Threats Tagged 'shell companies'
View all threats tagged with 'shell companies'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'shell companies'
Click on any threat for detailed analysis and mitigation recommendations
A financially-motivated cybercrime cluster designated CL-CRI-1089 has launched Operation FlutterBridge, deploying FlutterShell backdoor malware targeting macOS systems through malvertising. Built with the Flutter framework, FlutterShell masquerades as legitimate applications including podcast players and PDF viewers, delivering adware with full backdoor capabilities such as shell command execution and file system manipulation. The malware uses a WebView-based architecture with JavaScript-to-native bridge, allowing attackers to dynamically modify behavior without recompiling. Distribution occurs through hundreds of Google-verified advertisements controlled by shell companies including AdsParkPro LTD and Advantage Web Marketing LLC. The campaign primarily targets Anglophone and Western European markets. All samples were signed with valid Apple Developer IDs and successfully passed notarization, achieving zero detections on VirusTotal initially. The malware hijacks Google Chrome browsers, redirecting traffic ... Join the discussion | AlienVault OTX General | 06/02/2026, 14:33:49 UTC Added: 06/03/2026, 09:33:37 UTC |
Fibergrid has operated as a bulletproof hosting provider for nearly a decade, currently hosting 16,700 active fraudulent e-commerce sites. The network exploits stolen African IPv4 address space worth $20-25 million, originally acquired through improper AFRINIC registrations. Despite claiming Seychelles-based operations, multilateration analysis reveals infrastructure concentrated in the United States, United Kingdom, Netherlands, Canada, and other Western countries, primarily within Equinix data centers. Fibergrid operates through a complex web of UK and Estonian shell companies using multiple autonomous systems to evade detection and enforcement. Fake shops constitute 70% of malicious activity on this infrastructure, targeting consumers through search engines and social media with counterfeit goods and payment fraud schemes. Disruption opportunities exist through upstream provider intervention, regional internet registry action, domain-level takedowns, and indicator sharing with security providers. Join the discussion | AlienVault OTX General | 04/27/2026, 16:16:01 UTC Added: 04/27/2026, 16:30:05 UTC |
TamperedChef is a sophisticated global malvertising and SEO-driven campaign that delivers malicious payloads via seemingly legitimate, digitally signed installers. It leverages social engineering, malvertising, and abused code-signing certificates obtained through U. S. -registered shell companies to evade detection and increase user trust. The campaign primarily targets healthcare, construction, and manufacturing sectors, establishing persistence and deploying obfuscated JavaScript for remote access and control. Attackers may use this access for credential theft, ransomware preparation, or espionage. Although currently concentrated in the Americas, European organizations in similar sectors are at risk due to the campaign's stealth and persistence techniques. Mitigation requires enhanced scrutiny of signed applications, network monitoring for unusual JavaScript execution, and strict controls on software installation sources. Countries with significant healthcare and manufacturing industries, such as Germany, France, and the UK, are most likely to be affected. Given the medium severity rating and the complexity of exploitation, the threat is assessed as high severity for European contexts due to potential impact and stealth. Join the discussion | AlienVault OTX General | 11/20/2025, 08:15:41 UTC Added: 11/20/2025, 09:46:48 UTC |
Showing 1 to 3 of 3 results