AI is increasingly integrated into security operations, but many SOCs lack a structured approach, limiting its effectiveness. Proper application of AI in well-defined, targeted tasks can significantly enhance detection, hunting, and reporting capabilities. #AI #SOC #DetectionEngineering #ThreatHunting #Automation…
Tag: THREAT HUNTING
CYFIRMA attributes a targeted multi-stage, fileless espionage campaign to APT36 (Transparent Tribe) that uses weaponized LNK files masquerading as PDFs to deliver HTA loaders and in-memory .NET deserialization payloads. The operation deploys configuration and RAT payloads (ReadOnly/WriteOnly -> ki2mtmkl.dll, iinneldc.dll), adapts persistence based on detected AV products, and maintains encrypted C2 communications to 2.56.10.86 for surveillance and data exfiltration. #APT36 #ReadOnly
This article highlights the evolving cybersecurity landscape, emphasizing that by 2026, security strategies will focus on governance, accountability, and advanced technologies like AI-driven security operations. It warns that traditional security programs will become obsolete, urging CISOs to adopt stricter controls and innovative tools to stay ahead of sophisticated threats. #Ransomware #CybleBlazeAI…
The Cyber Threat Landscape Report 2025 by Ensign InfoSecurity highlights the increasing sophistication and collaboration among ransomware groups, state-sponsored actors, and organised crime in the Asia Pacific region. It emphasizes emerging threats such as advanced ransomware evasion techniques, hacktivist evolutions, and targeted attacks on business professional services. #LockBit #DragonForce #EnsignInfoSecurity
APT37’s “Artemis” campaign uses social engineering to deliver malicious HWP documents that embed OLE objects and abuse Sysinternals utilities to perform DLL side-loading and deploy RoKRAT. The multi-stage attack leverages steganography, multi-layer XOR decryption, and cloud-based C2 (Yandex/pCloud) to evade signature-based detection and highlights the need for EDR-driven behavior monitoring. #APT37 #RoKRAT
CYFIRMA analyzed a targeted APT-36 campaign that used a malicious Windows shortcut masquerading as a government advisory PDF to retrieve an MSI installer which deployed a .NET loader, malicious DLLs (including wininet.dll), dropped a decoy PDF, and established registry-run persistence via an HTA. Although the C2 domain wmiprovider[.]com was inactive during analysis, the loader contains obfuscated HTTP endpoints that enable remote command execution and long-term access. #APT36 #NCERT_Whatsapp_Advisory
Zscaler Threat Hunting uncovered a targeted espionage campaign impersonating the Income Tax Department of India that uses URL shorteners and public file hosting to deliver a DLL side-loading implant linked to SideWinder activity. The campaign leverages signed Microsoft binaries (SenseCE.exe) to load a malicious MpGear.dll, performs timezone-based geofencing for India (UTC+5:30), and communicates with C2 servers to deploy a resident agent. #SideWinder #SenseCE
ReversingLabs uncovered a NuGet supply-chain campaign (July–October 2025) involving 14 malicious packages that impersonated legitimate crypto libraries to steal wallet secrets, OAuth credentials, or redirect funds. The packages used homoglyphs, version bumping, inflated download counts and hidden functions (e.g., Shuffle, MapAddress) to exfiltrate data to hxxps://solananetworkinstance[.]info/api/gads or overwrite transaction destinations. #Netherеum.All #NuGet
Modern security teams need to shift from reactive firefighting to proactive threat detection by using contextual threat intelligence. Implementing tools like ANY.RUN’s Threat Intelligence Lookup enables SOCs to understand, prioritize, and respond to cyber threats tailored to their industry and geography. #Tycoon2FA #LummaStealer…
This December’s Patch Tuesday includes critical updates for Windows, Notepad++, Fortinet, Ivanti, and more, addressing vulnerabilities actively exploited or publicly known. Timely application of these patches is essential to prevent privilege escalation, remote code execution, and credential bypass attacks. #CVE202562221 #Notepad++V8.8.9…
In late November 2025 a malicious Visual Studio Code extension named “prettier-vscode-plus” was published to the official Marketplace and used as a supply-chain entry point to deliver a multi-stage attack targeting developers. The chain deployed an Anivia loader (AES-encrypted in-memory decryption and process hollowing into vbc.exe) which dropped the OctoRAT remote access toolkit with extensive data-theft, persistence, privilege‑escalation and C2 capabilities. #Anivia #OctoRAT
CVE-2025-55182 (React2Shell) is a critical (CVSS 10.0) pre-authentication remote code execution in React Server Components that allows attackers to craft Flight payload chunks to reach the Function constructor and execute arbitrary Node.js commands. Trend observed widespread in-the-wild exploitation and multiple campaigns (e.g., emerald, nuts) delivering Cobalt Strike, Mirai variants, Nezha, Sliver,…
U.S. and international agencies assess that pro‑Russia hacktivist groups—including Cyber Army of Russia Reborn (CARR), NoName057(16), Z‑Pentest, and Sector16—are conducting opportunistic intrusions against critical infrastructure by scanning for internet‑facing VNC services and exploiting default or weak credentials to access HMI/OT devices. These unsophisticated but impactful operations involve VPS‑based brute‑force attacks, GUI…
Microsoft is addressing an outage affecting users in Europe and the UK from accessing its Copilot AI assistant due to capacity scaling issues. Additional incidents include disruptions in Microsoft Defender for Endpoint and load balancing problems, impacting service availability and functionality. #MicrosoftCopilot #MicrosoftDefender #ServiceOutage
Trend Research describes the discovery and technical analysis of GhostPenguin, a previously undocumented multi-threaded Linux backdoor that provides a remote /bin/sh shell and extensive filesystem operations over an RC5-encrypted UDP channel (initial handshake over UDP port 53). The backdoor was found using an AI-driven VirusTotal zero-detection hunting pipeline that decompiled and…