Threats Tagged 't1074'
View all threats tagged with 't1074'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1074'
Click on any threat for detailed analysis and mitigation recommendations
CoolClient backdoor goes deeper: Windows kernel rootkit added 0 The HoneyMyte APT group (Mustang Panda) has enhanced its CoolClient backdoor by adding a signed Windows kernel-mode rootkit driver (msagent.sys). This driver operates as a Windows service and provides stealth capabilities such as hiding processes, protecting files and registry entries, and filtering network traffic. The malware uses DLL sideloading via a legitimate Sangfor application, persists through scheduled tasks and AutoRun entries, and bypasses User Account Control (UAC). CoolClient injects into synchost.exe and communicates with the kernel driver using IOCTL requests. The rootkit hooks Nsiproxy to filter command and control (C2) addresses. Initial infection vectors include PlugX malware. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia. Join the discussion | AlienVault OTX General | 08/14/2026, 10:50:02 UTC Added: 08/14/2026, 11:26:13 UTC |
ACR Stealer: Two observed intrusion chains amid increased threat activity 0 Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i... Join the discussion | AlienVault OTX General | 07/17/2026, 01:19:38 UTC Added: 07/18/2026, 08:55:18 UTC |
Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk 0 Kratos is a phishing-as-a-service (PhaaS) operation targeting Microsoft 365 users primarily in the United States, Spain, and Southern Europe. It enables attackers to steal credentials via sophisticated phishing pages with anti-bot measures and trusted platform mimicry. The kit has evolved through three generations and includes an operator panel for managing phishing campaigns with geographic restrictions and multiple delivery methods. Activity has been observed since early 2026. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:39 UTC Added: 07/16/2026, 10:17:37 UTC |
Showing 1 to 3 of 3 results