Threats Tagged 'exfiltration'
View all threats tagged with 'exfiltration'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'exfiltration'
Click on any threat for detailed analysis and mitigation recommendations
TeamPCP uploaded malicious versions of the telnyx Python SDK to PyPI, compromising a package with 750,000 monthly downloads. The attack uses a three-stage architecture: a trojanized package triggers a platform-specific loader, which downloads a second-stage payload hidden in a WAV file using steganography, deploying a credential harvester. The harvester steals various credentials, encrypts them, and exfiltrates to the attacker's C2. The attack works across major operating systems and spreads through Kubernetes clusters. This is part of a broader TeamPCP supply chain campaign that has targeted multiple packages over nine days. The sophisticated attack includes WAV and PNG steganography, hybrid encryption, Kubernetes lateral movement, and a full-featured RAT on Windows with advanced evasion techniques. Join the discussion | AlienVault OTX General | 03/31/2026, 16:14:18 UTC Added: 04/08/2026, 11:05:57 UTC |
A new supply chain attack targeting Trivy has compromised 75 out of 76 version tags in the aquasecurity/trivy-action GitHub repository. The attacker force-pushed these tags to serve malicious payloads, effectively turning trusted version references into a distribution mechanism for an infostealer. The malicious code executes within GitHub Actions runners, targeting sensitive data in CI/CD environments. It harvests secrets from runner process memory and the filesystem, encrypts the collected data, and exfiltrates it to an attacker-controlled endpoint or a fallback GitHub-based channel. The attack's scope is significant, potentially affecting over 10,000 workflow files on GitHub referencing this action. Join the discussion | AlienVault OTX General | 03/20/2026, 09:51:35 UTC Added: 03/20/2026, 21:08:28 UTC |
This analysis delves into the Beast ransomware, a Ransomware-as-a-Service (RaaS) that emerged in June 2024 as a successor to Monster ransomware. The investigation focuses on a Beast ransomware server detected in March 2026, revealing the operators' toolkit and attack methodology. The toolkit includes various tools for reconnaissance, network mapping, credential theft, persistence, lateral movement, exfiltration, and impact. Notable findings include the presence of both Windows and Linux versions of Beast ransomware, indicating targeting of workstations and Linux servers on VMware ESXi hypervisors. The report highlights the importance of proactive collection of internet telemetry in identifying ransomware operators' toolkits before they can be used against targets. Join the discussion | AlienVault OTX General | 03/20/2026, 08:12:00 UTC Added: 03/20/2026, 08:23:29 UTC |
The Contagious Trader campaign is a sophisticated malware operation targeting cryptocurrency users, attributed to North Korea with high confidence. It involves malicious cryptocurrency trading bot projects on GitHub that exfiltrate sensitive data and private keys using various techniques, including malicious npm dependencies. The campaign demonstrates overlaps with known North Korean tactics, particularly those of FAMOUS CHOLLIMA, including the use of GitHub, npm, and Vercel infrastructure, Base64-encoded payload URLs, and anonymizing VPNs for npm package publishing. The operation represents a shift in tactics, expanding beyond the previous Contagious Interview campaign to target a broader range of cryptocurrency users. Join the discussion | AlienVault OTX General | 03/18/2026, 10:49:56 UTC Added: 03/18/2026, 11:12:34 UTC |
An active supply chain worm campaign, dubbed SANDWORM_MODE, is spreading through typosquatting and AI toolchain poisoning across at least 19 malicious npm packages. The worm exhibits Shai-Hulud characteristics, incorporating GitHub API exfiltration with DNS fallback, hook-based persistence, SSH propagation, and MCP server injection targeting AI coding assistants. It harvests credentials from developer and CI environments, exfiltrates data via multiple channels, and uses stolen identities to propagate. The campaign also includes a weaponized GitHub Action for CI secret harvesting. The worm employs a multi-stage design with obfuscated loaders, time-gated execution, and extensive configuration options. It targets high-traffic developer utilities, crypto tooling, and AI coding tools, posing a significant threat to the software supply chain. Join the discussion | AlienVault OTX General | 02/23/2026, 10:04:22 UTC Added: 02/23/2026, 10:16:19 UTC |
Operation MacroMaze, attributed to APT28 (Fancy Bear), targets entities in Western and Central Europe from September 2025 to January 2026. The campaign utilizes basic tools and legitimate services for infrastructure and data exfiltration. Multiple documents with varying macro variants act as droppers, establishing a foothold by creating files in the %USERPROFILE% folder. The attack chain involves VBScript execution, scheduled task creation for persistence, and a multi-stage process using batch files. Exfiltration is achieved through HTML-based techniques, leveraging webhook.site for data transmission. Despite its simplicity, the campaign demonstrates effective operational tradeoffs, making detection and attribution challenging. Join the discussion | AlienVault OTX General | 02/16/2026, 14:28:58 UTC Added: 02/17/2026, 16:15:34 UTC |
Operation MoneyMount is a Russian phishing campaign targeting finance and accounting sectors by delivering Phantom stealer malware through fake payment confirmation emails. The attack uses a ZIP file containing an ISO image; when mounted, it reveals an executable that loads the stealer. Phantom stealer employs anti-analysis techniques and steals sensitive data including cryptocurrency wallets, browser data, and Discord tokens. It also features keylogging and clipboard monitoring to capture additional credentials and information. Stolen data is exfiltrated via Telegram, Discord webhooks, or FTP, making detection and blocking more challenging. The use of ISO files for initial access helps evade traditional security controls. This campaign highlights the growing sophistication of commodity stealers and the strategic targeting of financial sectors. No known exploits in the wild or CVE identifiers are associated with this malware yet. The campaign’s medium severity reflects its targeted nature and complexity of attack chain. Join the discussion | AlienVault OTX General | 12/12/2025, 08:45:04 UTC Added: 12/12/2025, 13:12:01 UTC |
Shai-Hulud V2 is an advanced malware campaign targeting the npm software supply chain, compromising over 700 npm packages and creating more than 27,000 malicious GitHub repositories. It introduces sophisticated techniques including pre-install phase execution, persistent backdoors via self-hosted GitHub Actions runners, credential harvesting and recycling across victims, and a destructive failsafe mechanism. The malware exfiltrates data through GitHub and propagates within the npm ecosystem, also exploiting Azure DevOps build agents. This supply chain attack enables persistent remote code execution and widespread credential theft without requiring user interaction. European organizations relying on npm packages and GitHub Actions for CI/CD pipelines face significant risks of data breaches, system compromise, and operational disruption. Mitigation requires enhanced supply chain security practices, strict GitHub Actions runner controls, credential hygiene, and proactive monitoring for anomalous activity. Countries with strong software development sectors and high npm usage, such as Germany, France, the UK, and the Netherlands, are particularly vulnerable. Given its broad impact and advanced persistence mechanisms, the threat severity is assessed as high. Join the discussion | AlienVault OTX General | 12/03/2025, 08:47:16 UTC Added: 12/03/2025, 11:01:25 UTC |
Over the past few weeks, Rapid7 has observed increased activity of a new threat group attacking AWS cloud environments with the goal of data exfiltration and subsequent extortion of the victim. This threat group refers to itself as ‘Crimson Collective’ and has recently announced that it is behind an attack on Red Hat, wherein it claims to have stolen private repositories from Red Hat’s GitLab. Join the discussion | AlienVault OTX General | 10/10/2025, 17:12:14 UTC Added: 10/10/2025, 17:24:52 UTC |
LAB52 has identified a new backdoor called NotDoor, attributed to APT28, a Russian intelligence-linked threat group. NotDoor is a VBA macro for Outlook that monitors incoming emails for specific trigger words, enabling data exfiltration, file uploads, and command execution on victim computers. The backdoor is deployed via Microsoft OneDrive.exe using DLL side-loading, and it establishes persistence by modifying registry keys. NotDoor employs obfuscation techniques and a custom string encoding method. It can execute commands, exfiltrate files, and upload files to the victim's machine. The malware demonstrates APT28's continuous evolution in bypassing defense mechanisms, posing a significant threat to NATO member countries across various sectors. Join the discussion | AlienVault OTX General | 09/03/2025, 17:31:14 UTC Added: 09/03/2025, 19:47:48 UTC |
Showing 1 to 10 of 14 results