, and overseas relay infrastructure. #DPRK #GRIB #NIA #KWP #Lazarus #Kimsuky #Andariel #Reaper #Bybit #HuioneGroup
AhnLab’s analysis explains how the Syslogk rootkit hides processes, TCP connections, files, and its own kernel module on Linux by using inline hooking, VFS table hooking, and module-list manipulation. It also shows that V3 Net for Linux Server can detect the hidden kernel module and restore visibility after remediation. #Syslogk #AhnLab…
Rapid7 Labs uncovered a previously undocumented Linux toolkit using a trojanized HAProxy build and modified system daemons to target South Korean automotive and media organizations for long-term espionage. The campaign used the ted backdoor, CurlRAT, and an SSH keylogger to steal credentials, inject malicious web content, and maintain stealthy control, with infrastructure and tactics suggesting possible DPRK-linked actors such as APT37 and Kimsuky. #HAProxy #ted #CurlRAT #APT37 #Kimsuky #Rapid7 #SouthKorea