Threats Tagged 't1087'
View all threats tagged with 't1087'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1087'
Click on any threat for detailed analysis and mitigation recommendations
A six-month sophisticated campaign targeted quantitative and DeFi developers by distributing malicious npm packages masquerading as legitimate mathematics libraries. The campaign uses encrypted loaders that activate only during specific cryptographic operations, such as solving linear equations with certain matrices. Command and control is conducted via Ethereum Sepolia testnet smart contracts and a secondary Slack channel, enabling encrypted tasking of compromised systems. The threat actors inflated download counts using GitHub Actions workers to build false credibility. Fourteen smart contracts across five wallets managed over 1,000 encrypted taskings. The operation shows advanced operational security including disposable accounts, ephemeral key encryption, and infection markers hidden in license files. Join the discussion | AlienVault OTX General | 09/22/2026, 07:30:17 UTC Added: 09/22/2026, 08:02:57 UTC |
Active exploitation of three critical vulnerabilities in JFrog Artifactory has been identified, with attackers chaining CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 to bypass authentication and gain administrative control. CVE-2026-42018 exposes internal anonymous-user tokens, CVE-2026-42016 enables privilege escalation through insufficient token validation, and CVE-2026-82329 allows unauthenticated access to administrative privileges. Post-exploitation activities include creating persistent administrator accounts, deploying malicious Groovy plugins for code execution, and installing Rust-based backdoors. Exploitation was observed between August 15 and September 8, 2026, affecting multiple organizations. Data indicates 67-69% of organizations running Artifactory had vulnerable instances at initial publication, with slow patching velocity for lower-severity CVEs despite active exploitation across environments. Join the discussion | CVE Database V5 | 09/11/2026, 07:05:53 UTC Added: 08/28/2026, 19:40:07 UTC |
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection. Join the discussion | AlienVault OTX General | 09/09/2026, 20:33:03 UTC Added: 09/10/2026, 05:52:16 UTC |
0 A Chinese-speaking cybercrime group dubbed Gambling Goblin has conducted a sustained campaign against Brazilian organizations since mid-2025, primarily targeting government and educational institutions. The attackers compromise web servers and install malicious Apache modules that silently reverse-proxy visitors to phishing pages while appearing to originate from legitimate domains. These phishing pages impersonate trusted app stores like Google Play and Microsoft Store but actually promote online gambling and sports betting. The operation manipulates search engine rankings by chaining together compromised high-reputation domains, particularly Brazilian government sites. The group deploys an extensive Linux toolkit including custom downloaders, backdoors, credential stealers, and reconnaissance tools, most heavily obfuscated to evade detection. Evidence shows the operation extends beyond Brazil with parallel infrastructure targeting Vietnamese, Spanish, and English-speaking victims. Join the discussion | AlienVault OTX General | 09/02/2026, 13:40:05 UTC Added: 09/08/2026, 10:51:59 UTC |
0 Since mid-2025, a Chinese-speaking cybercrime group dubbed Gambling Goblin has conducted a sustained campaign targeting Brazilian organizations, mainly government and educational institutions. The attackers compromise web servers and install malicious Apache modules that stealthily reverse-proxy visitors to phishing pages impersonating trusted app stores. These phishing pages promote online gambling and sports betting while leveraging hijacked high-reputation domains to manipulate search engine rankings and hijack traffic. The group uses a heavily obfuscated Linux toolkit including downloaders, backdoors, credential stealers, and brute-forcers. The infrastructure is scalable and extends beyond Brazil, with parallel phishing networks targeting Vietnamese, Spanish, and English-speaking victims. The phishing infrastructure could be reconfigured to deliver malware directly, posing a latent escalation risk. Join the discussion | Check Point Research | 09/02/2026, 13:40:05 UTC Added: 09/02/2026, 10:30:02 UTC |
Beginning in 2024, a financially motivated threat actor designated BREEZE COMET has conducted sophisticated operations targeting Brazilian financial services, retail, and eCommerce organizations. The group specializes in manipulating payment systems including Pix, STR, and Boleto to conduct fraudulent transfers worth tens of thousands of USD. Their evolved tactics leverage customized malware suites written in multiple languages including Rust, Nim, Golang, and Java, alongside compromised government websites for initial access and command and control. The threat actor demonstrates advanced capabilities by targeting banking software, payment APIs, and mTLS credentials while maintaining persistent access through multiple backdoors. Evidence indicates BREEZE COMET uses generative AI to accelerate malware development and script creation, suggesting potential expansion to other Latin American and African countries based on infrastructure replication observed in Nigeria, Paraguay, Ghana, and Venezuela. Join the discussion | AlienVault OTX General | 09/01/2026, 07:05:40 UTC Added: 09/01/2026, 08:37:15 UTC |
JSCeal is a sophisticated cryptocurrency-focused stealer malware delivered as compiled V8 bytecode executed by a bundled Node.js runtime. It uses multiple layers of JavaScript obfuscation and compilation to evade analysis. The malware includes capabilities such as keylogging, browser and credential theft, screenshot capture, and HTTPS traffic interception via a local man-in-the-middle proxy. Check Point Research developed a static deobfuscation pipeline to analyze JSCeal without execution, enabling detailed understanding of its behavior and evolution. The malware targets multiple platforms including macOS and continues to evolve with new payload encryption and targeting techniques. Join the discussion | Check Point Research | 08/31/2026, 14:00:18 UTC Added: 08/31/2026, 13:46:18 UTC |
0 A suspected Chinese-speaking threat actor conducted targeted intrusions against Philippine nuclear research and defense organizations. On August 13, 2026, an open directory on a VPS exposed custom Python scripts exploiting CVE-2023-49105 in ownCloud and CVE-2024-28000 in WordPress LiteSpeed Cache. The operator exfiltrated approximately 9 GB from a nuclear agency, including reactor core databases, radiation safety documentation, employee PII, BitLocker keys, and strategic planning materials. A second victim, a marine engineering firm serving the Philippine Navy, had its complete WordPress installation compromised. Simplified Chinese language usage throughout scripts, logs, and folder structures indicates operator origin. The methodical targeting of nuclear and naval defense sectors aligns with South China Sea tensions and broader Chinese espionage activities against Philippine government infrastructure. Join the discussion | CVE Database V5 | 08/26/2026, 17:18:25 UTC Added: 04/23/2026, 22:34:35 UTC |
Analysis of over 400 AI-enabled malware samples shows that most remain confined to research and sandbox environments, with only a small fraction observed on protected endpoints across three countries. These samples span five malware families including FunkSec ransomware and Oyster backdoor. Existing behavioral detection, cloud sandboxing, and endpoint analytics successfully detect and block all observed samples. The AI component primarily accelerates malware development rather than enabling evasion of defenses. Distribution patterns are opportunistic rather than targeted. Join the discussion | AlienVault OTX General | 08/25/2026, 11:59:25 UTC Added: 08/25/2026, 17:22:13 UTC |
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment. Join the discussion | AlienVault OTX General | 08/17/2026, 15:03:54 UTC Added: 08/18/2026, 09:26:43 UTC |
Showing 1 to 10 of 101 results