Threats Tagged 't1021'
View all threats tagged with 't1021'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1021'
Click on any threat for detailed analysis and mitigation recommendations
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America 0 Two distinct multi-stage network intrusion campaigns are actively targeting Latin American organizations, with attackers leveraging artificial intelligence tools to enhance their capabilities. The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances. The Brazilian financial campaign (CL-CRI-1163) employed custom RATs and tunneling tools including a Go-based SOCKS5 proxy. Both operations demonstrate technical overlaps including shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration. Attackers used AI to generate scripts and troubleshoot execution failures, evidenced by iterative file naming patterns and exposed NextChat interfaces. However, fundamental operational security failures, including exposed staging directories and unsecured interfaces, provided defenders clear visibility... Join the discussion | AlienVault OTX General | 09/03/2026, 12:45:15 UTC Added: 09/03/2026, 16:22:14 UTC |
How guardrails might become the attacker's best friend 0 This analysis examines how poorly-designed AI guardrails in security operations can inadvertently assist threat actors by hindering defensive capabilities. The piece argues that while guardrails are necessary, their implementation and control by third-party AI providers can create safety penalties that slow or halt security investigations. When agentic Security Operations Centers experience refusals from overly restrictive filters, attackers gain valuable time to complete their missions. The author advocates for operational sovereignty, where security teams maintain control over their own guardrails and can customize them according to their specific threat models. Organizations need flexibility to temporarily adjust safeguards under authorized circumstances, something impossible with inflexible frontier provider controls. The piece emphasizes that defenders' traditional advantage requires engaging with threat landscape realities while ensuring adversaries cannot derail investigation and response processes. Join the discussion | AlienVault OTX General | 08/27/2026, 21:51:45 UTC Added: 08/28/2026, 09:07:13 UTC |
Extended Rapid Response: RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile 0 Threat actors are conducting sophisticated recruitment-themed phishing campaigns by impersonating HR personnel from prominent companies. The attacks leverage Browser-in-the-Browser techniques on desktop, while mobile devices display full-screen counterfeit login pages without visible URL indicators. The malicious infrastructure actively screens victims, rejecting personal emails to specifically target corporate credentials and enterprise access. Analysis reveals persistent hosting patterns primarily using Amazon and SEDO networks, with attackers impersonating brands including Amazon, Louis Vuitton, Apple, FIFA, Emirates, Boeing, Heineken, Deloitte, and Lego. Traditional threat feeds show significant delays in detecting these domains, with detection gaps ranging from 7 days to over 6 years. The campaign enables credential harvesting, OAuth token theft, and lateral movement within organizations. Join the discussion | AlienVault OTX General | 08/25/2026, 02:55:59 UTC Added: 08/25/2026, 10:52:01 UTC |
How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product 0 Investigation into residential proxy networks reveals that bandwidth-sharing applications like PEER2PROFIT recruit users to share internet connections for payment, then monetize this bandwidth through commercial proxy service ASTROPROXY at up to 27 times the original cost. Over 72 hours, researchers identified 117,224 unique IPs across residential, mobile, and datacenter pools, with residential pools adding over 1,000 new IPs hourly. These applications install through official channels with user consent, making them invisible to traditional security tools. Reverse engineering of the Windows SDK revealed the communications protocol and backconnect infrastructure coordinating proxy sessions. Testing demonstrated that proxy networks could access internal network resources through simple DNS entries resolving to internal IPs, potentially exposing corporate assets. The scale, legitimacy, and internal network access capabilities present significant risks to organizations where employees may unknowingly expose co... Join the discussion | AlienVault OTX General | 08/20/2026, 17:09:15 UTC Added: 08/20/2026, 23:22:26 UTC |
Showing 1 to 4 of 4 results