Threats Tagged 'sqlmap'
View all threats tagged with 'sqlmap'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'sqlmap'
Click on any threat for detailed analysis and mitigation recommendations
The NKNShell malware campaign involves a compromised South Korean VPN provider website used to distribute a multi-stage malware payload. The threat actor Larva-24010 deploys several backdoors including MeshAgent, gs-netcat, and a novel Go-based backdoor called NKNShell, which leverages NKN and MQTT protocols for command and control. The infection chain uses trojanized installers and PowerShell scripts, employing advanced evasion techniques such as AMSI and UAC bypasses. Additional tools like SQLMap are deployed to facilitate further exploitation. While primarily targeting Korean VPN users, the sophisticated use of blockchain-based networking protocols and multiple backdoors poses risks to any users of the compromised VPN service. The campaign's medium severity reflects its complexity and targeted nature, but it has not yet been observed exploiting widespread vulnerabilities or causing large-scale impact beyond South Korea. Join the discussion | AlienVault OTX General | 11/20/2025, 14:45:54 UTC Added: 11/20/2025, 22:13:41 UTC |
Showing 1 to 1 of 1 result