Threats Tagged 't1047'
View all threats tagged with 't1047'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1047'
Click on any threat for detailed analysis and mitigation recommendations
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is. Join the discussion | AlienVault OTX General | 09/23/2026, 20:08:58 UTC Added: 09/23/2026, 20:17:47 UTC |
Settra is a ransomware variant first observed in June 2026 that targets organizations through VPNs or compromised credentials. Two incidents were investigated in July and September 2026, affecting the consumer services, retail, and manufacturing sectors. Attackers deployed MeshAgent RMM for persistence, naming ransomware executables after victim domain names. The malicious activity included file encryption with .locked or .locked_wip extensions, deployment of RESTORE_FILES.txt ransom notes, clearing Windows event logs, and disabling Windows recovery options using reagentc and diskpart utilities. One incident featured Bring Your Own Vulnerable Driver (BYOVD) tactics using gdrv.sys. A notable operational security failure occurred when attackers misspelled the Windows Defender Event Log path, preventing its deletion. Both attacks followed remarkably similar operational patterns, with MeshAgent installations pointing to different C2 IP addresses (45.13.122[.]7 and 193.5.65[.]114), and malicious workstation WIN... Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:01 UTC Added: 09/18/2026, 08:46:41 UTC |
Brazilian banking malware operation REF9334 has been deploying KREMLIN toolkit since May 2025, targeting Brazilian financial institutions through malicious browser extensions. The operation uses multi-stage JavaScript loaders, custom C++ installers, and exploits Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs. Infrastructure leverages Ethereum smart contracts as dead-drop resolvers for dynamic C2 configuration. Seven distinct campaigns over 15 months show evolution from PULSAR RAT to REMCOS RAT delivery. Attackers impersonate twelve Brazilian banks through Portuguese-language lures, with transaction patterns clustering during São Paulo working hours. The malicious extensions intercept credentials, session tokens, and sensitive banking data through keylogging and request interception capabilities. Over 1,500 infections have been temporarily disrupted through network canary registration, with 98.75% of victims located in Brazil. Join the discussion | AlienVault OTX General | 09/16/2026, 10:28:34 UTC Added: 09/16/2026, 10:46:50 UTC |
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack. Join the discussion | AlienVault OTX General | 09/09/2026, 15:55:37 UTC Added: 09/10/2026, 05:37:27 UTC |
The Gentlemen is a ransomware group active since July 2025, operating a Ransomware-as-a-Service model with dual-extortion tactics. They target Windows, Linux, and ESXi systems, focusing on extensive preparation before encrypting data. Their methods include privilege escalation using legitimate tools, persistence via registry and scheduled tasks, disabling security tools, deleting logs, and terminating backup services. They use strong encryption algorithms XChaCha20 and Curve25519. The group primarily targets medium-to-large organizations in the Asia-Pacific region, with a recent surge in activity. Victims face ransom demands with about 10-day deadlines and threats of data publication if unpaid. Join the discussion | AlienVault OTX General | 08/27/2026, 13:05:03 UTC Added: 08/27/2026, 22:07:26 UTC |
Analysis of over 400 AI-enabled malware samples shows that most remain confined to research and sandbox environments, with only a small fraction observed on protected endpoints across three countries. These samples span five malware families including FunkSec ransomware and Oyster backdoor. Existing behavioral detection, cloud sandboxing, and endpoint analytics successfully detect and block all observed samples. The AI component primarily accelerates malware development rather than enabling evasion of defenses. Distribution patterns are opportunistic rather than targeted. Join the discussion | AlienVault OTX General | 08/25/2026, 11:59:25 UTC Added: 08/25/2026, 17:22:13 UTC |
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT. Join the discussion | Reddit NetSec | 08/05/2026, 08:26:37 UTC Added: 08/04/2026, 18:26:01 UTC |
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically... Join the discussion | AlienVault OTX General | 08/04/2026, 18:20:59 UTC Added: 08/05/2026, 09:26:29 UTC |
A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection. Join the discussion | AlienVault OTX General | 07/29/2026, 02:59:33 UTC Added: 07/29/2026, 12:07:07 UTC |
The Gentlemen ransomware group, which emerged in July 2025, employed a zero-day vulnerability in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint detection and response systems. During an incident investigated in early April, the group leveraged an obscure third-party driver named ktapi.sys from Kontron to bypass security protections. The sophisticated exploit chains multiple advanced techniques to navigate Windows exploit mitigations, including bypassing Supervisor Mode Access Prevention and Supervisor Mode Execution Prevention. The toolkit enables the attackers to call privileged kernel mode functions from user mode processes, ultimately terminating EDR processes including Windows Defender, ESET, Palo Alto Cortex XDR, and SentinelOne. The vulnerability had no prior public documentation and was previously absent from vulnerable driver blocklists. Join the discussion | AlienVault OTX General | 06/30/2026, 16:35:05 UTC Added: 07/01/2026, 07:21:30 UTC |
Showing 1 to 10 of 46 results