Author
Tanium Cyber Threat Intelligence Team

CTI roundup: SantaStealer, BlackForce, Ink Dragon
SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

CTI roundup: Shanya, GrayBravo, Storm-0249
Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

CTI roundup: Hybrid 2FA phishing, RomCom, MuddyWater
Hybrid 2FA phishing threatens enterprises, RomCom uses SocGholish to deploy Mythic Agent malware, and MuddyWater targets critical infrastructure with evolving tactics

CTI roundup: Whisper Leak, @acitons/artifact, Quantum Route Redirect
Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

CTI roundup: RMM abuse, SesameOp, Google’s 2026 Cybersecurity Forecast
Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

CTI roundup: DragonForce, Qilin, Water Saci
Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

CTI roundup: Famous Chollima, COLDRIVER, Vidar Stealer 2.0
Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities

CTI roundup: Astaroth, TA585, Microsoft tech support scams
Astaroth trojan uses GitHub to host malware configurations, TA585 delivers MonsterV2 malware in phishing campaigns, and threat actors exploit Microsoft’s logo in tech support scams

CTI roundup: XWorm, Microsoft Teams, Storm-1175
XWorm malware reemerges with ransomware, Microsoft disrupts multiple threats targeting Teams, and Storm-1175 exploits a critical GoAnywhere MFT vulnerability

CTI roundup: DarkCloud, Trinity of Chaos, WARMCOOKIE
Check out the latest insights on DarkCloud malware, the “Trinity of Chaos” alliance, and WARMCOOKIE updates.

CTI Roundup: SystemBC, ShinyHunters, AI-obfuscated Phishing
SystemBC botnet targets VPS infrastructure, ShinyHunters targets enterprise cloud applications, and a phishing campaign uses AI-generated code to avoid detection

CTI Roundup: AMOS, TAG-150, GPUGate
AMOS Stealer campaign targets macOS, TAG-150 deploys new CastleRAT malware, and GPUGate targets IT firms in Western Europe

CTI Roundup: HexStrike AI, TinkyWinkey, Silver Fox APT
The latest on HexStrike AI, TinkyWinkey’s keylogging, and Silver Fox APT’s driver abuse bypassing endpoint defenses.

CTI Roundup: Linux Malware, UNC5518, PRC-Nexus
New Linux malware evades antivirus detection, UNC5518 deploys CORNFLAKE.V3 using ClickFix and fake CAPTCHA pages, and a PRC-Nexus campaign hijacks web traffic.

CTI Roundup: Malicious Python Packages, PipeMagic, Noodlophile Stealer
Researchers uncover malicious Python packages, PipeMagic masquerades as a ChatGPT desktop app, and Noodlophile Stealer targets enterprises through social media

CTI Roundup: EDR Killer, PS1Bot, Charon Ransomware
Ransomware groups adopt shared EDR-killing tool, PS1Bot spreads via malvertising, and Charon ransomware uses APT-style tactics to target critical sectors

CTI Roundup: ClickFix, New Attacker Insights, PXA Stealer
Discover how attackers hijack CAPTCHAs, why CVE activity spikes matter, and global PXA threats.

CTI Roundup: Katz Stealer, Lumma, NailaoLocker
Katz Stealer seeks credentials and crypto assets, Lumma Stealer returns after a disruption, NailaoLocker ransomware targets Windows

CTI Roundup: BlackSuit, AsyncRAT, HazyBeacon
BlackSuit ransomware combines data exfiltration and encryption, AsyncRAT spawns multiple forks, and HazyBeacon abuses AWS Lambda for command and control

CTI Roundup: BERT Ransomware, TGR-CRI-0045, XWorm
Get the latest on BERT ransomware, TGR-CRI-0045 exploits, and XWorm’s stealthy evolution in this week’s CTI roundup.

CTI Roundup: GIFTEDCROOK, H1 2025 Threats, Jasper Sleet
Get the latest on GIFTEDCROOK’s evolution, Jasper Sleet’s infiltration tactics, and rising cyber threats in ESET’s H1 2025 report.

CTI Roundup: Rogue Tools, ClickFix, and BlueNoroff
Cyber attackers exploit legitimate tools, ClickFix attacks accelerate, and BlueNoroff targets macOS devices

CTI Roundup: UNC6032, APT41, Void Blizzard
The latest on UNC6032 fake AI websites, APT41’s use of Google Calendar, and Void Blizzard targeting critical sectors.

CTI Roundup: Hazy Hawk, Remcos RAT, and npm Phishing
Recent news on Hazy Hawk using DNS records, a fileless Remcos RAT campaign, and the use of AES encryption with malicious npm packages in phishing attack.

CTI Roundup: Marbled Dust, Horabot, and TA406
Learn about Marbled Dust exploiting a zero-day vulnerability in Output Messenger, a new phishing campaign using Horabot malware, and TA406 changing targets.

CTI Roundup: Luna Moth, Venom Spider, StealC V2
Updates on Luna Moth threatening U.S. legal and financial firms, Venom Spider targeting hiring managers and recruiters, and StealC malware getting upgrades.

CTI Roundup: Infostealers, Zero-Day Attacks, and Gremlin Stealer
The latest news on infostealers, Google observing 75 zero-day exploits in 2024, and new threat Gremlin Stealer.

CTI Roundup: Deepfakes, ToyMaker IAB, and ClickFix
Recent news about threat actors using real-time deepfakes to land remote work, ToyMaker initial access broker, and state-sponsored hackers using ClickFix.

CTI Roundup: SMS Phishing, Node.js, and Fake PDF Converters
The latest news about threat actors exploiting SMS with social engineering, misusing Node.js for malware, and fake PDF converters delivering malware.

CTI Roundup: Email Attacks, Hunters International, and New Ransomware Data
Read the latest news about attacks combining credential phishing and malware, Hunters International pivoting to data extortion, and ransomware trends.

CTI Roundup: QR Code Phishing, Babuk Locker 2.0, and Qilin
QR code phishing accelerates, LockBit 3.0 rebrands, and Qilin affiliates target downstream customers of an MSP.

CTI Roundup: StilachiRAT, Reddit Infostealers, and New Password Reuse Data
The latest information about StilachiRAT malware, AMOS and Lumma stealers spreading via Reddit, and research on how many logins use compromised passwords.

CTI Roundup: Malvertising, XCSSET Variant, and GitHub Abuse
The latest news about a malvertising campaign threatening devices, XCSSET variant, and an ongoing campaign using fake GitHub repositories to spread malware.

CTI Roundup: Silk Typhoon, Fake Ransom Notes, and ClickFix
The latest cyber threat news on Silk Typhoon shifting tactics, threat actors targeting executives with physical ransom notes, and the ClickFix trick.

CTI Roundup: Auto-Color Malware, Vulnerable Windows Driver, and Lotus Blossom
Latest news about Auto-color Linux malware, attackers exploiting Truesight.sys, and Lotus Blossom.

CTI Roundup: Ferret Malware, macOS Stealers, and MS Power BI
Learn about North Korean hackers targeting job seekers, growing macOS infostealers, and MS Power BI phishing.

CTI Roundup: New TorNet Backdoor, Lynx Ransomware, and Q4 Trends
The latest on an ongoing TorNet backdoor campaign, Lynx ransomware group's advanced affiliate program, and Cisco Talos' Q4 incident response trends report.

CTI Roundup: 2024 Ransomware Recap, Breached Passwords, and O365 Exploits
Learn what researchers have to say about ransomware trends from 2024, as well as new insights on stolen passwords and two recent O365 attacks.

CTI Roundup: FunkSec, Malvertising, and Fake Software
News about FunkSec ransomware, a recent malvertising scam targeting Google Ads users, and threat actors using fake software and installers to push malware.

CTI Roundup: PayPal Phishing, PLAYFULGHOST, and NonEuclid
The latest on a PayPal impersonation phishing campaign, PLAYFULGHOST malware, and the new NonEuclid RAT.

CTI Roundup: Earth Koshchei, RiseLoader, and a New Ransomware Advisory
Earth Koshchei executes rogue RDP attacks, Zscaler releases technical details about RiseLoader malware, and Corvus issues a ransomware advisory.

CTI Roundup: Seasonal Phishing, Zloader, and Secret Blizzard
The latest news around threat actors impersonating HR in a seasonal phishing campaign, Zloader's new features and capabilities, and Secret Blizzard.

CTI Roundup: Rockstar 2FA, RevC2 and Venom Loader, and SmokeLoader Malware
Rockstar 2FA targets M365 users, new RevC2and Venom Loader malware, and SmokeLoader reappears.

CTI Roundup: Sophos vs. Chinese Threat Actors, CRON#TRAP Linux VM, Bing Phishing Campaign
Learn about ongoing battles between Sophos and multiple Chinese threat actors, CRON#TRAP infecting Windows with Linux VMs, and Bing being used for phishing.

CTI Roundup: Scattered Spider and RansomHub Partner, Infostealer Malware Bypasses Chrome Patches, Evasive Panda Back in the News
Latest news on Scattered Spider and RansomHub, infostealers evading Chrome defenses, and Evasive Panda.

CTI Roundup: Gophish Toolkit Phishing, Malicious Virtual Hard Drive Files, Return of Bumblebee Malware
Learn about the Gophish toolkit for phishing, attackers bypassing secure email gateways and antivirus scanners, and the return of Bumblebee malware.

CTI Roundup: Callback Phishing, Time-to-Exploit Trends, and PureLogs Infostealer
Learn about threat actors spreading malware via callback phishing, Mandiant's analysis of time-to-exploit trends, and PureLogs targeting Chrome browsers.

CTI Roundup: Rise in File Hosting Services Misuse, Mamba 2FA, and Dark Angels Ransomware Attacks
News around Microsoft attacks using file hosting services, phishing campaigns mimicking Microsoft 365 login pages, and Dark Angels ransomware group updates.

CTI Roundup: Sniper Dz, Elastic 2024 Global Threat Report Insights, and Andariel Financial Attacks
Latest news around Sniper Dz, insights from Elastic Security Labs 2024 Global Threat Report, and Andariel financial attacks against U.S. organizations.

CTI Roundup: North Korean-Sponsored Remote IT Workers, Legitimate Sites Sending Spam, and Political Deepfakes
North Korea exploiting remote roles, third-party infrastructure used to send spam, and insights from new deepfakes report.

CTI Roundup: HTTP Headers Phishing Technique, Scattered Spider Back in the News, and UNC2970 Targets Job Seekers
Learn about a phishing campaign using HTTP headers, Scattered Spider, and UNC2970 exploiting job seekers.

CTI Roundup: Emansrepo Infostealer and Earth Lusca Multiplatform Backdoor
Emansrepo Stealer spreads via email, Palo Alto sheds light on top-level domains, and Earth Lusca deploys a new multiplatform backdoor.

CTI Roundup: Xeon Sender Targets Cloud APIs and MoonPeak Malware Updates
Xeon Sender targets cloud APIs, Cisco Talos reveals UAT-5394 infrastructure, and attackers leverage public .env files to extort victims.

CTI Roundup: Mad Liberator Ransomware Targets AnyDesk Users
New tools appear in ongoing social engineering campaign, Mad Liberator ransomware targets AnyDesk users, and Bitdefender explores the evolving cybercriminal underground.

CTI Roundup: SharpRhino RAT Threatens IT Admins, Phishers Leverage Google Drawings and WhatsApp Links
SharpRhino RAT threatens IT admins, ransomware gangs ramp up pressure on targets, and a new phishing scam leverages Google Drawings and WhatsApp links.

CTI Roundup: Cisco Talos Q2 IR Trends Report, New GenAI Scams on the Horizon
Cisco Talos releases its Q2 IR trends report, ransomware groups target ESXi flaw, and scammers exploit GenAI in domain registration and network attacks.

CTI Roundup: Evasive Panda Deploys New Malware, Macma Backdoor and Nightdoor
Evasive Panda deploys new versions of Macma backdoor and Nightdoor, cybercriminals work independently after RaaS takedowns, and a new Linux Play variant targets VMware ESXi systems.

CTI Roundup: MuddyWater Deploys BugSleep Malware, New Attack From Void Banshee
MuddyWater deploys BugSleep malware, researchers discover malicious files on the npm registry, and Void Banshee exploits a Microsoft MHTML flaw.

CTI Roundup: Threat Actor Updates. APT40, CloudSorcerer, Eldorado
APT40 rapidly exploits network vulnerabilities, CloudSorcerer APT targets Russian organizations, and Eldorado threatens Windows and Linux systems.

CTI Roundup: FakeBat Loader-as-a-Service, ESET H1 2024 Threat Report
FakeBat loader spreads via multiple infection chains, and ESET releases its threat report from the first half of 2024.

CTI Roundup: Busy Days for Threat Actors ONNX Store, Boolka, & SneakyChef
ONNX Store targets the financial industry, Boolka delivers the BMANAGER trojan via SQLi attacks, and SneakyChef deploys SpiceRAT and SugarGh0st.

CTI Roundup: Vortax Spreads Infostealer Malware, Linux Malware Uses Emojis to Execute Commands
Vortax spreads infostealer malware, new malware campaign distributes fake error messages, and Linux malware uses emojis to execute commands.

CTI Roundup: Windows HTML Malware, Remcos RAT, & Black Basta Ransomware
CTI reports a malware campaign utilizing Windows search in HTML, Remcos RAT via UUE files, and a Black Basta ransomware exploit of a Windows vulnerability.

CTI Roundup: TargetCompany Ransomware, LilacSquid Cyber Espionage, & DarkGate Malware
TargetCompany’s Linux variant threatens ESXi environments, LilacSquid targets multiple sectors, and DarkGate malware switches from Autolt to AutoHotkey.

CTI Roundup: Social Engineering, DNS Tunneling, & Malvertising
Beware of an ongoing campaign targeting enterprises and other current cyber threat news to know.

CTI Roundup: Q1 Exploit Trends, HijackLoader, & the State of Pentesting
Kaspersky reveals the top exploit and vulnerability trends for the first quarter of 2024, HijackLoader evolves with new evasion techniques, and Cobalt releases its 2024 State of Pentesting report.

CTI Roundup: Cuttlefish Malware, Hackers Leverage Docker Hub
Cuttlefish malware targets SOHO routers, nation states and cybercriminals share compromised networks, and threat actors use Docker Hub to spread malware and phishing scams.

CTI Roundup: ToddyCat APT, GuptiMiner Malware, APT28 Exploits a Windows Print Spooler Flaw
ToddyCat deploys advanced tools for industrial scale data theft, hackers use eScan updates to spread GuptiMiner malware, and Russia’s APT28 exploits a Windows Print Spooler flaw.

CTI Roundup: A Malicious Notepad++ Plugin, “Junk Gun” Ransomware, and a Google Malvertising Campaign
Researchers discover modified Notepad++ plug-in, new junk gun ransomware appears on cybercrime forums, and a malvertising campaign targets IT teams.

CTI Roundup: LockBit Update, Earth Freybug Deploys UNAPIMON Malware
Law enforcement’s impact on LockBit, how unpatched vulnerabilities contribute to ransomware attacks, and Earth Freybug deploys UNAPIMON malware.

CTI Roundup: Tycoon Phishing-as-a-Service and TheMoon Malware Update
Researchers discover a new version of the Tycoon 2FA AiTM kit, a phishing attack disguises keylogger as bank payment notice, and TheMoon malware targets ASUS routers.

CTI Roundup: Fake Google Sites Pages, Hackers Target Global Governments
Hackers spread malware through fake Google Sites pages, cybercriminals exploit APIs, and an APT campaign targets global government entities.

CTI Roundup: 12 Million Secrets and Keys Leak on GitHub
BianLian threat actors exploit JetBrains TeamCity flaws, ransomware attacks continue to accelerate, and more than 12 million secrets and keys leak on GitHub.

CTI Roundup: Linux Servers Target of New Malware Campaign
New Linux malware campaign targets misconfigured servers, ransomware actors diversify their exfiltration tools, and Cado reveals its top cloud threat findings report for 2H23.

CTI Roundup: CVEs on the Rise, TimbreStealer Malware, and a New Phishing Report
Researchers predict a 25% rise in CVEs, TimbreStealer malware spreads through phishing, and Proofpoint releases its 2024 State of the Phish report.

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS
Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise
Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram
DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware
Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware
Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack
AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.

CTI Roundup: Remcos RAT Phishing Attacks, New Meduza Stealer Found on Dark Web
CISA adds two bugs to the KEV catalog, UAC-0050 distributes Remcos RAT with phishing tactics, and an updated version of Meduza Stealer launches on the dark web.

CTI Roundup – top 2023 stories: The latest on Chae$ 4, 3AM ransomware, DarkGate, and Andariel
Tanium’s Cyber Threat Intelligence (CTI) team looks at some of the top cybersecurity developments from 2023 that will continue to pose threats in 2024.

CTI Roundup: TA4557, OAuth Cryptomining, and the China-based KEYPLUG backdoor
TA4557 targets recruiters via email, threat actors use OAuth apps to automate BEC and cryptomining attacks, and researchers discover Sandman APT’s connection to the China-based KEYPLUG backdoor.

CTI Roundup: Russian threat actor APT28 exploits Outlook vulnerability
APT28 exploits a critical Outlook vulnerability, QR phishing campaigns grow more complex, and an SQL brute force attack results in BlueSky ransomware.

CTI Roundup: Multiple Cyber Threats from North Korean Groups and a Telegram Bot Phishing Scam
North Korean hackers pose as job seekers and recruiters, the Telekopye Telegram bot enables large-scale phishing scams, and DPRK-aligned threat actors target macOS in two campaigns.

CTI Roundup: AlphaLock, a New Russian Hacking Group is Discovered
Researchers discover a new Russian hacking group, Rhysida ransomware threatens multiple sectors, and a new campaign targets public Docker Engine APIs.

CTI Roundup: ChatGPT-Powered Infostealer Targets Cloud Platforms
Google Cloud releases its Q3 Threat Horizons report, BlueNoroff hacks macOS machines with ObjCshellz malware, and a ChatGPT-powered infostealer targets cloud platforms.

CTI Roundup: Hackers Target Crypto Experts with KANDYKORN Malware
Lazarus Group targets a software vendor, a link shortening service abuses the .US top-level domain, and hackers target crypto experts with KANDYKORN malware.

CTI Roundup: Ransomware Spikes in September, Updates on Octo Tempest & Quasar RAT
Octo Tempest threatens global organizations, ransomware activity spikes in September, and Quasar RAT evades detection with DLL sideloading.

CTI Roundup: North Korean Lazarus Group Exploits JetBrains TeamCity Flaw
BlackCat operators introduce Munchkin utility, North Korean threat actors exploit JetBrains TeamCity flaw, and threat actors target macOS with evolving techniques.

CTI Roundup: Smart Links Attacks Target Microsoft Accounts
Threat actors attempt moving laterally from SQL server to the cloud, ShellBot avoids detection in attacks on Linux SSH servers, and Smart Links attacks target Microsoft accounts.

CTI Roundup: The FBI takes down Qakbot and Bumblebee returns from hiatus
A look at the FBI’s recent Qakbot takedown, the return of Bumblebee after a two-month hiatus, and other developing cyberthreats from 2023.

CTI Roundup: FBI and CISA Issue a Joint Advisory for Snatch RaaS
Threat actors repurpose old code in fake vulnerability PoC, the FBI and CISA issue a joint advisory for Snatch RaaS, and threat actors deploy new SprySOCKS Linux malware in cyberespionage attacks.

CTI Roundup: Go Infostealers, 3AM Ransomware, & RedLine/Vidar Malware
New family of Go infostealers spreads in targeted attacks, researchers discover 3AM ransomware in the wild, and RedLine/Vidar threat actors pivot to ransomware.

CTI Roundup: Hackers Target Microsoft Teams with DarkGate Loader Malware
Hackers target Microsoft Teams with DarkGate Loader malware, phishing campaign leverages the new Agent Tesla variant, and Chaes malware uses the Chrome DevTools protocol to steal data.

CTI Roundup: Stop Making These Four Common Password Mistakes Now
Threat actors use misleading dates in phishing subject lines, four common password mistakes to avoid, and Earth Estries targets global governments and tech companies.

CTI Roundup: An XLoader macOS variant, Lazarus Group Update, and Hackers Abuse Facebook Ads
XLoader macOS variant poses as a productivity app, Lazarus Group uses new malware, and threat actors abuse Facebook promotions to spread malicious code.

CTI Roundup: Monti ransomware targets VMware ESXi servers with new Linux locker
Raccoon Stealer malware reappears, AI adoption remains low among threat actors, and Monti ransomware targets VMware ESXi servers with new Linux locker

CTI Roundup: Rhysida Ransomware Threatens the Healthcare Sector
Cloud takeover campaign targets top-level executives, Rhysida ransomware threatens the healthcare sector, and LOLKEK ransomware continues to evolve.

CTI Roundup: Google AMP & Salesforce Exploited for Phishing Attacks
Threat actors abuse Google AMP for evasive phishing attacks, hackers exploit Salesforce’s email services in targeted Facebook phishing campaign, and Russian actor BlueCharlie alters infrastructure in response to disclosures.

CTI Roundup: Realst Malware targets MacOS, Infostealer Malware Sees Exponential Growth
Realst malware targets macOS Sonoma ahead of public release, infostealer malware sees exponential growth, and new Nitrogen malware spreads via Google Ads for ransomware attacks.

CTI Roundup: Ransomware Impersonates Cybersecurity Firm, Espionage Tactics Evolve in China
Ransomware impersonates Sophos, FIN8 group uses modified backdoor to deliver BlackCat ransomware, and Chinese espionage actors continue to evolve.

CTI Roundup: Attacks Spike in 2023, Ransomware Payments Skyrocket
USB-based malware attacks spike during the first half of 2023, ransomware payments skyrocket, and Big Head ransomware accelerates.

CTI Roundup: Truebot infects US & Canada networks
Truebot infects networks throughout the US and Canada, Charming Kitten targets new operating systems, and SmugX targets European government entities.

CTI Roundup: North Korean Andariel Group Strikes With EarlyRat Malware
8Base ransomware activity spikes, China-linked Volt Typhoon APT uses novel tradecraft to gain initial access to target networks, and North Korean hacker group Andariel strikes with new EarlyRat malware.

CTI Roundup: New DoJ Cyber Unit Pursues State-Sponsored Threats
The DoJ launches a cyber unit to prosecute nation-state threat actors, cybercriminals use expired AWS S3 buckets to distribute malicious code, and a new exfiltration malware targets RDP workloads.

CTI Roundup: Skuld Malware Steals Discord Data From Windows PCs
Chinese hackers use DNS-over-HTTPS for Linux malware communication, a new Golang-based Skuld malware strand steals Discord and browser data from Windows PCs, and a massive phishing campaign uses 6,000 sites to impersonate brands.

CTI Roundup: North Korea’s Kimsuky Cyber Spies at it Again
Washington and Seoul expose North Korea’s Kimsuky cyber spies, the Asylum Ambuscade crimeware group conducts cyberespionage, and the Cyclops ransomware and stealer combo poses a dual threat.

CTI Roundup: Microsoft Finds a macOS Bug That Lets Hackers Bypass SIP Root Restrictions
Improved BlackCat ransomware variant strikes with lightning speed in stealthier attacks, Microsoft finds a macOS bug that lets hackers bypass SIP root restrictions, and Dark Pink hackers continue to target government and military organizations.

CTI Roundup: Russia, Iran, & North Korea Target Global SMBs
State-aligned threat actors target global SMBs, new PowerExchange malware backdoors Microsoft Exchange servers, and an IT security employee attempts to impersonate a ransomware gang during an attack on his own company.

CTI Roundup: Hackers target macOS systems with Cobalt Strike
Hackers use Golang variant of Cobalt Strike to target macOS systems, Cybercriminals adapt to Microsoft’s macro-blocking feature, and cybercriminals target the Microsoft VSCode Marketplace.

CTI Roundup: Hackers Use ChatGPT Lures to Spread Malware on Facebook
CISA issues a joint advisory on Russia’s Snake malware operation, hackers use ChatGPT lures to spread malware on Facebook, and a new phishing-as-a-service tool appears in the wild.

CTI Roundup: Google Ads pushes new BumbleBee malware
A new SLP bug potentially enables massive DDoS amplification attacks, Google Ads pushes new BumbleBee malware, and Chinese hackers use Linux malware variants for espionage .

CTI Roundup: CCP-Sponsored APT41 Deploys Google GC2 for Attacks
APT41 leverages Google GC2, ransomware gangs abuse Process Explorer driver to kill security software, and new details regarding 3CX’s software supply chain compromise emerge.

CTI Roundup: Microsoft Warns About Mercury and DEV-1084 Attacks on Hybrid Environments
Microsoft’s security advisory on Mercury and DEV-1084 and a report linking Russian hackers to attacks against NATO and the EU.

CTI Roundup: Threat Actors Use Self-Extracting (SFX) Archives for Backdoor Attacks
A new SFX exploit enables stealthy backdoor attacks, an ALPHV ransomware affiliate is targeting Veritas Backup Exec, and CTI tracks the emergence of Rorschach ransomware.

CTI Roundup: How Weak is Your Password?
Key findings from the Specops 2023 Weak Password Report, a look at the recently exposed APT43 hacking group, and a breakdown of the New AlienFox toolkit.

CTI Roundup: New CISA tool detects hacking activity in Microsoft cloud services
A joint advisory on LockBit 3.0 ransomware, CISA’s latest tool which detects hacking activity in Microsoft cloud services, and ScarCruft’s evolving arsenal.

CTI Roundup: US Federal Agency Hacked Using Telerik
Hackers used the Telerik bug to breach a US federal agency, a suspected Chinese actor used the Fortinet zero-day along with custom malware to engage in cyberespionage, and the Tick advanced persistent threat (APT) group targeted the customers of an East Asian data loss prevention (DLP) company.

CTI Roundup: FBI and CISA Issue Royal Ransomware Warning
A joint FBI and CISA advisory on Royal ransomware, Sharp Panda’s new malware variant, and an update on IceFire ransomware.

CTI Roundup: Threat Actors Exploiting ChatGPT
Hackers use fake ChatGPT apps to push Windows and Android malware, attackers flood NPM repository with over 15,000 spam packages containing phishing links, and New Stealc malware emerges with a wide set of stealing capabilities.

CTI Roundup: Business Email Compromise Groups Go Global
BEC groups target companies worldwide, RedEyes hackers use new malware to steal data, and Devs targeted by W4SP Stealer malware in malicious PyPI packages.

CTI Roundup: ESXiArgs Ransomware Attacks Target VMware
The latest on ESXiArgs ransomware attacks, new QakNote attacks pushing QBot malware via Microsoft OneNote files, and Biden’s attention to data privacy in the State of the Union.

CTI Roundup: Threat Actors Use Sliver C2 Framework
Sliver’s growing popularity as an open-source C2 framework, Emotet’s comeback and new evasion techniques, and how Chinese hackers exploited a Fortinet flaw using a 0-Day.

CTI Roundup: Ransomware Profits Drop as Attacks Remain High
Reporting revealed declining ransomware profits in 2022, a new backdoor based on the CIA’s Hive malware is discovered, and a new wave of BackdoorDiplomacy attacks are targeting Iranian government entities.

CTI Roundup: Malicious PyPI Packages Bypass Firewalls
PyPI packages use Cloudflare tunnels to bypass firewalls, new Raspberry Robin malware variant targets financial institutions in Portugal and Spain, and IcedID malware strikes again.

Rising Trend in APT Hackers Using Excel Add-ins as Intrusion Vector
APT hackers turn to malicious Excel add-ins as initial intrusion vector, PurpleUrchin bypasses CAPTCHA and steals cloud platform resources, and Russia’s Turla APT piggybacks on other hackers’ USB infections

Attackers Turn to SVG Files to Distribute QBot Malware
How hackers are using SVG files to smuggle QBot malware onto Windows systems, a new batch of ransomware families leading attacks on Windows systems, and this year’s spike in command-and-control servers.

Machine Learning. Security Friend or Foe?
Recent advancements in machine learning, the latest on Black Proxies, and the DHS Cyber Safety Board’s plan to review Lapsus$ gang’s hacking tactics.

Qakbot Malware Attacks on the Rise: Cyber Threat Intelligence Roundup
An aggressive Qakbot/Black Basta campaign that’s targeting US organizations, the US ban on Huawei, Hikvision, ZTE, and Dahua equipment, and a new report that links Chrome, Defender, and Firefox exploitation frameworks to a Spanish IT firm.

‘Tis the Season for a New Phishing Scam: Cyber Threat Intelligence Roundup
Organizations prioritize third-party risk management and gauge their own third-party security postures, Chinese hackers use Google Drive to drop malware, and a new phishing kit targets US shoppers this holiday season.

Australia Considers Ban on Ransomware Payments: Cyber Threat Intelligence Roundup
A new APT41 subgroup, Australia’s plan to ban ransomware payments, and Twitter’s mounting security woes.

Info-stealing Malware in Software Supply Chains: Cyber Threat Intelligence Roundup
Info-stealing malware in software supply chains and key findings from KELA’s latest cybercrime prevention report.

New Solutions for Addressing Software Supply Chain Attacks - Cyber Threat Intelligence Roundup
A pro-China disinformation campaign targeting US elections, Google’s new GUAC open-source project, and the ongoing debate about password expiration.

Zimbra Zero-Day Flaw: Cyber Threat Intelligence Roundup
Zimbra’s new zero-day flaw, a Ursnif malware variant focuses on ransomware and data theft, and a stealthy PowerShell backdoor disguises itself as a Windows update.

Emotet Malware Resurfaces: Cyber Threat Intelligence Roundup
The resurgence of Emotet, the evolution of IcedID, and the new Alchimist framework targeting Windows, macOS, and Linux

Business Email Compromise Attacks on the Rise: Cyber Threat Intelligence Roundup
The rising trend of business email compromise, the latest on the popular Bumblebee loader, and an overview of fake Microsoft Exchange ProxyNotShell exploits, which are now for sale on GitHub.

Hackers Use PowerPoint Files for “Mouseover” Malware: Cyber Threat Intelligence Roundup
Hackers use PowerPoint files for mouse-hover malware delivery, Russia plans “massive cyberattacks” on critical infrastructure, and researchers uncover a covert attack campaign targeting military contractors.

The Rise of Phishing-as-a-Service: Cyber Threat Intelligence Roundup
The minimal impact of offensive hacks in the Russia - Ukraine conflict, a new EvilProxy phishing toolkit and Monti ransomware emerges.

Kimsuky’s New Malware Attack Strategy: Cyber Threat Intelligence Roundup
Kimsuky’s new strategy for evading security researchers, Chinese hackers use ScanBox malware to target the Australian government, and new ransomware called Agenda that’s customized for each victim.

Nobelium's New ‘MagicWeb’ Malware: Cyber Threat Intelligence Roundup
The latest on APT29’s new post-exploitation strategy, an ongoing campaign against U.S. and NATO-affiliated organizations, and how hackers are using the Sliver toolkit as a Cobalt Strike alternative.

The State of Ransomware in 2022: Cyber Threat Intelligence Roundup
Investigating ransomware data from the first half of 2022, the latest on information-stealing malware deployed by Russia’s Shuckworm APT, and a look at UNC3890 activity observed actively targeting Israeli organizations.

BazarCall, Yanluowang, BumbleBee: Cyber Threat Intelligence Roundup
An advisory about BazarCall, the latest on the Yanluowang ransomware attack against Cisco, and more in our cyber threat intelligence roundup.

Malicious Macros, Dark Utilities, LockBit: Tanium Cyber Threat Intelligence Roundup
Ransomware gangs are exploiting macros, threat actors are leveraging the Dark Utilities platform, and more in the cyber threat intelligence roundup.

New Report Reveals Commodity Malware Surpasses Ransomware: Cyber Threat Intelligence Roundup
Top incident response trends from Q2, a new 'CosmicStrand' UEFI rootkit, and Censys discovers evidence of Russia-based ransomware network in the U.S.

Russian APT29 Hackers Use Google Drive and Dropbox to Evade Detection: Cyber Threat Intelligence Roundup
Russian APT29 hackers are using Google Drive and Dropbox to evade detection, new CloudMensis spyware is targeting Apple macOS users, and more in our cyber threat intelligence roundup.

Ransomware Gangs Make Stolen Data Searchable: Cyber Threat Intelligence Roundup
Ransomware groups are making stolen data searchable, Qakbot malware attacks are on the rise, and more in our cyber threat intelligence roundup.

FBI and MI5 Issue Warning of China Spying: Cyber Threat Intelligence Roundup
FBI and MI5 warn of massive China threat, a new red-teaming tool is being abused by threat actors, and an emerging supply-chain-style attack top our latest threat intelligence roundup

Tanium Cyber Threat Intelligence Roundup
The latest emerging threats, advancements in adversarial tactics, and trends observed across the cyber threat landscape.

What You Need to Know About Microsoft Office Zero-Day Vulnerability Follina
New Microsoft Office zero-day (CVE-2022-30190) named Follina is being exploited in attacks by cybercriminals and state-sponsored APT groups.