Threats Tagged 'cloud infrastructure'
View all threats tagged with 'cloud infrastructure'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cloud infrastructure'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-46316 is a guest-to-host escape vulnerability in the vGIC-ITS emulation within KVM on ARM64 platforms. It is caused by a race condition in the vgic_its_invalidate_cache() function leading to a double-put use-after-free, which allows execution of code in the host kernel context. This flaw resides in the in-kernel KVM module, enabling successful exploitation to gain host kernel privileges. The vulnerability affects multi-tenant ARM64 cloud environments and can be chained with local privilege escalation when guest root access is unavailable. A patch fixing this vulnerability was applied in the Linux kernel at commit 13031fb6b835. Two YARA rules have been developed to detect exploitation attempts based on specific constants and behavioral patterns. There are no known exploits in the wild as of the latest information. Join the discussion | AlienVault OTX General | 06/12/2026, 16:57:58 UTC Added: 06/15/2026, 18:45:13 UTC |
The 'Artemis' campaign, conducted by APT37, utilizes malicious HWP documents with embedded OLE objects to initiate attacks. The threat actor impersonates legitimate entities to gain trust before delivering the payload. The attack chain combines HWP execution with DLL side-loading techniques to evade detection. Steganography is employed to conceal malicious code, and legitimate processes are abused to load malicious DLLs. The campaign targets South Korean organizations, exploiting the widespread use of the HWP format. Multiple stages of encryption and decryption are used to obfuscate the final RoKRAT payload. The threat actor leverages cloud services like Yandex and pCloud for command and control infrastructure, complicating detection and attribution efforts. Join the discussion | AlienVault OTX General | 12/22/2025, 03:59:37 UTC Added: 12/22/2025, 10:37:54 UTC |
This report details two interconnected malware campaigns targeting Chinese-speaking users in 2025, using large-scale brand impersonation to deliver Gh0st RAT variants. The first campaign, active from February to March, mimicked three brands across over 2,000 domains. The second campaign, starting in May, impersonated over 40 applications with more sophisticated infection chains. Both campaigns used cloud infrastructure for payload delivery and DLL side-loading for evasion. The adversary demonstrated an evolving operational playbook, advancing from simple droppers to complex multi-stage infections. The campaigns' infrastructure remained active for months, indicating a persistent and well-resourced threat actor focused on Chinese-speaking targets globally. MediumMalware Join the discussion | AlienVault OTX General | 11/15/2025, 05:58:39 UTC Added: 11/17/2025, 09:32:29 UTC |
A large-scale attack infrastructure dubbed TruffleNet has been identified, built around the open-source tool TruffleHog. This infrastructure is used to systematically test compromised credentials and perform reconnaissance across AWS environments. The campaign involves over 800 unique hosts across 57 distinct Class C networks, characterized by consistent configurations and the use of Portainer. Alongside TruffleNet, adversaries are exploiting Amazon Simple Email Service (SES) to facilitate Business Email Compromise (BEC) campaigns. The attackers create email identities using compromised WordPress sites and conduct aggressive cloud reconnaissance. This activity highlights the evolving tactics of threat actors in exploiting cloud infrastructure at scale, combining credential theft, reconnaissance automation, and SES abuse to conduct high-volume fraud with minimal detection. Join the discussion | AlienVault OTX General | 11/01/2025, 10:24:25 UTC Added: 11/03/2025, 10:56:13 UTC |
Skeleton Spider, also known as FIN6, is a financially motivated cybercrime group that has evolved from POS breaches to broader enterprise threats. They employ social engineering tactics, posing as job seekers on platforms like LinkedIn to deliver phishing messages. Their preferred payload is more_eggs, a JavaScript-based backdoor. The group uses trusted cloud services like AWS to host malicious infrastructure, evading detection. Their phishing emails impersonate job applicants, with domains mimicking real names. FIN6 employs sophisticated filtering techniques to ensure malware delivery only to intended targets. The more_eggs malware, developed by Venom Spider, allows for command execution and credential theft. Defense strategies include cautious handling of resume links, blocking execution of suspicious files, and implementing EDR policies. Join the discussion | AlienVault OTX General | 06/11/2025, 09:28:26 UTC Added: 06/11/2025, 10:01:03 UTC |
Showing 1 to 5 of 5 results