Skip to main content

Threats Tagged 't1041'

View all threats tagged with 't1041'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1041

Threats Tagged 't1041'

Click on any threat for detailed analysis and mitigation recommendations

This campaign involves multiple cybersecurity incidents where trusted AI platforms have been exploited as channels for malware distribution. The threat actors employ advanced persistent threat techniques including exploitation of vulnerabilities, social engineering, and deployment of custom malware frameworks. Targets span government, technology, financial, and defense sectors, with a focus on supply chain attacks, credential harvesting, data exfiltration, system compromise, and lateral movement within networks. Several malicious domains have been identified as indicators related to this campaign.

Join the discussion

Vidar is an information-stealing malware first identified in 2018 that has progressively enhanced its string obfuscation methods to avoid detection and analysis. From May to September 2026, it evolved from simple XOR encryption to using ChaCha20-based algorithms and then implemented a custom virtual machine (VM) with a lightweight bytecode interpreter and custom stream ciphers that vary per build. The VM uses 14 opcode handlers with basic operations such as XOR, addition, rotation, and substitution. Version 2.0 introduced the VM, and versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build changes in opcodes, constants, and substitution tables complicate static and automated analysis efforts.

Join the discussion
0

This analysis details updates to Hangro, North Korea's state VPN and mail system infrastructure, spanning North Korean, Russian, and Chinese network address spaces. The service uses a certificate hierarchy with cryptographic anomalies and supports bulk mail transfers over intermittent connections. The infrastructure has evolved from a commercial email gateway to a certificate-bound VPN service for trade representatives. Network assignments linked to Silibank and infrastructure in the Russian Far East have been identified. The system employs large message limits and ETRN capabilities for mail relay.

Join the discussion

In late August, an organization experienced a ransomware attack by the INC group affecting at least 175 endpoints. The attack timeline shows two distinct phases separated by a 17-day gap, indicating possible involvement of an initial access broker followed by a ransomware affiliate. Initial activities included scheduled tasks with randomized names and lateral movement via RDP using compromised credentials. After the pause, attackers used AnyDesk for remote access, employed Bring Your Own Vulnerable Driver (BYOVD) techniques to disable security controls, and executed ransomware using Impacket tools. Two ransom notes were found: the standard INC-README.txt and a DATALEAK_PRESS_RELEASE.txt which threatened to leak stolen data to media, employees, and partners within 48 hours to increase pressure on the victim.

Join the discussion

In 2026, the DPRK-sponsored Lazarus subgroup TraderTraitor continued campaigns targeting cryptocurrency entities, including a high-profile attack on LayerZero resulting in $292 million theft from KelpDAO. Following this disclosure, an additional victim was identified: a smaller IT services provider in India with no cryptocurrency connections. The compromise involved a DevOps engineer targeted through fake job interview lures containing weaponized Terraform coding projects. Malicious GitHub repositories used typosquatted provider domains to deliver macOS backdoors FLATROOF and ROOFDECK when victims executed terraform init. The backdoors enabled reconnaissance, credential theft, and cloud environment escalation. One day after LayerZero's public disclosure, attackers deployed an updated stripped version of ROOFDECK and removed earlier implants. Activity continued until June 2026, suggesting the threat actor ultimately abandoned the intrusion after determining insufficient value from the smaller target.

Join the discussion

A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...

Join the discussion
0

LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan identified by Blackpoint, designed to masquerade as legitimate NVIDIA software. It provides comprehensive remote access capabilities including command execution, file operations, screen capture, and SOCKS5 proxying. The malware features configurable enrollment fields and an internal ZM_ configuration namespace, suggesting it is built on a reusable, multi-tenant framework consistent with a malware-as-a-service offering. LabubaRAT is managed through an associated backend infrastructure called LabubaPanel, hosted on German providers. The delivery mechanism utilized the RAT's own JavaScript execution capability. First observed in July 2026, it targets Windows platforms and employs various evasion techniques including masquerading as NVIDIA components and abusing legitimate Microsoft build utilities.

Join the discussion

Analysis reveals HEAVYGRAM, a multi-stage Windows backdoor attributed to Iran-linked threat actor Handala Hack, deployed since Fall 2023 targeting Iranian dissidents, journalists, and government opponents. The surveillance tool uses Telegram bot API for command-and-control operations, enabling remote command execution, screen capture, data exfiltration, and persistent access. Victims receive social-engineered files masquerading as legitimate applications like Telegram, KeePass, or Pictory. The implant supports DLL side-loading, registry persistence, and system reconnaissance. Infrastructure analysis identified 29 samples utilizing networks of Telegram bots and groups for operations. The malware aligns with activity disclosed by U.S. Department of Justice regarding Iran's Ministry of Intelligence and Security infrastructure seizures, with tradecraft including Vultr Object Storage and Persian-language decoys targeting specific victim profiles including academics and media personnel.

Join the discussion
0

A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution.

Join the discussion

ESET researchers have documented SparroWocky, a sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This China-aligned threat actor has shifted focus to extensively targeting governmental organizations across Latin America, likely in response to increased US interest in the region. SparroWocky replaced the group's previous SparrowDoor backdoor and demonstrates advanced capabilities including reflective loading, anti-analysis techniques like SilentMoonwalk for call stack spoofing, and the ability to execute Beacon Object Files. The modular backdoor incorporates open-source projects directly into its codebase, uses TLS-encrypted communications with RC4 encryption for data exfiltration, and employs sophisticated evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting pattern reflects China's strategic interest in monitoring Latin American governmental responses to current US pressures regarding investments and infrastruc...

Join the discussion

Showing 1 to 10 of 270 results

Filters:Tag: t1041
Page 1 of 27
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses