Threat Research | Weekly Recap [29 Jun 2025]

This week’s cybersecurity recap highlights sophisticated state-sponsored espionage campaigns by North Korea and Iran, targeting financial, technological, and critical infrastructure sectors globally. Additionally, emerging malware, supply chain attacks, and phishing campaigns continue to evolve, including AI-related threats using prompt injection techniques. #APT38 #IranianCyberThreats #ContagiousInterview #CVE-2025-5777 #RapperBot

Read More
APT38 Infrastructure Hunt Uncovers macOS Malware

North Korean threat actor Lazarus Group and its financially motivated subgroup APT38 (Bluenoroff) have conducted extensive cyberattacks targeting financial institutions worldwide, including the notable 2016 Bangladesh Bank heist. The malware family Cosmic Rust, associated with APT38, targets macOS and communicates with known command and control servers, aiding threat hunting efforts using identified IPs and domains. #LazarusGroup #APT38 #CosmicRust

Read More
Hunting Fileless Malware in the Windows Registry

This article explores methodologies for detecting fileless malware that leverages the Windows Registry for staging payloads and persistence, focusing on analytics using Microsoft Defender for Endpoint (MDE). It emphasizes identifying registry-based anomalies through behavioral and statistical techniques, especially involving LOLBins and indirect execution chains. #FilelessMalware #RegistryThreats

Read More
Mastering Threat Hunting with Criminal IP: The Dorks Query Playbook (Part 2)

This article explores the importance of manual threat reconnaissance and proactive hunting strategies using Criminal IP’s Tag and Filter functions to identify malicious infrastructure. These real-world query examples help cybersecurity professionals detect C2 servers, exposed DevOps platforms, SSL VPNs, and compromised systems, improving early attack detection. #Mythic #C2servers #DevOps #SSLVPN #ThreatDetection

Read More
ASP_Phishing_Targets_Critics_of_Russia

A Russia state-sponsored threat actor tracked as UNC6293 targeted academics critical of Russia by impersonating the U.S. Department of State and using social engineering to obtain application specific passwords (ASPs) for persistent mailbox access. Two distinct campaigns used tailored phishing lures and residential proxies to maintain access, with Google mitigating the threats and reinforcing security measures like the Advanced Protection Program. #UNC6293 #APT29 #ApplicationSpecificPasswords

Read More
Business Case for Agentic AI SOC Analysts

This article discusses how agentic AI SOC Analysts are transforming security operations by automating routine tasks, reducing false positives, and addressing the global shortage of skilled analysts. Implementing AI-driven solutions like Prophet Security can enhance efficiency, improve threat detection, and align security efforts with business outcomes. #AgenticAI #ProphetSecurity…

Read More
DeepSeek Deception: Sainbox RAT & Hidden Rootkit Delivery

Netskope Threat Labs uncovered a campaign using fake installers for popular Chinese software to deliver the Sainbox RAT and a Hidden rootkit, attributed with medium confidence to the Silver Fox group. The attackers employ phishing websites and MSI payloads that execute legitimate software alongside malicious components to maintain stealth and persistence. #SainboxRAT #SilverFox #HiddenRootkit

Read More
Microsoft Entra ID OAuth Phishing and Detections

Elastic’s TRADE team analyzed OAuth phishing attacks targeting Microsoft Entra ID, inspired by Volexity’s findings on UTA0352 threat actor exploiting OAuth workflows to access Microsoft 365 resources. Their research includes hands-on emulation of attacks, revealing token abuse mechanics, device registration, and detection strategies to mitigate such identity-based threats. #UTA0352 #MicrosoftEntraID #ROADtools

Read More
Top 3 Cyber Attacks in June 2025: GitHub Abuse, Control Flow Flattening, and More 

In June 2025, cyber attacks leveraged obfuscated scripts, public services like GitHub, and multi-stage delivery to deploy malware such as Braodo Stealer, Remcos, and NetSupport RAT. ANY.RUN’s Interactive Sandbox and Threat Intelligence Lookup provide vital tools for detecting, analyzing, and mitigating these sophisticated threats. #BraodoStealer #Remcos #NetSupportRAT…

Read More
Cybercriminals Abuse Open-Source Tools To Target Africa’s Financial Sector

Researchers identified a threat actor cluster named CL-CRI-1014 targeting financial institutions in Africa using open-source tools like PoshC2, Chisel, and Classroom Spy to gain initial access and sell it on dark web markets. The attackers employ evasion techniques such as forging legitimate file signatures and disguising malware to maintain persistence and…

Read More
PowerShell Loaders Deploy Cobalt Strike

A PowerShell script named y1.ps1 was discovered in an open directory on a Chinese server, acting as a shellcode loader that executes malicious code in-memory and connects to Cobalt Strike infrastructure for post-exploitation activities. The script utilizes evasion techniques like API hashing and reflective DLL injection and communicates with command-and-control servers hosted mainly in China, Russia, and other global locations. #PowerShellLoader #CobaltStrike #BaiduCloud #BegetLLC

Read More
AsyncRAT Campaign

A phishing campaign since early 2024 leverages legitimate cloud services like TryCloudflare to deliver evasive malware such as AsyncRAT, enabling remote access, credential theft, and ransomware across thousands of organizations. The campaign uses multi-stage execution with Python scripts and cloud tunneling to bypass traditional endpoint protections, highlighting the need for layered defense strategies. #AsyncRAT #TryCloudflare #Halcyon

Read More
Zooming through BlueNoroff Indicators with Validin

The article analyzes a targeted intrusion by the North Korean BlueNoroff threat group against a Web3 organization, focusing on phishing lures disguised as Zoom extensions and extensive infrastructure pivoting using DNS, host, and registration data. Nearly 200 related malicious domains and numerous IP addresses linked to DPRK activity were identified to enable proactive threat tracking. #BlueNoroff #APT38 #LazarusGroup #ZoomExtension #Validin

Read More