Threats Tagged 'hidden execution'
View all threats tagged with 'hidden execution'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'hidden execution'
Click on any threat for detailed analysis and mitigation recommendations
Investigating a Multi-Stage PowerShell Loader 0 A multi-stage PowerShell loader campaign was identified involving heavily obfuscated PowerShell scripts hosted on Vercel infrastructure. The loaders retrieve and execute payloads such as Grape.exe, UltraToolliteSetup.exe, and draw.io.exe. Obfuscation techniques include Base64 encoding, XOR with the key 'Write', and dynamic IEX command construction. Victims see a decoy 'Verification complete!' message disguised as Google.com during execution. The initial infection vector is unknown, indicating these URLs serve as second-stage delivery points in the attack chain. Join the discussion | AlienVault OTX General | 08/10/2026, 14:20:36 UTC Added: 08/10/2026, 15:56:14 UTC |
Showing 1 to 1 of 1 result