Threats Tagged 't1014'
View all threats tagged with 't1014'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1014'
Click on any threat for detailed analysis and mitigation recommendations
AvisLoader is a newly discovered Windows malware loader that uses the Tox encrypted peer-to-peer messaging network for command-and-control communications, making traditional domain-based takedowns ineffective. The infection begins with a ClickFix social engineering technique, where victims are tricked into copying and executing malicious commands disguised as document verification steps. The loader is delivered through Cloudflare infrastructure and includes various stealth capabilities such as shortcut modification for persistence, UAC bypass attempts via UACME method 41, and process-hiding functionality through API hooking. Operators manage infected systems through a web-based Command Center that enables client management, task configuration, and payload distribution over the Tox network. The malware's architecture allows operators to maintain control by simply copying their Tox save file when relocating infrastructure, with clients automatically following without requiring domain updates. Join the discussion | AlienVault OTX General | 09/23/2026, 17:33:28 UTC Added: 09/23/2026, 20:02:51 UTC |
Three years after its initial discovery, the Melofee Linux implant has evolved with sophisticated new capabilities. The malware now features modularized architecture with hot-loadable components for shell functionality, file management, and command execution. New versions incorporate remote C2 infrastructure reconfiguration and enhanced stealth through a kernel rootkit based on the Reptile project. The implant uses RC4 encryption and supports multiple communication protocols including TCP, HTTP, HTTPS, and TLS. Analysis reveals two infrastructure clusters utilizing fake certificates impersonating Symantec and other entities. Code similarities establish links with Windows-targeting implants including CrowDoor, Hemigate, and RatelS, suggesting tool sharing among multiple Chinese state-linked threat groups. The modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface. Join the discussion | AlienVault OTX General | 09/10/2026, 22:17:12 UTC Added: 09/11/2026, 14:17:10 UTC |
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment. Join the discussion | AlienVault OTX General | 08/14/2026, 10:50:02 UTC Added: 08/14/2026, 11:26:13 UTC |
0 A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24. Join the discussion | CVE Database V5 | 08/03/2026, 09:04:41 UTC Added: 04/15/2026, 19:32:09 UTC |
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks. Join the discussion | AlienVault OTX General | 07/20/2026, 09:36:09 UTC Added: 07/20/2026, 11:11:45 UTC |
Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:11 UTC Added: 07/15/2026, 21:47:49 UTC |
Researchers uncovered fast16, a cyber sabotage framework from 2005 that predates Stuxnet by five years. The toolset includes fast16.sys, a kernel driver that selectively targets high-precision calculation software by patching code in memory to corrupt computational results. Combined with self-propagation mechanisms via a Lua-powered carrier module (svcmgmt.exe), the framework spreads across facilities to produce consistent inaccurate calculations. This operation represents the first documented instance of strategic cyber sabotage targeting ultra-expensive computing workloads in advanced physics, cryptographic, and nuclear research. The framework uses an embedded Lua virtual machine predating Flame by three years and appears in the ShadowBrokers leak of NSA Territorial Dispute components with the evasion signature: 'fast16 *** Nothing to see here – carry on ***'. Join the discussion | AlienVault OTX General | 04/24/2026, 05:05:20 UTC Added: 04/24/2026, 08:21:28 UTC |
Elastic Security Labs analyzes VoidLink, a sophisticated Linux malware framework combining Loadable Kernel Modules (LKMs) and eBPF for persistence. The rootkit, developed by a Chinese-speaking threat actor, evolved through four generations, targeting kernels from CentOS 7 to Ubuntu 22.04. VoidLink employs advanced techniques like delayed initialization, runtime key rotation, and a hybrid LKM-eBPF architecture for comprehensive stealth. Notable features include an ICMP-based covert channel, process protection, and memfd-aware boot loading. Evidence suggests AI-assisted development, lowering the barrier for kernel-level rootkit creation. Detection strategies and defensive recommendations are provided to counter this emerging threat. Join the discussion | AlienVault OTX General | 03/26/2026, 11:59:44 UTC Added: 03/26/2026, 18:04:40 UTC |
The Sysdig Threat Research Team analyzed VoidLink, a sophisticated Linux malware framework targeting cloud environments. Key findings include the first documented Serverside Rootkit Compilation, Chinese development with AI assistance, adaptive detection evasion, and use of the Zig programming language. VoidLink employs a multi-stage loader architecture, fileless execution techniques, and kernel-level stealth mechanisms. It features three control channels, including a covert ICMP channel, and specialized functionality for cloud and container environments. Despite its sophistication, VoidLink can be detected using runtime monitoring tools. The malware shows indicators of Chinese-speaking developers with significant kernel expertise, likely using AI-assisted development methods. Join the discussion | AlienVault OTX General | 01/19/2026, 09:35:38 UTC Added: 01/19/2026, 09:56:45 UTC |
In mid-2025, a malicious driver file was discovered on Asian computer systems, signed with a compromised digital certificate. This driver injects a backdoor Trojan and protects malicious files, processes, and registry keys. The final payload is a new variant of the ToneShell backdoor, associated with the HoneyMyte APT group. The attacks, which began in February 2025, primarily target government organizations in Southeast and East Asia, especially Myanmar and Thailand. The malware uses various techniques to evade detection, including API obfuscation, process protection, and registry key protection. The ToneShell backdoor communicates with command-and-control servers using fake TLS headers and supports remote operations such as file transfer and shell access. Join the discussion | AlienVault OTX General | 12/29/2025, 13:22:26 UTC Added: 12/30/2025, 22:18:40 UTC |
Showing 1 to 10 of 18 results