Skip to main content

Threats Tagged 't1112'

View all threats tagged with 't1112'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1112

Threats Tagged 't1112'

Click on any threat for detailed analysis and mitigation recommendations

A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms.

Join the discussion

In 2026, the DPRK-sponsored Lazarus subgroup TraderTraitor continued campaigns targeting cryptocurrency entities, including a high-profile attack on LayerZero resulting in $292 million theft from KelpDAO. Following this disclosure, an additional victim was identified: a smaller IT services provider in India with no cryptocurrency connections. The compromise involved a DevOps engineer targeted through fake job interview lures containing weaponized Terraform coding projects. Malicious GitHub repositories used typosquatted provider domains to deliver macOS backdoors FLATROOF and ROOFDECK when victims executed terraform init. The backdoors enabled reconnaissance, credential theft, and cloud environment escalation. One day after LayerZero's public disclosure, attackers deployed an updated stripped version of ROOFDECK and removed earlier implants. Activity continued until June 2026, suggesting the threat actor ultimately abandoned the intrusion after determining insufficient value from the smaller target.

Join the discussion
0

A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution.

Join the discussion

Settra is a ransomware variant first observed in June 2026 that targets organizations through VPNs or compromised credentials. Two incidents were investigated in July and September 2026, affecting the consumer services, retail, and manufacturing sectors. Attackers deployed MeshAgent RMM for persistence, naming ransomware executables after victim domain names. The malicious activity included file encryption with .locked or .locked_wip extensions, deployment of RESTORE_FILES.txt ransom notes, clearing Windows event logs, and disabling Windows recovery options using reagentc and diskpart utilities. One incident featured Bring Your Own Vulnerable Driver (BYOVD) tactics using gdrv.sys. A notable operational security failure occurred when attackers misspelled the Windows Defender Event Log path, preventing its deletion. Both attacks followed remarkably similar operational patterns, with MeshAgent installations pointing to different C2 IP addresses (45.13.122[.]7 and 193.5.65[.]114), and malicious workstation WIN...

Join the discussion

Threat actors exploited trusted brands and cloud services in a sophisticated web campaign combining fraudulent DocuSign workflows, Florida healthcare screening lures, and deceptive cloud infrastructure to deploy ConnectWise ScreenConnect Access clients. The attack utilized Cloudflare Pages hosting with fake Cloudflare verification workflows to establish legitimacy. Victims were socially engineered to download a ZIP archive containing a malicious HTA file that employed Base64-encoded VBScript, fake Adobe interfaces, UAC privilege escalation, and Microsoft Defender SmartScreen registry modifications. The attack leveraged living-off-the-land techniques using native Windows tools like mshta.exe, curl.exe, and msiexec.exe for silent ScreenConnect installation, ultimately providing unauthorized remote access. The campaign was classified as Zero Hour Fraudulent and blocked at the web entry point before payload delivery could occur.

Join the discussion

Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

Join the discussion

Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

Join the discussion

A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

Join the discussion

Toy Ghouls, a financially motivated group targeting Russian organizations since 2025, has deployed custom backdoors for the first time. Two versions were identified: mqtt-bird-agent using HiveMQ MQTT broker and matrix-bird-agent using Element messenger as command and control infrastructure. The backdoors are delivered via Windows Remote Management (WinRM) using tools like Evil-WinRM and WinRM-fs. They establish persistence as Windows services, encrypt configuration files using ChaCha20-Poly1305 algorithm, and execute commands via PowerShell or command line. The backdoors collect system metrics including CPU load, memory, and disk usage, and communicate with attackers through unconventional channels. This represents a significant evolution from their previous reliance on public GitHub tools and leaked ransomware builders to custom-developed malware.

Join the discussion

Attack campaigns targeting Korean users have been observed deploying remote control tools including Radmin and UltraVNC to compromise systems. The initial intrusion vector remains unidentified, but attackers download compressed files containing batch scripts and remote administration software. Following Radmin installation, threat actors leverage access to deploy UltraVNC alongside proxy tools such as Netch-gateway and CCProxy, ultimately utilizing compromised systems as proxy nodes. Recent variants include SoftEther VPN deployment to establish VPN servers on infected infrastructure. PowerShell scripts containing Chinese language comments, combined with tools familiar to Chinese-speaking actors, suggest attribution to Chinese threat operators. The campaigns enable both remote system control and abuse of compromised infrastructure for proxy services.

Join the discussion

Showing 1 to 10 of 215 results

Filters:Tag: t1112
Page 1 of 22
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses