Threats Tagged 'iso'
View all threats tagged with 'iso'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'iso'
Click on any threat for detailed analysis and mitigation recommendations
Transparent Tribe, also known as APT36, has expanded its targeting to include India's startup ecosystem, particularly those in the cybersecurity domain. The group is using startup-oriented themed lure material delivered via ISO container-based files to deploy Crimson RAT. This campaign deviates from their typical government and defense targets, suggesting a shift in strategy towards companies providing open-source intelligence services and collaborating with law enforcement agencies. The attack chain involves spear-phishing emails, malicious LNK files, and batch scripts to execute the Crimson RAT payload. The malware employs extensive obfuscation techniques and uses a custom TCP protocol for command and control communications. This activity demonstrates the group's adaptation of proven tooling for new victim profiles while maintaining its core behavioral tactics, techniques, and procedures. Join the discussion | AlienVault OTX General | 02/04/2026, 15:57:21 UTC Added: 02/04/2026, 21:00:08 UTC |
0 A threat group is targeting Afghan government employees using a fake lure mimicking an official government document. The campaign, named Operation Nomad Leopard, uses a malicious ISO file containing a PDF decoy, LNK file, and the FALSECUB malware. The infection chain involves executing the LNK file to display the PDF and run the malware, which establishes persistence and connects to a command and control server. The malware performs system reconnaissance, file enumeration, and data exfiltration. The threat actor, believed to be regionally focused with low-to-moderate sophistication, uses GitHub for malware distribution and has connections to Pakistan. The campaign demonstrates careful attention to detail in creating convincing lures and leverages legitimate platforms for malicious purposes. Join the discussion | AlienVault OTX General | 01/20/2026, 08:51:25 UTC Added: 01/20/2026, 09:05:55 UTC |
Operation MoneyMount is a Russian phishing campaign targeting finance and accounting sectors by delivering Phantom stealer malware through fake payment confirmation emails. The attack uses a ZIP file containing an ISO image; when mounted, it reveals an executable that loads the stealer. Phantom stealer employs anti-analysis techniques and steals sensitive data including cryptocurrency wallets, browser data, and Discord tokens. It also features keylogging and clipboard monitoring to capture additional credentials and information. Stolen data is exfiltrated via Telegram, Discord webhooks, or FTP, making detection and blocking more challenging. The use of ISO files for initial access helps evade traditional security controls. This campaign highlights the growing sophistication of commodity stealers and the strategic targeting of financial sectors. No known exploits in the wild or CVE identifiers are associated with this malware yet. The campaign’s medium severity reflects its targeted nature and complexity of attack chain. Join the discussion | AlienVault OTX General | 12/12/2025, 08:45:04 UTC Added: 12/12/2025, 13:12:01 UTC |
Showing 1 to 3 of 3 results