Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

The slow Tick-ing time bomb: Tick APT group compromise of a DLP software developer in East Asia

March 8, 2023October 14, 2025 Securonix

ESET linked a campaign to the Tick APT group targeting an East Asian data-loss prevention (DLP) software developer, where attackers trojanized installers and compromised update servers to spread malware to the company’s customers. The operation involved Shadow…

Read More
Threat Research

New HiatusRAT router malware covertly spies on victims – Lumen

March 6, 2023October 14, 2025 CTI

Lumen Black Lotus Labs discovered the “Hiatus” campaign that compromises business-grade DrayTek Vigor routers to deploy HiatusRAT and a tcpdump variant, enabling remote access, SOCKS5 proxying, and packet capture. Lumen observed ~100 infected routers (primaril…

Read More
Threat Research

IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks

March 6, 2023October 15, 2025 Securonix

IceFire re-emerges with a Linux variant that targeted enterprise networks, expanding beyond its previous Windows focus. It exploits a deserialization vulnerability in IBM Aspera Faspex (CVE-2022-47986) to drop and execute a Linux payload that encrypts files an…

Read More
Threat Research

Old Cyber Gang Uses New Crypter – ScrubCrypt | FortiGuard Labs

March 4, 2023October 16, 2025 Securonix

Fortinet FortiGuard Labs tracked the 8220 Gang’s use of ScrubCrypt to obfuscate and encrypt payloads and deliver a Monero-mining operation via a WebLogic vulnerability. The operation combines PowerShell-based loading, in-memory execution, registry-based persis…

Read More
Threat Research

Qakbot Evolves to OneNote Malware Distribution

March 1, 2023October 16, 2025 Securonix

Two sentences summarizing the content. Trellix researchers document Qakbot’s evolution to OneNote-based malware distribution, showing how OneNote attachments deliver a loader DLL and the main Qakbot payload across multiple campaigns. The report also covers how…

Read More
Threat Research

GlobeImposter Ransomware Being Distributed with MedusaLocker via RDP – ASEC BLOG

March 1, 2023October 14, 2025 Securonix

GlobeImposter ransomware is being distributed by MedusaLocker actors, with evidence suggesting the RDP vector facilitates initial access. The operation deploys Mimikatz and port scanners among other tools to map networks, exfiltrate credentials, and extend the…

Read More
Threat Research

Pandas with a Soul: Chinese Espionage Attacks Against Southeast Asian Government Entities – Check Point Research

March 1, 2023October 19, 2025 Securonix

Check Point Research traces the evolution of Sharp Panda tools into a newer Soul malware framework used against Southeast Asian government entities, culminating in late-2022 activity that loaded the Soul modular backdoor. The report links these campaigns to a …

Read More
Threat Research

Cybercrime Takes Advantage of 2023-Recession with Job-Themed Scams

February 28, 2023October 13, 2025 Securonix

Two sentences: Trellix researchers warn that job-themed phishing and malware campaigns surge in economic downturns, targeting job seekers and employers with fake resumes, fake documents, and malicious links. The campaigns leverage typosquatted domains and well…

Read More
Threat Research

SCARLETEEL: Operation leveraging Terraform, Kubernetes, and AWS for data theft

February 28, 2023October 13, 2025 Securonix

Sysdig’s Threat Research Team uncovered SCARLETEEL, a sophisticated cloud-attack operation that started in a Kubernetes pod and escalated into AWS to steal proprietary software and credentials. The operation leveraged Terraform state and AWS services to move l…

Read More
Threat Research

MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT

February 27, 2023October 14, 2025 Securonix

MQsTTang is a new Mustang Panda backdoor that uses MQTT for C2 and operates as a single-stage, minimally obfuscated tool. The campaign targets government and diplomatic entities, employs spearphishing distribution with decoy filenames, and includes anti-analys…

Read More
Threat Research

OneNote: A Growing Threat for Malware Distribution

February 23, 2023October 15, 2025 Securonix

Microsoft OneNote is becoming a growing vector for malware delivery, as threat actors embed malicious payloads in OneNote documents distributed via phishing emails and other deceptive tactics. Across multiple case studies, attackers use obfuscation and scripti…

Read More
Threat Research

Malware: The Rise of Threat Actors Using OneNote for Campaigns – InQuest

February 23, 2023October 13, 2025 Securonix

Microsoft OneNote is increasingly used as a carrier to deliver malware via phishing attachments, exploiting benign file formats to bypass defenses. The piece traces its evolution, highlights sample campaigns and loader stages, and outlines layered defenses org…

Read More
Threat Research

Blind Eagle Deploys Fake UUE Files and Fsociety to Target Colombia’s Judiciary, Financial, Public, and Law Enforcement Entities

February 23, 2023October 13, 2025 Securonix

Blind Eagle (APT-C-36) targeted Colombia and nearby Latin American entities with spear-phishing PDFs impersonating the DIAN tax authority to deploy a multi-stage infection chain, culminating in AsyncRAT payloads hosted via Discord. The campaign uses in-memory …

Read More
Threat Research

TA569 Threat Actor Overview: SocGholish & Beyond | Proofpoint US

February 22, 2023October 15, 2025 Securonix

TA569 operates a prolific injection-based operation delivering SocGholish and other payloads, functioning as an initial access broker and potentially a pay-per-install service. The campaigns rely on diverse injections, Traffic Distribution Services, and reinfe…

Read More
Threat Research

Clasiopa: New Group Targets Materials Research

February 20, 2023October 23, 2025 Securonix

A hitherto unknown attack group named Clasiopa was observed targeting a materials research organization in Asia, wielding a distinct toolset that includes a custom backdoor (Atharvan). The operation exhibits multiple defense-evading and data-exfiltrating techn…

Read More

Posts pagination

Previous 1 … 206 207 208 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.