Threats Tagged 'attribution'
View all threats tagged with 'attribution'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'attribution'
Click on any threat for detailed analysis and mitigation recommendations
A hybrid phishing threat combining Salty2FA and Tycoon2FA phishing kits has emerged, leveraging code and infrastructure from both frameworks. This hybridization appears driven by Salty2FA infrastructure failures, causing fallback to Tycoon2FA hosting and payload delivery. The overlap complicates attribution and weakens detection rules tailored to either kit alone. The threat is linked to the Storm-1747 adversary group, known for Tycoon2FA operations. Indicators include multiple suspicious domains used for hosting phishing pages. Defenders should update detection logic to address cross-kit overlaps and prepare for more resilient phishing campaigns that can adapt to infrastructure disruptions. The threat is rated medium severity and does not require exploits in the wild or CVSS scoring. European organizations should be vigilant due to the widespread use of 2FA and phishing susceptibility. Mitigation requires tailored detection updates, domain monitoring, and user awareness enhancements. Join the discussion | AlienVault OTX General | 12/02/2025, 21:13:43 UTC Added: 12/03/2025, 11:15:39 UTC |
RondoDox v2 is a significantly evolved botnet variant that has expanded its exploit capabilities by 650%, now leveraging over 75 CVEs across 16 different architectures. Originally targeting DVRs and routers, it has broadened its scope to include enterprise systems, indicating a shift towards more valuable targets. The botnet employs new command and control (C&C) infrastructure hosted on compromised residential IP addresses, complicating detection and takedown efforts. Although no known exploits are currently observed in the wild, the botnet's increased sophistication and scale pose a high risk. The threat actor is identifiable by an open signature email, and detailed technical analysis including dropper behavior, binary decoding, and detection rules are available. European organizations face heightened risk due to the targeting of enterprise systems and the widespread use of vulnerable devices. Mitigation requires targeted patch management, network segmentation, deployment of YARA and IDS/IPS rules, and enhanced monitoring of residential IP traffic. Countries with large enterprise sectors and significant IoT device usage, such as Germany, France, Italy, and the UK, are most likely to be affected. Given the high impact on confidentiality, integrity, and availability, ease of exploitation, and broad scope, this threat is assessed as high severity. Join the discussion | Reddit NetSec | 11/04/2025, 09:08:40 UTC Added: 11/04/2025, 09:13:51 UTC |
RondoDox v2 is an advanced IoT botnet that has significantly expanded its attack surface, now supporting over 15 exploitation vectors and targeting enterprise environments beyond consumer devices. It supports 16 different CPU architectures and uses XOR obfuscation to evade detection. Command and control infrastructure is hosted on compromised residential IPs and multiple AWS EC2 instances, indicating a sophisticated and distributed setup. This evolution from a simple DDoS botnet to an enterprise-ready threat raises concerns about its potential impact on critical infrastructure and business networks. Detection rules and IOCs are available, including YARA and Snort/Suricata signatures. Although no known exploits in the wild have been reported yet, the high number of exploit vectors and expanded target scope make it a high-severity threat. European organizations, especially those with extensive IoT deployments and cloud infrastructure, should be vigilant. Countries with large enterprise sectors and significant AWS usage are particularly at risk. Immediate mitigation steps include deploying updated detection signatures, network segmentation, and enhanced monitoring of IoT devices and cloud assets. Join the discussion | Reddit NetSec | 11/03/2025, 14:16:53 UTC Added: 11/03/2025, 14:21:05 UTC |
This analysis examines the Bookworm malware family and its connection to the Chinese APT group Stately Taurus. Using a structured attribution framework, the study evaluates tactics, tooling, operational security, infrastructure, victimology and timelines to establish a high-confidence link between Bookworm and Stately Taurus. Key evidence includes shared program database paths, overlapping command and control infrastructure, and consistent targeting of Southeast Asian governments. The framework assigns scores to each piece of evidence, resulting in an overall attribution confidence score of 58.4 out of 100, indicating strong confidence in the connection. This systematic approach aims to improve analytical rigor and collaboration in threat intelligence. Join the discussion | AlienVault OTX General | 09/25/2025, 14:11:18 UTC Added: 09/25/2025, 18:56:29 UTC |
Showing 1 to 4 of 4 results