Threats Tagged 'enterprise targeting'
View all threats tagged with 'enterprise targeting'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'enterprise targeting'
Click on any threat for detailed analysis and mitigation recommendations
KongTuke, a threat actor tracked since 2025, has launched a new campaign using a malicious browser extension called NexShield that impersonates uBlock Origin Lite. The extension causes browser crashes and displays fake security warnings to trick users into executing malicious commands. The campaign targets both home and corporate users, with domain-joined machines receiving a more sophisticated Python-based RAT named ModeloRAT. The attack chain involves multiple stages of obfuscation, anti-analysis techniques, and a Domain Generation Algorithm (DGA) for C2 communication. KongTuke employs extensive fingerprinting to avoid detection in analysis environments. The campaign demonstrates evolving social engineering tactics and a focus on infiltrating enterprise networks for potential lateral movement and data exfiltration. Join the discussion | AlienVault OTX General | 01/17/2026, 13:17:09 UTC Added: 01/19/2026, 09:26:45 UTC |
The Gentlemen ransomware group has emerged as a sophisticated threat actor targeting multiple industries across 17 countries, with a focus on the Asia-Pacific region. Their campaign demonstrates advanced capabilities, including the use of custom tools to bypass enterprise endpoint protections, exploitation of legitimate drivers, Group Policy manipulation, and encrypted data exfiltration. The group's tactics involve thorough reconnaissance, adaptive defense evasion techniques, and systematic compromise of enterprise environments. They have shown the ability to tailor their approach based on the specific security solutions encountered, highlighting a significant evolution in ransomware operations. The attackers leveraged various tools and techniques for lateral movement, persistence, and ransomware deployment, including the abuse of privileged domain accounts and Group Policy Objects. Join the discussion | AlienVault OTX General | 09/09/2025, 11:34:12 UTC Added: 09/09/2025, 22:05:26 UTC |
Showing 1 to 2 of 2 results