Threats Tagged 't1113'
View all threats tagged with 't1113'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1113'
Click on any threat for detailed analysis and mitigation recommendations
Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal... Join the discussion | AlienVault OTX General | 09/18/2026, 21:49:13 UTC Added: 09/21/2026, 08:46:37 UTC |
Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands. Join the discussion | AlienVault OTX General | 09/18/2026, 13:20:16 UTC Added: 09/18/2026, 14:16:39 UTC |
LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan identified by Blackpoint, designed to masquerade as legitimate NVIDIA software. It provides comprehensive remote access capabilities including command execution, file operations, screen capture, and SOCKS5 proxying. The malware features configurable enrollment fields and an internal ZM_ configuration namespace, suggesting it is built on a reusable, multi-tenant framework consistent with a malware-as-a-service offering. LabubaRAT is managed through an associated backend infrastructure called LabubaPanel, hosted on German providers. The delivery mechanism utilized the RAT's own JavaScript execution capability. First observed in July 2026, it targets Windows platforms and employs various evasion techniques including masquerading as NVIDIA components and abusing legitimate Microsoft build utilities. Join the discussion | AlienVault OTX General | 09/18/2026, 12:51:24 UTC Added: 09/18/2026, 14:01:41 UTC |
Analysis reveals HEAVYGRAM, a multi-stage Windows backdoor attributed to Iran-linked threat actor Handala Hack, deployed since Fall 2023 targeting Iranian dissidents, journalists, and government opponents. The surveillance tool uses Telegram bot API for command-and-control operations, enabling remote command execution, screen capture, data exfiltration, and persistent access. Victims receive social-engineered files masquerading as legitimate applications like Telegram, KeePass, or Pictory. The implant supports DLL side-loading, registry persistence, and system reconnaissance. Infrastructure analysis identified 29 samples utilizing networks of Telegram bots and groups for operations. The malware aligns with activity disclosed by U.S. Department of Justice regarding Iran's Ministry of Intelligence and Security infrastructure seizures, with tradecraft including Vultr Object Storage and Persian-language decoys targeting specific victim profiles including academics and media personnel. Join the discussion | AlienVault OTX General | 09/17/2026, 21:02:31 UTC Added: 09/18/2026, 08:16:51 UTC |
ESET researchers have documented SparroWocky, a sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This China-aligned threat actor has shifted focus to extensively targeting governmental organizations across Latin America, likely in response to increased US interest in the region. SparroWocky replaced the group's previous SparrowDoor backdoor and demonstrates advanced capabilities including reflective loading, anti-analysis techniques like SilentMoonwalk for call stack spoofing, and the ability to execute Beacon Object Files. The modular backdoor incorporates open-source projects directly into its codebase, uses TLS-encrypted communications with RC4 encryption for data exfiltration, and employs sophisticated evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting pattern reflects China's strategic interest in monitoring Latin American governmental responses to current US pressures regarding investments and infrastruc... Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:02 UTC Added: 09/18/2026, 08:46:41 UTC |
VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations. Join the discussion | AlienVault OTX General | 09/16/2026, 17:03:00 UTC Added: 09/17/2026, 10:46:37 UTC |
Brazilian banking malware operation REF9334 has been deploying KREMLIN toolkit since May 2025, targeting Brazilian financial institutions through malicious browser extensions. The operation uses multi-stage JavaScript loaders, custom C++ installers, and exploits Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs. Infrastructure leverages Ethereum smart contracts as dead-drop resolvers for dynamic C2 configuration. Seven distinct campaigns over 15 months show evolution from PULSAR RAT to REMCOS RAT delivery. Attackers impersonate twelve Brazilian banks through Portuguese-language lures, with transaction patterns clustering during São Paulo working hours. The malicious extensions intercept credentials, session tokens, and sensitive banking data through keylogging and request interception capabilities. Over 1,500 infections have been temporarily disrupted through network canary registration, with 98.75% of victims located in Brazil. Join the discussion | AlienVault OTX General | 09/16/2026, 10:28:34 UTC Added: 09/16/2026, 10:46:50 UTC |
BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o... Join the discussion | AlienVault OTX General | 09/16/2026, 09:45:38 UTC Added: 09/16/2026, 12:31:39 UTC |
Mythic is an open-source collaborative command-and-control framework with plugin-based architecture supporting multiple agent types and transport profiles. It features a web-based operator interface used by red teams for authorized engagements, though threat actors have also deployed it in unauthorized intrusions. Analysis identifies 131 unique hosts exposing Mythic on the public Internet, with 115 carrying default certificate configurations. The infrastructure spans predominantly DigitalOcean, AWS, and Azure environments, concentrated in the United States, Hong Kong, and China. Default deployment artifacts including TLS certificates with O=Mythic subjects, port 7443 responses, and internal PKI chains enable detection. Multi-framework clusters suggest training environments, while isolated deployments with custom domains and staged payloads indicate operational use with Discord-based transports and steganographic techniques. Join the discussion | AlienVault OTX General | 09/16/2026, 07:07:09 UTC Added: 09/16/2026, 11:02:00 UTC |
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack. Join the discussion | AlienVault OTX General | 09/09/2026, 15:55:37 UTC Added: 09/10/2026, 05:37:27 UTC |
Showing 1 to 10 of 233 results