Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1036'

View all threats tagged with 't1036'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1036

Threats Tagged 't1036'

Click on any threat for detailed analysis and mitigation recommendations

Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data
0

Six Chrome and Firefox extensions linked through shared code, C2 infrastructure, and publishing history have been identified targeting cryptocurrency traders. Four malicious extensions steal authenticated session tokens and wallet data from Axiom Trade and Padre users, while two earlier extensions reveal a pattern of repackaging crypto trading tools. The extensions J7Tracker, VREO, and Orbit Tracker automatically retrieve user information, wallet bundles, Firebase tokens, and application state, then exfiltrate data to threat actor-controlled Vercel deployments. The campaign targets an active trading community with Axiom processing over $15 billion in volume across 650,000 wallets. The malicious code runs inside authenticated sessions, collecting localStorage, IndexedDB data, and API responses containing authentication tokens and wallet keys. Data is Base64-encoded and transmitted via browser navigation to avoid CORS restrictions, enabling account compromise and cryptocurrency theft.

Join the discussion
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
0

Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

Join the discussion
Grand Theft Auto VI hype leads to malware
0

Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

Join the discussion
ASCII smuggling crosses over from AI prompt injection to phishing evasion
0

Microsoft researchers identified a high-volume phishing campaign utilizing invisible Unicode tag characters (U+E0000 to U+E007F), a technique originally associated with AI prompt injection research known as ASCII Smuggling. The attackers inserted these invisible characters into financial keywords like 'funding' to evade email filters rather than hiding instructions from users. The campaign began February 9, 2026, generating millions of daily messages for approximately three months with a distinctive weekday-only pattern. Finance-themed disposable domains were used to send business loan and credit-line phishing through a legitimate email marketing platform. The technique, while designed for AI security contexts, proved effective at bypassing traditional keyword-based detection by splitting words with invisible characters that appear normal to recipients but break signature matches and alter ML tokenization.

Join the discussion
CVE-2026-85046: Type confusion in Google ChromeCVE-2026-85046
0

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Join the discussion
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
0

Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.

Join the discussion
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
0

An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.

Join the discussion
One leftover build path links an infostealer, a remote-access tool, and a ransomware family
0

A compilation artifact, specifically a developer's home directory path (/home/tcherber/.cargo/), linked multiple malware families including a Rust-based infostealer named Zer0day Stealer, an HVNC remote-control tool, and ENIGMA Locker ransomware to a single developer. The infostealer exfiltrates cryptocurrency wallets, browser credentials, Office documents, and VPN configurations. The HVNC tool enables hidden remote desktop sessions and implements AMSI and ETW evasion techniques. Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS. Multiple droppers written in C, Rust, and PowerShell were discovered delivering the malicious payloads. Build timestamps indicated development occurred within weeks, and infrastructure leaked evidence of additional tools including FUD-Crypter, Botnet, and C2 Agent components, demonstrating how overlooked compilation artifacts enable comprehensive attribution and threat mapping.

Join the discussion
Toolkit: AI-Assisted Development and Persistent Threat Operations
0

The Gryxa toolkit is a malware toolkit developed with significant assistance from an AI coding agent, enabling a threat actor with limited development skills to create sophisticated persistent attack infrastructure. It operates across hundreds of hosts and uses multiple persistence mechanisms such as scheduled tasks, Windows event subscriptions, and redundant file copies to resist removal. Gryxa also monitors Windows logs and host artifacts after remediation attempts, potentially exposing defender tools and accounts. The actor iteratively improved the toolkit through numerous failed installations, enhancing its resilience. Organizations face challenges in remediation, especially on devices outside centralized management, as Gryxa can rebuild faster than manual response efforts.

Join the discussion
ValleyRAT is spreading disguised as adware
0

ValleyRAT is a backdoor malware distributed disguised as legitimate Chinese adware called QN Wallpaper. It uses DLL sideloading to execute malicious code under a signed process. The malware includes capabilities such as keylogging, clipboard monitoring, screenshot capture, and module delivery. The campaign has impacted over 1,500 users mainly in China and India with over 100,000 detections in 2026. The Silver Fox threat group is attributed to this campaign. The malware disables Windows Defender, establishes persistence, and protects its processes by marking them critical to cause system crashes if terminated.

Join the discussion

Showing 1 to 10 of 23 results

Filters:Tag: t1036
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses