Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

QakBot Malware Bypass Windows Security Using Unpatched Vulnerability

January 10, 2023October 15, 2025 Securonix

EclecticIQ details a QakBot phishing campaign that bypasses Windows Mark of the Web (MoTW) using an unpatched vulnerability, enabling malware installation. The campaign leverages LOLBINS like Regsvr32 and WScript, delivers payloads via encrypted ZIP/ISO, and c…

Read More
Threat Research

HIVE Ransomware Attack Research & Analysis | Rapid7 Blog

January 9, 2023October 16, 2025 Securonix

Rapid7 details how threat actors deploy Hive ransomware with a mix of known techniques and new methods to drop defenses, enable lateral movement, and encrypt across victim machines and network shares. The article also covers new Hive flags (-timer, -low-key) a…

Read More
Threat Research

Gootkit Loader Actively Targets Australian Healthcare Industry

January 6, 2023October 16, 2025 Securonix

Trend Micro analyzes Gootkit loader’s infection routine targeting Australian healthcare, showing SEO poisoning for initial access and abuse of VLC Media Player for DLL sideloading and Cobalt Strike usage. The campaign features obfuscated JavaScript, fake WordP…

Read More
Threat Research

SCATTERED SPIDER Attempts to Avoid Detection with Bring-Your-Own-Driver Tactic

January 5, 2023October 15, 2025 Securonix

SCATTERED SPIDER attempted a Bring-Your-Own-Vulnerable-Driver (BYOVD) operation to load a kernel driver via CVE-2015-2291 in the Intel Ethernet Diagnostics driver (iqvw64.sys) to gain kernel access and persistence. CrowdStrike detected and blocked the attempt,…

Read More
Threat Research

THREAT ANALYSIS: From IcedID to Domain Compromise

January 5, 2023October 14, 2025 Securonix

Cybereason’s Threat Analysis chronicles an IcedID (BokBot) campaign, detailing its use as a dropper and initial access tool, TTPs, and post-compromise activity across a Windows environment. The report notes a shift to ISO/LNK infection vectors, cross-group tec…

Read More
Threat Research

ASEC Weekly Phishing Email Threat Trends (December 18th, 2022 – December 24th, 2022) – ASEC BLOG

January 5, 2023October 23, 2025 Securonix

ASEC tracked phishing email threats for December 18–24, 2022, finding Infostealer attachments (AgentTesla, FormBook) as the top threat type, followed by FakePage and Worm Malware; attackers also used various file extensions and C2 payloads. The report highligh…

Read More
Threat Research

ASEC Weekly Phishing Email Threat Trends (December 25th, 2022 – December 31st, 2022) – ASEC BLOG

January 4, 2023October 13, 2025 Securonix

This weekly ASEC report analyzes phishing email threats from December 25–31, 2022, focusing on attachments used to deliver malware. It highlights Infostealer, FakePage, and Worm Malware as top attachment-based threats, detailing file extensions, distribution s…

Read More
Threat Research

Crypto-inspired Magecart skimmer surfaces via digital crime haven

January 4, 2023October 18, 2025 Securonix

Researchers identified a crypto-themed Magecart skimmer built on the Mr.SNIFFA toolkit that targets e-commerce sites, employing obfuscation and whitespace encoding to load its payload and exfiltrate payment data. The operation runs on Russian-hosted infrastruc…

Read More
Threat Research

Emotet returns and deploys loaders

January 4, 2023October 13, 2025 Securonix

Emotet has returned after four months of inactivity, reviving spam campaigns and leveraging its loader-as-a-service model to deploy other malware. The campaign shows evolving social engineering and obfuscation techniques, continuing to drop modules like IcedID…

Read More
Threat Research

Turla: A Galaxy of Opportunity

December 28, 2022October 16, 2025 Securonix

Two sentences summarizing the Turla activity described: Turla leveraged USB spread to introduce legacy ANDROMEDA into Ukrainian and other targets, then deployed KOPILUWAK to profile victims and QUIETCANARY to exfiltrate data, with multiple stages delivered via…

Read More
Threat Research

Unwrapping Ursnifs Gifts

December 28, 2022October 22, 2025 TheDFIR

Ursnif (Gozi/ISFB) was delivered via a malicious ISO containing a LNK file, leading to a complex execution flow that included a renamed rundll32 and later persistence. The attackers then deployed Cobalt Strike, performed manual discovery, dumped LSASS memory, …

Read More
Threat Research

BlindEagle Targeting Ecuador With Sharpened Tools – Check Point Research

December 23, 2022October 15, 2025 Securonix

Blind Eagle (APT-C-36) has intensified its Ecuador-focused campaign with an upgraded infection chain, delivering a QuasarRAT-based payload via a password‑protected LHA package and multiple stages. The operation combines geo-filtered phishing, a MediaFire drop,…

Read More
Threat Research

BlueNoroff introduces new methods bypassing MoTW

December 22, 2022October 13, 2025 Securonix

BlueNoroff group expanded its malware delivery methods to bypass Mark-of-the-Web (MOTW) protections by using ISO and VHD disk image formats, and began experimenting with Visual Basic Script, Windows Batch scripts, and a Windows executable. They also operated a…

Read More
Threat Research

Unveiling the IcedID BackConnect Protocol: Team Cymru Reveals

December 21, 2022October 13, 2025 Securonix

Team Cymru analyzes IcedID’s BackConnect protocol and uncovers how operators repurpose infected hosts as proxies to support distributed C2 activity, including VPN/Starlink/Tor-based routing and remote-access channels. The post also highlights observed tools an…

Read More
Threat Research

Custom-Branded Ransomware: The Vice Society Group and the Threat of Outsourced Development

December 20, 2022October 17, 2025 Securonix

Vice Society has adopted a new custom-branded ransomware payload named PolyVice that uses NTRUEncrypt and ChaCha20-Poly1305 for strong encryption. The analysis indicates the same developers are selling customized payloads to multiple groups, signaling an outso…

Read More

Posts pagination

Previous 1 … 210 211 212 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.