Skip to main content

Threats Tagged 't1021'

View all threats tagged with 't1021'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1021

Threats Tagged 't1021'

Click on any threat for detailed analysis and mitigation recommendations

Galago is a newly identified ransomware operation that emerged in September 2026, claiming operational partnership with the Panzer ransomware group. The connection is suggested through shared infrastructure, specifically matching prefixes in their Tor leak-site addresses (pnzr4del for Galago and pnzruro for Panzer). Galago was first detected following an alleged attack on an Icelandic healthcare organization on 9 September 2026, though this claim remains unverified as their dark leak site showed no published victims. Panzer, described as a ransomware-as-a-service operation, has published 32 victims between August and September 2026 and employs double extortion tactics. While the naming pattern and self-reported claims suggest a relationship, no independent evidence confirms shared operators, malware, or infrastructure control between the two groups.

Join the discussion

This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

Join the discussion

Two distinct multi-stage network intrusion campaigns are actively targeting Latin American organizations, with attackers leveraging artificial intelligence tools to enhance their capabilities. The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances. The Brazilian financial campaign (CL-CRI-1163) employed custom RATs and tunneling tools including a Go-based SOCKS5 proxy. Both operations demonstrate technical overlaps including shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration. Attackers used AI to generate scripts and troubleshoot execution failures, evidenced by iterative file naming patterns and exposed NextChat interfaces. However, fundamental operational security failures, including exposed staging directories and unsecured interfaces, provided defenders clear visibility...

Join the discussion

This analysis discusses how poorly designed AI guardrails in security operations can unintentionally aid attackers by impeding defensive actions. Overly restrictive or inflexible AI filters controlled by third-party providers may cause delays or refusals in security investigations, giving adversaries more time to complete their objectives. The author recommends that security teams maintain operational sovereignty over guardrails, allowing customization and temporary adjustments to safeguards to better align with specific threat models. This flexibility is essential to prevent attackers from exploiting rigid controls to disrupt incident response processes.

Join the discussion

RecruitTrap is a sophisticated phishing campaign targeting enterprise credentials by impersonating HR personnel from well-known companies. It uses Browser-in-the-Browser techniques on desktop and full-screen fake login pages on mobile without visible URL indicators. The campaign actively screens victims to focus on corporate accounts, rejecting personal emails. Attackers impersonate multiple global brands and use persistent hosting on Amazon and SEDO networks. Detection of malicious domains is significantly delayed by traditional threat feeds. The campaign facilitates credential harvesting, OAuth token theft, and lateral movement within organizations.

Join the discussion

Peer2Profit and Astroproxy are bandwidth-sharing applications that recruit users to share their internet connections for payment. This bandwidth is then monetized through a commercial proxy service at significantly higher rates. The applications install through official channels with user consent, making them difficult to detect with traditional security tools. Researchers identified over 117,000 unique IPs in 72 hours, with rapid growth in residential IPs. Reverse engineering revealed the communications protocol and backconnect infrastructure managing proxy sessions. Testing showed these proxy networks can access internal network resources via DNS entries resolving to internal IPs, potentially exposing corporate assets. The scale and internal access capabilities present significant risks to organizations where employees run these applications.

Join the discussion

An authentication bypass vulnerability, CVE-2026-18577, affecting N-able N-central Remote Monitoring and Management platform has been actively exploited since August 1, 2026. This vulnerability emerged after an incomplete fix for a previous authentication bypass issue CVE-2026-18556. The flaw allows remote unauthenticated attackers to bypass authentication mechanisms and gain administrative control over vulnerable N-central servers. Attackers have exploited this vulnerability to leverage the platform's Take Control functionality for remote access to managed endpoints and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. Given that N-central is widely used by managed service providers and enterprise IT teams with extensive administrative privileges, successful compromise provides attackers an efficient pathway to compromise downstream managed systems. CISA added this vulnerability to its Known Exploited Vulnerability catalog on August 3, 2026.

Join the discussion

GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

Join the discussion

A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices.

Join the discussion

Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem.

Join the discussion

Showing 1 to 10 of 62 results

Filters:Tag: t1021
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses