Threats Tagged 't1012'
View all threats tagged with 't1012'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1012'
Click on any threat for detailed analysis and mitigation recommendations
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them 0 StealC and Amadey are malware families involved in credential theft and enterprise breaches. StealC is a C++ infostealer that collects credentials from browsers, wallets, messaging apps, email clients, and gaming platforms, also acting as a secondary loader. Amadey is a modular backdoor loader active since 2018, delivering payloads including StealC, Lumma Stealer, and ransomware. Both operate on rental models where stolen credentials are sold through underground markets to access brokers. On June 24, 2026, law enforcement disrupted over 200 command-and-control domains supporting these malware operations. Join the discussion | AlienVault OTX General | 06/24/2026, 13:40:01 UTC Added: 06/24/2026, 17:54:44 UTC |
FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad 0 Gamaredon, an FSB-operated cyberespionage group, continues targeting Ukrainian government, military, and critical infrastructure through sophisticated multi-stage infection chains. This analysis examines GammaLoad, a collection of VBScript loaders that establish continuous access through three distinct stages. The malware leverages Dead Drop Resolvers on legitimate platforms including Telegram, Telegraph, and Check-Host to maintain persistent C2 communications while storing configurations in Windows registry keys. Each stage employs different techniques: the first fingerprints hosts and uses failover mechanisms, the second writes payloads to Alternate Data Streams and establishes persistence via scheduled tasks, and the third executes obfuscated PowerShell to deliver the final GammaSteel payload. This matryoshka architecture enables operators to deploy arbitrary payloads while remaining largely invisible by abusing trusted Windows features and cloud platforms. Join the discussion | AlienVault OTX General | 06/03/2026, 13:18:24 UTC Added: 06/04/2026, 08:48:45 UTC |
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT 0 DesckVB RAT emerged in February 2026 through a sophisticated malspam campaign utilizing a dynamic delivery kit that personalizes lures on-the-fly by extracting victim email addresses and pulling company logos in real-time. The attack chain routes through Google's DoubleClick domain to evade email gateways before delivering a five-stage infection: HTML redirect, JScript loader, PowerShell dropper, .NET loader, and finally the RAT itself. The malware employs extensive anti-analysis techniques including sandbox detection, forced reboots upon detection, and in-memory execution via .NET reflection. Once established, it patches AMSI and ETW at the native API level, injects into legitimate Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe, and establishes persistence through registry keys and scheduled tasks. The RAT communicates with DDNS-based C2 infrastructure on non-standard ports, performs system reconnaissance including GPU enumeration possibly for crypto mining, and can deliver additional payl... Join the discussion | AlienVault OTX General | 06/03/2026, 13:18:22 UTC Added: 06/04/2026, 08:48:45 UTC |
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet 0 Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation. Join the discussion | AlienVault OTX General | 05/26/2026, 15:20:06 UTC Added: 05/27/2026, 14:03:32 UTC |
Showing 1 to 4 of 4 results