Threats Tagged 'homoglyphs'
View all threats tagged with 'homoglyphs'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'homoglyphs'
Click on any threat for detailed analysis and mitigation recommendations
A malware campaign discovered on the NuGet package repository targets the cryptocurrency ecosystem by distributing 14 malicious packages impersonating legitimate crypto-related tools. These packages employ techniques such as homoglyphs, version bumping, and inflated download counts to appear trustworthy and evade detection. The malware aims to steal crypto funds by redirecting transactions and exfiltrating secrets, including OAuth tokens for Google Ads accounts. The campaign highlights the risks of software supply chain attacks, especially for projects relying on compromised dependencies. No known exploits in the wild have been reported yet, but the threat poses a significant risk to developers and organizations integrating these packages. The attack affects . NET developers using NuGet packages related to cryptocurrency and OAuth services. The severity is assessed as medium due to the potential confidentiality and financial impact, combined with moderate exploitation complexity. European organizations involved in blockchain development, fintech, and digital advertising are particularly at risk. Mitigation requires strict dependency vetting, use of package integrity verification, and monitoring of OAuth token usage. Join the discussion | AlienVault OTX General | 12/17/2025, 21:22:37 UTC Added: 12/17/2025, 23:15:13 UTC |
A seemingly harmless desktop application named calendaromatic.exe was discovered to be a sophisticated malware utilizing NeutralinoJS, Unicode homoglyphs, and hidden payloads. The malware, distributed through an aggressive ad campaign, exploited NeutralinoJS's native APIs to interact directly with the host operating system. The key to its operation was a function named clean() that scanned for Unicode homoglyphs in holiday JSON data, using them to encode hidden instructions. This technique allowed the malware to receive and execute arbitrary code smuggled into holiday names using lookalike characters. The investigation was accelerated by AI, which helped parse and annotate the minified JavaScript code. Join the discussion | AlienVault OTX General | 09/23/2025, 21:47:58 UTC Added: 09/23/2025, 21:57:24 UTC |
Showing 1 to 2 of 2 results