Threats Tagged 't1033'
View all threats tagged with 't1033'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1033'
Click on any threat for detailed analysis and mitigation recommendations
Fake AI Tools Deliver Infostealer 0 In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges... Join the discussion | AlienVault OTX General | 08/04/2026, 18:21:01 UTC Added: 08/05/2026, 09:11:32 UTC |
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant 0 A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain Join the discussion | AlienVault OTX General | 08/05/2026, 08:30:10 UTC Added: 08/05/2026, 08:56:25 UTC |
Shai-Hulud-Style npm Worm Hits 0 Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity. Join the discussion | AlienVault OTX General | 07/29/2026, 08:57:13 UTC Added: 07/29/2026, 11:52:25 UTC |
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor 0 Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b... Join the discussion | AlienVault OTX General | 07/27/2026, 16:45:15 UTC Added: 07/28/2026, 10:22:27 UTC |
Upgrades MaaS Ecosystem with Modular Tools 0 Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem. Join the discussion | AlienVault OTX General | 07/23/2026, 16:30:34 UTC Added: 07/23/2026, 23:37:06 UTC |
Portugal-focused phishing campaign delivers multistage malware 0 An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims. Join the discussion | AlienVault OTX General | 07/21/2026, 16:05:04 UTC Added: 07/22/2026, 08:07:06 UTC |
Targeted Attack on Government Entities in the Middle East | Part 1 0 A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures. Join the discussion | AlienVault OTX General | 08/03/2026, 21:38:36 UTC Added: 07/21/2026, 10:27:03 UTC |
Novel Starland RAT and bespoke WLDR C2 implant deployed in financially motivated campaign 0 A sophisticated Russian-speaking financially motivated adversary designated UAT-11795 has been conducting malicious operations targeting users in the United States and Europe since June 2025. The campaign delivers a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as the WLDR agent. The actor distributes trojanized installers disguised as legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT through likely ClickFix social engineering techniques. The operation targets victims' credentials and cryptocurrency wallet assets while establishing persistent connections for additional payload delivery. Alternative payloads include CastleStealer and Remcos RAT. The infrastructure utilizes distributed staging and C2 domains, Telegram bots for notifications, and a Polygon smart contract as a fallback mechanism for C2 domain resolution. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine for exe... Join the discussion | AlienVault OTX General | 07/16/2026, 11:34:02 UTC Added: 07/17/2026, 00:32:32 UTC |
11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload 0 Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777. Join the discussion | AlienVault OTX General | 07/15/2026, 16:29:28 UTC Added: 07/15/2026, 22:03:24 UTC |
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor 0 Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:11 UTC Added: 07/15/2026, 21:47:49 UTC |
Showing 1 to 10 of 15 results