Threats Tagged 'ocr'
View all threats tagged with 'ocr'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ocr'
Click on any threat for detailed analysis and mitigation recommendations
A data breach attributed to a North Korean-affiliated actor known as "Kim" has provided new insights into Kimsuky (APT43) tactics and infrastructure. The actor's operations focus on credential-based intrusions targeting South Korean and Taiwanese networks, utilizing Chinese-language tools and infrastructure. The leaked data includes bash histories, phishing domains, OCR workflows, compiled stagers, and rootkit evidence, revealing a hybrid operation between DPRK attribution and Chinese resource utilization. The actor demonstrated sophisticated credential harvesting techniques, including targeting South Korea's Government Public Key Infrastructure (GPKI) and reconnaissance of Taiwanese government and academic institutions. The leak exposes the evolution of DPRK cyber capabilities and highlights the complex attribution challenges in modern nation-state cyber operations. Join the discussion | AlienVault OTX General | 09/08/2025, 09:35:57 UTC Added: 09/08/2025, 10:01:46 UTC |
The CopyRh(ight)adamantys campaign is a large-scale phishing operation distributing the latest Rhadamanthys stealer malware (version 0.7). It uses copyright infringement-themed bait emails impersonating companies mainly in the Entertainment/Media and Technology/Software sectors. The campaign employs automation and possibly AI tools to tailor and distribute lures globally. Rhadamanthys stealer targets sensitive information by leveraging various techniques including OCR-based text recognition and credential theft. Although the malware claims AI-powered capabilities, it primarily uses traditional machine learning OCR methods. The campaign is financially motivated, not linked to nation-state actors, and poses a medium severity threat. European organizations in targeted sectors face risks of data theft and credential compromise. Mitigation requires targeted phishing awareness, enhanced email filtering, endpoint detection, and credential hygiene. Countries with strong media and tech industries and high phishing exposure are most at risk. Join the discussion | AlienVault OTX General | 11/06/2024, 18:33:53 UTC Added: 12/10/2025, 09:35:38 UTC |
Showing 1 to 2 of 2 results