Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1008'

View all threats tagged with 't1008'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1008

Threats Tagged 't1008'

Click on any threat for detailed analysis and mitigation recommendations

Implants in the Supply Chain
0

Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...

Join the discussion
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
0

A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

Join the discussion
How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product
0

Investigation into residential proxy networks reveals that bandwidth-sharing applications like PEER2PROFIT recruit users to share internet connections for payment, then monetize this bandwidth through commercial proxy service ASTROPROXY at up to 27 times the original cost. Over 72 hours, researchers identified 117,224 unique IPs across residential, mobile, and datacenter pools, with residential pools adding over 1,000 new IPs hourly. These applications install through official channels with user consent, making them invisible to traditional security tools. Reverse engineering of the Windows SDK revealed the communications protocol and backconnect infrastructure coordinating proxy sessions. Testing demonstrated that proxy networks could access internal network resources through simple DNS entries resolving to internal IPs, potentially exposing corporate assets. The scale, legitimacy, and internal network access capabilities present significant risks to organizations where employees may unknowingly expose co...

Join the discussion
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
0

A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: t1008
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses