Threats Tagged 't1001'
View all threats tagged with 't1001'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1001'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience. Join the discussion | AlienVault OTX General | 08/06/2026, 09:42:36 UTC Added: 08/06/2026, 10:56:12 UTC |
An MDR investigation successfully mapped the complete operational infrastructure of Banana RAT, a Brazilian banking trojan operated by threat cluster SHADOW-WATER-063. The investigation uncovered both server-side and client-side components, revealing a sophisticated FastAPI-based polymorphic payload generation system that produces hash-unique builds to evade detection. The malware employs layered obfuscation, AES-wrapped payloads, and fileless PowerShell execution. Once deployed, it enables operator-driven fraud through remote input control, keylogging, screen streaming, bank-branded overlays, and Pix QR code interception specifically targeting Brazilian financial institutions. The tooling exclusively targets 16 Brazilian banks and crypto exchanges, with all operator artifacts written in Brazilian Portuguese, indicating a financially motivated actor operating within the Tetrade banking trojan ecosystem. Join the discussion | AlienVault OTX General | 05/19/2026, 22:26:55 UTC Added: 05/21/2026, 00:33:32 UTC |
Iranian intelligence services are increasingly engaging with the cyber crime ecosystem, leveraging criminal tools, services, and operational models to support state objectives. This trend is particularly evident among actors linked to the Ministry of Intelligence and Security (MOIS), such as Void Manticore and MuddyWater. These actors are not merely imitating criminal behavior but actively associating with the cyber criminal ecosystem, using its infrastructure, malware, and affiliate-style relationships. This approach enhances their operational capabilities, complicates attribution, and contributes to confusion around Iranian threat activity. Examples include the use of ransomware branding, commercial infostealers, and overlaps with criminal malware clusters. This shift from imitation to active engagement with cyber crime offers both improved deniability and expanded technical capabilities for Iranian actors. Join the discussion | AlienVault OTX General | 03/10/2026, 21:10:43 UTC Added: 03/11/2026, 10:13:55 UTC |
The analysis examines Iranian state-aligned threat actors and their infrastructure patterns during heightened geopolitical tensions. It focuses on mapping network infrastructure, ASN patterns, TLS fingerprints, and hosting clusters associated with various Iranian APT groups. The report highlights the importance of proactive infrastructure monitoring to detect and disrupt potential cyber operations. Key findings include the identification of previously unreported hosts, domains, and servers linked to Iranian operations, as well as insights into the tactics used by groups like MuddyWater and Dark Scepter. The article emphasizes the value of infrastructure intelligence in early threat detection and provides recommendations for organizations to monitor and defend against these threats. MediumMalware Join the discussion | AlienVault OTX General | 03/04/2026, 19:42:41 UTC Added: 03/05/2026, 09:37:49 UTC |
The LABYRINTH CHOLLIMA threat group has split into three distinct adversaries: GOLDEN CHOLLIMA, PRESSURE CHOLLIMA, and core LABYRINTH CHOLLIMA. Each subgroup has specialized malware, objectives, and tradecraft. GOLDEN CHOLLIMA and PRESSURE CHOLLIMA focus on cryptocurrency entities, while core LABYRINTH CHOLLIMA continues espionage operations targeting industrial, logistics, and defense companies. Despite operating independently, these groups share tools and infrastructure, indicating coordinated resource allocation within North Korea's cyber ecosystem. The evolution stems from the KorDLL malware framework, which spawned several malware families. Recent operations demonstrate cloud-focused tradecraft and the use of zero-day vulnerabilities to deliver malware. Join the discussion | AlienVault OTX General | 01/30/2026, 08:48:36 UTC Added: 01/30/2026, 08:57:47 UTC |
An analysis of Chinese hosting environments reveals over 18,000 active command-and-control (C2) servers distributed across 48 infrastructure providers. C2 infrastructure dominates malicious activity at 84%, followed by phishing at 13%. China Unicom hosts nearly half of all observed C2 servers, with Alibaba Cloud and Tencent following. A small set of malware families, including Mozi, ARL, and Cobalt Strike, accounts for most C2 activity. The infrastructure supports both cybercrime and state-linked operations, with RATs, cryptominers, and APT tooling coexisting. High-trust networks like China169 Backbone and CERNET are actively exploited. This host-centric approach exposes long-running abuse patterns and infrastructure reuse across campaigns, enabling more resilient threat detection and mitigation strategies. Join the discussion | AlienVault OTX General | 01/15/2026, 12:03:35 UTC Added: 01/19/2026, 09:11:45 UTC |
This report describes how generative AI techniques were utilized to accelerate the reverse engineering of XLoader malware, specifically version 8.0. By combining cloud-based static analysis of IDA exported data with dynamic checks, researchers rapidly unpacked encrypted code, deobfuscated API calls, and decrypted strings and domain names. The analysis uncovered three distinct function encryption schemes and a complex domain generation algorithm used by XLoader. The AI-assisted approach significantly reduced analysis time from days to hours, enabling faster extraction of indicators of compromise (IoCs). Despite AI's assistance, human expertise remained essential for overcoming the most sophisticated protections. The report highlights that generative AI can serve as a force multiplier for malware analysis, though malware authors may adapt their techniques in response. The threat is assessed as medium severity, with no known exploits in the wild currently. Several IoCs including hashes and suspicious domains are provided for detection and blocking. Join the discussion | AlienVault OTX General | 11/03/2025, 14:28:33 UTC Added: 11/03/2025, 20:00:46 UTC |
In October 2025, a wave of sophisticated cyber attacks targeted corporate environments, leveraging phishing campaigns exploiting trusted platforms like Google Careers and ClickUp, abusing Figma for credential theft, and deploying the LockBit 5.0 ransomware variant against ESXi and Linux systems. Attackers used legitimate cloud services and multi-stage redirection to evade detection, while a new phishing kit named TyKit emerged. These campaigns threaten corporate credentials, infrastructure integrity, and data confidentiality across multiple sectors. The attacks do not require known exploits in the wild but rely heavily on social engineering and abuse of trusted platforms. Security operations centers (SOCs) must enhance detection capabilities, harden access controls, and employ advanced threat intelligence to mitigate these evolving threats. The overall severity is medium, reflecting the complexity and multi-vector nature of the attacks but without widespread exploitation of zero-day vulnerabilities. European organizations, especially those using affected platforms and cloud services, face significant risks from credential theft and ransomware infection. Join the discussion | AlienVault OTX General | 10/29/2025, 18:37:27 UTC Added: 10/29/2025, 20:13:19 UTC |
GhostSocks is a Malware-as-a-Service (MAAS) that converts compromised devices into residential proxies, enabling threat actors to bypass anti-fraud mechanisms. Introduced in October 2023, it gained popularity after partnering with LummaStealer in February 2024. The malware, coded in Golang, uses obfuscation techniques and can be built as a 32-bit DLL or executable. It doesn't implement persistence mechanisms but focuses on SOCKS5 functionality. GhostSocks uses a configuration file or hardcoded config to connect to C2 servers, randomly generates credentials, and establishes a SOCKS5 connection using open-source libraries. Despite law enforcement actions against related platforms, GhostSocks continues to operate, posing ongoing risks of double victimization and long-term network access for cybercriminals. Join the discussion | AlienVault OTX General | 10/01/2025, 07:39:51 UTC Added: 10/01/2025, 08:49:39 UTC |
A sophisticated SEO spam infection was discovered utilizing a cleverly crafted plugin that mimics the infected domain's name to avoid detection. The malware injects spam content into websites, targeting search engine rankings, and only activates under specific conditions like when a crawler is detected. The plugin's code is heavily obfuscated, using thousands of variable assignments broken into small parts. When decoded, the malware downloads files from external hosts, fetches remote content, and delivers custom spam to search engines while appearing normal to regular users. The attacker's domain, mag1cw0rld[.]com, is used for remote control. This technique allows the spam to remain undetected for longer periods, making it challenging to identify with traditional tools. Join the discussion | AlienVault OTX General | 07/06/2025, 13:13:42 UTC Added: 07/07/2025, 09:54:20 UTC |
Showing 1 to 10 of 13 results