Threats Tagged 't1120'
View all threats tagged with 't1120'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1120'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated phishing campaign impersonating Tesseract OCR was discovered, utilizing typosquatting and ClickFix techniques. The attack chain, named OCRFix, employed multi-stage malware deployments with heavy obfuscation and defense evasion techniques, including EtherHiding. The campaign used BNB Smart Chain TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like ClickFix and the importance of robust phishing defenses. Join the discussion | AlienVault OTX General | 02/27/2026, 09:28:41 UTC Added: 02/27/2026, 09:55:15 UTC |
The Water Saci campaign is a sophisticated malware operation targeting Portuguese-language systems, leveraging WhatsApp Web hijacking and multi-vector persistence mechanisms. It uses script-based techniques such as VBS downloaders and PowerShell scripts to automate malware distribution and maintain resilience. The campaign employs an email-based command and control infrastructure using IMAP for command retrieval, supplemented by HTTP polling for continuous communication. It features advanced anti-analysis capabilities and real-time remote control, enabling infected machines to operate as a coordinated botnet. The malware shares similarities with the Coyote banking trojan, indicating ties to Brazilian cybercriminal groups. Although no known exploits are reported in the wild, the campaign's complexity and persistence mechanisms pose a medium-level threat. European organizations with Portuguese-speaking user bases or connections to Brazil should be particularly vigilant. Mitigation requires targeted detection of script-based loaders, monitoring of WhatsApp Web session anomalies, and securing email clients against unauthorized IMAP access. Countries with strong economic or cultural ties to Brazil, such as Portugal and Spain, are most likely to be affected. Join the discussion | AlienVault OTX General | 10/27/2025, 15:20:48 UTC Added: 10/27/2025, 16:37:36 UTC |
A coordinated spearphishing campaign targeted NGOs and Ukrainian government administrations involved in war relief efforts. The attack used emails impersonating the Ukrainian President's Office with weaponized PDFs, employing a fake Cloudflare captcha page to execute malware. The final payload was a WebSocket RAT enabling remote command execution and data exfiltration. Despite six months of preparation, the attackers' infrastructure was only active for one day, indicating sophisticated planning and operational security. An additional mobile attack vector was discovered, using fake applications to collect data from Android devices. The campaign demonstrated extensive operational planning, compartmentalized infrastructure, and deliberate exposure control. Join the discussion | AlienVault OTX General | 10/22/2025, 19:45:18 UTC Added: 10/22/2025, 19:52:59 UTC |
A wide-ranging phishing campaign has been identified that enables threat actors to bypass traditional security controls and delay detection. The campaign, tracked since 2024, has facilitated remote surveillance, credential theft, lateral movement, data exfiltration, and ransomware across numerous organizations. The likely new or rebranded cybercriminal group behind this campaign uses legitimate services like TryCloudflare to host and deliver highly evasive malware such as AsyncRAT and other Remote Access Trojans. This malware allows threat actors to remotely control infected networks throughout the full attack lifecycle. The campaign targets organizations globally across multiple sectors without industry preference, using widely available malware and difficult-to-detect techniques involving Python scripts, obfuscated batch scripts, trusted cloud services, and dynamic infrastructure. Join the discussion | AlienVault OTX General | 06/17/2025, 20:39:06 UTC Added: 06/18/2025, 11:34:31 UTC |
This investigation delves into information operations conducted by Russian actors known as Doppelgänger, focusing on their activities from early June to late-July 2024. It examines their tactics, associated infrastructure, and motivations, particularly in relation to the unexpected snap general election in France during this period. The analysis reveals a persistent and complex effort to disseminate disinformation through social media, impersonating legitimate news websites and employing intricate redirection chains. The operations primarily target conservative and nationalist sentiments, aiming to destabilize Western democracies by exploiting existing societal and political divisions. Join the discussion | AlienVault OTX General | 07/30/2024, 14:44:01 UTC Added: 08/07/2025, 13:02:45 UTC |
Showing 1 to 5 of 5 results