Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1049'

View all threats tagged with 't1049'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1049

Threats Tagged 't1049'

Click on any threat for detailed analysis and mitigation recommendations

Node.js: Old Technique Makes a Comeback
0

A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

Join the discussion
Toolkit: AI-Assisted Development and Persistent Threat Operations
0

A threat actor developed the Gryxa toolkit with substantial assistance from an AI coding agent, demonstrating how artificial intelligence lowers the skill barrier for creating sophisticated attack infrastructure. The actor operated across several hundred hosts despite lacking development experience, deceiving the AI agent by falsely claiming authorized testing purposes. Gryxa employs multiple persistence mechanisms including seven scheduled tasks, Windows event subscriptions, and redundant file copies, making it resilient to removal attempts. The toolkit includes monitoring capabilities that collect Windows logs and host artifacts after remediation attempts, potentially exposing defender tools and accounts. The actor iteratively improved the toolkit through 35 documented failed installations, working with the AI agent to enhance resilience. Organizations face challenges remediating devices outside centralized management, where Gryxa can rebuild faster than manual response efforts.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: t1049
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses