*Total Collection : 7959 Threat Research (auto update every day)
Last Threat Research
-
Data access: the hidden cost of security vendor lock-in

The article argues that SOC teams should treat security telemetry as their most valuable asset and demand open data access that is free, complete, and real time. It warns that vendors who charge for export, delay delivery, or only provide partial data create lock-in and weaken incident response, with references to CrowdStrike’s 2026 Global Threat Report and Elastic’s own stance on live access. #CrowdStrike #Elastic #SIEM #SOC
-
Angry Birds: Toy Ghouls’ new toys

Toy Ghouls, also tracked as Bearlyfy, Laboo.boo, and Feral Wolf, is using custom backdoors that communicate through HiveMQ MQTT and the Element/Matrix platform after previously relying on public tools and leaked ransomware builders. The campaign targets Russian organizations and has been linked to GenieLocker, with infrastructure and artifacts including #ToyGhouls #GenieLocker #broker.hivemq.com #meet.element.tw.
-
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

ASEC found attack cases where threat actors used Radmin and UltraVNC to take over infected systems, then deployed Netch, CCProxy, and SoftEther VPN to turn them into proxy nodes and VPN servers. The activity involved downloads from 103.86.86[.]244 and used Chinese-language scripts and configuration files, suggesting a Chinese-speaking operator. #Radmin #UltraVNC…
-
Node.js: Old Technique Makes a Comeback

Symantec reports that attackers have revived abuse of Node.js since February 2026, using the trusted node.exe runtime for persistence and execution against victims including government departments, technology companies, and hotels. In the observed campaigns, actors tied to Woodgnat/KongTuke and other threats used ClickFix, AdaptixC2, Cobalt Strike, ModeloRAT, Backdoor.Mistic, C2Looper, and EtherHiding-style Ethereum blockchain lookups to maintain access and evade defenses. #Node.js #AdaptixC2 #CobaltStrike #ModeloRAT #BackdoorMistic #C2Looper #EtherHiding #Woodgnat #KongTuke
-
BengalSEO Part 1: Anatomy of the Operation
DFIR Report identified BengalSEO, a Rajasthan-based scam operation that has used SEO poisoning, malicious lure pages, and a traffic distribution system to deliver the MayaBot malware and drive tech support fraud since at least 2015. The campaign relies on companies such as WeConnect Solutions LLC and Garage2Global, along with infrastructure spanning GitHub, Hostmaza, Cloudflare, Matomo, and numerous redirector and payload domains. #BengalSEO #MayaBot #WeConnectSolutionsLLC #Garage2Global #Hostmaza #Cloudflare #Matomo
-
Remote access hardening playbook: Reducing RMM tool risk for SMBs

This article turns telemetry from over 1.8 million endpoints into a practical hardening guide for remote access tools most often abused by attackers, including RDP, ScreenConnect, MeshAgent, and VNC. It recommends a tiered defense strategy of blocking, monitoring, and tightly auditing remote tools to reduce attack surface and detect attacker-deployed access quickly. #RDP #ScreenConnect #MeshAgent #VNC #AmmyyAdmin #UltraVNC #RDPWrap
-
False reimbursement of TARI used in new phishing campaigns targeting PagoPA

CERT-AGID identified fraudulent sites impersonating PagoPA to steal personal data and payment card information by offering a fake TARI overpayment refund. The campaign used a staged online form to collect identity details, contact information, and card data for potential fraud and future phishing operations. #PagoPA #CERT-AGID #TARI
-
H1 2026 Malware Vulnerability Trends

H1 2026 threat activity was dominated by abuse of legitimate tools, trusted platforms, and routine workflows, while AI mainly augmented existing intrusion tradecraft rather than replacing it. The report also highlights widespread exploitation of exposed CVEs, persistent RAT and stealware activity, evolving supply-chain compromises, NFC-based mobile fraud, and Magecart campaigns that leveraged trusted third-party services. #AsyncRAT #CobaltStrike #XWorm #Stealc #REMCOSRAT #PromptSpy #NGate #NFCShare #Magecart #ShaiHulud #TeamPCP
-
Malware on the Blockchain: An Ongoing Campaign’s New WebRTC Twist

EtherHiding has been used on more than 5,400 compromised small-business websites to fetch payloads from BNB Smart Chain testnet smart contracts, enabling takedown-resistant delivery of ClickFix lures or a covert WebRTC command channel. Netskope says the campaign spans over 2,200 organizations worldwide and continues to grow as operators rewrite a single on-chain contract to change what victims receive. #EtherHiding #BNBSmartChain #ClickFix #WebRTC
-
Modern Adventures in Azure Privilege Escalation

The article explains how Azure RBAC and ABAC can be analyzed at the permission level to uncover privilege escalation paths, including a built-in role that once allowed arbitrary escalation to Owner. It also describes an undocumented ARM API for mapping permissions to roles, the discovery and remediation of the Anyscale Platform Administrator Role issue, and recommendations for reducing attack surface in Azure. #AzureRBAC #ABAC #AnyscalePlatformAdministratorRole
-
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

This report details two AI-assisted intrusion campaigns in Latin America: CL-CRI-1131 against Mexican transportation and government-related targets, and CL-CRI-1163 against Brazil’s financial sector. Attackers used living-off-the-land techniques, custom RATs, SOCKS5 tunneling tools, and exposed NextChat/LLM infrastructure to troubleshoot failures, stage scripts, and exfiltrate data. #CL-CRI-1131 #CL-CRI-1163 #NextChat #SockTz #Claude #GPT-4.1…
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Check Point Research describes Gambling Goblin, a Chinese-speaking cybercrime group linked to Earth Berberoka, as running a sustained campaign against Brazilian government and educational organizations since mid-2025. The operation uses malicious Apache modules, SEO manipulation, and a large Linux toolkit to hijack traffic, serve phishing pages that impersonate Google Play, Microsoft Store, and Amazon, and scale into Vietnamese, Spanish, and English targeting. #GamblingGoblin #EarthBerberoka #Apache #GooglePlay #MicrosoftStore #Amazon
-
Kim Sooki again? This time, it was disguised as a request for seafood ingredients

A malicious LNK file disguised as a seafood ingredient purchase request was used to deliver a decoy HWP document while PowerShell, scheduled tasks, and external communications ran in the background. The attack exfiltrated system information, fetched additional commands from Backblaze B2, and was linked by AhnLab to Kimsuky. #Kimsuky #BackblazeB2 #AhnLab…
-
Python NodeStealer: AI-Assisted to Full Spyware

Netskope Threat Labs reports that Python-based NodeStealer has evolved from a Facebook credential stealer into a spyware-capable tool with keylogging, clipboard monitoring, screenshot capture, and a split Telegram C2 design. The new variant also expands Facebook Graph API collection to more than 20 endpoints, suggesting AI-assisted development and broader abuse of Facebook and Ads Manager data. #NodeStealer #NetskopeThreatLabs #Facebook #AdsManager #Telegram
-
“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing

MoiClient is an evasive backdoor distributed as an invoice-lure VHDX file that uses DLL side-loading, process injection, RPC-based UAC bypass, and BYOVD to evade defenses and maintain persistence. It repeatedly reappears through Task Scheduler and ultimately delivers MoiXD Stealer to steal browser information. #MoiClient #MoiXDStealer #BootRepairSys #LenovoPCManager #SumatraPDF…
-
Peer Pressure: Inside the Sality Botnet Disruption Operation
CrowdStrike and international law enforcement disrupted the Sality P2P botnet, isolating infected machines and cutting off its ability to distribute payloads after more than two decades of operation. Sality had infected over 15,000 machines worldwide and was used to spread EggJagger, DDoS payloads, and other malware families for financial gain and…
-
Advanced Search and Live Scan Improvements

Validin expanded its Advanced Search with broader registration filters and new regular-expression domain matching, making it easier to find related domains and IPs across registration, host, and DNS attributes. It also introduced a beta behavioral live scan that captures browser-rendered screenshots, full request artifacts, and HTTP2 activity for richer investigation context. #Validin #AdvancedSearch #LiveScan
-
Password spraying campaign targets AWS root user accounts across 150+ organizations

Datadog Security Research observed a password spraying campaign against AWS root user accounts from July 24 to August 23, 2026, affecting more than 150 organizations with repeated failed ConsoleLogin attempts. The activity used two distinctive browser user agents and proxy infrastructure, while the attacker’s intent remains unknown. #Datadog #AWS #ConsoleLogin
-
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk

August’s attacks showed that attackers increasingly exploit trusted business activity, from Microsoft 365 sessions and hiring workflows to remote-management tools and business-themed files, to gain access and maintain control. The incidents involving Mirage2FA, 3DBlast, SnakeBiteAgent, the US-first RMM campaign, and Famous Chollima highlight how identity compromise, session theft, and insider-style access…
-
Dual-RMM Phishing and PowerShell RAT Campaign Hits SLTTs

CIS CTI identified an active phishing campaign targeting U.S. SLTT networks with a custom PowerShell WebSocket RAT that leads to persistent dual-RMM access through ScreenConnect and Pulseway. The operation uses Google Drive lures, Google Cloud Storage infrastructure, and continuously updated delivery variants that align with the cargo theft and freight fraud…
>> Access All Threat Research
Reference for Threat Research
This Threat Research category section will FILTER and FETCH the POST (related with Analysis Report only) from the following sites:
- asec.ahnlab.com
- any.run/cybersecurity-blog/
- attackiq.com
- bitdefender.com/blog/labs/
- cadosecurity.com/blog/
- cisa.gov/news-events/cybersecurity-advisories/
- crowdstrike.com/blog/
- cybereason.com/blog/category/research/
- darktrace.com/blog/
- fortinet.com/blog/threat-research/
- harfanglab.io/en/insidethelab/
- malwarebytes.com/blog/threat-intelligence/
- mandiant.com/resources/blog/
- mcafee.com/blogs/other-blogs/mcafee-labs/
- proofpoint.com/us/blog
- securelist.com/tag/malware-descriptions/
- securityintelligence.com/category/x-force/threat-intelligence/
- blog.talosintelligence.com
- trendmicro.com/en_us/research/
- unit42.paloaltonetworks.com
- nextron-systems.com/blog/
- team-cymru.com/blog/categories/threat-research/
- zscaler.com/blogs/
- blog.sonicwall.com
- labs.k7computing.com/
- recordedfuture.com/blog
- blog.sekoia.io/category/research-threat-intelligence/
- embee-research.ghost.io
- netspi.com/blog/technical/
- huntress.com/blog
- other 100++ sources
For the sites below, automatic FETCH cannot be performed
(i need to monitor it manual, will be delay 3-7 days)
Bellow are other reference, but for some reason i’m not fetching it automatically
(i need to review the article manually, will be delay 3-5 days)
- cleafy.com/labs (update 1-2 months)
- guidepointsecurity.com/blog/ > category: threat advisory
- research.openanalysis.net
- blog.phylum.io/tag/research/
- shadowstackre.com/analysis/
- mssplab.github.io
- farghlymal.github.io
- asec.ahnlab.com/ko/
- blog.bushidotoken.net
- kroll.com/en/insights/publications/cyber
- Sentinelone.com
- blog.lumen.com
Update
- December, 2024: securonixblog – Fixed (xpath error)
- December, 2024: huntress – Fixed (xpath error)
- December, 2024: nccgroup – Failed (Incapsula)
- December, 2024: Mandiant – Removed (now part of Google Cloud)
- December, 2024: antiy.cn – Failed (curl or xpath error)
- December, 2024: sonicwall.com – Failed (curl error)
- January, 2025: team-cymru.com (RSS Feed Removed)
Update January, 2025
“Due to copyright reasons, starting January 2025, this site will no longer display the full content of sourced articles. Only Summaries, Key Points, MITRE Tactics for Threat Research, and selected IoCs will be provided. To read the full article, please click on the ‘source’ link to view it on the original website.”