Threats Tagged 't1087.001'
View all threats tagged with 't1087.001'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1087.001'
Click on any threat for detailed analysis and mitigation recommendations
0 On August 31, 2026, threat actors exploited two zero-day vulnerabilities in PaperCut MF affecting a customer in the Education sector. The attackers targeted an internet-facing print server running vulnerable PaperCut MF version 24.0.2, deploying an in-memory Java loader that established a web shell. Through this web shell, they delivered a trojanized Microsoft Copilot binary containing an AdaptixC2 implant. The implant connected to command-and-control infrastructure hosted on Alibaba servers. After remaining dormant for approximately one day, attackers returned to perform reconnaissance and Active Directory enumeration. They then stole a token from a domain-privileged service account and moved laterally to a domain controller. On the compromised domain controller, they dumped credentials from memory and registry, enabled Windows Restricted Admin mode for pass-the-hash attacks, and extracted the NTDS.dit database containing password hashes for all domain accounts, achieving complete domain compromise. Join the discussion | CVE Database V5 | 10/01/2026, 04:37:48 UTC Added: 08/28/2026, 15:38:05 UTC |
0 KATARU is an IoT malware variant discovered in August 2026 through Telnet credential brute-forcing against a honeypot from Vietnam. While maintaining traditional Mirai-style botnet capabilities, it distinguishes itself through an extensive feature set including multiple Linux local privilege escalation exploits, comprehensive persistence mechanisms across Linux and embedded platforms, encrypted C2 communications using X25519 and ChaCha20-Poly1305, anti-analysis techniques, and decoy traffic generation. Implementation artifacts strongly suggest AI-assisted development, evidenced by architecture-mismatched x86 shellcode in ARM binaries, RFC test vectors as configuration values, and untested cross-platform persistence logic. The malware attempts various privilege escalation paths through system misconfigurations and public exploits, establishes persistence across numerous startup mechanisms, and supports multiple DDoS attack vectors alongside SSH brute-forcing capabilities. Join the discussion | AlienVault OTX General | 09/11/2026, 17:55:38 UTC Added: 05/04/2026, 14:36:50 UTC |
Active exploitation of three critical vulnerabilities in JFrog Artifactory has been identified, with attackers chaining CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 to bypass authentication and gain administrative control. CVE-2026-42018 exposes internal anonymous-user tokens, CVE-2026-42016 enables privilege escalation through insufficient token validation, and CVE-2026-82329 allows unauthenticated access to administrative privileges. Post-exploitation activities include creating persistent administrator accounts, deploying malicious Groovy plugins for code execution, and installing Rust-based backdoors. Exploitation was observed between August 15 and September 8, 2026, affecting multiple organizations. Data indicates 67-69% of organizations running Artifactory had vulnerable instances at initial publication, with slow patching velocity for lower-severity CVEs despite active exploitation across environments. Join the discussion | CVE Database V5 | 09/11/2026, 07:05:53 UTC Added: 08/28/2026, 19:40:07 UTC |
Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig. Join the discussion | AlienVault OTX General | 07/06/2026, 14:02:13 UTC Added: 07/07/2026, 14:14:38 UTC |
0 On June 25, 2026, the first active exploitation of CVE-2026-55255, a critical CVSS 9.9 Langflow vulnerability, was documented. Langflow is an open-source framework for building AI agents and RAG pipelines. A single operator exploited both CVE-2026-55255 (cross-tenant IDOR) and CVE-2026-33017 (unauthenticated RCE, CVSS 9.3) against the same instance. Despite its lower score, the RCE has been exploited thousands of times and is listed in CISA KEV, while the IDOR showed no prior in-the-wild exploitation. The operator focused primarily on the RCE for code execution and implant delivery, using the IDOR opportunistically for credential theft across tenants. The financially motivated threat actor deployed a scripted loader to harvest AWS keys, environment files, and API credentials. This demonstrates that CVSS scores don't always correlate with real-world exploitation rates, as unauthenticated vulnerabilities require less effort than those needing authorization and disclosed object IDs. Join the discussion | CVE Database V5 | 06/26/2026, 21:31:36 UTC Added: 03/20/2026, 05:24:20 UTC |
In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access. CriticalVulnerability Join the discussion | CVE Database V5 | 06/25/2026, 15:21:09 UTC Added: 02/25/2026, 21:47:05 UTC |
An active supply-chain attack targeted over 1.2 million WordPress sites using OptinMonster, TrustPulse, and PushEngage plugins operated by Awesome Motive. Attackers injected malicious JavaScript into legitimate files served through Awesome Motive's CDN endpoints. The malware activates when a logged-in administrator accesses the site, creating backdoor admin accounts (developer_api1 and randomized dev_xxxxxx accounts) and installing a self-hiding PHP plugin. The backdoor provides unauthenticated code execution through a web shell and eval endpoint. Stolen credentials are exfiltrated to tidio.cc, a lookalike domain mimicking the legitimate tidio.com. The breach likely originated from compromised Awesome Motive servers or their BunnyNet CDN account. The campaign began in late April 2026 and remained active through mid-June, affecting OptinMonster (over 1 million installations), TrustPulse, and PushEngage users. Join the discussion | AlienVault OTX General | 06/14/2026, 14:55:34 UTC Added: 06/15/2026, 17:15:21 UTC |
Chinese threat actor VerdantBamboo compromised a victim organization and its Managed Services Provider over an 18-month period, deploying malware on network edge devices lacking EDR coverage. The initial breach involved an Egnyte Storage Sync system, where attackers exploited a sudo misconfiguration for privilege escalation and installed BRICKSTORM backdoor and AGENTPSD fallback implant. Investigation revealed the MSP's pfSense firewall was also compromised with a FreeBSD variant of BRICKSTORM. After remediation, VerdantBamboo regained access through stolen firewall credentials, enabling custom VPN access and deploying PLENET backdoor on a Synology NAS. The threat actor leveraged compromised systems as proxies to access Microsoft 365 environments while evading security controls. VerdantBamboo demonstrated operational discipline by targeting appliances without EDR capabilities and using sophisticated malware including PLENET, compiled with .NET Native AOT to hinder analysis. Join the discussion | AlienVault OTX General | 06/05/2026, 18:07:50 UTC Added: 06/08/2026, 08:48:39 UTC |
A sophisticated npm supply chain attack was uncovered involving the typosquatted package crypto-javascri, designed to mimic the legitimate crypto-js library. The malware harvests npm and GitHub credentials from infected systems, hijacks maintainer accounts, and automatically republishes trojanized versions of packages under trusted identities. The final payload incorporates a weaponized Arti Tor client with credential theft, cryptomining capabilities, privilege escalation via SUID exploitation, and systemd-based persistence mechanisms. The campaign specifically targets Linux developer systems and CI/CD environments, using Tor-based command-and-control infrastructure to maintain anonymity and resilience. The attack creates significant downstream supply chain risk through its worm-like propagation model. Join the discussion | AlienVault OTX General | 05/20/2026, 11:12:11 UTC Added: 05/21/2026, 16:29:45 UTC |
Iranian state-sponsored threat group Seedworm conducted a widespread espionage campaign in early 2026, compromising at least nine organizations across nine countries on four continents. Victims included a major South Korean electronics manufacturer, government agencies, an international airport in the Middle East, Southeast Asian industrial manufacturers, a Latin American financial services provider, and educational institutions. The attackers utilized DLL sideloading techniques with legitimately signed Fortemedia and SentinelOne binaries to execute malicious payloads, deployed Node.js-based implants for orchestration, and employed multiple PowerShell scripts for reconnaissance, credential theft, and privilege escalation. Data exfiltration was conducted through public file-transfer service sendit.sh to blend malicious traffic with legitimate cloud services. The campaign demonstrates Seedworm's evolved tradecraft and expanded targeting beyond traditional Middle Eastern focus areas. Join the discussion | AlienVault OTX General | 05/12/2026, 13:58:56 UTC Added: 05/12/2026, 16:51:32 UTC |
Showing 1 to 10 of 16 results