Threats Tagged 'geofencing'
View all threats tagged with 'geofencing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'geofencing'
Click on any threat for detailed analysis and mitigation recommendations
In August 2026, a Casbaneiro campaign targeted Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The multi-stage infection chain includes HTA downloaders and AutoIt loaders, employing geofencing to filter victims by IP address location. The malware exhibits sophisticated evasion techniques, including distributed data-receiving servers, deliberate HTTP 403 responses, and activation only when victims access targeted banking websites. Casbaneiro steals email data, performs clipboard injection, and creates fake windows for fraudulent activities. The campaign specifically targets Argentina, Peru, Colombia, and Mexico while avoiding German, French, and English language systems. The malware splits stolen data across multiple servers and uses malformed HTTP packets to complicate detection and analysis efforts. Join the discussion | AlienVault OTX General | 09/10/2026, 17:27:46 UTC Added: 09/11/2026, 09:02:09 UTC |
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets. Join the discussion | AlienVault OTX General | 07/01/2026, 21:35:11 UTC Added: 07/02/2026, 07:06:43 UTC |
Savvy Seahorse, a DNS threat actor, employs sophisticated techniques to lure victims into fake investment platforms through Facebook ads. They use DNS CNAME records to create a traffic distribution system, enabling dynamic IP address updates and evasion of detection. The campaigns target multiple languages and involve fake ChatGPT and WhatsApp bots. Victims are convinced to create accounts, make deposits, and unknowingly transfer funds to Russian banks. The actor has been operating since August 2021, using dedicated hosting and frequently changing IP addresses. Their infrastructure includes approximately 4,200 base domains with CNAME records linked to subdomains of b36cname[.]site. The campaigns are short-lived, typically lasting 5-10 days per subdomain. MediumCampaign Join the discussion | AlienVault OTX General | 02/19/2026, 15:26:29 UTC Added: 02/19/2026, 18:01:12 UTC |
A compromised EmEditor installer was used in a software supply chain attack to deliver multistage malware. The attack, discovered in late December 2025, targeted users of this widely-used text editor. The malware performs credential theft, data exfiltration, and enables lateral movement. It uses obfuscated PowerShell scripts and geofencing techniques, suggesting possible Russian origin. The malware disables security features, gathers system information, and exfiltrates data to a command-and-control server. This incident highlights the importance of validating installer integrity, monitoring PowerShell usage, preserving endpoint telemetry, and enforcing least privilege principles. Software publishers are advised to secure download infrastructure and prepare incident response plans. Join the discussion | AlienVault OTX General | 01/23/2026, 11:47:40 UTC Added: 01/23/2026, 23:05:56 UTC |
A sophisticated espionage campaign targeting Indian entities has been identified, masquerading as the Income Tax Department of India. The activity is associated with the SideWinder APT group, which has evolved its toolkit to evade detection by mimicking Chinese enterprise software. The campaign uses DLL side-loading techniques with legitimate Microsoft Defender binaries to bypass EDR, and utilizes public cloud storage and URL shorteners to evade reputation-based detections. The threat actors employ geofencing behavior, focusing on systems in South Asian timezones. The attack chain includes phishing emails, fraudulent websites, and malicious payloads delivered through file-sharing services. The final stage involves a resident agent that beacons to a command-and-control server, mimicking Chinese endpoint tool protocols. Join the discussion | AlienVault OTX General | 12/20/2025, 17:19:05 UTC Added: 12/22/2025, 10:37:54 UTC |
The Hannibal Stealer is a sophisticated information-stealing malware, rebranded from Sharp and TX stealers. Developed in C#, it targets Chromium and Gecko-based browsers, extracting sensitive data while bypassing Chrome Cookie V20 protection. Its capabilities extend to cryptocurrency wallets, FTP clients, VPN credentials, and various system information. The malware includes a crypto clipper module and is controlled via a dedicated C2 panel. Sold on dark web forums, it employs geofencing, domain-matching, and comprehensive system profiling. The threat actor behind Hannibal Stealer has been linked to previous iterations, indicating minimal innovation beyond rebranding and updated communication methods. Active Telegram channels and control panels suggest ongoing operations and infrastructure maintenance. Join the discussion | AlienVault OTX General | 04/26/2025, 10:16:16 UTC Added: 05/26/2025, 10:07:43 UTC |
Showing 1 to 6 of 6 results