Skip to main content

Threats Tagged 'campaign'

View all threats tagged with 'campaign'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: campaign

Threats Tagged 'campaign'

Click on any threat for detailed analysis and mitigation recommendations

A Chinese-speaking threat actor group known as Red Heron exploited a recently disclosed remote code execution vulnerability (CVE-2026-60004) in Gitea, a self-hosted Git service, in a multinational campaign. The campaign targeted internet-facing Gitea instances across multiple countries, including Canada, Argentina, Taiwan, the United States, and Sri Lanka, focusing on sectors such as defense, elections, energy, aerospace, telecommunications, government, and research. The attackers used automated tools to steal source code, credentials, and maintain persistent access, including root-level control on some infrastructure. They deployed a novel Linux implant named JITTERLY with extensive post-exploitation capabilities and embedded a previously undocumented rootkit called SIXZUT to maintain stealth and persistence. The campaign demonstrates rapid weaponization of n-day vulnerabilities in development platforms and highlights significant risks to source code confidentiality and infrastructure integrity.

Join the discussion

A threat actor exploited CVE-2026-15409, a critical unauthenticated server-side request forgery vulnerability in SonicWall SMA1000 appliances, to gain command execution and steal credentials. The attacker used a modified public proof-of-concept exploit to access internal Erlang services on the appliance, enabling remote code execution. This allowed extraction of LDAP configurations, Active Directory credentials, and deployment of tools to dump secrets from internal Windows systems. The campaign targeted at least 250 SonicWall SMA1000 devices across multiple countries and sectors, with confirmed credential theft in France, India, Italy, and the US. The attack leveraged compromised appliances as pivots into internal networks, exposing sensitive Active Directory data and enabling DCSync attacks against domain controllers. The targeting was opportunistic and technology-driven rather than sector-specific. The campaign was uncovered through an open directory left exposed by the attacker, providing a comprehensive view of the operation.

Join the discussion

A large-scale distributed denial-of-service (DDoS) campaign targeted AI Weekly following their investigative reporting on Meta's advertising partner GatherOne and associated nudify apps with child-safety concerns. The attack generated roughly four billion HTTP requests, primarily targeting the specific investigative article. The campaign caused significant server resource exhaustion, including maxing out Nginx worker connections, filling disk storage, and causing numerous server errors and job failures. The attack persisted in waves, shifting focus from the article to the homepage when mitigated, and returning weeks later. There is no evidence implicating Meta, GatherOne, or related entities in orchestrating the attacks. The campaign weaponized infrastructure to disrupt reporting rather than engage in direct rebuttal or criticism.

Join the discussion

A large-scale phishing campaign used invisible Unicode characters from the deprecated Unicode Tags block to obfuscate keywords related to loans and financing, bypassing email filters that rely on contiguous ASCII string matching. The campaign sent between 1 million and 2.37 million messages daily at its peak in early 2026, primarily targeting recipients with fraudulent loan offers. The messages were routed through the legitimate marketing platform ActiveCampaign, leveraging its reputation to evade detection. There is no software vulnerability or patch associated with this technique; it exploits differences in how email clients and filters process Unicode text. Mitigation requires enhanced email filtering that inspects raw Unicode content and flags or removes invisible characters to detect obfuscated phishing keywords.

Join the discussion

This report analyzes a scam campaign observed through the lens of a URL shortener service. The campaign involved three short links that collectively received nearly 90,000 clicks in 48 hours. The destination URLs employed sophisticated cloaking techniques, including user-agent checks, Selenium/Puppeteer detection, ad blocker detection, mouse movement sampling, and device fingerprinting to evade detection and only target real human victims. Attempts to block the malicious destination were circumvented by the attackers quickly reusing the same short links with new domains forwarding to the same scam content. The URL shortener operator implemented a fix by reserving purged slugs to prevent reuse. This analysis provides insight into the evasive tactics used in this scam campaign and the challenges in detecting it.

Join the discussion

A malware campaign targeting Indian users leverages a GST-themed lure to distribute ValleyRAT, a remote access trojan. The campaign uses a Microsoft-signed executable for DLL sideloading, employs process injection, UAC bypass, and security product tampering to evade detection. It features keylogging, screenshot capture, clipboard theft, and multiple command-and-control endpoints with a complex delivery infrastructure. The campaign is actively analyzed with indicators of compromise and infrastructure details published.

Join the discussion

This content is a request posted on Reddit seeking repositories or datasets containing samples of malicious email campaigns. The user references existing resources like phishing_pot on GitHub and malware-traffic-analysis.net but is looking for collections of multiple emails from the same campaign. There is no specific vulnerability or exploit detailed in this content.

Join the discussion

This analysis covers a Windows-targeted cyber campaign involving social engineering via fake interviews leading to cryptocurrency theft. The campaign notably did not use DPRK malware but leveraged known malware-as-a-service (MaaS) tools and unidentified Go and Rust-based stealers and remote access trojans (RATs). The threat actor may be using DPRK tradecraft as a false flag to confuse attribution, possibly indicating Russian operators. The campaign targets web3 organizations and involves a multi-stage payload delivery chain using signed ClickOnce applications.

Join the discussion

A large-scale adware campaign involving over 700 Chrome extensions linked to the operators Ovkas, Gameograf, and Kidswallpapers/Owhit has been identified. These extensions, primarily wallpaper-related, engage in ad fraud by generating unauthorized ad impressions and exhibit malicious behaviors such as deleting browser IndexedDB data and injecting unsanitized HTML popups. The campaign has over 30,000 installs, with most extensions still active on the Chrome Web Store and distributed via grayware websites employing bot protection. The extensions also track uninstall events to enable retargeting. Evidence suggests the extensions were likely authored using AI coding agents. Only a few extensions have been removed so far, indicating ongoing risk to users.

Join the discussion

SeasonalInvite is a phishing campaign identified in 2026 that abuses commercial Remote Monitoring and Management (RMM) tools and eCards to conduct social engineering attacks aligned with seasonal events. The campaign has been active since at least January 2026 and leverages legitimate RMM software to facilitate malicious activity. There is no specific patch or fix since this is a phishing campaign exploiting social engineering and tool misuse rather than a software vulnerability. Organizations are advised to maintain strict control and inventory of approved RMM tools to mitigate risk.

Join the discussion

Showing 1 to 10 of 96 results

Filters:Tag: campaign
Page 1 of 10
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses