Threats Tagged 'sparkrat'
View all threats tagged with 'sparkrat'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'sparkrat'
Click on any threat for detailed analysis and mitigation recommendations
This analysis challenges the notion that cyber threat actors are always sophisticated and organized. Through examining three incidents, it reveals that attackers often make mistakes, face obstacles, and adapt their tactics based on trial and error. The incidents showcase how threat actors struggled with Windows Defender, mistyped commands, and failed to start malicious services. Despite using similar tactics and infrastructure across attacks, the perpetrators had to refine their methods in response to setbacks. The study emphasizes that understanding these roadblocks and attacker reactions provides valuable insights for improving cybersecurity defenses. Join the discussion | AlienVault OTX General | 12/23/2025, 01:59:50 UTC Added: 12/23/2025, 09:21:49 UTC |
The NKNShell malware campaign involves a compromised South Korean VPN provider website used to distribute a multi-stage malware payload. The threat actor Larva-24010 deploys several backdoors including MeshAgent, gs-netcat, and a novel Go-based backdoor called NKNShell, which leverages NKN and MQTT protocols for command and control. The infection chain uses trojanized installers and PowerShell scripts, employing advanced evasion techniques such as AMSI and UAC bypasses. Additional tools like SQLMap are deployed to facilitate further exploitation. While primarily targeting Korean VPN users, the sophisticated use of blockchain-based networking protocols and multiple backdoors poses risks to any users of the compromised VPN service. The campaign's medium severity reflects its complexity and targeted nature, but it has not yet been observed exploiting widespread vulnerabilities or causing large-scale impact beyond South Korea. Join the discussion | AlienVault OTX General | 11/20/2025, 14:45:54 UTC Added: 11/20/2025, 22:13:41 UTC |
RedNovember, a Chinese state-sponsored threat group, has expanded its cyber-espionage activities globally. The group targets high-profile government, intergovernmental, and private sector organizations, focusing on defense, aerospace, and technology sectors. It uses the Go-based backdoor Pantegana and Cobalt Strike for intrusions, exploiting vulnerabilities in perimeter appliances. RedNovember's tactics include combining weaponized proof-of-concept exploits with open-source tools, allowing for scalable operations and attribution obfuscation. The group has shown particular interest in targets across the US, Taiwan, South Korea, and Panama, often aligning its activities with geopolitical events and Chinese strategic interests. Join the discussion | AlienVault OTX General | 09/24/2025, 17:18:47 UTC Added: 09/24/2025, 19:44:52 UTC |
Between March and June 2025, three Chinese state-sponsored threat actors conducted targeted phishing campaigns against the Taiwanese semiconductor industry. The campaigns targeted organizations involved in semiconductor manufacturing, design, testing, supply chain, and financial analysis. This activity likely reflects China's strategic priority to achieve semiconductor self-sufficiency and decrease reliance on international supply chains. The threat actors used various tactics including job application lures, investment collaboration pitches, and credential phishing. They deployed custom malware like Voldemort backdoor and HealthKick, as well as tools like Cobalt Strike. The targeting extended beyond semiconductor companies to include financial analysts specializing in the Taiwanese semiconductor market, indicating comprehensive intelligence collection efforts across the sector. Join the discussion | AlienVault OTX General | 07/17/2025, 20:06:52 UTC Added: 07/17/2025, 20:16:10 UTC |
Showing 1 to 4 of 4 results