Skip to main content

Threats Tagged 't1105'

View all threats tagged with 't1105'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1105

Threats Tagged 't1105'

Click on any threat for detailed analysis and mitigation recommendations

0

In early September 2026, Chinese threat actor UTA0565 exploited unpatched zero-day vulnerabilities in Google Chrome and Microsoft Windows through sophisticated phishing campaigns. The actor registered fake domains impersonating legitimate organizations including China Digital Times and the Center for American Progress, sending targeted phishing emails to Asian government entities. Victims were directed to spoofed websites hosting an exploit chain leveraging CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The attacks delivered CLEANGULP, a previously undocumented malware family with backdoor capabilities including command execution, file operations, and beacon object file execution. The malware communicated with command-and-control infrastructure via encrypted HTTP traffic using custom encoding. Multiple Chinese APT groups demonstrated coordinated access to this exploit kit, suggesting widespread sharing within the Chinese cyber espionage community during the vulnerability window.

Join the discussion

This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

Join the discussion
0

A deep technical analysis reveals updates to Hangro, North Korea's state VPN and mail product, operating on servers in Pyongyang and the Russian Far East. A new certificate hierarchy deployed in July 2026 differs significantly from the 2024 version, with both containing cryptographic anomalies where signatures fail verification. Investigation uncovered six network assignments in Chinese address space linked to a single registry contact associated with Silibank, plus infrastructure in Russian Far East networks designated KPOST. The service evolved from a commercial email gateway in 2001 to a certificate-bound VPN deployment issued to trade representatives through consulates. Technical evidence indicates structured infrastructure spanning North Korean, Russian, and Chinese address space, with mail systems configured for bulk transfers over intermittent connections using ten gigabyte message limits and ETRN capabilities.

Join the discussion

In late August, an organization was compromised by INC ransomware across at least 175 endpoints. The attack timeline spanned from early to late August with a 17-day gap, suggesting involvement of an initial access broker and a separate ransomware affiliate. Early August activity included scheduled tasks with randomized names and lateral movement via RDP using a compromised account. After the lull, attackers deployed AnyDesk for remote access, used Bring Your Own Vulnerable Driver tactics to disable security controls, and executed ransomware via Impacket tools. Uniquely, two ransom notes were discovered: the standard INC-README.txt and a subsequent DATALEAK_PRESS_RELEASE.txt containing detailed stolen file listings, threatening to contact media, employees, and partners within 48 hours to increase pressure on victims.

Join the discussion

A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms.

Join the discussion

Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal...

Join the discussion

A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...

Join the discussion

Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.

Join the discussion

Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...

Join the discussion

An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...

Join the discussion

Showing 1 to 10 of 494 results

Filters:Tag: t1105
Page 1 of 50
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses