Threats Tagged 'remote access trojans'
View all threats tagged with 'remote access trojans'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'remote access trojans'
Click on any threat for detailed analysis and mitigation recommendations
A threat campaign linked to the Scattered Lapsus$ Hunters group is targeting Zendesk users through over 40 typosquatted domains impersonating Zendesk and various organizations. These domains host phishing pages to harvest credentials. Attackers also submit fraudulent tickets to Zendesk portals to infect support staff with remote access trojans (RATs). This campaign follows similar attacks on other SaaS platforms like Salesforce, with Discord reportedly breached via its Zendesk support system. The attack leverages phishing, typosquatting, and social engineering to compromise customer service environments. Organizations are advised to implement strong authentication, monitor for typosquatted domains, and secure Zendesk chat to mitigate risks. The threat poses a medium severity risk due to its potential to compromise sensitive support operations and enable persistent access. No CVSS score is available, but the attack's impact on confidentiality and integrity, combined with ease of exploitation, warrants a medium severity rating. Join the discussion | AlienVault OTX General | 11/27/2025, 14:13:07 UTC Added: 11/27/2025, 18:38:55 UTC |
A financially motivated Vietnamese threat actor group UNC6229 is conducting a campaign using fake job postings on legitimate platforms to target remote workers in digital advertising and marketing. They create credible fake company profiles and lure victims with attractive remote job offers. Upon victim engagement, they deliver malware attachments or phishing links, often leveraging legitimate business and CRM platforms to increase trust. The goal is to steal credentials and compromise high-value corporate and digital advertising accounts. The campaign relies heavily on social engineering and victim-initiated contact. Indicators include malware hashes and a suspicious domain (staffvirtual.website). This medium-severity threat poses risks to confidentiality and integrity of corporate accounts, especially in organizations with remote digital advertising staff. Join the discussion | AlienVault OTX General | 10/23/2025, 21:49:49 UTC Added: 10/24/2025, 09:12:29 UTC |
Showing 1 to 2 of 2 results