Threats Affecting Thailand
View all threats affecting or targeting Thailand. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Thailand
Click on any threat for detailed analysis and mitigation recommendations
Uncovering a Global Android Carrier Billing Fraud Campaign 0 A sophisticated Android malware campaign has been identified conducting carrier billing fraud through premium SMS abuse across Malaysia, Thailand, Romania, and Croatia. The operation comprises nearly 250 malicious applications that selectively target users based on their mobile operators, silently subscribing victims to premium services without consent. The malware demonstrates advanced capabilities including precise regional targeting with hardcoded SIM operator validation, automated subscription workflows using WebView manipulation and JavaScript injection, OTP interception via abuse of Google's SMS Retriever API, and Telegram-based exfiltration of device metadata. The campaign impersonates popular applications including Facebook, Instagram, TikTok, Minecraft, and Grand Theft Auto to lure victims. Active from March 2025 through January 2026, the operation employs three distinct variants with increasing levels of sophistication, utilizing distributed command and control infrastructure and systematic refer... Join the discussion | AlienVault OTX General | 05/20/2026, 22:37:47 UTC Added: 05/21/2026, 16:59:45 UTC |
Beyond Tax Returns: How Shared Malware Infrastructure Scales Brand Abuse In Indonesia 0 A sophisticated fraud campaign exploiting Indonesia's tax season targeted 67 million residents through fake Coretax applications distributed via phishing websites and WhatsApp social engineering. The GoldFactory threat cluster orchestrated operations using Gigabud.RAT and MMRat malware families with shared infrastructure abusing over 16 trusted brands across government and financial sectors. The attack chain combines vishing, screen recording, and remote access capabilities to achieve device compromise and unauthorized financial transfers. Estimated financial impact reaches USD 1.5-2 million nationwide, with global implications extending to USD 6 million annually across multiple countries. The industrialized malware-as-a-service infrastructure enables horizontal scaling across Thailand, Vietnam, Philippines, and South Africa, demonstrating a shift toward unified cross-border operations that systematically undermine trust in digital government services. Join the discussion | AlienVault OTX General | 05/20/2026, 12:33:54 UTC Added: 05/21/2026, 16:29:45 UTC |
Vendor Says Daemon Tools Supply Chain Attack Contained 0 The software developer has identified the impacted systems, removed potentially compromised files, and validated installation packages. The post Vendor Says Daemon Tools Supply Chain Attack Contained appeared first on SecurityWeek . Join the discussion | SecurityWeek | 05/07/2026, 13:21:02 UTC Added: 05/07/2026, 13:22:46 UTC |
Supply chain attack via DAEMON Tools | Kaspersky official blog 0 Kaspersky experts have detected a supply chain attack using the popular DAEMON Tools software. Join the discussion | Kaspersky Security Blog | 05/05/2026, 12:09:52 UTC Added: 05/05/2026, 12:23:38 UTC |
CVE-2026-30643: n/aCVE-2026-30643 0 An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. Join the discussion | CVE Database V5 | 04/01/2026, 00:00:00 UTC Added: 04/01/2026, 18:38:25 UTC |
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets 0 Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment. The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8. […] The post Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets appeared first on Check Point Research . Join the discussion | Check Point Research | 03/31/2026, 13:16:50 UTC Added: 03/31/2026, 20:38:27 UTC |
A cunning predator: How Silver Fox preys on Japanese firms this tax season 0 Silver Fox, a threat actor, is exploiting Japan's tax filing and organizational change season with a targeted spearphishing campaign against Japanese businesses. The group sends convincing phishing emails related to tax compliance, salary adjustments, and HR matters, tricking recipients into opening malicious links or attachments. The campaign capitalizes on the high volume of legitimate financial and HR communications during this period, increasing the risk of compromise. Silver Fox has expanded its targets from Chinese-speaking entities to Southeast Asia, Japan, and potentially North America. The group uses ValleyRAT, a remote access trojan, to gain control of compromised machines and steal sensitive information. To protect against this threat, organizations should increase vigilance, reinforce awareness about phishing attempts, and verify the authenticity of tax- and HR-themed requests. Join the discussion | AlienVault OTX General | 03/28/2026, 16:12:50 UTC Added: 03/30/2026, 10:08:15 UTC |
CVE-2026-4960: Stack-based Buffer Overflow in Tenda AC6CVE-2026-4960 0 A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. Join the discussion | CVE Database V5 | 03/27/2026, 16:09:34 UTC Added: 03/27/2026, 18:04:01 UTC |
CVE-2026-4961: Stack-based Buffer Overflow in Tenda AC6CVE-2026-4961 0 A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Join the discussion | CVE Database V5 | 03/27/2026, 16:09:39 UTC Added: 03/27/2026, 17:44:46 UTC |
CVE-2026-29839: n/aCVE-2026-29839 0 DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php. Join the discussion | CVE Database V5 | 03/24/2026, 00:00:00 UTC Added: 03/24/2026, 16:01:47 UTC |
Showing 1 to 10 of 599 results