Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'obfuscation techniques'

View all threats tagged with 'obfuscation techniques'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: obfuscation techniques

Threats Tagged 'obfuscation techniques'

Click on any threat for detailed analysis and mitigation recommendations

Inside a TrickBot Variant Using DNS Tunneling for C2
0

A TrickBot malware variant has been identified that uses DNS tunneling for command-and-control (C2) communications, bypassing traditional HTTP channels. It persists on infected Windows systems by creating disguised scheduled tasks that run at startup and every five minutes. Configuration data is hidden in NTFS Alternate Data Streams to evade detection. The malware uses multiple obfuscation methods, including encrypted strings and runtime API resolution, and supports a modular architecture with twelve control commands enabling advanced capabilities such as module downloads, process injection via hollowing and doppelgänging, PowerShell execution, and raw machine code execution. Data transfer occurs through crafted DNS queries to public DNS servers, encoding commands in malformed domain names and receiving responses in multiple IPv4 addresses, achieving transfer speeds of about 30.7 KB/s.

Join the discussion
Portugal-focused phishing campaign delivers multistage malware
0

An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: obfuscation techniques
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses