Threats Tagged 't1059'
View all threats tagged with 't1059'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1059'
Click on any threat for detailed analysis and mitigation recommendations
This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations. Join the discussion | AlienVault OTX General | 09/22/2026, 07:27:17 UTC Added: 09/22/2026, 08:02:57 UTC |
Vidar is an information stealer first observed in 2018 that has continuously evolved its string obfuscation techniques to evade detection and analysis. Between May and September 2026, the malware progressed from basic XOR encryption to ChaCha20-based algorithms, and most recently implemented a custom virtual machine executed via a lightweight bytecode interpreter combined with custom stream ciphers that change per build. The VM uses 14 opcode handlers with simple primitives including XOR, addition, rotation, and substitution. Version 2.0 introduced this VM approach, while versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build variations in opcodes, constants, and substitution tables significantly hinder static and automated analysis capabilities. Join the discussion | AlienVault OTX General | 09/21/2026, 16:45:51 UTC Added: 09/22/2026, 08:02:57 UTC |
0 A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution. Join the discussion | CVE Database V5 | 09/17/2026, 16:23:20 UTC Added: 02/24/2026, 14:47:12 UTC |
Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a modular remote access trojan with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. Previously misclassified as variants of Gh0st RAT or Rekoobe, it is now recognized as a distinct backdoor family. The malware has been deployed in espionage and cybercrime campaigns targeting entities across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan. Multiple threat groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have utilized this tool. Both variants feature shared command-and-control architecture, similar configuration structures, and modular capabilities. The Windows version operates as an in-memory backdoor with file management and proxy capabilities, while the Linux variant provides reverse shell, SOCKS tunneling, and task scheduling functionalities. Evidence suggests an actively maintained, possibly commercial malware toolkit. Join the discussion | AlienVault OTX General | 09/16/2026, 17:02:59 UTC Added: 09/17/2026, 10:46:37 UTC |
In July 2026, IIJ discovered and analyzed an unknown .NET-based malicious tool hosted on a public directory. This tool, named PIVOTPIPE, exhibits functionality similar to Cobalt Strike Beacon, communicating with C2 servers using configurations close to default profiles and supporting numerous C2 commands. However, PIVOTPIPE differs from official Cobalt Strike Beacon through unique implementations including detection evasion code, custom loaders, and obfuscated strings. The tool consists of two components: a loader and RAT module. The loader implements AMSI bypass, indirect syscalls, and sleep masking for EDR evasion. PIVOTPIPE supports TCP Beacon and SMB Beacon functionality for peer-to-peer communication through compromised hosts. Debug artifacts suggest the tool was still under development at the time of discovery, indicating potential future enhancements. Join the discussion | AlienVault OTX General | 09/16/2026, 07:16:35 UTC Added: 09/16/2026, 12:16:36 UTC |
Mythic is an open-source collaborative command-and-control framework with plugin-based architecture supporting multiple agent types and transport profiles. It features a web-based operator interface used by red teams for authorized engagements, though threat actors have also deployed it in unauthorized intrusions. Analysis identifies 131 unique hosts exposing Mythic on the public Internet, with 115 carrying default certificate configurations. The infrastructure spans predominantly DigitalOcean, AWS, and Azure environments, concentrated in the United States, Hong Kong, and China. Default deployment artifacts including TLS certificates with O=Mythic subjects, port 7443 responses, and internal PKI chains enable detection. Multi-framework clusters suggest training environments, while isolated deployments with custom domains and staged payloads indicate operational use with Discord-based transports and steganographic techniques. Join the discussion | AlienVault OTX General | 09/16/2026, 07:07:09 UTC Added: 09/16/2026, 11:02:00 UTC |
Cybercriminals are using fake websites that mimic the legitimate Bitrefill site to defraud users. These lookalike sites appear in search engine results and use domains similar to Bitrefill's, including Punycode variants. Victims are tricked into completing checkout processes that resemble Bitrefill's, paying cryptocurrency to attacker-controlled addresses with no recovery option. The campaign uses sophisticated analytics to optimize victim conversion, indicating organized criminal activity. Join the discussion | AlienVault OTX General | 09/15/2026, 12:44:15 UTC Added: 09/15/2026, 13:47:19 UTC |
Active exploitation of three critical vulnerabilities in JFrog Artifactory has been identified, with attackers chaining CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 to bypass authentication and gain administrative control. CVE-2026-42018 exposes internal anonymous-user tokens, CVE-2026-42016 enables privilege escalation through insufficient token validation, and CVE-2026-82329 allows unauthenticated access to administrative privileges. Post-exploitation activities include creating persistent administrator accounts, deploying malicious Groovy plugins for code execution, and installing Rust-based backdoors. Exploitation was observed between August 15 and September 8, 2026, affecting multiple organizations. Data indicates 67-69% of organizations running Artifactory had vulnerable instances at initial publication, with slow patching velocity for lower-severity CVEs despite active exploitation across environments. Join the discussion | CVE Database V5 | 09/11/2026, 07:05:53 UTC Added: 08/28/2026, 19:40:07 UTC |
Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain... Join the discussion | AlienVault OTX General | 09/09/2026, 15:55:36 UTC Added: 09/10/2026, 05:52:16 UTC |
The Gryxa toolkit is a malware toolkit developed with significant assistance from an AI coding agent, enabling a threat actor with limited development skills to create sophisticated persistent attack infrastructure. It operates across hundreds of hosts and uses multiple persistence mechanisms such as scheduled tasks, Windows event subscriptions, and redundant file copies to resist removal. Gryxa also monitors Windows logs and host artifacts after remediation attempts, potentially exposing defender tools and accounts. The actor iteratively improved the toolkit through numerous failed installations, enhancing its resilience. Organizations face challenges in remediation, especially on devices outside centralized management, as Gryxa can rebuild faster than manual response efforts. Join the discussion | AlienVault OTX General | 08/31/2026, 15:39:24 UTC Added: 08/31/2026, 15:52:13 UTC |
Showing 1 to 10 of 274 results