Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • Security Report
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

Qbot and Zerologon Lead To Full Domain Compromise

February 9, 2022October 15, 2025 Securonix

In a November 2021 intrusion, threat actors gained a foothold with Qbot (Quakbot) and used Zerologon to elevate to domain admin, enabling Cobalt Strike deployment and broader network compromise. They conducted AD discovery, exfiltrated sensitive documents, and…

Read More
Threat Research

Guard Your Drive from DriveGuard: Moses Staff Campaigns Against Israeli Organizations Span Several Months | FortiGuard Labs

February 8, 2022October 16, 2025 Securonix

Fortinet FortiEDR uncovered a Moses Staff campaign targeting Israeli organizations, leveraging ProxyShell exploits to deploy web shells and a multi-component backdoor for espionage, data exfiltration, and payload delivery. The operation includes a loader that …

Read More
Threat Research

Lockbit 2.0 Ransomware: TTPs Used in Emerging Ransomware Campaigns

February 3, 2022October 18, 2025 Picussecurity

Picus Security analyzes LockBit 2.0 ransomware, detailing its evolution as a RaaS operator, its anti-detection techniques, and its methods to disrupt victim recovery and logging. The post also lists IOCs and maps LockBit 2.0 behaviors to MITRE ATT&CK technique…

Read More
Threat Research

Ugg Boots 4 Sale: A Tale of Palestinian-Aligned Espionage | Proofpoint US

January 31, 2022October 13, 2025 Securonix

TA402, a Palestinian-aligned APT, has deployed NimbleMamba, a new implant intended to replace LastConn, in targeted Middle East campaigns. The operation blends geofenced links, actor-controlled domains, and Dropbox-based C2/exfiltration with redirects to legit…

Read More
Threat Research

Zoom For You — SEO Poisoning to Distribute BATLOADER and Atera Agent

January 28, 2022October 17, 2025 Securonix

Mandiant ties a campaign that uses SEO poisoning to distribute BATLOADER and ATERA Agent to techniques disclosed after a CONTI ransomware affiliate leak in August 2021. The report also provides extensive indicators, a YARA rule, and a MITRE ATT&CK mapping span…

Read More
Threat Research

Antlion: Chinese APT Uses Custom Backdoor to Target Financial Institutions in Taiwan

January 28, 2022October 16, 2025 Securonix

Antlion, a Chinese APT, deployed a custom .NET loader called xPack to compromise Taiwanese targets, focusing on financial and manufacturing organizations and conducting extended credential dumping and data staging. The operation used a mix of custom loaders an…

Read More
Threat Research

Qbot Likes to Move It, Move It

January 27, 2022October 14, 2025 Securonix

Qbot (QakBot) campaigns spread rapidly by delivering a malicious Excel macro that loads a QBot DLL, then injects into msra.exe to harvest browser data and Outlook emails. The operation escalates privileges, moves laterally across all workstations, and uses mul…

Read More
Threat Research

Arid Viper APT targets Palestine with new wave of politically themed phishing attacks, malware

January 25, 2022October 14, 2025 Securonix

Cisco Talos identifies a new wave of the Delphi-based Micropsia implant operated by Arid Viper, targeting Palestinian entities and activists with politically themed decoys. The latest implants add multiple RAT and information-gathering capabilities, persistenc…

Read More
Threat Research

Hacktivist group shares details related to Belarusian Railways hack

January 21, 2022October 16, 2025 Securonix

The Belarusian Cyber Partisans disclosed documents related to a railway-targeting incident and discussed that Curated Intelligence member SttyK would study the methods used. The published material outlines an incident aimed at hindering operations and details …

Read More
Threat Research

Log4U, Shell4Me

January 20, 2022October 13, 2025 Securonix

BlackBerry researchers link the Prophet Spider Initial Access Broker (IAB) group to exploiting the Log4j (Log4Shell) vulnerabilities in VMware Horizon to break into organizations. The article outlines IoCs, observed post-exploitation payloads (cryptomining, Co…

Read More
Threat Research

Watering hole deploys new macOS malware, DazzleSpy, in Asia

January 19, 2022October 18, 2025 Securonix

ESET analyzes a watering-hole campaign that delivers a new macOS backdoor named DazzleSpy via a WebKit/Safari exploit chain. Targets were Hong Kong pro-democracy individuals, with infection hosted on amnestyhk.org and other compromised sites like fightforhk.co…

Read More
Threat Research

DoNot Go! Do not respawn!

January 13, 2022October 19, 2025 Securonix

Donot Team (also known as APT-C-35 and SectorE02) is a long-running South Asia-focused threat actor linked to Windows and Android malware, with Amnesty International alleging links to an Indian cybersecurity company that may sell spyware or hackers-for-hire se…

Read More
Threat Research

HANCITOR DOC drops via CLIPBOARD | McAfee Blog

December 13, 2021October 15, 2025 McAfee

By Sriram P & Lakshya Mathur  Hancitor, a loader that provides Malware as a Service, has been observed distributing malware such as…
The post HANCITOR DOC drops via CLIPBOARD appeared first on McAfee Blog….

Read More
Threat Research

Phishing as a Ransomware Precursor | Ransomware Delivery

September 24, 2021October 16, 2025 admin

Phishing is increasingly a preliminary step in multi-stage ransomware campaigns: attackers use phishing to gain initial access, then deploy loaders/RATs to perform reconnaissance, lateral movement, persistence and finally deliver ransomware. Detecting and bloc…

Read More
Threat Research

New Ryuk Ransomware Sample Targets Webservers | McAfee Blog

July 7, 2021October 13, 2025 McAfee

Executive Summary Ryuk is a ransomware that encrypts a victim’s files and requests payment in Bitcoin cryptocurrency to release the…
The post New Ryuk Ransomware Sample Targets Webservers appeared first on McAfee Blog….

Read More

Posts pagination

Previous 1 … 222 223 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
Twitter/X @TweetThreatNews
Facebook @Cybersecurity
LinkedIn Hendry Adrian

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.