Threats Tagged 'lateral movement'
View all threats tagged with 'lateral movement'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'lateral movement'
Click on any threat for detailed analysis and mitigation recommendations
In late August, an organization was compromised by INC ransomware across at least 175 endpoints. The attack timeline spanned from early to late August with a 17-day gap, suggesting involvement of an initial access broker and a separate ransomware affiliate. Early August activity included scheduled tasks with randomized names and lateral movement via RDP using a compromised account. After the lull, attackers deployed AnyDesk for remote access, used Bring Your Own Vulnerable Driver tactics to disable security controls, and executed ransomware via Impacket tools. Uniquely, two ransom notes were discovered: the standard INC-README.txt and a subsequent DATALEAK_PRESS_RELEASE.txt containing detailed stolen file listings, threatening to contact media, employees, and partners within 48 hours to increase pressure on victims. Join the discussion | AlienVault OTX General | 09/21/2026, 16:35:37 UTC Added: 09/22/2026, 08:18:01 UTC |
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT. Join the discussion | Reddit NetSec | 08/05/2026, 08:26:37 UTC Added: 08/04/2026, 18:26:01 UTC |
A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified. Join the discussion | AlienVault OTX General | 07/16/2026, 11:39:23 UTC Added: 07/17/2026, 00:32:32 UTC |
A sophisticated multi-stage phishing campaign delivers a previously undocumented framework called Avalon through spoofed legal documents hosted on Proton Drive. The intrusion begins with password-protected archives containing ISO images that execute malicious MSBuild projects, loading payloads entirely in memory without conventional executable attachments. Avalon consolidates credential theft, lateral movement, recovery disruption, and ransomware capabilities within a single framework, with its encryption component branded as CrownX. The framework demonstrates hallmarks of AI-assisted development, rapidly combining multiple post-exploitation capabilities that previously required sustained development effort. Avalon targets browsers, cryptocurrency wallets, messaging platforms, VPN configurations, and infrastructure systems while implementing extensive defense evasion techniques against major security products. The framework disrupts recovery by eliminating Volume Shadow Copies, Windows Recovery Environment... Join the discussion | AlienVault OTX General | 07/02/2026, 20:59:12 UTC Added: 07/03/2026, 07:06:38 UTC |
In July 2025, threat actors compromised organizations through SEO poisoning campaigns targeting users searching for legitimate IT management tools. Users downloading trojanized installers for ManageEngine OpManager received Bumblebee malware, granting initial access. The attackers exploited the fact that users executing these IT tools were privileged administrators, enabling rapid lateral movement to domain controllers. They dumped credentials using wbadmin, created backdoor accounts with enterprise admin privileges, and installed RustDesk for persistent access. AdaptixC2 beacons were deployed for command and control. The threat actors conducted extensive reconnaissance, dumped LSASS memory across multiple systems, attempted Veeam credential theft, and exfiltrated data via SFTP using FileZilla. The intrusion culminated in Akira ransomware deployment across both root and child domains within 44 hours, with subsequent re-encryption two days later affecting the child domain. Join the discussion | AlienVault OTX General | 06/29/2026, 15:46:49 UTC Added: 06/30/2026, 11:21:46 UTC |
The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors. Join the discussion | AlienVault OTX General | 06/29/2026, 11:01:00 UTC Added: 06/30/2026, 06:51:30 UTC |
A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller. Join the discussion | AlienVault OTX General | 06/16/2026, 14:27:51 UTC Added: 06/16/2026, 17:30:50 UTC |
0 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. Join the discussion | CVE Database V5 | 05/25/2026, 19:06:37 UTC Added: 05/25/2026, 19:40:00 UTC |
A sophisticated multi-stage malware execution chain was discovered during proactive threat hunting activities using endpoint telemetry and dynamic analysis. The attack sequence demonstrates advanced techniques including script masquerading, defense evasion mechanisms, staged payload extraction, and establishment of command-and-control communications. The malware exhibits capabilities for downloading additional payloads, presenting risks of data exfiltration and lateral movement within compromised networks. Immediate network isolation of affected systems is critical, with full system reimaging strongly recommended to ensure complete removal of all malicious components. The investigation identified multiple malicious file hashes, a command-and-control IP address, and an associated domain used for maintaining persistent access to compromised environments. Join the discussion | AlienVault OTX General | 04/29/2026, 10:49:26 UTC Added: 04/29/2026, 10:51:22 UTC |
Check Point Research discovered critical flaws in VECT 2.0 ransomware affecting Windows, Linux, and ESXi platforms. A fundamental encryption implementation error causes files larger than 128 KB to be permanently destroyed rather than encrypted. The malware uses ChaCha20-IETF cipher but only saves one of four decryption nonces required for large files, making recovery impossible even after ransom payment. VECT's encryption speed modes are non-functional, thread scheduling degrades performance, and anti-analysis code is unreachable. Despite partnerships with TeamPCP and BreachForums for distribution, the technical implementation demonstrates amateur execution behind a professional facade. The nonce-handling flaw exists across all platform variants since initial deployment, effectively transforming this ransomware into a wiper for enterprise assets including VM disks, databases, and backups. Join the discussion | AlienVault OTX General | 04/28/2026, 16:34:45 UTC Added: 04/29/2026, 07:06:22 UTC |
Showing 1 to 10 of 32 results