Skip to main content

Threats Tagged 't1090.001'

View all threats tagged with 't1090.001'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1090.001

Threats Tagged 't1090.001'

Click on any threat for detailed analysis and mitigation recommendations

On August 31, 2026, threat actors exploited two zero-day vulnerabilities in PaperCut MF affecting a customer in the Education sector. The attackers targeted an internet-facing print server running vulnerable PaperCut MF version 24.0.2, deploying an in-memory Java loader that established a web shell. Through this web shell, they delivered a trojanized Microsoft Copilot binary containing an AdaptixC2 implant. The implant connected to command-and-control infrastructure hosted on Alibaba servers. After remaining dormant for approximately one day, attackers returned to perform reconnaissance and Active Directory enumeration. They then stole a token from a domain-privileged service account and moved laterally to a domain controller. On the compromised domain controller, they dumped credentials from memory and registry, enabled Windows Restricted Admin mode for pass-the-hash attacks, and extracted the NTDS.dit database containing password hashes for all domain accounts, achieving complete domain compromise.

Join the discussion

ESET researchers have documented SparroWocky, a sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This China-aligned threat actor has shifted focus to extensively targeting governmental organizations across Latin America, likely in response to increased US interest in the region. SparroWocky replaced the group's previous SparrowDoor backdoor and demonstrates advanced capabilities including reflective loading, anti-analysis techniques like SilentMoonwalk for call stack spoofing, and the ability to execute Beacon Object Files. The modular backdoor incorporates open-source projects directly into its codebase, uses TLS-encrypted communications with RC4 encryption for data exfiltration, and employs sophisticated evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting pattern reflects China's strategic interest in monitoring Latin American governmental responses to current US pressures regarding investments and infrastruc...

Join the discussion

VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.

Join the discussion

Mythic is an open-source command-and-control (C2) framework used by red teams and threat actors. Analysis found 131 unique Mythic C2 hosts exposed on the public Internet, with most using default TLS certificates. These deployments span major cloud providers and are concentrated in the US, Hong Kong, and China. Default artifacts such as TLS certificates with O=Mythic and port 7443 responses enable detection. Some clusters appear to be training environments, while isolated deployments with custom domains and advanced transport methods like Discord and steganography indicate operational use.

Join the discussion

In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

Join the discussion

Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately.

Join the discussion

Between late July and mid-August 2026, multiple organizations were compromised by a sophisticated modular RAT disguised as a legitimate Exodus cryptocurrency wallet. Victims were tricked through fake PDFs or software updates delivered via JavaScript files that downloaded a tampered Windows Installer package. The installer deploys genuine Exodus wallet version 24.33.4 with three modified files that prevent the user interface from displaying while establishing persistent access. The payload includes six modules providing hidden VNC, SOCKS proxy, browser credential theft, file management, remote shell, and script execution capabilities. Communication occurs via Azure Table Storage as a dead drop mechanism, avoiding traditional command and control domains. The RAT maintains persistence through scheduled tasks executing hourly and includes mechanisms to bypass corporate proxy configurations.

Join the discussion

Mirage Kitten, an APT group historically focused on the Middle East and Africa, has deployed two previously undocumented cross-platform remote access trojans: NodeRabbit (Node.js-based) and PollCat (JavaScript-based). Both malware families mark the group's first departure from native malware toward scripting languages compatible with Windows, Linux, and macOS. Operators deliver these tools through sophisticated social engineering campaigns involving fake recruiters on LinkedIn who distribute trojanized coding challenges via Amazon S3 buckets. The malicious projects contain backdoored npm packages that silently install persistent implants. NodeRabbit implements comprehensive command-and-control capabilities including file operations, process management, and proxy-aware C2 communications through Azure and Cloudflare infrastructure. PollCat provides similar RAT functionality with specialized developer persistence mechanisms targeting VS Code extensions and Git hooks. Targeted sectors include aviation, aerospa...

Join the discussion

A China-linked cyber espionage infrastructure provider operates a multi-component 'quartermaster' system that offers reconnaissance, proxy orchestration, and traffic routing services to Chinese state-sponsored actors. The infrastructure includes QScan for reconnaissance, Fast Labyrinth for encrypted relay networks using commercial proxy services, QTRouter for proxy access management, and QTProxy for operational node control. It targets research universities, defense networks, government agencies, and critical infrastructure worldwide, with notable focus on the U.S., U.K., and Asia-Pacific regions. The operation leverages commercial proxy services designed to bypass China's Great Firewall, enabling multiple threat actors to maintain anonymity and coordinate operations via shared infrastructure. This represents an advanced evolution in state-enabled cyber espionage capabilities.

Join the discussion

During a targeted intrusion investigation in June 2026, investigators uncovered GoCaracal, a previously undocumented modular framework written in Go. This sophisticated toolkit exists in two operational profiles: a lightweight implant for establishing access and delivering payloads, and an extended build for sustained intelligence collection with capabilities including keylogging, browser credential theft, WebRTC remote desktop, and SOCKS5 proxying. Analysis of 249 samples traced the framework's evolution from January to July 2026, revealing active development and maturation. A notable innovation includes an Ethereum smart-contract fallback mechanism enabling operators to update C2 infrastructure without redeploying malware. The activity targeted a Venezuelan communications organization using Spanish-language financial lures, weaponized SVG files, and delivery methods consistent with established tradecraft. GoCaracal was deployed alongside an updated Bandook variant, suggesting the new framework currently ...

Join the discussion

Showing 1 to 10 of 30 results

Filters:Tag: t1090.001
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses