Threats Tagged 't1055'
View all threats tagged with 't1055'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1055'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms. Join the discussion | AlienVault OTX General | 09/21/2026, 15:16:13 UTC Added: 09/21/2026, 15:31:54 UTC |
In April 2026, a manufacturing organization in the Middle East suffered a ransomware attack where threat actors with domain admin privileges weaponized Active Directory Group Policy Objects to achieve domain-wide impact without deploying ransomware binaries on Windows endpoints. The attackers created malicious GPOs linked at the domain root, delivering ransom notes, hijacking wallpapers and lock screens, enforcing logon banners, and disabling local administrator accounts across all domain-joined workstations. No file encryption occurred on Windows systems; instead, the operation focused on encryptionless extortion through operational disruption and data exfiltration. Initial access was gained via compromised VPN credentials. The attack remained dormant for one day between GPO creation and detonation, evading file-based detection entirely by abusing trusted AD infrastructure. Join the discussion | AlienVault OTX General | 09/21/2026, 11:54:10 UTC Added: 09/21/2026, 15:31:54 UTC |
A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c... Join the discussion | AlienVault OTX General | 09/18/2026, 13:37:03 UTC Added: 09/18/2026, 14:31:52 UTC |
0 A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution. Join the discussion | CVE Database V5 | 09/17/2026, 16:23:20 UTC Added: 02/24/2026, 14:47:12 UTC |
Settra is a ransomware variant first observed in June 2026 that targets organizations through VPNs or compromised credentials. Two incidents were investigated in July and September 2026, affecting the consumer services, retail, and manufacturing sectors. Attackers deployed MeshAgent RMM for persistence, naming ransomware executables after victim domain names. The malicious activity included file encryption with .locked or .locked_wip extensions, deployment of RESTORE_FILES.txt ransom notes, clearing Windows event logs, and disabling Windows recovery options using reagentc and diskpart utilities. One incident featured Bring Your Own Vulnerable Driver (BYOVD) tactics using gdrv.sys. A notable operational security failure occurred when attackers misspelled the Windows Defender Event Log path, preventing its deletion. Both attacks followed remarkably similar operational patterns, with MeshAgent installations pointing to different C2 IP addresses (45.13.122[.]7 and 193.5.65[.]114), and malicious workstation WIN... Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:01 UTC Added: 09/18/2026, 08:46:41 UTC |
Brazilian banking malware operation REF9334 has been deploying KREMLIN toolkit since May 2025, targeting Brazilian financial institutions through malicious browser extensions. The operation uses multi-stage JavaScript loaders, custom C++ installers, and exploits Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs. Infrastructure leverages Ethereum smart contracts as dead-drop resolvers for dynamic C2 configuration. Seven distinct campaigns over 15 months show evolution from PULSAR RAT to REMCOS RAT delivery. Attackers impersonate twelve Brazilian banks through Portuguese-language lures, with transaction patterns clustering during São Paulo working hours. The malicious extensions intercept credentials, session tokens, and sensitive banking data through keylogging and request interception capabilities. Over 1,500 infections have been temporarily disrupted through network canary registration, with 98.75% of victims located in Brazil. Join the discussion | AlienVault OTX General | 09/16/2026, 10:28:34 UTC Added: 09/16/2026, 10:46:50 UTC |
BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o... Join the discussion | AlienVault OTX General | 09/16/2026, 09:45:38 UTC Added: 09/16/2026, 12:31:39 UTC |
In July 2026, IIJ discovered and analyzed an unknown .NET-based malicious tool hosted on a public directory. This tool, named PIVOTPIPE, exhibits functionality similar to Cobalt Strike Beacon, communicating with C2 servers using configurations close to default profiles and supporting numerous C2 commands. However, PIVOTPIPE differs from official Cobalt Strike Beacon through unique implementations including detection evasion code, custom loaders, and obfuscated strings. The tool consists of two components: a loader and RAT module. The loader implements AMSI bypass, indirect syscalls, and sleep masking for EDR evasion. PIVOTPIPE supports TCP Beacon and SMB Beacon functionality for peer-to-peer communication through compromised hosts. Debug artifacts suggest the tool was still under development at the time of discovery, indicating potential future enhancements. Join the discussion | AlienVault OTX General | 09/16/2026, 07:16:35 UTC Added: 09/16/2026, 12:16:36 UTC |
Mythic is an open-source collaborative command-and-control framework with plugin-based architecture supporting multiple agent types and transport profiles. It features a web-based operator interface used by red teams for authorized engagements, though threat actors have also deployed it in unauthorized intrusions. Analysis identifies 131 unique hosts exposing Mythic on the public Internet, with 115 carrying default certificate configurations. The infrastructure spans predominantly DigitalOcean, AWS, and Azure environments, concentrated in the United States, Hong Kong, and China. Default deployment artifacts including TLS certificates with O=Mythic subjects, port 7443 responses, and internal PKI chains enable detection. Multi-framework clusters suggest training environments, while isolated deployments with custom domains and staged payloads indicate operational use with Discord-based transports and steganographic techniques. Join the discussion | AlienVault OTX General | 09/16/2026, 07:07:09 UTC Added: 09/16/2026, 11:02:00 UTC |
LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands. Join the discussion | AlienVault OTX General | 09/11/2026, 13:15:36 UTC Added: 09/11/2026, 14:32:10 UTC |
Showing 1 to 10 of 399 results