Threats Tagged 't1106'
View all threats tagged with 't1106'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1106'
Click on any threat for detailed analysis and mitigation recommendations
Fake CAPTCHA, Real Business: Traffic Distribution for Hire 0 A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines. MediumMalware Join the discussion | AlienVault OTX General | 08/05/2026, 14:36:07 UTC Added: 08/06/2026, 08:56:14 UTC |
CVE-2026-66747: CWE-506 Embedded Malicious Code in Zbtlink CPE2801 FirmwareCVE-2026-66747 0 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root. Join the discussion | CVE Database V5 | 08/05/2026, 10:50:45 UTC Added: 08/05/2026, 11:11:59 UTC |
Phishing Email Delivers ScreenConnect Malware 0 A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads. Join the discussion | AlienVault OTX General | 08/04/2026, 18:14:35 UTC Added: 08/05/2026, 09:26:29 UTC |
Fake AI Tools Deliver Infostealer 0 In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges... Join the discussion | AlienVault OTX General | 08/04/2026, 18:21:01 UTC Added: 08/05/2026, 09:11:32 UTC |
Analysis of a Phishing Email Attack Case 0 The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation. Join the discussion | AlienVault OTX General | 08/03/2026, 16:50:56 UTC Added: 08/04/2026, 08:34:07 UTC |
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan 0 Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations. Join the discussion | AlienVault OTX General | 07/29/2026, 02:59:33 UTC Added: 07/29/2026, 12:07:07 UTC |
Inside a TrickBot Variant Using DNS Tunneling for C2 0 A TrickBot variant has been identified that uses DNS tunneling for command-and-control communications instead of traditional HTTP protocols. The malware maintains persistence through Windows Task Scheduler, creating disguised tasks that execute at startup and repeat every five minutes. Configuration data is stored in NTFS Alternate Data Streams to evade detection. The malware employs multiple obfuscation techniques including encrypted strings, runtime API resolution via hash-based lookups, and dynamically calculated constants. Its modular architecture supports twelve different control commands enabling capabilities such as module downloads, process injection through hollowing and doppelgänging techniques, PowerShell execution, and raw machine code execution. The variant transfers data through specially crafted DNS queries to public DNS servers, encoding command data in malformed domain names and receiving responses embedded within multiple IPv4 addresses, achieving transfer speeds of approximately 30.7 KB/s. Join the discussion | AlienVault OTX General | 07/22/2026, 19:55:37 UTC Added: 07/22/2026, 22:22:19 UTC |
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI 0 A newly discovered Windows stealer and remote access trojan called Dolphin X targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. The malware collects credentials ranging from browser logins to SSH keys, .env files, and cloud tokens. A distinctive feature called the AI Profiler automatically scores infected victims based on application usage, browsing activity, and installed software, helping attackers identify high-value targets through daily summaries. The malware builder operates through a remote server that compiles agents and offers optional mutation engines to evade detection. Advertised by a vendor using the alias Kontraktnik, Dolphin X poses significant risk to developers and organizations by potentially exposing access to entire production environments through compromised DevOps credentials. Join the discussion | AlienVault OTX General | 07/22/2026, 19:55:38 UTC Added: 07/22/2026, 22:22:19 UTC |
Targeted Attack on Government Entities in the Middle East | Part 1 0 A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures. Join the discussion | AlienVault OTX General | 08/03/2026, 21:38:36 UTC Added: 07/21/2026, 10:27:03 UTC |
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service 0 Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks. Join the discussion | AlienVault OTX General | 07/20/2026, 09:36:09 UTC Added: 07/20/2026, 11:11:45 UTC |
Showing 1 to 10 of 16 results