Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "explorer.exe"
Click on any threat for detailed analysis and mitigation recommendations
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the server-supplied length (req_fsize) instead of cb. A malicious or compromised RDP server can return an oversized CB_FILECONTENTS_RESPONSE, causing an out-of-bounds write of attacker-controlled data into the paste consumer's heap buffer when a user pastes server-offered clipboard file contents. Join the discussion | GCVE Database | 08/02/2026, 13:16:00 UTC Added: 08/02/2026, 21:27:07 UTC |
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns. Join the discussion | AlienVault OTX General | 07/12/2026, 22:28:10 UTC Added: 07/13/2026, 10:32:46 UTC |
CVE-2026-25880 is a high-severity vulnerability in SumatraPDF versions 3.5.2 and earlier, involving an untrusted search path weakness (CWE-426). When a user opens a PDF and clicks File → “Show in folder”, the application executes a binary named explorer.exe located in the same directory as the PDF without proper validation. This allows an attacker to place a malicious executable in the PDF’s folder, leading to arbitrary code execution with the current user's privileges. Exploitation requires user interaction limited to clicking the menu option, with no additional warnings. The vulnerability affects Windows systems running vulnerable SumatraPDF versions. Although no known exploits are reported in the wild yet, the ease of exploitation and high impact on confidentiality, integrity, and availability make this a significant threat. European organizations using SumatraPDF on Windows should prioritize patching or mitigating this issue to prevent potential compromise. Join the discussion | CVE Database V5 | 02/09/2026, 21:10:59 UTC Added: 02/09/2026, 21:31:17 UTC |
Threat actors exploited Cloudflare's free-tier infrastructure and Python environments to deploy AsyncRAT, demonstrating advanced evasion techniques. The attack begins with phishing emails containing Dropbox links to malicious files. It uses legitimate Python downloads and sophisticated code injection targeting explorer.exe. The campaign ensures persistence through multiple vectors, including startup folder scripts and WebDAV mounting. It abuses trusted infrastructure like Cloudflare to mask activities and evade detection. The attackers employ social engineering tactics, such as displaying legitimate PDF documents, to reduce suspicion. This campaign highlights the trend of abusing cloud services for malware delivery and execution, emphasizing the need for multi-layered security approaches. Join the discussion | AlienVault OTX General | 01/12/2026, 20:30:28 UTC Added: 01/13/2026, 16:11:30 UTC |
DarkComet RAT malware has resurfaced disguised as a fake Bitcoin-related tool, distributed via a RAR archive containing a UPX-packed executable. Upon execution, it installs itself as 'explorer.exe' in the user's AppData folder and establishes persistence through a registry run key. The malware communicates with its command and control server at kvejo991.ddns.net on port 1604. It performs keylogging, storing captured keystrokes in a dedicated folder, and uses process injection into notepad.exe to evade detection. The malware also spawns multiple cmd.exe and conhost. Join the discussion | AlienVault OTX General | 11/14/2025, 12:09:29 UTC Added: 11/14/2025, 12:31:21 UTC |
A new two-stage malware named LeakyInjector and LeakyStealer has been identified, targeting cryptocurrency wallets and browser history. LeakyInjector uses low-level APIs for injection to avoid detection and injects LeakyStealer into explorer.exe. LeakyStealer implements a polymorphic engine to modify its memory area at runtime. Both stages were signed with valid Extended Validation certificates. The malware performs reconnaissance on infected machines, targeting multiple crypto wallets, including browser extensions, and searches for browser history files from various browsers. It establishes persistence through registry manipulation and beacons to the C2 server at regular intervals. The malware exfiltrates sensitive data and can execute additional commands received from the C2 server. Join the discussion | AlienVault OTX General | 11/07/2025, 09:02:26 UTC Added: 11/07/2025, 09:22:45 UTC |
0 Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privileges opens the crafted backup file and proceeds to mount it, Reflect launches the renamed executable (e.g., explorer.exe), which is under attacker control. This occurs because of insufficient validation of companion files referenced during backup mounting. Join the discussion | CVE Database V5 | 08/04/2025, 00:00:00 UTC Added: 08/04/2025, 18:47:41 UTC |
Showing 1 to 7 of 7 results