Skip to main content

Threats Tagged 't1105'

View all threats tagged with 't1105'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1105

Threats Tagged 't1105'

Click on any threat for detailed analysis and mitigation recommendations

This campaign involves multiple cybersecurity incidents where trusted AI platforms have been exploited as channels for malware distribution. The threat actors employ advanced persistent threat techniques including exploitation of vulnerabilities, social engineering, and deployment of custom malware frameworks. Targets span government, technology, financial, and defense sectors, with a focus on supply chain attacks, credential harvesting, data exfiltration, system compromise, and lateral movement within networks. Several malicious domains have been identified as indicators related to this campaign.

Join the discussion
0

This analysis details updates to Hangro, North Korea's state VPN and mail system infrastructure, spanning North Korean, Russian, and Chinese network address spaces. The service uses a certificate hierarchy with cryptographic anomalies and supports bulk mail transfers over intermittent connections. The infrastructure has evolved from a commercial email gateway to a certificate-bound VPN service for trade representatives. Network assignments linked to Silibank and infrastructure in the Russian Far East have been identified. The system employs large message limits and ETRN capabilities for mail relay.

Join the discussion

In late August, an organization experienced a ransomware attack by the INC group affecting at least 175 endpoints. The attack timeline shows two distinct phases separated by a 17-day gap, indicating possible involvement of an initial access broker followed by a ransomware affiliate. Initial activities included scheduled tasks with randomized names and lateral movement via RDP using compromised credentials. After the pause, attackers used AnyDesk for remote access, employed Bring Your Own Vulnerable Driver (BYOVD) techniques to disable security controls, and executed ransomware using Impacket tools. Two ransom notes were found: the standard INC-README.txt and a DATALEAK_PRESS_RELEASE.txt which threatened to leak stolen data to media, employees, and partners within 48 hours to increase pressure on the victim.

Join the discussion

A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms.

Join the discussion

Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal...

Join the discussion

A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...

Join the discussion

Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.

Join the discussion

Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...

Join the discussion

An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...

Join the discussion

Brazilian banking malware operation REF9334 has been deploying KREMLIN toolkit since May 2025, targeting Brazilian financial institutions through malicious browser extensions. The operation uses multi-stage JavaScript loaders, custom C++ installers, and exploits Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs. Infrastructure leverages Ethereum smart contracts as dead-drop resolvers for dynamic C2 configuration. Seven distinct campaigns over 15 months show evolution from PULSAR RAT to REMCOS RAT delivery. Attackers impersonate twelve Brazilian banks through Portuguese-language lures, with transaction patterns clustering during São Paulo working hours. The malicious extensions intercept credentials, session tokens, and sensitive banking data through keylogging and request interception capabilities. Over 1,500 infections have been temporarily disrupted through network canary registration, with 98.75% of victims located in Brazil.

Join the discussion

Showing 1 to 10 of 494 results

Filters:Tag: t1105
Page 1 of 50
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses