Skip to main content

Threats Tagged 'nexshield'

View all threats tagged with 'nexshield'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: nexshield

Threats Tagged 'nexshield'

Click on any threat for detailed analysis and mitigation recommendations

Mistic is a stealthy backdoor malware linked to the Woodgnat initial access broker, active since April 2026. It uses sideloading of legitimate Microsoft files to execute payloads in memory without disk writes, enhancing stealth. Mistic includes typical backdoor functions and a self-delete kill switch. It has been observed deployed alongside ModeloRAT, another tool associated with Woodgnat. Targeting is opportunistic across sectors such as insurance, education, IT, and professional services. Woodgnat sells persistent remote access to ransomware affiliates involved with multiple ransomware families. The threat leverages social engineering lures delivered via compromised WordPress sites.

Join the discussion

KongTuke, a threat actor tracked since 2025, has launched a new campaign using a malicious browser extension called NexShield that impersonates uBlock Origin Lite. The extension causes browser crashes and displays fake security warnings to trick users into executing malicious commands. The campaign targets both home and corporate users, with domain-joined machines receiving a more sophisticated Python-based RAT named ModeloRAT. The attack chain involves multiple stages of obfuscation, anti-analysis techniques, and a Domain Generation Algorithm (DGA) for C2 communication. KongTuke employs extensive fingerprinting to avoid detection in analysis environments. The campaign demonstrates evolving social engineering tactics and a focus on infiltrating enterprise networks for potential lateral movement and data exfiltration.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: nexshield
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses