Threats Tagged 'spear-phishing'
View all threats tagged with 'spear-phishing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'spear-phishing'
Click on any threat for detailed analysis and mitigation recommendations
North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs. Join the discussion | AlienVault OTX General | 09/24/2026, 12:40:35 UTC Added: 09/24/2026, 19:33:01 UTC |
0 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) Join the discussion | CVE Database V5 | 09/03/2026, 19:26:12 UTC Added: 09/03/2026, 19:37:53 UTC |
In July 2026, multiple APT campaigns targeted South Korean entities using spear phishing emails with malicious LNK files. Seven distinct attack types employed various techniques such as PowerShell scripts, AutoIt programs, DLL side-loading, and curl.exe downloads. Malware was distributed via platforms like GitHub, Google Drive, and Dropbox, disguised as legitimate documents or resumes. The campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate sensitive information and maintain persistence through Task Scheduler entries. Communication with command and control servers used PubNub channels with Base64-encoded data. The attacks focused on deceiving victims with work-related content to execute malicious payloads. Join the discussion | AlienVault OTX General | 08/28/2026, 10:52:45 UTC Added: 08/28/2026, 16:57:13 UTC |
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications. Join the discussion | AlienVault OTX General | 07/13/2026, 12:54:54 UTC Added: 07/13/2026, 21:02:35 UTC |
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns. Join the discussion | AlienVault OTX General | 07/12/2026, 22:28:10 UTC Added: 07/13/2026, 10:32:46 UTC |
A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par... MediumCampaign Join the discussion | AlienVault OTX General | 07/09/2026, 11:27:09 UTC Added: 07/09/2026, 13:04:37 UTC |
A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise. Join the discussion | AlienVault OTX General | 07/07/2026, 14:14:56 UTC Added: 07/07/2026, 14:28:23 UTC |
Kaspersky uncovered a sophisticated phishing campaign by the APT group Armored Likho, deploying a previously undocumented Python-based infostealer dubbed BusySnake Stealer. The campaign targets government agencies and electric power sectors across Russia, Brazil, and Kazakhstan through spear-phishing emails containing malicious EXE or LNK attachments. BusySnake Stealer features advanced obfuscation using PyArmor Pro, extracts credentials from browsers using DPAPI and NSS libraries, captures screenshots, logs keystrokes, scrapes cryptocurrency wallets and 2FA tokens, and establishes reverse SSH tunnels for remote access. The threat actor leverages AI-generated code for first-stage payloads and distributes components via GitHub repositories. The stealer maintains persistence through scheduled tasks and communicates with C2 infrastructure to receive commands dynamically, representing a significant evolution in the group's technical capabilities. Join the discussion | AlienVault OTX General | 07/03/2026, 12:13:50 UTC Added: 07/06/2026, 09:21:27 UTC |
0 An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector. Join the discussion | AlienVault OTX General | 07/02/2026, 11:29:26 UTC Added: 07/02/2026, 11:36:39 UTC |
A sophisticated China-aligned cyber espionage campaign targeting India's tax infrastructure was identified between May and June 2026. The operation impersonates the Income Tax Department, Ministry of Finance, exploiting the AY2026-27 ITR filing season to target corporate entities, tax professionals, chartered accountants, and taxpayers. The attack employs spear-phishing emails with malicious attachments mimicking legitimate government utilities. The multi-stage infection chain deploys DcRAT through steganographic payload concealment, fileless .NET execution, AMSI bypass, and Windows service persistence. The threat actor demonstrates operational maturity through active payload rotation achieving 0/66 detection rates, encrypted TLS-based C2 communications, and infrastructure hosted across multiple ASNs linked to China. The campaign shows overlaps with the China-nexus threat actor Silver Fox, featuring screen capture capabilities, data exfiltration, and systematic intelligence collection from high-value India... MediumMalware Join the discussion | AlienVault OTX General | 06/26/2026, 12:50:31 UTC Added: 06/26/2026, 17:57:21 UTC |
Showing 1 to 10 of 53 results