Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1074'

View all threats tagged with 't1074'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1074

Threats Tagged 't1074'

Click on any threat for detailed analysis and mitigation recommendations

CoolClient backdoor goes deeper: Windows kernel rootkit added
0

The HoneyMyte APT group (Mustang Panda) has enhanced its CoolClient backdoor by adding a signed Windows kernel-mode rootkit driver (msagent.sys). This driver operates as a Windows service and provides stealth capabilities such as hiding processes, protecting files and registry entries, and filtering network traffic. The malware uses DLL sideloading via a legitimate Sangfor application, persists through scheduled tasks and AutoRun entries, and bypasses User Account Control (UAC). CoolClient injects into synchost.exe and communicates with the kernel driver using IOCTL requests. The rootkit hooks Nsiproxy to filter command and control (C2) addresses. Initial infection vectors include PlugX malware. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia.

Join the discussion
ACR Stealer: Two observed intrusion chains amid increased threat activity
0

Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...

Join the discussion
​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​
0

Kratos is a phishing-as-a-service (PhaaS) operation targeting Microsoft 365 users primarily in the United States, Spain, and Southern Europe. It enables attackers to steal credentials via sophisticated phishing pages with anti-bot measures and trusted platform mimicry. The kit has evolved through three generations and includes an operator panel for managing phishing campaigns with geographic restrictions and multiple delivery methods. Activity has been observed since early 2026.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: t1074
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses