Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1036'

View all threats tagged with 't1036'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1036

Threats Tagged 't1036'

Click on any threat for detailed analysis and mitigation recommendations

Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
0

Vanta Stealer is a Python-based cross-platform information stealer malware that targets credentials from Chromium browsers, communication apps like Discord and Telegram, gaming platforms, cryptocurrency wallets, VPN configurations, and sensitive documents. It uses PyArmor and PyInstaller to hinder analysis and employs a modular design to download extraction tools at runtime. The malware enriches stolen Discord tokens by querying the Discord API for detailed account information. Harvested data is compiled into structured reports and exfiltrated via HTTP POST to attacker-controlled servers. Distribution likely involves social engineering such as phishing and trojanized files. No patches or vendor mitigations are applicable as this is malware rather than a software vulnerability.

Join the discussion
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
0

On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.

Join the discussion
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
0

A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

Join the discussion
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
0

Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

Join the discussion
Fake AI Tools Deliver Infostealer
0

In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...

Join the discussion
XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens
0

In May 2026, a sophisticated Monero cryptomining campaign was identified targeting Linux environments. Attackers gained initial access through trusted third-party relationships, then escalated to root privileges. Rather than operating openly as root, they weaponized Linux Pluggable Authentication Modules (PAM) to impersonate multiple low-privileged users, creating a forensic smokescreen and establishing redundant persistence through cronjobs. The operators suppressed system logging and deployed a customized XMRig 6.25.0 implant that self-unlinks after execution, running entirely in memory. The binary uses XOR encryption for configuration obfuscation and employs process masquerading to blend with legitimate processes. Campaign tracking revealed operations linked to the V25 Generation 26 family, connecting to the domain unable.download for mining pool communication.

Join the discussion
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
0

A fraudulent website impersonating Corepack, the Node.js package manager tool, is distributing malware to developers. The attackers exploit timing around Corepack's removal from Node.js bundling, targeting developers searching for installation instructions. The site offers Windows executables that deliver OpenShield infostealer and proxyware, enrolling victim machines in bandwidth-sharing networks without consent. The payload steals browser credentials, SSH keys, establishes persistence, and routes third-party traffic through compromised systems. An alternative download path delivers adware and trojan components disguised as OperaGX installer. The site features AI-generated content with obvious errors, including confusing Yarn package manager with textile crafts. The domain has been reported to registrars for takedown after community members identified the threat.

Join the discussion
June 2026 Threat Trend Report on APT Attacks (South Korea)
0

AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

Join the discussion
Email threat landscape: Q2 2026 trends and insights
0

During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end.

Join the discussion
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
0

Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

Join the discussion

Showing 1 to 10 of 22 results

Filters:Tag: t1036
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses