Threats Tagged 'malware-as-a-service'
View all threats tagged with 'malware-as-a-service'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'malware-as-a-service'
Click on any threat for detailed analysis and mitigation recommendations
On 5 May 2026, a Jamf Protect deployment blocked a download attempt from jacksonvillemma[.]com, four days after the operator's previous MacSync C2 was publicly disclosed. The new C2's TLS certificate was issued within 24 hours of that disclosure. Analysis revealed a Stage 2 zsh loader containing a static api-key value observed across four distinct C2 domains spanning December 2025 to May 2026. URI-pattern pivoting through any.run identified eleven additional candidate C2 domains dating back to February 2026, suggesting parallel infrastructure operation rather than sequential rotation. The loader exfiltrates macOS credentials, browser data, and cryptocurrency wallets, and transmits the victim's account password in cleartext via URL query strings, making it visible in web proxy logs. Join the discussion | AlienVault OTX General | 08/18/2026, 20:05:15 UTC Added: 08/19/2026, 15:22:26 UTC |
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks. Join the discussion | AlienVault OTX General | 07/20/2026, 09:36:09 UTC Added: 07/20/2026, 11:11:45 UTC |
Infostealers remain among the most pervasive cybercrime threats, silently harvesting passwords, cookies, and session tokens that enable enterprise breaches. StealC is a malware-as-a-service infostealer written in C++ that collects credentials from browsers, cryptocurrency wallets, messaging applications, email clients, and gaming platforms while functioning as a secondary loader. Amadey operates as a modular backdoor loader active since 2018, delivering downstream payloads including StealC, Lumma Stealer, and ransomware through various backdoor commands. Both operate on commodity rental models where stolen credentials flow through underground markets to access brokers who resell enterprise access. On June 24, 2026, Microsoft's Digital Crimes Unit coordinated with Europol to disrupt over 200 malicious command-and-control domains supporting these operations, using AI-assisted analysis tools including Microsoft Copilot for binary analysis and configuration extraction. Join the discussion | AlienVault OTX General | 06/24/2026, 13:40:01 UTC Added: 06/24/2026, 17:54:44 UTC |
OnyxC2 emerged in early 2026 as a malware-as-a-service stealer sold on cybercrime networks for $250 monthly. The platform includes a web panel, payload builder, and tiered pricing structure with refund guarantees. Written in C++ with assembly for direct syscalls, it targets approximately 210 applications across nine categories: 45 browsers, 109 extensions including 2FA tools, 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, 5 email clients, and VPN/messaging applications. The stealer achieves 99% detection evasion through mutated builds and delivers via DLL sideloading using signed binaries. Higher tiers unlock remote access capabilities including HVNC, LSASS dumping, reverse SOCKS5 proxy, keylogging, and reverse shell. Distribution occurs through fake installers delivered as password-protected archives, with C2 communication over Cloudflare-fronted HTTPS to akmuniverstall.top. Join the discussion | AlienVault OTX General | 06/15/2026, 14:58:17 UTC Added: 06/15/2026, 17:30:16 UTC |
BTMOB is an Android remote access trojan that evolved from SpySolr malware and poses significant threats beyond traditional banking trojans. The malware combines phishing-led delivery with an APK builder interface that enables rapid payload generation without coding skills. Distributed through fake app stores impersonating streaming services, cryptocurrency platforms, and government agencies, BTMOB abuses Android Accessibility Services to gain elevated permissions. Marketed as malware-as-a-service with a reported $5,000 lifetime license, it provides adversaries with capabilities to exfiltrate sensitive data, capture screenshots, record device activity, and establish remote control. The tool's customizable phishing lures have been adapted for specific regions, including campaigns impersonating Argentine tax authorities, making it a rapidly evolving threat with global reach. Join the discussion | AlienVault OTX General | 05/31/2026, 23:32:45 UTC Added: 06/01/2026, 08:48:35 UTC |
In March 2026, a new MaaS active campaign was discovered promoting previously unknown malware in private Telegram chats. The Trojan features an extensive arsenal of capabilities. On the panel provided to third‑party actors, in addition to the standard features of RAT‑like malware, a stealer, keylogger, clipper, and spyware are also available. Join the discussion | AlienVault OTX General | 04/01/2026, 06:24:47 UTC Added: 04/01/2026, 10:23:16 UTC |
A new malware-as-a-service (MaaS) called TrustConnect has been discovered masquerading as a legitimate remote monitoring and management (RMM) tool. The malware, classified as a remote access trojan (RAT), uses a fake business website as its command and control center and MaaS portal. Priced at $300 per month, it offers features like a web-based C2 dashboard, automated payload generation with digital signatures, and remote desktop capabilities. The malware has been distributed through various email campaigns, often alongside legitimate RMM tools. Proofpoint researchers identified links between TrustConnect's creator and previous users of Redline stealer. The emergence of this new MaaS demonstrates the ongoing evolution of the cybercrime market and the thriving ecosystem of RMM abuse. Join the discussion | AlienVault OTX General | 02/19/2026, 11:10:29 UTC Added: 02/19/2026, 12:50:31 UTC |
Insikt Group has identified four distinct activity clusters associated with GrayBravo's CastleLoader malware, each with unique tactics and victim profiles. This supports the assessment that GrayBravo operates a malware-as-a-service model. One cluster, TAG-160, impersonates logistics firms and uses phishing lures with the ClickFix technique to distribute CastleLoader. Another cluster, TAG-161, impersonates Booking.com and employs similar techniques. The analysis also uncovered potential links to the online persona "Sparja" and the broader cybercriminal ecosystem. GrayBravo demonstrates rapid evolution, technical sophistication, and adaptability in response to public exposure. The report recommends various security measures to defend against these threats. Join the discussion | AlienVault OTX General | 12/09/2025, 05:39:34 UTC Added: 12/09/2025, 12:43:02 UTC |
Albiriox is a newly identified Android banking malware family that enables cybercriminals to remotely control infected devices and conduct financial fraud. It operates as Malware-as-a-Service (MaaS), featuring modular components such as loaders, command modules, and control panels designed specifically for targeting banking, fintech, payment, and cryptocurrency applications. Distributed via fake apps and social engineering, it mimics legitimate brands and app stores to deceive users. The malware abuses Android accessibility features and employs black-screen masking to hide malicious activity. Notably, it can bypass multi-factor authentication and device fingerprinting, increasing its effectiveness. Although currently rated medium severity, its capabilities pose significant risks to user confidentiality and financial integrity. European organizations with mobile banking users are at risk, especially in countries with high Android adoption and fintech usage. Mitigation requires verifying app sources, maintaining updated devices, deploying advanced anti-malware solutions, and educating users about social engineering tactics. Join the discussion | AlienVault OTX General | 12/03/2025, 20:19:08 UTC Added: 12/04/2025, 14:44:50 UTC |
Herodotus is a newly discovered Android malware designed to perform device takeover by mimicking human behavior to evade biometric and automated detection. It is distributed via side-loading and targets financial organizations and cryptocurrency wallets, with active campaigns observed in Italy and Brazil and potential for global spread. The malware is offered as Malware-as-a-Service and is linked to the Brokewell malware family. It steals credentials and remotely controls infected devices, using randomized delays between inputs to simulate human interaction. This behavior mimicry complicates detection by security solutions relying on behavioral analysis. The malware’s focus on financial targets and crypto wallets poses significant risks to confidentiality and financial integrity. European organizations, especially in Italy and Poland, are currently targeted and should prepare for potential expansion. Mitigation requires advanced layered security, including strict app installation policies, behavioral anomaly detection tuned for such mimicry, and user education on side-loading risks. Join the discussion | AlienVault OTX General | 10/28/2025, 18:24:45 UTC Added: 10/28/2025, 19:25:46 UTC |
Showing 1 to 10 of 26 results