Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1033'

View all threats tagged with 't1033'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1033

Threats Tagged 't1033'

Click on any threat for detailed analysis and mitigation recommendations

Angry Birds: Toy Ghouls’ new toys
0

Toy Ghouls, a financially motivated group targeting Russian organizations since 2025, has deployed custom backdoors for the first time. Two versions were identified: mqtt-bird-agent using HiveMQ MQTT broker and matrix-bird-agent using Element messenger as command and control infrastructure. The backdoors are delivered via Windows Remote Management (WinRM) using tools like Evil-WinRM and WinRM-fs. They establish persistence as Windows services, encrypt configuration files using ChaCha20-Poly1305 algorithm, and execute commands via PowerShell or command line. The backdoors collect system metrics including CPU load, memory, and disk usage, and communicate with attackers through unconventional channels. This represents a significant evolution from their previous reliance on public GitHub tools and leaked ransomware builders to custom-developed malware.

Join the discussion
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC
0

This campaign targets Korean users by installing remote control tools such as Radmin and UltraVNC to compromise systems. Attackers download compressed files containing batch scripts and remote administration software. After installing Radmin, they deploy UltraVNC and proxy tools like Netch-gateway and CCProxy to use compromised systems as proxy nodes. Recent variants also deploy SoftEther VPN to establish VPN servers on infected machines. PowerShell scripts with Chinese language comments and tools familiar to Chinese-speaking actors suggest attribution to Chinese threat actors. The campaign enables remote control and proxy abuse of compromised infrastructure.

Join the discussion
Node.js: Old Technique Makes a Comeback
0

Since February 2026, there has been a resurgence of abuse involving Node.js binaries to execute malicious JavaScript payloads, targeting government, technology, and hospitality sectors. Attackers use the legitimate signed node.exe to evade signature-based detection and deploy various malware including ModeloRAT and the Rust-based C2Looper backdoor. These campaigns are linked to the initial access broker Woodgnat and multiple ransomware families. Techniques such as EtherHiding and ClickFix are employed for stealthy communication and initial access. The threat actors combine living-off-the-land tactics with commodity malware to maintain persistence and conduct operations.

Join the discussion
Inside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research
0

This threat involves the discovery and analysis of the TukTuk Command and Control (C2) framework version 2.0, used by the threat actor group known as The Gentlemen. The framework supports cross-platform agents for Windows and Linux, includes backend infrastructure and a management panel, and contains components such as eb.sys linked to the GentleKiller malware. The server also held extensive training materials for EDR neutralization techniques, including BYOVD, vulnerable driver exploitation, and kernel-level research. DLL sideloading configurations targeting legitimate applications like Greenshot, ProcMon, Slack, and Postman were identified. Data exfiltrated by this framework includes sensitive Jira tickets related to U.S. defense organizations and contractors, as well as credentials exposing cloud infrastructure and production environments of a global healthcare company. The threat is assessed as medium severity and currently has no known exploits in the wild or publicly available patches.

Join the discussion
Toolkit: AI-Assisted Development and Persistent Threat Operations
0

The Gryxa toolkit is a malware toolkit developed with significant assistance from an AI coding agent, enabling a threat actor with limited development skills to create sophisticated persistent attack infrastructure. It operates across hundreds of hosts and uses multiple persistence mechanisms such as scheduled tasks, Windows event subscriptions, and redundant file copies to resist removal. Gryxa also monitors Windows logs and host artifacts after remediation attempts, potentially exposing defender tools and accounts. The actor iteratively improved the toolkit through numerous failed installations, enhancing its resilience. Organizations face challenges in remediation, especially on devices outside centralized management, as Gryxa can rebuild faster than manual response efforts.

Join the discussion
ValleyRAT is spreading disguised as adware
0

ValleyRAT is a backdoor malware distributed disguised as legitimate Chinese adware called QN Wallpaper. It uses DLL sideloading to execute malicious code under a signed process. The malware includes capabilities such as keylogging, clipboard monitoring, screenshot capture, and module delivery. The campaign has impacted over 1,500 users mainly in China and India with over 100,000 detections in 2026. The Silver Fox threat group is attributed to this campaign. The malware disables Windows Defender, establishes persistence, and protects its processes by marking them critical to cause system crashes if terminated.

Join the discussion
A ClickFix cluster: Observed activity from recent ClickFix campaigns
0

Multiple ClickFix campaigns were identified employing three distinct delivery mechanisms while sharing common characteristics including DLL sideloading, consistent file-naming conventions, and command-and-control dead drops. The first campaign used remotely hosted MSI packages containing legitimate software to sideload malicious DLLs. The second leveraged NodeJS to execute JavaScript files, while the third utilized Python 3.5 to conceal and execute payloads. All campaigns originated from ClickFix lures and employed aggressive social engineering tactics, including direct phone contact directing victims to compromised WordPress sites. Post-compromise activity included extensive discovery commands and Active Directory enumeration. Infrastructure overlap and tactics indicate connections to the Lorem Ipsum malware family and Vanilla Tempest operations, with potential ransomware deployment as the final objective.

Join the discussion
Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
0

On August 20, 2026, malicious versions of three Rust crates were published to crates.io: [email protected], [email protected], and [email protected]. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary at compile time. The payload is a featureful backdoor that beacons to C2 via HTTPS, exfiltrates host information, enumerates installed applications, reads browser profiles for saved logins, and persists via Registry Run key, LaunchAgent, or systemd user service. The campaign's infrastructure substantially overlaps with operations attributed to North Korean actors, including shared C2 endpoint patterns with the Mastra campaign and IP addresses used in the axios npm attack.

Join the discussion
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
0

A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

Join the discussion
SynkLoader: when you throw in everything but the kitchen sink
0

A sophisticated modular loader utilizing multiple programming languages to evade detection has been discovered. The attack begins with Microsoft Teams phishing where attackers impersonate IT helpdesk personnel, convincing targets to install a fake PowerShell cleaner via MSI installer. The malware deploys memory-resident components bridging Python, C#, C++, and PowerShell to profile systems, establish persistence via scheduled tasks, and deploy a fake Windows lock screen to phish user credentials. Additional modules include a reverse proxy for network tunneling, enabling threat actors to access internal corporate systems using compromised credentials, plus remote shell and VNC capabilities for hands-on-keyboard attacks. The elaborate multi-stage infection chain suggests potential ransomware operations or initial access brokering.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Tag: t1033
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses