Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "svchost.exe"
Click on any threat for detailed analysis and mitigation recommendations
A phishing campaign targets Indian organizations by impersonating the Indian Income Tax Department. Victims receive emails containing links to spoofed notice pages that download ZIP archives. These archives include a legitimately signed Overwolf executable and two hidden files: a malicious DLL and an encrypted binary. When executed, the signed binary side-loads the malicious DLL through DLL hijacking. The DLL is UPX-packed and modified with Astral-PE, and decrypts the binary file containing ValleyRAT. The payload uses modified RC4 encryption with a 115-byte key and deploys entirely in memory. Once active, ValleyRAT establishes persistence through scheduled tasks masquerading as OneDrive entries, marks dropped files as hidden and system files, and performs process hollowing into svchost.exe to evade detection before connecting to command and control infrastructure. Join the discussion | AlienVault OTX General | 08/18/2026, 15:23:42 UTC Added: 08/18/2026, 20:04:25 UTC |
A Windows 11 host running svchost.exe generated unusual DNS queries including google.com.onion, wildcard, and malformed domains within a very short time frame. These queries returned NXDOMAIN responses and did not lead to any follow-up connections or IP resolutions. The behavior resembles synthetic or malformed DNS queries rather than user-initiated activity and is similar to DNS probing or spoof detection patterns observed on other devices. The source of these queries under svchost.exe is unclear, and it is uncertain whether this is normal Windows DNS client behavior, network validation, or triggered by security tools. No confirmed malicious activity or exploit is reported. Join the discussion | Reddit BlueTeam | 06/18/2026, 13:07:39 UTC Added: 06/18/2026, 13:20:03 UTC |
In July-August 2025, India faced a surge of cross-border cyberattacks combining data breaches, DDoS, defacement, phishing, and malware. Pakistani, Bangladeshi, Russian, Indonesian, and likely Chinese actors targeted Indian judicial, defense, and transport systems. High-impact incidents included judicial server breaches, government website disruptions, retaliatory defacements, phishing schemes, and malware campaigns. Indian groups retaliated under 'Operation Vasudev Strike'. The attacks demonstrated the growing scale, sophistication, and multinational nature of hacktivist operations targeting India's digital infrastructure, blending hacktivism and cybercrime to challenge national security and public trust. Join the discussion | AlienVault OTX General | 09/15/2025, 18:48:16 UTC Added: 09/15/2025, 19:20:01 UTC |
A new ransomware variant named Crux has been identified, claiming association with the BlackByte group. Observed in three separate incidents, Crux encrypts files with a .crux extension and leaves ransom notes. Initial access appears to involve Remote Desktop Protocol (RDP) using valid credentials. The ransomware executable, with varying names and locations, follows a distinct process tree involving svchost.exe, cmd.exe, and bcdedit.exe. It disables system recovery to hinder restoration attempts. Data exfiltration using Rclone was observed in one incident. The threat actor demonstrates prior knowledge of targeted infrastructures and prefers using legitimate Windows processes. While claiming BlackByte affiliation, this hasn't been independently verified. Join the discussion | AlienVault OTX General | 07/21/2025, 08:15:21 UTC Added: 07/21/2025, 08:31:05 UTC |
Showing 1 to 4 of 4 results