Skip to main content

Threats Tagged 'infrastructure'

View all threats tagged with 'infrastructure'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: infrastructure

Threats Tagged 'infrastructure'

Click on any threat for detailed analysis and mitigation recommendations

China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.

Join the discussion

A phishing campaign targeting Chile continues to evolve with significant infrastructure expansion. Security researchers identified 99 new domains impersonating the legitimate PasasteSinTAG portal, with 22 domains confirmed active and 77 registered but not yet activated. The active domains utilize various top-level domains including .click, .cfd, .cyou, .mom, .best, .rest, .top, .help, .sbs, .icu, .life, .xyz, .buzz, .casa, and .pics. The infrastructure is hosted across seven IP addresses. This campaign represents an ongoing threat to Chilean users through brand impersonation tactics, with threat actors maintaining a large reserve of dormant domains for future rotation.

Join the discussion

LockBit 5.0, the latest version of the notorious ransomware, has been released with support for Windows, Linux, and ESXi systems. This update brings improved defense evasion, faster encryption, and enhanced modularity. The Windows variant employs extensive anti-analysis techniques, while Linux and ESXi versions remain unpacked. All variants share a common encryption scheme using XChaCha20 and Curve25519. LockBit 5.0 demonstrates a focus on enterprise and infrastructure targets, including explicit support for Proxmox virtualization. The group's data leak site reveals a primary focus on the U.S.business sector, with victims spanning various industries. LockBit's infrastructure has shown connections to SmokeLoader, suggesting possible cooperation or infrastructure reuse among malware operators.

Join the discussion

An analysis of Chinese hosting environments reveals over 18,000 active command-and-control (C2) servers distributed across 48 infrastructure providers. C2 infrastructure dominates malicious activity at 84%, followed by phishing at 13%. China Unicom hosts nearly half of all observed C2 servers, with Alibaba Cloud and Tencent following. A small set of malware families, including Mozi, ARL, and Cobalt Strike, accounts for most C2 activity. The infrastructure supports both cybercrime and state-linked operations, with RATs, cryptominers, and APT tooling coexisting. High-trust networks like China169 Backbone and CERNET are actively exploited. This host-centric approach exposes long-running abuse patterns and infrastructure reuse across campaigns, enabling more resilient threat detection and mitigation strategies.

Join the discussion
0

This analysis explores the corporate structure and operations of Intellexa, a mercenary spyware vendor. It reveals new companies likely tied to Intellexa's network, particularly within a Czech cluster, and examines their roles in product shipment and potential infection vectors. The report traces Intellexa's activities across multiple countries, including new evidence of Predator spyware deployment in Iraq. It highlights the challenges in tracking such operations due to complex corporate structures and evolving techniques. The analysis also discusses broader trends in the spyware ecosystem, including geopolitical fragmentation, persistent facilitators, and expanding targeting beyond traditional victims to include corporate leaders.

Join the discussion

On February 24, 2022, a cyberattack exploited a VPN vulnerability in Viasat's KA-SAT satellite network, deploying AcidRain wiper malware. This attack disrupted satellite communications for thousands of users in Ukraine and disabled 5,800 wind turbines in Germany. The malware shares similarities with the VPNFilter malware family and targeted management systems to cause widespread operational disruption. Although impactful, the attack was less severe than other infrastructure attacks on Ukraine during the same period. The incident underscores the vulnerabilities in satellite network security and the critical need for robust defenses against sophisticated cyber threats targeting critical infrastructure. No known exploits are currently active in the wild, and the attack required access through a VPN vulnerability. European organizations relying on satellite communications and renewable energy infrastructure are particularly at risk. Mitigation requires patching VPN vulnerabilities, enhancing network segmentation, and monitoring for indicators of compromise related to AcidRain. Germany is notably affected due to the impact on its wind turbines, and other European countries with similar infrastructure and satellite dependencies should remain vigilant.

Join the discussion

The German hosting provider aurologic GmbH has become a critical infrastructure hub for multiple high-risk and sanctioned cybercrime networks, including entities involved in disinformation and malware campaigns. Despite public scrutiny and sanctions, aurologic continues to provide upstream transit services, enabling threat actors to maintain operational stability. The provider's approach to abuse handling is reactive and legally compliant rather than proactive, allowing malicious infrastructure to persist. This situation highlights challenges in accountability within the hosting ecosystem and the risks posed by infrastructure neutrality when it enables cybercrime. Numerous suspicious domains linked to aurologic-hosted networks have been identified, associated with malware families and threat actor tools. European organizations, especially in Germany, face increased risks due to this infrastructure's stability and continued operation. Mitigation requires enhanced monitoring of traffic from these domains, collaboration with upstream providers, and pressure on hosting providers to adopt proactive abuse prevention. Countries with significant internet infrastructure and cybercrime targets in Europe are most likely to be affected.

Join the discussion

A new component of PolarEdge's infrastructure, RPX_Client, has been discovered, revealing insights into the threat actor's relay operations. The investigation uncovered 140 VPS nodes acting as RPX Servers and over 25,000 infected devices serving as RPX Clients. The system uses a multi-hop design to conceal attack sources, with compromised IoT devices and VPS servers forming robust barriers. RPX_Client functions as a jumpserver in the Operational Relay Box (ORB) network, providing proxy services and enabling remote command execution. The analysis also revealed connections between previously known PolarEdge infrastructure and the newly discovered components, confirming the attribution to this threat actor.

Join the discussion

This analysis examines the Bookworm malware family and its connection to the Chinese APT group Stately Taurus. Using a structured attribution framework, the study evaluates tactics, tooling, operational security, infrastructure, victimology and timelines to establish a high-confidence link between Bookworm and Stately Taurus. Key evidence includes shared program database paths, overlapping command and control infrastructure, and consistent targeting of Southeast Asian governments. The framework assigns scores to each piece of evidence, resulting in an overall attribution confidence score of 58.4 out of 100, indicating strong confidence in the connection. This systematic approach aims to improve analytical rigor and collaboration in threat intelligence.

Join the discussion
0

The SystemBC botnet, composed of over 80 C2s and 1,500 daily victims, primarily targets VPS systems from commercial providers. It creates proxies enabling high volumes of malicious traffic for various criminal threat groups. The network is used by multiple proxy services, including REM Proxy, which offers tiered packages for different cybercriminal needs. SystemBC's infrastructure allows for massive data transfers, with some bots generating over 16 GB of proxy data in 24 hours. The botnet is used for various malicious activities, including brute-forcing WordPress credentials, web-scraping, and supporting ransomware operations. The report highlights the evolving nature of proxy services in the cybercriminal ecosystem and their role in facilitating large-scale attacks.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Tag: infrastructure
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses