Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
HAProxy backdoor attributed to North Korea ran undetected inside two South Korean organizations for nine to ten months, using ...
Russia GRU espionage campaign targeting NATO defense and diplomatic networks in Romania, Spain, and Turkey deployed the ...
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno JavaScript and TypeScript runtime to execute ...
Cisco Talos has uncovered a cryptocurrency theft campaign that abuses Google Sheets and the Google Visualization API as a command-and-control (C2) channel. The attackers use ClickFix-style social ...
A new DCRat campaign is using a familiar image format to hide a dangerous malware archive. The operation begins with phishing emails that pose as legal notifications and urge recipients to open an ...
BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments.