Skip to main content

Author

Tanium Cyber Threat Intelligence Team

Desktop featured image: CTI blog 1
Jan 7, 2026

SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

Desktop featured image: CTI blog 2
Dec 16, 2025

Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

Desktop featured image: CTI blog 4 - wide
Dec 10, 2025

Hybrid 2FA phishing threatens enterprises, RomCom uses SocGholish to deploy Mythic Agent malware, and MuddyWater targets critical infrastructure with evolving tactics

Desktop featured image: CTI blog 3 - wide
Nov 18, 2025

Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

Desktop featured image: CTI blog 1 - wide
Nov 14, 2025

Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

Desktop featured image: CTI blog 2 - wide
Nov 5, 2025

Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

Desktop featured image: CTI blog 4 - wide
Oct 28, 2025

Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities

Desktop featured image: CTI blog 3 - wide
Oct 22, 2025

Astaroth trojan uses GitHub to host malware configurations, TA585 delivers MonsterV2 malware in phishing campaigns, and threat actors exploit Microsoft’s logo in tech support scams

Desktop featured image: CTI blog 1 - wide
Oct 15, 2025

XWorm malware reemerges with ransomware, Microsoft disrupts multiple threats targeting Teams, and Storm-1175 exploits a critical GoAnywhere MFT vulnerability

Desktop featured image: CTI blog 2 - wide
Oct 8, 2025

Check out the latest insights on DarkCloud malware, the “Trinity of Chaos” alliance, and WARMCOOKIE updates.

Desktop featured image: CTI blog 4 - wide
Oct 1, 2025

SystemBC botnet targets VPS infrastructure, ShinyHunters targets enterprise cloud applications, and a phishing campaign uses AI-generated code to avoid detection

Desktop featured image: CTI blog 3
Sep 17, 2025

AMOS Stealer campaign targets macOS, TAG-150 deploys new CastleRAT malware, and GPUGate targets IT firms in Western Europe

Desktop featured image: CTI blog 1 - wide
Sep 10, 2025

The latest on HexStrike AI, TinkyWinkey’s keylogging, and Silver Fox APT’s driver abuse bypassing endpoint defenses.

Desktop featured image: CTI blog 2 - wide
Sep 2, 2025

New Linux malware evades antivirus detection, UNC5518 deploys CORNFLAKE.V3 using ClickFix and fake CAPTCHA pages, and a PRC-Nexus campaign hijacks web traffic.

Desktop featured image: CTI blog 4 - wide
Aug 27, 2025

Researchers uncover malicious Python packages, PipeMagic masquerades as a ChatGPT desktop app, and Noodlophile Stealer targets enterprises through social media

Desktop featured image: CTI blog 3 - wide
Aug 20, 2025

Ransomware groups adopt shared EDR-killing tool, PS1Bot spreads via malvertising, and Charon ransomware uses APT-style tactics to target critical sectors

Desktop featured image: CTI blog 1 - wide
Aug 13, 2025

Discover how attackers hijack CAPTCHAs, why CVE activity spikes matter, and global PXA threats.

Desktop featured image: CTI blog 2 - wide
Jul 30, 2025

Katz Stealer seeks credentials and crypto assets, Lumma Stealer returns after a disruption, NailaoLocker ransomware targets Windows

Desktop featured image: CTI blog 4 - wide
Jul 23, 2025

BlackSuit ransomware combines data exfiltration and encryption, AsyncRAT spawns multiple forks, and HazyBeacon abuses AWS Lambda for command and control

Desktop featured image: CTI blog 3 - wide
Jul 16, 2025

Get the latest on BERT ransomware, TGR-CRI-0045 exploits, and XWorm’s stealthy evolution in this week’s CTI roundup.

Desktop featured image: CTI blog 1 - wide
Jul 9, 2025

Get the latest on GIFTEDCROOK’s evolution, Jasper Sleet’s infiltration tactics, and rising cyber threats in ESET’s H1 2025 report.

Desktop featured image: CTI blog 2 - wide
Jun 25, 2025

Cyber attackers exploit legitimate tools, ClickFix attacks accelerate, and BlueNoroff targets macOS devices

CTI Roundup: UNC6032, APT41, Void Blizzard
Jun 4, 2025

The latest on UNC6032 fake AI websites, APT41’s use of Google Calendar, and Void Blizzard targeting critical sectors.

CTI Roundup: Hazy Hawk, Remcos RAT, and npm Phishing
May 28, 2025

Recent news on Hazy Hawk using DNS records, a fileless Remcos RAT campaign, and the use of AES encryption with malicious npm packages in phishing attack.

CTI Roundup: Marbled Dust, Horabot, and TA406
May 21, 2025

Learn about Marbled Dust exploiting a zero-day vulnerability in Output Messenger, a new phishing campaign using Horabot malware, and TA406 changing targets.

CTI Roundup: Luna Moth, Venom Spider, StealC V2
May 14, 2025

Updates on Luna Moth threatening U.S. legal and financial firms, Venom Spider targeting hiring managers and recruiters, and StealC malware getting upgrades.

CTI Roundup: Infostealers, Zero-Day Attacks, and Gremlin Stealer
May 7, 2025

The latest news on infostealers, Google observing 75 zero-day exploits in 2024, and new threat Gremlin Stealer.

CTI Roundup: Deepfakes, ToyMaker IAB, and ClickFix
Apr 30, 2025

Recent news about threat actors using real-time deepfakes to land remote work, ToyMaker initial access broker, and state-sponsored hackers using ClickFix.

CTI Roundup: SMS Phishing, Node.js, and Fake PDF Converters
Apr 23, 2025

The latest news about threat actors exploiting SMS with social engineering, misusing Node.js for malware, and fake PDF converters delivering malware.

CTI Roundup: Email Attacks, Hunters International, and New Ransomware Data
Apr 16, 2025

Read the latest news about attacks combining credential phishing and malware, Hunters International pivoting to data extortion, and ransomware trends.

CTI Roundup: QR Code Phishing, Babuk Locker 2.0, and Qilin
Apr 9, 2025

QR code phishing accelerates, LockBit 3.0 rebrands, and Qilin affiliates target downstream customers of an MSP.

CTI Roundup: StilachiRAT, Reddit Infostealers, and New Password Reuse Data
Mar 26, 2025

The latest information about StilachiRAT malware, AMOS and Lumma stealers spreading via Reddit, and research on how many logins use compromised passwords.

CTI Roundup: Malvertising, XCSSET Variant, and GitHub Abuse
Mar 19, 2025

The latest news about a malvertising campaign threatening devices, XCSSET variant, and an ongoing campaign using fake GitHub repositories to spread malware.

CTI Roundup: Silk Typhoon, Fake Ransom Notes, and ClickFix
Mar 12, 2025

The latest cyber threat news on Silk Typhoon shifting tactics, threat actors targeting executives with physical ransom notes, and the ClickFix trick.

CTI Roundup: Auto-Color Malware, Vulnerable Windows Driver, and Lotus Blossom
Mar 5, 2025

Latest news about Auto-color Linux malware, attackers exploiting Truesight.sys, and Lotus Blossom.

CTI Roundup: Ferret Malware, macOS Stealers, and MS Power BI
Feb 12, 2025

Learn about North Korean hackers targeting job seekers, growing macOS infostealers, and MS Power BI phishing.

CTI Roundup: New TorNet Backdoor, Lynx Ransomware, and Q4 Trends
Feb 5, 2025

The latest on an ongoing TorNet backdoor campaign, Lynx ransomware group's advanced affiliate program, and Cisco Talos' Q4 incident response trends report.

CTI Roundup: 2024 Ransomware Recap, Breached Passwords, and O365 Exploits
Jan 29, 2025

Learn what researchers have to say about ransomware trends from 2024, as well as new insights on stolen passwords and two recent O365 attacks.

CTI Roundup: FunkSec, Malvertising, and Fake Software
Jan 22, 2025

News about FunkSec ransomware, a recent malvertising scam targeting Google Ads users, and threat actors using fake software and installers to push malware.

CTI Roundup: PayPal Phishing, PLAYFULGHOST, and NonEuclid
Jan 15, 2025

The latest on a PayPal impersonation phishing campaign, PLAYFULGHOST malware, and the new NonEuclid RAT.

CTI Roundup: Earth Koshchei, RiseLoader, and a New Ransomware Advisory
Dec 25, 2024

Earth Koshchei executes rogue RDP attacks, Zscaler releases technical details about RiseLoader malware, and Corvus issues a ransomware advisory.

CTI Roundup: Seasonal Phishing, Zloader, and Secret Blizzard
Dec 18, 2024

The latest news around threat actors impersonating HR in a seasonal phishing campaign, Zloader's new features and capabilities, and Secret Blizzard.

CTI Roundup: Rockstar 2FA, RevC2 and Venom Loader, and SmokeLoader Malware
Dec 11, 2024

Rockstar 2FA targets M365 users, new RevC2and Venom Loader malware, and SmokeLoader reappears.

CTI Roundup: Sophos vs. Chinese Threat Actors, CRON#TRAP Linux VM, Bing Phishing Campaign
Nov 13, 2024

Learn about ongoing battles between Sophos and multiple Chinese threat actors, CRON#TRAP infecting Windows with Linux VMs, and Bing being used for phishing.

CTI Roundup: Scattered Spider and RansomHub Partner, Infostealer Malware Bypasses Chrome Patches, Evasive Panda Back in the News
Nov 6, 2024

Latest news on Scattered Spider and RansomHub, infostealers evading Chrome defenses, and Evasive Panda.

CTI Roundup: Gophish Toolkit Phishing, Malicious Virtual Hard Drive Files, Return of Bumblebee Malware
Oct 30, 2024

Learn about the Gophish toolkit for phishing, attackers bypassing secure email gateways and antivirus scanners, and the return of Bumblebee malware.

CTI Roundup: Callback Phishing, Time-to-Exploit Trends, and PureLogs Infostealer
Oct 23, 2024

Learn about threat actors spreading malware via callback phishing, Mandiant's analysis of time-to-exploit trends, and PureLogs targeting Chrome browsers.

CTI Roundup: Rise in File Hosting Services Misuse, Mamba 2FA, and Dark Angels Ransomware Attacks
Oct 16, 2024

News around Microsoft attacks using file hosting services, phishing campaigns mimicking Microsoft 365 login pages, and Dark Angels ransomware group updates.

CTI Roundup: Sniper Dz, Elastic 2024 Global Threat Report Insights, and Andariel Financial Attacks
Oct 9, 2024

Latest news around Sniper Dz, insights from Elastic Security Labs 2024 Global Threat Report, and Andariel financial attacks against U.S. organizations.

CTI Roundup: North Korean-Sponsored Remote IT Workers, Legitimate Sites Sending Spam, and Political Deepfakes
Oct 2, 2024

North Korea exploiting remote roles, third-party infrastructure used to send spam, and insights from new deepfakes report.

CTI Roundup: HTTP Headers Phishing Technique, Scattered Spider Back in the News, and UNC2970 Targets Job Seekers
Sep 25, 2024

Learn about a phishing campaign using HTTP headers, Scattered Spider, and UNC2970 exploiting job seekers.

CTI Roundup: Emansrepo Infostealer and Earth Lusca Multiplatform Backdoor
Sep 12, 2024

Emansrepo Stealer spreads via email, Palo Alto sheds light on top-level domains, and Earth Lusca deploys a new multiplatform backdoor.

CTI Roundup: Xeon Sender Targets Cloud APIs and MoonPeak Malware Updates
Aug 28, 2024

Xeon Sender targets cloud APIs, Cisco Talos reveals UAT-5394 infrastructure, and attackers leverage public .env files to extort victims.

CTI Roundup: Mad Liberator Ransomware Targets AnyDesk Users
Aug 21, 2024

New tools appear in ongoing social engineering campaign, Mad Liberator ransomware targets AnyDesk users, and Bitdefender explores the evolving cybercriminal underground.

CTI Roundup: SharpRhino RAT Threatens IT Admins, Phishers Leverage Google Drawings and WhatsApp Links
Aug 14, 2024

SharpRhino RAT threatens IT admins, ransomware gangs ramp up pressure on targets, and a new phishing scam leverages Google Drawings and WhatsApp links.

CTI Roundup: Cisco Talos Q2 IR Trends Report, New GenAI Scams on the Horizon
Aug 7, 2024

Cisco Talos releases its Q2 IR trends report, ransomware groups target ESXi flaw, and scammers exploit GenAI in domain registration and network attacks.

CTI Roundup: Evasive Panda Deploys New Malware, Macma Backdoor and Nightdoor
Jul 31, 2024

Evasive Panda deploys new versions of Macma backdoor and Nightdoor, cybercriminals work independently after RaaS takedowns, and a new Linux Play variant targets VMware ESXi systems.

CTI Roundup: MuddyWater Deploys BugSleep Malware, New Attack From Void Banshee
Jul 24, 2024

MuddyWater deploys BugSleep malware, researchers discover malicious files on the npm registry, and Void Banshee exploits a Microsoft MHTML flaw.

CTI Roundup: Threat Actor Updates. APT40, CloudSorcerer, Eldorado
Jul 17, 2024

APT40 rapidly exploits network vulnerabilities, CloudSorcerer APT targets Russian organizations, and Eldorado threatens Windows and Linux systems.

CTI Roundup: FakeBat Loader-as-a-Service, ESET H1 2024 Threat Report
Jul 10, 2024

FakeBat loader spreads via multiple infection chains, and ESET releases its threat report from the first half of 2024.

CTI Roundup: Busy Days for Threat Actors ONNX Store, Boolka, & SneakyChef
Jul 3, 2024

ONNX Store targets the financial industry, Boolka delivers the BMANAGER trojan via SQLi attacks, and SneakyChef deploys SpiceRAT and SugarGh0st.

CTI Roundup: Vortax Spreads Infostealer Malware, Linux Malware Uses Emojis to Execute Commands
Jun 26, 2024

Vortax spreads infostealer malware, new malware campaign distributes fake error messages, and Linux malware uses emojis to execute commands.

CTI Roundup: Windows HTML Malware, Remcos RAT, & Black Basta Ransomware
Jun 19, 2024

CTI reports a malware campaign utilizing Windows search in HTML, Remcos RAT via UUE files, and a Black Basta ransomware exploit of a Windows vulnerability.

CTI Roundup: TargetCompany Ransomware, LilacSquid Cyber Espionage, & DarkGate Malware
Jun 12, 2024

TargetCompany’s Linux variant threatens ESXi environments, LilacSquid targets multiple sectors, and DarkGate malware switches from Autolt to AutoHotkey.

CTI Roundup: Social Engineering, DNS Tunneling, & Malvertising
May 22, 2024

Beware of an ongoing campaign targeting enterprises and other current cyber threat news to know.

CTI Roundup: Q1 Exploit Trends, HijackLoader, & the State of Pentesting
May 15, 2024

Kaspersky reveals the top exploit and vulnerability trends for the first quarter of 2024, HijackLoader evolves with new evasion techniques, and Cobalt releases its 2024 State of Pentesting report.

CTI Roundup: Cuttlefish Malware, Hackers Leverage Docker Hub
May 8, 2024

Cuttlefish malware targets SOHO routers, nation states and cybercriminals share compromised networks, and threat actors use Docker Hub to spread malware and phishing scams.

CTI Roundup: ToddyCat APT, GuptiMiner Malware, APT28 Exploits a Windows Print Spooler Flaw
May 1, 2024

ToddyCat deploys advanced tools for industrial scale data theft, hackers use eScan updates to spread GuptiMiner malware, and Russia’s APT28 exploits a Windows Print Spooler flaw.

CTI Roundup: A Malicious Notepad++ Plugin, “Junk Gun” Ransomware, and a Google Malvertising Campaign
Apr 24, 2024

Researchers discover modified Notepad++ plug-in, new junk gun ransomware appears on cybercrime forums, and a malvertising campaign targets IT teams.

CTI Roundup: LockBit Update, Earth Freybug Deploys UNAPIMON Malware
Apr 10, 2024

Law enforcement’s impact on LockBit, how unpatched vulnerabilities contribute to ransomware attacks, and Earth Freybug deploys UNAPIMON malware.

CTI Roundup: Tycoon Phishing-as-a-Service and TheMoon Malware Update
Apr 3, 2024

Researchers discover a new version of the Tycoon 2FA AiTM kit, a phishing attack disguises keylogger as bank payment notice, and TheMoon malware targets ASUS routers.

CTI Roundup: Fake Google Sites Pages, Hackers Target Global Governments
Apr 1, 2024

Hackers spread malware through fake Google Sites pages, cybercriminals exploit APIs, and an APT campaign targets global government entities.

CTI Roundup: 12 Million Secrets and Keys Leak on GitHub
Mar 20, 2024

BianLian threat actors exploit JetBrains TeamCity flaws, ransomware attacks continue to accelerate, and more than 12 million secrets and keys leak on GitHub.

CTI Roundup: Linux Servers Target of New Malware Campaign
Mar 13, 2024

New Linux malware campaign targets misconfigured servers, ransomware actors diversify their exfiltration tools, and Cado reveals its top cloud threat findings report for 2H23.

CTI Roundup: CVEs on the Rise, TimbreStealer Malware, and a New Phishing Report
Mar 6, 2024

Researchers predict a 25% rise in CVEs, TimbreStealer malware spreads through phishing, and Proofpoint releases its 2024 State of the Phish report.

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS
Feb 21, 2024

Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise
Feb 14, 2024

Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram
Feb 7, 2024

DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware
Jan 31, 2024

Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware
Jan 24, 2024

Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack
Jan 18, 2024

AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.

CTI Roundup: Remcos RAT Phishing Attacks, New Meduza Stealer Found on Dark Web
Jan 10, 2024

CISA adds two bugs to the KEV catalog, UAC-0050 distributes Remcos RAT with phishing tactics, and an updated version of Meduza Stealer launches on the dark web.

CTI Roundup – top 2023 stories: The latest on Chae$ 4, 3AM ransomware, DarkGate, and Andariel
Jan 3, 2024

Tanium’s Cyber Threat Intelligence (CTI) team looks at some of the top cybersecurity developments from 2023 that will continue to pose threats in 2024.

CTI Roundup: TA4557, OAuth Cryptomining, and the China-based KEYPLUG backdoor
Dec 21, 2023

TA4557 targets recruiters via email, threat actors use OAuth apps to automate BEC and cryptomining attacks, and researchers discover Sandman APT’s connection to the China-based KEYPLUG backdoor.

CTI Roundup: Russian threat actor APT28 exploits Outlook vulnerability
Dec 13, 2023

APT28 exploits a critical Outlook vulnerability, QR phishing campaigns grow more complex, and an SQL brute force attack results in BlueSky ransomware.

Tanium–Blog-2.3.22-Naveen Goela’s Mission to Mature Security with Science
Dec 6, 2023

North Korean hackers pose as job seekers and recruiters, the Telekopye Telegram bot enables large-scale phishing scams, and DPRK-aligned threat actors target macOS in two campaigns.

CTI Roundup: AlphaLock, a New Russian Hacking Group is Discovered
Nov 21, 2023

Researchers discover a new Russian hacking group, Rhysida ransomware threatens multiple sectors, and a new campaign targets public Docker Engine APIs.

CTI Roundup: ChatGPT-Powered Infostealer Targets Cloud Platforms
Nov 16, 2023

Google Cloud releases its Q3 Threat Horizons report, BlueNoroff hacks macOS machines with ObjCshellz malware, and a ChatGPT-powered infostealer targets cloud platforms.

CTI Roundup: Hackers Target Crypto Experts with KANDYKORN Malware
Nov 8, 2023

Lazarus Group targets a software vendor, a link shortening service abuses the .US top-level domain, and hackers target crypto experts with KANDYKORN malware.

CTI Roundup: Ransomware Spikes in September, Updates on Octo Tempest & Quasar RAT
Nov 1, 2023

Octo Tempest threatens global organizations, ransomware activity spikes in September, and Quasar RAT evades detection with DLL sideloading.

CTI Roundup: North Korean Lazarus Group Exploits JetBrains TeamCity Flaw
Oct 25, 2023

BlackCat operators introduce Munchkin utility, North Korean threat actors exploit JetBrains TeamCity flaw, and threat actors target macOS with evolving techniques.

Image for MITRE ATT&CK blog post
Oct 18, 2023

Threat actors attempt moving laterally from SQL server to the cloud, ShellBot avoids detection in attacks on Linux SSH servers, and Smart Links attacks target Microsoft accounts.

CTI Roundup: The FBI takes down Qakbot and Bumblebee returns from hiatus
Oct 11, 2023

A look at the FBI’s recent Qakbot takedown, the return of Bumblebee after a two-month hiatus, and other developing cyberthreats from 2023.

stock image: face in dark room lit by glow of a computer monitor
Sep 27, 2023

Threat actors repurpose old code in fake vulnerability PoC, the FBI and CISA issue a joint advisory for Snatch RaaS, and threat actors deploy new SprySOCKS Linux malware in cyberespionage attacks.

CTI Roundup: Go Infostealers, 3AM Ransomware, & RedLine/Vidar Malware
Sep 21, 2023

New family of Go infostealers spreads in targeted attacks, researchers discover 3AM ransomware in the wild, and RedLine/Vidar threat actors pivot to ransomware.

CTI Roundup: Hackers Target Microsoft Teams with DarkGate Loader Malware
Sep 13, 2023

Hackers target Microsoft Teams with DarkGate Loader malware, phishing campaign leverages the new Agent Tesla variant, and Chaes malware uses the Chrome DevTools protocol to steal data.

CTI Roundup: Stop Making These Four Common Password Mistakes Now
Sep 6, 2023

Threat actors use misleading dates in phishing subject lines, four common password mistakes to avoid, and Earth Estries targets global governments and tech companies.

Tanium–Blog-2.3.22-Naveen Goela’s Mission to Mature Security with Science
Aug 29, 2023

XLoader macOS variant poses as a productivity app, Lazarus Group uses new malware, and threat actors abuse Facebook promotions to spread malicious code.

CTI Roundup: Monti ransomware targets VMware ESXi servers with new Linux locker
Aug 23, 2023

Raccoon Stealer malware reappears, AI adoption remains low among threat actors, and Monti ransomware targets VMware ESXi servers with new Linux locker

CTI Roundup: Rhysida Ransomware Threatens the Healthcare Sector
Aug 16, 2023

Cloud takeover campaign targets top-level executives, Rhysida ransomware threatens the healthcare sector, and LOLKEK ransomware continues to evolve.

CTI Roundup: Google AMP & Salesforce Exploited for Phishing Attacks
Aug 9, 2023

Threat actors abuse Google AMP for evasive phishing attacks, hackers exploit Salesforce’s email services in targeted Facebook phishing campaign, and Russian actor BlueCharlie alters infrastructure in response to disclosures.

CTI Roundup: Realst Malware targets MacOS, Infostealer Malware Sees Exponential Growth
Aug 2, 2023

Realst malware targets macOS Sonoma ahead of public release, infostealer malware sees exponential growth, and new Nitrogen malware spreads via Google Ads for ransomware attacks.

Image for MITRE ATT&CK blog post
Jul 26, 2023

Ransomware impersonates Sophos, FIN8 group uses modified backdoor to deliver BlackCat ransomware, and Chinese espionage actors continue to evolve.

CTI Roundup: Attacks Spike in 2023, Ransomware Payments Skyrocket
Jul 19, 2023

USB-based malware attacks spike during the first half of 2023, ransomware payments skyrocket, and Big Head ransomware accelerates.

CTI Roundup: Truebot infects US & Canada networks
Jul 12, 2023

Truebot infects networks throughout the US and Canada, Charming Kitten targets new operating systems, and SmugX targets European government entities.

CTI Roundup: North Korean Andariel Group Strikes With EarlyRat Malware
Jul 6, 2023

8Base ransomware activity spikes, China-linked Volt Typhoon APT uses novel tradecraft to gain initial access to target networks, and North Korean hacker group Andariel strikes with new EarlyRat malware.

CTI Roundup: New DoJ Cyber Unit Pursues State-Sponsored Threats
Jun 27, 2023

The DoJ launches a cyber unit to prosecute nation-state threat actors, cybercriminals use expired AWS S3 buckets to distribute malicious code, and a new exfiltration malware targets RDP workloads.

CTI Roundup: Skuld Malware Steals Discord Data From Windows PCs
Jun 21, 2023

Chinese hackers use DNS-over-HTTPS for Linux malware communication, a new Golang-based Skuld malware strand steals Discord and browser data from Windows PCs, and a massive phishing campaign uses 6,000 sites to impersonate brands.

CTI Roundup: North Korea’s Kimsuky Cyber Spies at it Again
Jun 14, 2023

Washington and Seoul expose North Korea’s Kimsuky cyber spies, the Asylum Ambuscade crimeware group conducts cyberespionage, and the Cyclops ransomware and stealer combo poses a dual threat.

CTI Roundup: Microsoft Finds a macOS Bug That Lets Hackers Bypass SIP Root Restrictions
Jun 7, 2023

Improved BlackCat ransomware variant strikes with lightning speed in stealthier attacks, Microsoft finds a macOS bug that lets hackers bypass SIP root restrictions, and Dark Pink hackers continue to target government and military organizations.

CTI Roundup: Russia, Iran, & North Korea Target Global SMBs
Jun 1, 2023

State-aligned threat actors target global SMBs, new PowerExchange malware backdoors Microsoft Exchange servers, and an IT security employee attempts to impersonate a ransomware gang during an attack on his own company.

CTI Roundup: Hackers target macOS systems with Cobalt Strike
May 24, 2023

Hackers use Golang variant of Cobalt Strike to target macOS systems, Cybercriminals adapt to Microsoft’s macro-blocking feature, and cybercriminals target the Microsoft VSCode Marketplace.

Image for MITRE ATT&CK blog post
May 16, 2023

CISA issues a joint advisory on Russia’s Snake malware operation, hackers use ChatGPT lures to spread malware on Facebook, and a new phishing-as-a-service tool appears in the wild.

CTI Roundup: Google Ads pushes new BumbleBee malware
May 3, 2023

A new SLP bug potentially enables massive DDoS amplification attacks, Google Ads pushes new BumbleBee malware, and Chinese hackers use Linux malware variants for espionage .

CTI Roundup: CCP-Sponsored APT41 Deploys Google GC2 for Attacks
Apr 25, 2023

APT41 leverages Google GC2, ransomware gangs abuse Process Explorer driver to kill security software, and new details regarding 3CX’s software supply chain compromise emerge.

CTI Roundup: Microsoft Warns About Mercury and DEV-1084 Attacks on Hybrid Environments
Apr 19, 2023

Microsoft’s security advisory on Mercury and DEV-1084 and a report linking Russian hackers to attacks against NATO and the EU.

CTI Roundup: Threat Actors Use Self-Extracting (SFX) Archives for Backdoor Attacks
Apr 12, 2023

A new SFX exploit enables stealthy backdoor attacks, an ALPHV ransomware affiliate is targeting Veritas Backup Exec, and CTI tracks the emergence of Rorschach ransomware.

CTI Roundup: How Weak is Your Password?
Apr 4, 2023

Key findings from the Specops 2023 Weak Password Report, a look at the recently exposed APT43 hacking group, and a breakdown of the New AlienFox toolkit.

CTI Roundup: New CISA tool detects hacking activity in Microsoft cloud services
Mar 29, 2023

A joint advisory on LockBit 3.0 ransomware, CISA’s latest tool which detects hacking activity in Microsoft cloud services, and ScarCruft’s evolving arsenal.

CTI Roundup: US Federal Agency Hacked Using Telerik
Mar 21, 2023

Hackers used the Telerik bug to breach a US federal agency, a suspected Chinese actor used the Fortinet zero-day along with custom malware to engage in cyberespionage, and the Tick advanced persistent threat (APT) group targeted the customers of an East Asian data loss prevention (DLP) company.

CTI Roundup: FBI and CISA Issue Royal Ransomware Warning
Mar 15, 2023

A joint FBI and CISA advisory on Royal ransomware, Sharp Panda’s new malware variant, and an update on IceFire ransomware.

CTI Roundup: Threat Actors Exploiting ChatGPT
Feb 28, 2023

Hackers use fake ChatGPT apps to push Windows and Android malware, attackers flood NPM repository with over 15,000 spam packages containing phishing links, and New Stealc malware emerges with a wide set of stealing capabilities.

CTI Roundup: Business Email Compromise Groups Go Global
Feb 21, 2023

BEC groups target companies worldwide, RedEyes hackers use new malware to steal data, and Devs targeted by W4SP Stealer malware in malicious PyPI packages.

CTI Roundup: ESXiArgs Ransomware Attacks Target VMware
Feb 14, 2023

The latest on ESXiArgs ransomware attacks, new QakNote attacks pushing QBot malware via Microsoft OneNote files, and Biden’s attention to data privacy in the State of the Union.

CTI Roundup: Threat Actors Use Sliver C2 Framework
Feb 1, 2023

Sliver’s growing popularity as an open-source C2 framework, Emotet’s comeback and new evasion techniques, and how Chinese hackers exploited a Fortinet flaw using a 0-Day.

CTI Roundup: Ransomware Profits Drop as Attacks Remain High
Jan 25, 2023

Reporting revealed declining ransomware profits in 2022, a new backdoor based on the CIA’s Hive malware is discovered, and a new wave of BackdoorDiplomacy attacks are targeting Iranian government entities.

CTI Roundup: Malicious PyPI Packages Bypass Firewalls
Jan 18, 2023

PyPI packages use Cloudflare tunnels to bypass firewalls, new Raspberry Robin malware variant targets financial institutions in Portugal and Spain, and IcedID malware strikes again.

Rising Trend in APT Hackers Using Excel Add-ins as Intrusion Vector
Jan 12, 2023

APT hackers turn to malicious Excel add-ins as initial intrusion vector, PurpleUrchin bypasses CAPTCHA and steals cloud platform resources, and Russia’s Turla APT piggybacks on other hackers’ USB infections

Attackers Turn to SVG Files to Distribute QBot Malware
Dec 19, 2022

How hackers are using SVG files to smuggle QBot malware onto Windows systems, a new batch of ransomware families leading attacks on Windows systems, and this year’s spike in command-and-control servers.

Machine Learning. Security Friend or Foe?
Dec 14, 2022

Recent advancements in machine learning, the latest on Black Proxies, and the DHS Cyber Safety Board’s plan to review Lapsus$ gang’s hacking tactics.

Qakbot Malware Attacks on the Rise: Cyber Threat Intelligence Roundup
Dec 7, 2022

An aggressive Qakbot/Black Basta campaign that’s targeting US organizations, the US ban on Huawei, Hikvision, ZTE, and Dahua equipment, and a new report that links Chrome, Defender, and Firefox exploitation frameworks to a Spanish IT firm.

‘Tis the Season for a New Phishing Scam: Cyber Threat Intelligence Roundup
Nov 30, 2022

Organizations prioritize third-party risk management and gauge their own third-party security postures, Chinese hackers use Google Drive to drop malware, and a new phishing kit targets US shoppers this holiday season.

Australia Considers Ban on Ransomware Payments: Cyber Threat Intelligence Roundup
Nov 21, 2022

A new APT41 subgroup, Australia’s plan to ban ransomware payments, and Twitter’s mounting security woes.

Info-stealing Malware in Software Supply Chains: Cyber Threat Intelligence Roundup
Nov 8, 2022

Info-stealing malware in software supply chains and key findings from KELA’s latest cybercrime prevention report.

New Solutions for Addressing Software Supply Chain Attacks - Cyber Threat Intelligence Roundup
Nov 4, 2022

A pro-China disinformation campaign targeting US elections, Google’s new GUAC open-source project, and the ongoing debate about password expiration.

Zimbra Zero-Day Flaw: Cyber Threat Intelligence Roundup
Oct 25, 2022

Zimbra’s new zero-day flaw, a Ursnif malware variant focuses on ransomware and data theft, and a stealthy PowerShell backdoor disguises itself as a Windows update.

Emotet Malware Resurfaces: Cyber Threat Intelligence Roundup
Oct 18, 2022

The resurgence of Emotet, the evolution of IcedID, and the new Alchimist framework targeting Windows, macOS, and Linux

Business Email Compromise Attacks on the Rise: Cyber Threat Intelligence Roundup
Oct 11, 2022

The rising trend of business email compromise, the latest on the popular Bumblebee loader, and an overview of fake Microsoft Exchange ProxyNotShell exploits, which are now for sale on GitHub.

Hackers Use PowerPoint Files for “Mouseover” Malware: Cyber Threat Intelligence Roundup
Oct 5, 2022

Hackers use PowerPoint files for mouse-hover malware delivery, Russia plans “massive cyberattacks” on critical infrastructure, and researchers uncover a covert attack campaign targeting military contractors.

The Rise of Phishing-as-a-Service: Cyber Threat Intelligence Roundup
Sep 14, 2022

The minimal impact of offensive hacks in the Russia - Ukraine conflict, a new EvilProxy phishing toolkit and Monti ransomware emerges.

Kimsuky’s New Malware Attack Strategy: Cyber Threat Intelligence Roundup
Sep 8, 2022

Kimsuky’s new strategy for evading security researchers, Chinese hackers use ScanBox malware to target the Australian government, and new ransomware called Agenda that’s customized for each victim.

Nobelium's New ‘MagicWeb’ Malware: Cyber Threat Intelligence Roundup
Aug 30, 2022

The latest on APT29’s new post-exploitation strategy, an ongoing campaign against U.S. and NATO-affiliated organizations, and how hackers are using the Sliver toolkit as a Cobalt Strike alternative.

The State of Ransomware in 2022: Cyber Threat Intelligence Roundup
Aug 23, 2022

Investigating ransomware data from the first half of 2022, the latest on information-stealing malware deployed by Russia’s Shuckworm APT, and a look at UNC3890 activity observed actively targeting Israeli organizations.

BazarCall, Yanluowang, BumbleBee: Cyber Threat Intelligence Roundup
Aug 17, 2022

An advisory about BazarCall, the latest on the Yanluowang ransomware attack against Cisco, and more in our cyber threat intelligence roundup.

Malicious Macros, Dark Utilities, LockBit: Tanium Cyber Threat Intelligence Roundup
Aug 9, 2022

Ransomware gangs are exploiting macros, threat actors are leveraging the Dark Utilities platform, and more in the cyber threat intelligence roundup.

New Report Reveals Commodity Malware Surpasses Ransomware: Cyber Threat Intelligence Roundup
Aug 2, 2022

Top incident response trends from Q2, a new 'CosmicStrand' UEFI rootkit, and Censys discovers evidence of Russia-based ransomware network in the U.S.

Russian APT29 Hackers Use Google Drive and Dropbox to Evade Detection: Cyber Threat Intelligence Roundup
Jul 27, 2022

Russian APT29 hackers are using Google Drive and Dropbox to evade detection, new CloudMensis spyware is targeting Apple macOS users, and more in our cyber threat intelligence roundup.

Ransomware Gangs Make Stolen Data Searchable: Cyber Threat Intelligence Roundup
Jul 19, 2022

Ransomware groups are making stolen data searchable, Qakbot malware attacks are on the rise, and more in our cyber threat intelligence roundup.

FBI and MI5 Issue Warning of China Spying: Cyber Threat Intelligence Roundup
Jul 12, 2022

FBI and MI5 warn of massive China threat, a new red-teaming tool is being abused by threat actors, and an emerging supply-chain-style attack top our latest threat intelligence roundup

Tanium Cyber Threat Intelligence Roundup
Jul 7, 2022

The latest emerging threats, advancements in adversarial tactics, and trends observed across the cyber threat landscape.

What You Need to Know About Microsoft Office Zero-Day Vulnerability Follina
Jun 1, 2022

New Microsoft Office zero-day (CVE-2022-30190) named Follina is being exploited in attacks by cybercriminals and state-sponsored APT groups.