Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1124'

View all threats tagged with 't1124'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1124

Threats Tagged 't1124'

Click on any threat for detailed analysis and mitigation recommendations

C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
0

C2Looper is a Rust-based backdoor malware identified in mid-2026, likely linked to ransomware threat actors. It is delivered via multi-stage ClickFix infection chains and provides remote shell execution, reconnaissance, and payload deployment capabilities. The malware uses dynamic Windows API resolution and XOR string encryption. It initially communicates over plaintext HTTP but evolved versions use GitHub repositories for command-and-control, storing commands and exfiltrated data in JSON files. Version 2 adds commands for reconnaissance, drive enumeration, shellcode injection, and file listing. C2Looper is actively developed and likely serves initial access brokers facilitating data theft and ransomware attacks.

Join the discussion
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
0

A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: t1124
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses