Threats Tagged 'remote desktop'
View all threats tagged with 'remote desktop'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'remote desktop'
Click on any threat for detailed analysis and mitigation recommendations
NightSpire ransomware, first discovered in February 2025, presents a categorization challenge regarding whether it operates as Ransomware-as-a-Service (RaaS). Analysis of two incidents from December 2025 and March 2026 reveals significant variations in tactics, techniques, and procedures between attacks. The March 2026 incident involved threat actors installing Chrome Remoting Desktop and AnyDesk for persistence, using Everything and 7Zip for data staging, MEGASync for exfiltration, and deploying VMWare Workstation and WPS Office. The attacker accessed systems via RDP days before detection. Comparison with the December 2025 incident shows evolution in the ransomware encryptor, including modified ransom note filenames and contents. These variations in TTPs and indicators suggest either operational evolution or involvement of multiple affiliates, demonstrating that ransomware indicators aren't consistent across campaigns. Join the discussion | AlienVault OTX General | 04/08/2026, 09:15:51 UTC Added: 04/08/2026, 11:05:57 UTC |
APT-C-26 (Lazarus) has conducted a sophisticated attack campaign deploying customized monitoring software disguised as remote IT tools. The malware includes a registration program, daemon process, and DLL, leveraging Windows Shell extensions for persistence and creating a covert remote desktop environment. It employs advanced evasion techniques such as disabling Windows Defender and manipulating firewall rules. The monitoring software captures screen data and uploads it to a remote server, enabling persistent surveillance and remote control. This campaign targets various industries globally and is attributed to the North Korean Lazarus group. The attack does not require known exploits but uses stealthy persistence and privilege escalation tactics. European organizations face risks of espionage, data leakage, and operational disruption. Mitigation requires targeted detection of the specific malware components, strict control of remote IT access, and enhanced endpoint monitoring. Countries with high adoption of Windows enterprise environments and strategic industries are most at risk, including Germany, France, the UK, and the Netherlands. Join the discussion | AlienVault OTX General | 11/21/2025, 22:11:40 UTC Added: 11/21/2025, 22:16:22 UTC |
Since the release of XWorm V6.0 on June 4, 2025, we have noted a surge in samples identified as XWorm V6.0 on VirusTotal, reflecting its rapid adoption by threat actors. One prominent campaign illustrates its delivery: a malicious JavaScript (JS) file initiates a PowerShell (PS1) script, which deploys an injector to deliver the XWorm Client. Join the discussion | AlienVault OTX General | 10/06/2025, 18:58:53 UTC Added: 10/06/2025, 19:03:49 UTC |
Showing 1 to 3 of 3 results