Threats Tagged 'osint'
View all threats tagged with 'osint'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'osint'
Click on any threat for detailed analysis and mitigation recommendations
Transparent Tribe, also known as APT36, has expanded its targeting to include India's startup ecosystem, particularly those in the cybersecurity domain. The group is using startup-oriented themed lure material delivered via ISO container-based files to deploy Crimson RAT. This campaign deviates from their typical government and defense targets, suggesting a shift in strategy towards companies providing open-source intelligence services and collaborating with law enforcement agencies. The attack chain involves spear-phishing emails, malicious LNK files, and batch scripts to execute the Crimson RAT payload. The malware employs extensive obfuscation techniques and uses a custom TCP protocol for command and control communications. This activity demonstrates the group's adaptation of proven tooling for new victim profiles while maintaining its core behavioral tactics, techniques, and procedures. Join the discussion | AlienVault OTX General | 02/04/2026, 15:57:21 UTC Added: 02/04/2026, 21:00:08 UTC |
A multi-domain traffic distribution system (TDS) operation was discovered, centered around the domain toxicsnake-wifes.com. The infrastructure serves as a commodity cybercrime TDS farm, routing victims to phishing, scams, or malware payloads. The operation uses a first-stage JavaScript loader, followed by a second-stage that attempts to fetch upstream payloads. The cluster shares common WHOIS, DNS, and hosting patterns, indicative of bulletproof VPS usage. Multiple burner domains with similar tradecraft were identified, suggesting an organized operator cluster. The infrastructure employs obfuscation, dynamic remote injection, and disposable registration techniques. While the main payload was unreachable during analysis, historical evidence suggests the delivery of malicious content. Join the discussion | AlienVault OTX General | 01/30/2026, 08:44:03 UTC Added: 01/30/2026, 08:57:47 UTC |
The XCTDH Crypto Heist Part 4 is a medium-severity cyber threat linked to North Korean actors targeting software supply chains and development tools. It involves compromising software dependencies and development environments to facilitate unauthorized access or manipulation, leveraging application layer protocols for communication or data exfiltration. Although no specific affected product versions or patches are identified, the threat highlights risks associated with supply chain attacks. European organizations relying on affected software development tools or dependencies could face risks of intellectual property theft, operational disruption, or unauthorized access. Mitigation requires enhanced supply chain security practices, including rigorous code and dependency auditing, network segmentation, and monitoring for anomalous application layer traffic. Countries with significant software development sectors and historical exposure to North Korean cyber activities, such as the UK, Germany, and France, are more likely to be impacted. Given the medium severity, the threat poses a moderate risk that demands proactive defense but does not indicate immediate critical exploitation. Defenders should prioritize supply chain security and monitor for related attack patterns to reduce exposure. MediumUnknown Join the discussion | CIRCL OSINT Feed | 12/18/2025, 00:00:00 UTC Added: 12/19/2025, 16:30:26 UTC |
Sha1-Hulud is a newly identified cyber threat involving supply chain compromise and covert command and control (C2) communications using application layer protocols. Attackers exploit link-local IP addresses such as 169.254.169.254 and 169.254.170.2, commonly associated with cloud metadata services, to bypass perimeter defenses and blend malicious traffic with legitimate communications. A JavaScript component named bun_environment.js has been identified as part of the attack chain. MediumUnknown Join the discussion | CIRCL OSINT Feed | 11/26/2025, 00:00:00 UTC Added: 11/29/2025, 08:19:38 UTC |
Salesforce Gainsight Security Advisory - Nov 2025 MediumMalware Join the discussion | CIRCL OSINT Feed | 11/26/2025, 00:00:00 UTC Added: 11/29/2025, 08:19:38 UTC |
OSINT of Exchange 0-day campaign (Atos) HighCampaign Join the discussion | CIRCL OSINT Feed | 10/03/2022, 00:00:00 UTC Added: 05/27/2025, 11:06:05 UTC |
Showing 1 to 6 of 6 results