Threats Tagged 't1078.004'
View all threats tagged with 't1078.004'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1078.004'
Click on any threat for detailed analysis and mitigation recommendations
The TensorLake npm SDK version 0.5.144 was compromised in a supply chain attack involving ChainDrop/Shai-Hulud malware. The malicious package, downloaded approximately 12,000 times weekly, contains obfuscated code that steals credentials from various sources such as npm tokens, GitHub tokens, AWS credentials, HashiCorp Vault, Kubernetes configs, SSH keys, and AI development tools. It executes via a preinstall hook, establishes persistence through scheduled tasks, and supports remote code execution. The attack uses an Ethereum contract for command-and-control and includes a dead-man switch that triggers destructive actions if stolen GitHub tokens are revoked. The malware can self-propagate by republishing compromised versions to other npm packages linked to the victim's publishing identity, spreading across the npm ecosystem. Join the discussion | AlienVault OTX General | 10/08/2026, 07:08:15 UTC Added: 10/08/2026, 08:03:43 UTC |
Attackers who obtain AWS credentials are actively validating them to determine their usefulness for accessing Amazon Bedrock services. Credential harvesting platforms, including KMON_NOC, test stolen AWS keys by calling GetCallerIdentity, then verifying Bedrock access through ListFoundationModels and Converse API calls. This validation enables attackers to assess the value of credentials for resale in token-jacking markets, where stolen AI model access is sold below retail price. The testing targets Anthropic Claude models and enumerates promotional credits to estimate financial worth. This behavior represents an evolution in credential validation techniques similar to those previously observed with AWS SES and SNS services. Join the discussion | AlienVault OTX General | 10/06/2026, 17:14:48 UTC Added: 10/07/2026, 09:48:30 UTC |
0 On August 31, 2026, threat actors exploited two zero-day vulnerabilities in PaperCut MF affecting a customer in the Education sector. The attackers targeted an internet-facing print server running vulnerable PaperCut MF version 24.0.2, deploying an in-memory Java loader that established a web shell. Through this web shell, they delivered a trojanized Microsoft Copilot binary containing an AdaptixC2 implant. The implant connected to command-and-control infrastructure hosted on Alibaba servers. After remaining dormant for approximately one day, attackers returned to perform reconnaissance and Active Directory enumeration. They then stole a token from a domain-privileged service account and moved laterally to a domain controller. On the compromised domain controller, they dumped credentials from memory and registry, enabled Windows Restricted Admin mode for pass-the-hash attacks, and extracted the NTDS.dit database containing password hashes for all domain accounts, achieving complete domain compromise. Join the discussion | CVE Database V5 | 10/01/2026, 04:37:48 UTC Added: 08/28/2026, 15:38:05 UTC |
0 KATARU is an IoT malware variant discovered in August 2026 through Telnet credential brute-forcing against a honeypot from Vietnam. While maintaining traditional Mirai-style botnet capabilities, it distinguishes itself through an extensive feature set including multiple Linux local privilege escalation exploits, comprehensive persistence mechanisms across Linux and embedded platforms, encrypted C2 communications using X25519 and ChaCha20-Poly1305, anti-analysis techniques, and decoy traffic generation. Implementation artifacts strongly suggest AI-assisted development, evidenced by architecture-mismatched x86 shellcode in ARM binaries, RFC test vectors as configuration values, and untested cross-platform persistence logic. The malware attempts various privilege escalation paths through system misconfigurations and public exploits, establishes persistence across numerous startup mechanisms, and supports multiple DDoS attack vectors alongside SSH brute-forcing capabilities. Join the discussion | AlienVault OTX General | 09/11/2026, 17:55:38 UTC Added: 05/04/2026, 14:36:50 UTC |
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection. Join the discussion | AlienVault OTX General | 09/09/2026, 20:33:03 UTC Added: 09/10/2026, 05:52:16 UTC |
An attacker exploited a flawed GitHub Actions workflow in the npm package @7nohe/openapi-react-query-codegen to publish 10 malicious versions. The vulnerability stemmed from an issue_comment trigger lacking author-association checks, allowing arbitrary users to trigger npm publishing from forked repositories. The malicious payload used multiple execution methods, including a binding.gyp file exploiting node-gyp's Python evaluation and a preinstall hook, ultimately delivering a large obfuscated script that downloaded Bun v1.4.0. This attack aligns with the Mini Shai-Hulud toolkit previously seen in other supply chain compromises. All malicious versions have been removed from npm. Join the discussion | AlienVault OTX General | 08/31/2026, 09:00:33 UTC Added: 08/31/2026, 09:37:18 UTC |
This analysis examines infrastructure used by multiple Russian cyber espionage clusters targeting individuals in academia, think tanks, and organizations across Europe and the United States. The investigation expands on three threat clusters (UNC6293, UNC7005, and UNC5976) that employed OAuth phishing, Microsoft device code phishing, and WhatsApp targeting. UNC6293 utilized lure domains impersonating the Council on Foreign Relations and government portals, with possible Evilginx configurations. UNC7005 demonstrated lower sophistication with poor operational security, using domains like my-invite[.]org for phishing campaigns. UNC5976 employed Google Drive impersonation domains for OAuth phishing. The analysis leverages historical DNS data, CSS hash similarities, favicon analysis, registration patterns, and certificate information to identify additional infrastructure and tracking methods for discovering related malicious domains and IP addresses. Join the discussion | AlienVault OTX General | 08/26/2026, 21:58:59 UTC Added: 08/27/2026, 22:07:26 UTC |
RecruitTrap is a sophisticated phishing campaign targeting enterprise credentials by impersonating HR personnel from well-known companies. It uses Browser-in-the-Browser techniques on desktop and full-screen fake login pages on mobile without visible URL indicators. The campaign actively screens victims to focus on corporate accounts, rejecting personal emails. Attackers impersonate multiple global brands and use persistent hosting on Amazon and SEDO networks. Detection of malicious domains is significantly delayed by traditional threat feeds. The campaign facilitates credential harvesting, OAuth token theft, and lateral movement within organizations. Join the discussion | AlienVault OTX General | 08/25/2026, 02:55:59 UTC Added: 08/25/2026, 10:52:01 UTC |
Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—target individuals in academia, aerospace, defense, governments, and think tanks in Europe and the US. They use sophisticated phishing techniques including app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are linked with moderate confidence to ICE RELIC (APT29), while UNC5976 is distinct. Their operations involve social engineering tactics such as fake diplomatic invitations and conference registrations. They abuse legitimate authentication mechanisms like Google OAuth and Microsoft device codes, complicating detection. Join the discussion | AlienVault OTX General | 08/20/2026, 17:09:14 UTC Added: 08/20/2026, 23:22:26 UTC |
Educational institutions continue to be the most targeted sector globally, experiencing an average of 4,696 weekly cyberattacks per organization between January and July 2026, representing an 8% increase year-over-year and more than double the cross-industry average. The back-to-school period sees intensified malicious activity, with July 2026 recording 4,848 weekly attacks. Threat actors are registering thousands of education-themed domains, with one in every 226 newly registered domains being malicious. APAC leads with 7,452 weekly attacks, while Europe and Latin America show the fastest growth at 18% and 42% respectively. Attackers deploy phishing campaigns impersonating retailers, schools, and Microsoft 365 to steal credentials and financial information from students, educators, and families during peak enrollment periods. Join the discussion | AlienVault OTX General | 08/20/2026, 11:45:48 UTC Added: 08/20/2026, 23:07:12 UTC |
Showing 1 to 10 of 70 results