Threats Tagged 'spain'
View all threats tagged with 'spain'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'spain'
Click on any threat for detailed analysis and mitigation recommendations
0 ESET researchers uncovered a Lazarus attack against a Spanish aerospace company where attackers masqueraded as Meta recruiters on LinkedIn, sending trojanized coding challenges to employees. The campaign deployed multiple tools including LightlessCan, a previously undocumented backdoor that mimics native Windows commands to evade detection. Initial access was achieved through spearphishing via LinkedIn Messaging, delivering malicious executables disguised as C++ programming tests. The attack chain involved DLL side-loading techniques delivering payloads including NickelLoader downloader, miniBlindingCan variant, and the sophisticated LightlessCan RAT supporting 68 commands. LightlessCan represents a significant advancement over its predecessor BlindingCan, implementing execution guardrails and enhanced stealth capabilities. The campaign targeted aerospace technology and know-how for cyberespionage purposes, consistent with North Korean strategic objectives in missile development. Join the discussion | AlienVault OTX General | 09/18/2026, 21:29:42 UTC Added: 09/21/2026, 08:46:37 UTC |
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications. Join the discussion | AlienVault OTX General | 09/02/2026, 13:39:04 UTC Added: 09/02/2026, 16:22:27 UTC |
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:39 UTC Added: 07/16/2026, 10:17:37 UTC |
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets. Join the discussion | AlienVault OTX General | 07/01/2026, 21:35:11 UTC Added: 07/02/2026, 07:06:43 UTC |
Showing 1 to 4 of 4 results