Threats Tagged 't1027'
View all threats tagged with 't1027'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1027'
Click on any threat for detailed analysis and mitigation recommendations
A six-month sophisticated campaign targeted quantitative and DeFi developers by distributing malicious npm packages masquerading as legitimate mathematics libraries. The campaign uses encrypted loaders that activate only during specific cryptographic operations, such as solving linear equations with certain matrices. Command and control is conducted via Ethereum Sepolia testnet smart contracts and a secondary Slack channel, enabling encrypted tasking of compromised systems. The threat actors inflated download counts using GitHub Actions workers to build false credibility. Fourteen smart contracts across five wallets managed over 1,000 encrypted taskings. The operation shows advanced operational security including disposable accounts, ephemeral key encryption, and infection markers hidden in license files. Join the discussion | AlienVault OTX General | 09/22/2026, 07:30:17 UTC Added: 09/22/2026, 08:02:57 UTC |
This campaign involves multiple cybersecurity incidents where trusted AI platforms have been exploited as channels for malware distribution. The threat actors employ advanced persistent threat techniques including exploitation of vulnerabilities, social engineering, and deployment of custom malware frameworks. Targets span government, technology, financial, and defense sectors, with a focus on supply chain attacks, credential harvesting, data exfiltration, system compromise, and lateral movement within networks. Several malicious domains have been identified as indicators related to this campaign. Join the discussion | AlienVault OTX General | 09/22/2026, 07:27:17 UTC Added: 09/22/2026, 08:02:57 UTC |
Vidar is an information-stealing malware first identified in 2018 that has progressively enhanced its string obfuscation methods to avoid detection and analysis. From May to September 2026, it evolved from simple XOR encryption to using ChaCha20-based algorithms and then implemented a custom virtual machine (VM) with a lightweight bytecode interpreter and custom stream ciphers that vary per build. The VM uses 14 opcode handlers with basic operations such as XOR, addition, rotation, and substitution. Version 2.0 introduced the VM, and versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build changes in opcodes, constants, and substitution tables complicate static and automated analysis efforts. Join the discussion | AlienVault OTX General | 09/21/2026, 16:45:51 UTC Added: 09/22/2026, 08:02:57 UTC |
In late August, an organization experienced a ransomware attack by the INC group affecting at least 175 endpoints. The attack timeline shows two distinct phases separated by a 17-day gap, indicating possible involvement of an initial access broker followed by a ransomware affiliate. Initial activities included scheduled tasks with randomized names and lateral movement via RDP using compromised credentials. After the pause, attackers used AnyDesk for remote access, employed Bring Your Own Vulnerable Driver (BYOVD) techniques to disable security controls, and executed ransomware using Impacket tools. Two ransom notes were found: the standard INC-README.txt and a DATALEAK_PRESS_RELEASE.txt which threatened to leak stolen data to media, employees, and partners within 48 hours to increase pressure on the victim. Join the discussion | AlienVault OTX General | 09/21/2026, 16:35:37 UTC Added: 09/22/2026, 08:18:01 UTC |
A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms. Join the discussion | AlienVault OTX General | 09/21/2026, 15:16:13 UTC Added: 09/21/2026, 15:31:54 UTC |
In 2026, the DPRK-sponsored Lazarus subgroup TraderTraitor continued campaigns targeting cryptocurrency entities, including a high-profile attack on LayerZero resulting in $292 million theft from KelpDAO. Following this disclosure, an additional victim was identified: a smaller IT services provider in India with no cryptocurrency connections. The compromise involved a DevOps engineer targeted through fake job interview lures containing weaponized Terraform coding projects. Malicious GitHub repositories used typosquatted provider domains to deliver macOS backdoors FLATROOF and ROOFDECK when victims executed terraform init. The backdoors enabled reconnaissance, credential theft, and cloud environment escalation. One day after LayerZero's public disclosure, attackers deployed an updated stripped version of ROOFDECK and removed earlier implants. Activity continued until June 2026, suggesting the threat actor ultimately abandoned the intrusion after determining insufficient value from the smaller target. Join the discussion | AlienVault OTX General | 09/19/2026, 08:44:15 UTC Added: 09/21/2026, 08:46:37 UTC |
Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal... Join the discussion | AlienVault OTX General | 09/18/2026, 21:49:13 UTC Added: 09/21/2026, 08:46:37 UTC |
Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands. Join the discussion | AlienVault OTX General | 09/18/2026, 13:20:16 UTC Added: 09/18/2026, 14:16:39 UTC |
PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft. Join the discussion | AlienVault OTX General | 09/18/2026, 12:51:25 UTC Added: 09/18/2026, 14:16:39 UTC |
An Israeli influence-for-hire company called BlackCore has been identified conducting digital manipulation campaigns across multiple countries. The company operates through a sophisticated infrastructure offering services including discourse dominance, organic engagement manipulation, and counter-operations. Researchers identified a specific campaign involving a 14-week training program delivered to Angolan government employees in early 2026, which included the creation and deployment of fake social media personas and coordinated inauthentic behavior. The operation utilized AI-generated profile pictures, fake news outlets like 'Agita News', and coordinated amplification tactics across Facebook, Instagram, and TikTok. BlackCore's promotional materials openly advertised their capabilities to conduct deceptive influence operations on behalf of government clients, demonstrating how influence-for-hire services have become accessible to state actors seeking to manipulate online discourse. MediumCampaign Join the discussion | AlienVault OTX General | 09/17/2026, 21:02:33 UTC Added: 09/18/2026, 09:01:46 UTC |
Showing 1 to 10 of 801 results