Threats Tagged 'coroxy'
View all threats tagged with 'coroxy'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'coroxy'
Click on any threat for detailed analysis and mitigation recommendations
A large-scale attack infrastructure dubbed TruffleNet has been identified, built around the open-source tool TruffleHog. This infrastructure is used to systematically test compromised credentials and perform reconnaissance across AWS environments. The campaign involves over 800 unique hosts across 57 distinct Class C networks, characterized by consistent configurations and the use of Portainer. Alongside TruffleNet, adversaries are exploiting Amazon Simple Email Service (SES) to facilitate Business Email Compromise (BEC) campaigns. The attackers create email identities using compromised WordPress sites and conduct aggressive cloud reconnaissance. This activity highlights the evolving tactics of threat actors in exploiting cloud infrastructure at scale, combining credential theft, reconnaissance automation, and SES abuse to conduct high-volume fraud with minimal detection. Join the discussion | AlienVault OTX General | 11/01/2025, 10:24:25 UTC Added: 11/03/2025, 10:56:13 UTC |
Agenda ransomware group, also known as Qilin, has been deploying a Linux-based ransomware binary on Windows hosts using legitimate remote management and file transfer tools. This cross-platform execution technique bypasses Windows-centric detections and security solutions. The attack chain includes the use of BYOVD for defense evasion, deployment of multiple SOCKS proxy instances for C&C traffic obfuscation, and targeted theft of backup credentials. Agenda has affected 591 victims across 58 countries since January 2025, primarily targeting organizations in developed markets and high-value industries. The group's sophisticated approach combines legitimate tools, cross-platform execution, and strategic targeting of backup infrastructure, making detection significantly more challenging for organizations. Join the discussion | AlienVault OTX General | 10/23/2025, 13:51:01 UTC Added: 11/03/2025, 11:25:58 UTC |
Showing 1 to 2 of 2 results