Skip to main content

Threats Tagged 'asia'

View all threats tagged with 'asia'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: asia

Threats Tagged 'asia'

Click on any threat for detailed analysis and mitigation recommendations

This intelligence report details a hybrid cryptocurrency investment scam campaign targeting users in Asia, particularly Japan. The scam combines malvertising techniques to attract victims with pig butchering tactics using AI-powered chatbots for sustained engagement. Victims are lured through social media ads impersonating financial experts, directed to lure websites, and then to messaging apps where automated bots manipulate them into making increasingly large investments. The campaign uses over 23,000 domains, many generated algorithmically, and shows signs of expanding globally. This approach represents a scalable, automated evolution of traditional investment fraud methods, potentially transforming labor-intensive scams into more efficient operations.

Join the discussion

UAT-8099 is a malware campaign active from August 2025 to early 2026 targeting vulnerable IIS servers, primarily in Asia, with a focus on Thailand and Vietnam. It uses web shells, PowerShell scripts, and the GotoHTTP tool to maintain persistent remote access. New BadIIS malware variants show enhanced persistence, regional customization, and SEO fraud capabilities, with a Linux ELF variant indicating cross-platform targeting. The campaign shares infrastructure with the WEBJACK campaign, suggesting operational overlap. Although no known exploits are reported in the wild, advanced evasion and persistence techniques pose risks to confidentiality, integrity, and availability. European organizations with exposed IIS servers, especially those with business ties to Asia, should be vigilant. Targeted detection of web shells, PowerShell abuse, and monitoring for GotoHTTP traffic are critical mitigations. Germany, France, and the UK are most likely affected due to IIS usage and strategic interests in Asia.

Join the discussion

Phantom Taurus, a newly identified Chinese state-sponsored threat actor, has been conducting espionage operations targeting government and telecommunications organizations across Africa, the Middle East, and Asia. The group's primary focus includes ministries of foreign affairs, embassies, and military operations, with the objective of gathering sensitive information. Phantom Taurus employs distinctive tactics, techniques, and procedures, including a new malware suite called NET-STAR. This suite consists of three web-based backdoors designed to target Internet Information Services (IIS) web servers. The group has recently shifted from targeting emails to directly accessing databases, demonstrating their ability to adapt and evolve their methods. Phantom Taurus' activities align with Chinese strategic interests, and their infrastructure overlaps with other known Chinese APT groups.

Join the discussion

A sophisticated backdoor targeting Exchange servers of high-value organizations in Asia has been discovered. The malware, named GhostContainer, is a multi-functional backdoor that can be dynamically extended with additional modules. It leverages several open-source projects and employs various evasion techniques to avoid detection. The backdoor grants attackers full control over the Exchange server and can function as a proxy or tunnel. The malware is believed to be part of an APT campaign targeting government and high-tech companies in Asia. It includes components for C2 parsing, virtual page injection, and web proxy functionality. The attackers demonstrated expertise in exploiting Exchange systems and assembling sophisticated espionage tools.

Join the discussion

A newly emerged ransomware group called BERT has been targeting organizations across Asia and Europe since April. The group employs simple code with effective execution, impacting sectors such as healthcare, technology, and event services. BERT's ransomware operates on both Windows and Linux platforms, using PowerShell-based loaders, privilege escalation, and concurrent file encryption. On Linux systems, it can support up to 50 threads for fast encryption and forcibly shut down ESXi virtual machines. The group's tactics include disabling security features, terminating specific processes, and using standard encryption algorithms. BERT's variants have evolved, streamlining their encryption process and expanding their targeting activities. The Linux variant shows similarities to the REvil ransomware, suggesting possible code reuse.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: asia
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses