CrowdStrike and international law enforcement disrupted the Sality P2P botnet, isolating infected machines and cutting off its ability to distribute payloads after more than two decades of operation. Sality had infected over 15,000 machines worldwide and was used to spread EggJagger, DDoS payloads, and other malware families for financial gain and…
Category: Threat Research
Validin expanded its Advanced Search with broader registration filters and new regular-expression domain matching, making it easier to find related domains and IPs across registration, host, and DNS attributes. It also introduced a beta behavioral live scan that captures browser-rendered screenshots, full request artifacts, and HTTP2 activity for richer investigation context. #Validin #AdvancedSearch #LiveScan
Datadog Security Research observed a password spraying campaign against AWS root user accounts from July 24 to August 23, 2026, affecting more than 150 organizations with repeated failed ConsoleLogin attempts. The activity used two distinctive browser user agents and proxy infrastructure, while the attacker’s intent remains unknown. #Datadog #AWS #ConsoleLogin
August’s attacks showed that attackers increasingly exploit trusted business activity, from Microsoft 365 sessions and hiring workflows to remote-management tools and business-themed files, to gain access and maintain control. The incidents involving Mirage2FA, 3DBlast, SnakeBiteAgent, the US-first RMM campaign, and Famous Chollima highlight how identity compromise, session theft, and insider-style access…
CIS CTI identified an active phishing campaign targeting U.S. SLTT networks with a custom PowerShell WebSocket RAT that leads to persistent dual-RMM access through ScreenConnect and Pulseway. The operation uses Google Drive lures, Google Cloud Storage infrastructure, and continuously updated delivery variants that align with the cargo theft and freight fraud…
Attackers distributed a trojanized Exodus Wallet installer that silently installed a hidden, modified wallet and a modular RAT with browser theft, VNC, SOCKS proxy, and command execution capabilities. The campaign used fake documents, ZIP-delivered JavaScript, WebDAV search-ms redirection, and Azure Table Storage C2, while artifacts such as jn0101.msi, jg0384.msi, ExodusHelper, and ExdBackupTool helped reveal the operation. #Exodus #ExodusHelper #ExdBackupTool #AzureTableStorage #us05org #jn0101msi #jg0384msi
August’s security briefing covers ChainDrop’s rapid npm supply chain poisoning, Ghostjacking attacks against AI coding agents, and incidents where Claude Code was used in ransomware intrusions. It also highlights Sysdig’s finding that most AI-enabled attacks relied on ordinary command execution, along with Cl0p’s exploitation of PTC Windchill and broader governance updates from OWASP, CIRCIA, and NIST. #ShaiHulud #ChainDrop #ClaudeCode #PTCWindchill #Cl0p #NIST #CIRCIA
Scam sites impersonating GTA 6 are using fake countdown pages, leaked-copy offers, and wallet-draining code to steal cryptocurrency and digital assets from visitors. The campaign combines convincing Rockstar details with deceptive approval requests, region blocking, and reusable drainer infrastructure to target wallets across multiple blockchain networks. #GTA6 #Rockstar #Solana #Phantom…
Kaspersky identified two previously undocumented cross-platform RAT families, NodeRabbit and PollCat, used by Mirage Kitten in trojanized coding challenges delivered through recruiter lures on LinkedIn and other job platforms. The campaign targets Windows, Linux, and macOS, with infrastructure and lures tied to domains and services including Amazon S3, Azure Websites, Cloudflare, and the domains oracle-challenge.s3[.]us-east-1.amazonaws[.]com, plugplay.azurewebsites[.]net, and lifespotify[.]com. #MirageKitten #NodeRabbit #PollCat #LinkedIn #AmazonS3 #AzureWebsites #Cloudflare
BREEZE COMET is a financially motivated threat actor that targets Brazilian financial services, retail, and eCommerce organizations by abusing compromised websites, custom malware, and stolen credentials to manipulate payment systems and fraudulent transfers. The group has also used generative AI to accelerate malware and script development, while expanding its infrastructure and tactics across Latin America and Africa. #BREEZECOMET #COBALTSPIN #REALBREEZE #MILDFROST #KICKPLATE #BOATBEAM #XWORM #ANYDESK
Stateful detections are emerging as a critical control for cloud-native runtime security because attacks such as React2Shell and AI-assisted intrusions can escalate from vulnerability disclosure to compromise in minutes. The article also highlights the rise of JADEPUFFER, widespread adoption of stateful detections, and the growing need for trusted automated response to keep pace with agentic threat actors. #React2Shell #JADEPUFFER #Sysdig
Socket’s Threat Research Team uncovered 13 malicious Composer theme packages on Packagist that inject JavaScript into Vietnamese streaming sites and, on iPhones, deliver a multi-stage exploit chain that ends in spyware and wallet theft. The campaign spans five vendor namespaces, uses FUNNULL-backed infrastructure, and includes the redeployment of fresh loaders and payloads to target unpatched iOS devices. #OphimCMS #KKPhim #FUNNULL #Packagist #Apple #WebKit
A signed adware-like installer was abused to deploy the ValleyRAT backdoor through DLL sideloading, disabling Windows Defender and persisting via startup entries. The campaign used QN Wallpaper components and targeted users mainly in China and India, with activity linked to Silver Fox. #ValleyRAT #QNWallpaper #SilverFox
Spring Ring was a coordinated social engineering operation that used external Microsoft Teams accounts to impersonate IT help desk staff and lure more than 150 employees across at least 10 companies into vishing calls. The campaign led to attempts to deploy RMM tools, an obfuscated PowerShell RAT from san-sid[.]com, and in…
Elastic improved AI verdict correctness in its SOC from 60% to 92% by enriching agent context with investigation guides, Workday user risk data, and 30 days of past case outcomes for the same detection rule. The post explains how the Agent Brainstorm workflow in Elastic Workflows and Agent Builder uses Pattern Finder, L1 Investigation, and Summarizer agents to generate faster, more trustworthy triage results. #Elastic #AgentBuilder #Workday #Kibana #ESQL