Threats Tagged 'reverse tunnel'
View all threats tagged with 'reverse tunnel'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'reverse tunnel'
Click on any threat for detailed analysis and mitigation recommendations
The TerminalFix campaign is a sophisticated multi-stage intrusion targeting organizations via compromised websites that display fake Cloudflare CAPTCHA overlays. Victims are tricked into executing malicious PowerShell commands that download and execute a signed legitimate binary alongside a malicious DLL for sideloading. This leads to steganographic payload extraction, extensive Active Directory reconnaissance, and deployment of a Python-based reverse-tunnel implant providing persistent network-level proxy access. The campaign enables attackers to pivot within the network, conduct domain enumeration, and maintain stealthy persistent access. Although no direct downstream actions were observed, the access gained could facilitate privilege escalation, data exfiltration, and ransomware deployment. The campaign combines advanced evasion techniques and persistent network access, posing a serious threat to enterprise environments. Join the discussion | Microsoft Security Blog | 08/31/2026, 00:14:29 UTC Added: 08/29/2026, 16:39:54 UTC |
ESET researchers uncovered a cyberespionage campaign by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has targeted Kurdish and Iraqi government officials since at least 2017, using various malicious tools including the Whisper backdoor, PrimeCache IIS module, and reverse tunnels. BladedFeline maintains persistent access to high-ranking officials in both the Kurdistan Regional Government and Iraqi government, likely for espionage purposes. The group's toolset includes sophisticated backdoors, webshells, and custom tunneling applications. ESET assesses with medium confidence that BladedFeline is a subgroup of OilRig, based on shared code, targets, and tactics. The campaign also extended to a telecommunications provider in Uzbekistan. Join the discussion | AlienVault OTX General | 06/10/2025, 18:09:11 UTC Added: 06/10/2025, 19:35:03 UTC |
Showing 1 to 2 of 2 results