Threats Tagged 'scheduled task persistence'
View all threats tagged with 'scheduled task persistence'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'scheduled task persistence'
Click on any threat for detailed analysis and mitigation recommendations
A masqueraded scheduled task alert triggered an aggressive threat hunt that uncovered a complete FakeAgent intrusion campaign within ten minutes using an automated threat hunting agent. The campaign leveraged malvertising on Bing to distribute trojanized Claude Desktop installers hosted on legitimate Anthropic infrastructure. The attack chain featured DLL sideloading via Java Chromium Embedded Framework, Microsoft Defender tampering, scheduled task persistence masquerading as Microsoft Edge updates, and blockchain-based command-and-control infrastructure using EtherHiding techniques. The hunting agent executed correlated queries across multiple kill chain phases simultaneously, providing confidence-scored findings that enabled rapid validation and remediation. The intrusion delivered SectopRAT malware with infostealing and remote desktop capabilities, requiring full endpoint reimaging and credential resets. Join the discussion | AlienVault OTX General | 08/24/2026, 21:19:19 UTC Added: 08/26/2026, 13:07:12 UTC |
A sophisticated cyber campaign targets Indian government job seekers using fake recruitment advertisements for Senior Field Officer positions in the Cabinet Secretariat. The attack chain begins with a malicious ZIP archive containing a disguised LNK file, PowerShell script, and .NET executable. Attackers abuse the legitimate ControlR remote management tool for persistent access and deploy SheetAgent RAT, a custom .NET malware that uses Google Sheets as a command-and-control channel. The malware employs multiple persistence mechanisms including scheduled tasks and startup folder entries, while incorporating extensive anti-analysis checks to detect virtualized environments. Infrastructure analysis reveals multiple web-based management panels and connections to APT36 based on targeting patterns and tradecraft similarities. MediumMalware Join the discussion | AlienVault OTX General | 07/14/2026, 11:51:21 UTC Added: 07/14/2026, 16:18:14 UTC |
A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par... MediumCampaign Join the discussion | AlienVault OTX General | 07/09/2026, 11:27:09 UTC Added: 07/09/2026, 13:04:37 UTC |
An investigation revealed a malicious email campaign directing victims to download a ZIP file from MediaFire. The infection chain began with a Python setup executable (Setu.exe) that side-loaded a malicious 400 MB python37.dll containing repeated byte padding. The DLL performed process injection into dllhost.exe, establishing communication with a C2 server at 138.124.186.2:7000. The threat actor deployed three persistence mechanisms: a PowerShell-based path, a fake EdgeUpdate Python executable with scheduled task, and NetSupport RMM as a third access method. The analysis highlights the importance of comparing file timestamps during triage to identify malicious artifacts within compressed archives. Join the discussion | AlienVault OTX General | 06/16/2026, 05:29:40 UTC Added: 06/16/2026, 16:45:15 UTC |
A sophisticated ClickFix campaign was observed in April 2026 deploying PySoxy, a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with social engineering that tricks users into executing obfuscated PowerShell commands, which then establishes scheduled task persistence and deploys an in-memory PowerShell-based command-and-control agent. Following domain reconnaissance activities, attackers deploy PySoxy to create a redundant encrypted access channel. The persistence mechanism continues attempting re-execution even after initial connections are blocked, demonstrating how single ClickFix executions can evolve into modular post-exploitation chains. This development represents a significant evolution from simple one-time execution to durable access with multiple redundant pathways, requiring comprehensive remediation beyond blocking initial callbacks. Join the discussion | AlienVault OTX General | 05/13/2026, 16:41:05 UTC Added: 05/14/2026, 08:36:23 UTC |
Showing 1 to 5 of 5 results