Threats Tagged 't1040'
View all threats tagged with 't1040'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1040'
Click on any threat for detailed analysis and mitigation recommendations
The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors. Join the discussion | AlienVault OTX General | 06/29/2026, 11:01:00 UTC Added: 06/30/2026, 06:51:30 UTC |
A massive network of over 20,000 fraudulent e-commerce domains has been uncovered, all sharing common infrastructure and design patterns. These fake shops, primarily using the .shop domain, are designed to steal payment details and personal data from unsuspecting consumers. The operation is highly industrialized, with domains resolving to just 36 IP addresses, indicating a franchise-style model where a core team manages servers and templates while individual operators launch storefronts. The shops use familiar e-commerce tactics and psychological pressure to lure victims. To protect yourself, use browser protection tools, scrutinize unfamiliar domains, be wary of deep discounts, and look for independent reviews before making purchases. MediumCampaign Join the discussion | AlienVault OTX General | 03/18/2026, 16:24:46 UTC Added: 03/18/2026, 16:27:29 UTC |
Cisco Talos uncovered 'DKnife', a sophisticated gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants. Used since 2019, DKnife performs deep-packet inspection, traffic manipulation, and malware delivery via routers and edge devices. It targets various devices, including PCs, mobile devices, and IoT, delivering ShadowPad and DarkNimbus backdoors. The framework primarily targets Chinese-speaking users, with evidence suggesting China-nexus threat actors as operators. DKnife's capabilities include DNS hijacking, Android application update hijacking, Windows binary hijacking, anti-virus traffic disruption, and user activity monitoring. A link to the WizardNet campaign was also discovered, indicating a shared development or operational lineage. Join the discussion | AlienVault OTX General | 02/05/2026, 20:16:27 UTC Added: 02/05/2026, 20:45:09 UTC |
An exposed open directory on a command and control server revealed a complete deployment of the BYOB (Build Your Own Botnet) framework. The multi-stage infection chain targets Windows, Linux, and macOS platforms, implementing seven persistence mechanisms. The malware includes extensive post-exploitation capabilities such as keylogging, packet capture, and email harvesting. Analysis uncovered a modular design with encrypted C2 communications and infrastructure reuse across multiple regions. Two nodes also hosted XMRig cryptocurrency miners, indicating additional monetization efforts. The campaign has been operational for approximately 10 months, demonstrating geographic and provider diversification in its infrastructure. Join the discussion | AlienVault OTX General | 01/29/2026, 12:49:58 UTC Added: 01/29/2026, 16:27:48 UTC |
The VVS Discord Stealer is a Python-based malware designed to exfiltrate sensitive Discord user data including credentials and tokens. It uses Pyarmor with BCC mode and AES-128-CTR encryption to heavily obfuscate its code, evading detection by static and dynamic analysis tools. The malware decrypts encrypted Discord tokens, queries Discord APIs for user information, injects malicious JavaScript into the Discord client to intercept active sessions, and extracts data from multiple web browsers. It achieves persistence by configuring itself to run at system startup and deceives victims by displaying a fake error message. While no known exploits or CVEs are reported, its capabilities pose a medium severity threat. The stealer primarily targets Windows environments where Discord and browsers are installed and relies on user interaction, likely via social engineering. European organizations with significant Discord usage, especially in technology, gaming, media, and education sectors, face risks of credential theft, unauthorized access, data leakage, and operational disruption. Detection requires behavioral and heuristic analysis due to strong obfuscation techniques. Join the discussion | AlienVault OTX General | 01/02/2026, 13:40:42 UTC Added: 01/02/2026, 16:28:44 UTC |
The ShadyPanda threat actor has conducted a sophisticated seven-year malware campaign infecting 4.3 million Chrome and Edge browsers via malicious extensions that were verified and featured by Google, enabling widespread trust and distribution. The campaign operates two main components: a 300,000-user remote code execution (RCE) backdoor and a 4-million-user spyware operation that harvests extensive user data such as browsing history, search queries, and mouse clicks, sending it to servers in China. This malware exploits vulnerabilities in browser extension marketplaces and trusted update mechanisms to maintain persistence and evade detection. The campaign highlights significant risks to user privacy and organizational security, especially for entities relying heavily on Chrome and Edge browsers. European organizations face risks of data exfiltration, espionage, and potential lateral movement within networks. Mitigation requires proactive extension management, network monitoring for suspicious domains, and enhanced user awareness. Countries with high Chrome/Edge usage and strategic geopolitical interest in China-related cyber espionage are most at risk. The threat severity is assessed as high due to the scale, stealth, and potential impact on confidentiality and integrity without requiring user interaction post-installation. Join the discussion | AlienVault OTX General | 12/03/2025, 20:19:10 UTC Added: 12/04/2025, 11:23:20 UTC |
Showing 1 to 6 of 6 results