Threats Tagged 't1090.002'
View all threats tagged with 't1090.002'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1090.002'
Click on any threat for detailed analysis and mitigation recommendations
A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection. Join the discussion | AlienVault OTX General | 09/29/2026, 06:34:53 UTC Added: 09/29/2026, 19:21:24 UTC |
An Israeli influence-for-hire company called BlackCore has been identified conducting digital manipulation campaigns across multiple countries. The company operates through a sophisticated infrastructure offering services including discourse dominance, organic engagement manipulation, and counter-operations. Researchers identified a specific campaign involving a 14-week training program delivered to Angolan government employees in early 2026, which included the creation and deployment of fake social media personas and coordinated inauthentic behavior. The operation utilized AI-generated profile pictures, fake news outlets like 'Agita News', and coordinated amplification tactics across Facebook, Instagram, and TikTok. BlackCore's promotional materials openly advertised their capabilities to conduct deceptive influence operations on behalf of government clients, demonstrating how influence-for-hire services have become accessible to state actors seeking to manipulate online discourse. MediumCampaign Join the discussion | AlienVault OTX General | 09/17/2026, 21:02:33 UTC Added: 09/18/2026, 09:01:46 UTC |
A significant supply chain attack compromised Brevo's infrastructure on September 14, 2026, affecting over 100,000 customer websites. Attackers injected malicious code into Brevo's JavaScript assets and widgets, delivering two distinct payloads: a WordPress plugin backdoor automatically installed when site administrators visited their own sites while logged in, and ClickFix overlays targeting regular visitors. The attack vector involved modification of Brevo's CDN-hosted files and creation of malicious subdomains under sendibt1.com. Evidence suggests attackers gained access to Brevo's Cloudflare account, allowing them to modify DNS records and rewrite content dynamically. The malicious activity lasted approximately four hours, from 16:05 to 20:12 UTC. Brevo's prominent clients include eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential impact significantly. Join the discussion | AlienVault OTX General | 09/17/2026, 20:54:15 UTC Added: 09/18/2026, 08:46:41 UTC |
ESET researchers have documented SparroWocky, a sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This China-aligned threat actor has shifted focus to extensively targeting governmental organizations across Latin America, likely in response to increased US interest in the region. SparroWocky replaced the group's previous SparrowDoor backdoor and demonstrates advanced capabilities including reflective loading, anti-analysis techniques like SilentMoonwalk for call stack spoofing, and the ability to execute Beacon Object Files. The modular backdoor incorporates open-source projects directly into its codebase, uses TLS-encrypted communications with RC4 encryption for data exfiltration, and employs sophisticated evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting pattern reflects China's strategic interest in monitoring Latin American governmental responses to current US pressures regarding investments and infrastruc... Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:02 UTC Added: 09/18/2026, 08:46:41 UTC |
Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm... Join the discussion | AlienVault OTX General | 09/16/2026, 17:20:48 UTC Added: 09/17/2026, 10:46:37 UTC |
Illegal online gambling infrastructure spans three distinct cybercrime categories that defenders often overlook. First, over 1.7 million Chinese-language casino domains facilitate illegal gambling and transnational money laundering, primarily operated by triad-aligned syndicates. Second, thousands of "scambling" websites target global audiences with rigged games and withdrawal fraud, using deposit bonuses to lure victims. Third, China-aligned APT groups deploy the PeckBirdy malware framework within fake casino and adult websites as command-and-control infrastructure, targeting education, government, finance and technology sectors across Asia. These operations exploit U.S. and European hosting providers through infrastructure laundering while maintaining bulletproof Asian hosting. The campaigns have escalated sharply since 2023, with PeckBirdy domains achieving zero detection rates on VirusTotal. All three types appear visually identical, creating detection challenges for security teams. Join the discussion | AlienVault OTX General | 09/16/2026, 12:31:13 UTC Added: 09/16/2026, 13:01:39 UTC |
A malicious browser extension called 'Twitch Enhanced Viewer | JeetBot' distributed on Chrome Web Store and Firefox Add-ons captures and forwards users' live Twitch OAuth session tokens to Russian-controlled proxy servers. The extension, with approximately 30,000 Chrome users and 552 Firefox users, markets itself as a quality-of-life tool for blocking ads and unlocking streams. While delivering these features, it secretly extracts users' account-scoped OAuth tokens and forwards them as query parameters to operator-controlled infrastructure. Current versions append tokens inline during video playlist redirects, while earlier builds explicitly POSTed tokens to dedicated collection endpoints. The operator is identified as a commercial Russian bot service called JeetBot, with infrastructure hosted across German and cloud providers. Join the discussion | AlienVault OTX General | 09/11/2026, 18:06:36 UTC Added: 09/14/2026, 10:02:03 UTC |
0 A Chinese-speaking cybercrime group dubbed Gambling Goblin has conducted a sustained campaign against Brazilian organizations since mid-2025, primarily targeting government and educational institutions. The attackers compromise web servers and install malicious Apache modules that silently reverse-proxy visitors to phishing pages while appearing to originate from legitimate domains. These phishing pages impersonate trusted app stores like Google Play and Microsoft Store but actually promote online gambling and sports betting. The operation manipulates search engine rankings by chaining together compromised high-reputation domains, particularly Brazilian government sites. The group deploys an extensive Linux toolkit including custom downloaders, backdoors, credential stealers, and reconnaissance tools, most heavily obfuscated to evade detection. Evidence shows the operation extends beyond Brazil with parallel infrastructure targeting Vietnamese, Spanish, and English-speaking victims. Join the discussion | AlienVault OTX General | 09/02/2026, 13:40:05 UTC Added: 09/08/2026, 10:51:59 UTC |
0 Since mid-2025, a Chinese-speaking cybercrime group dubbed Gambling Goblin has conducted a sustained campaign targeting Brazilian organizations, mainly government and educational institutions. The attackers compromise web servers and install malicious Apache modules that stealthily reverse-proxy visitors to phishing pages impersonating trusted app stores. These phishing pages promote online gambling and sports betting while leveraging hijacked high-reputation domains to manipulate search engine rankings and hijack traffic. The group uses a heavily obfuscated Linux toolkit including downloaders, backdoors, credential stealers, and brute-forcers. The infrastructure is scalable and extends beyond Brazil, with parallel phishing networks targeting Vietnamese, Spanish, and English-speaking victims. The phishing infrastructure could be reconfigured to deliver malware directly, posing a latent escalation risk. Join the discussion | Check Point Research | 09/02/2026, 13:40:05 UTC Added: 09/02/2026, 10:30:02 UTC |
BRIDGEHEAD is a supply-chain typosquatting campaign discovered in August 2026 that distributed 40 malicious npm packages impersonating popular libraries such as chalk, axios, and lodash. These packages contained install scripts that detect Windows or Windows Subsystem for Linux (WSL) environments and download a 22MB Rust-based executable from GitHub. The payload executes entirely in memory without writing files to disk and targets cryptocurrency wallets, browser credentials, cookies, and Telegram sessions. The campaign leverages legitimate services for reconnaissance and data exfiltration, complicating detection and takedown efforts. Although the malicious npm packages were removed within 84 minutes, the GitHub-hosted payload remained active for 39 hours, and the command-and-control server continued operating. This campaign specifically targets developers using WSL by crossing from Linux environments into Windows systems. Join the discussion | AlienVault OTX General | 08/20/2026, 17:08:20 UTC Added: 08/20/2026, 23:37:24 UTC |
Showing 1 to 10 of 26 results