Threats Tagged 't1189'
View all threats tagged with 't1189'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1189'
Click on any threat for detailed analysis and mitigation recommendations
APT Group Runs Espionage and Crypto Fraud Operations Side by Side 0 Jewelbug is a China-based hackers-for-hire group conducting espionage against government ministries and militaries in the Middle East, Southeast Asia, and South Asia, while simultaneously running cryptocurrency fraud operations. They use a browser-centric remote-access framework called XG-Web to control their operations. Their main implant is the Antino backdoor, supported by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. A major operation compromised over 15 government webmail tenants in a Middle Eastern country via a watering-hole attack, resulting in over one million implant check-ins and 580,000 stolen browser cookies in three months. The operators are linked to a company registered in Hunan Province, China, and also conduct SEO poisoning targeting Chinese-speaking cryptocurrency users. Join the discussion | AlienVault OTX General | 08/13/2026, 11:29:32 UTC Added: 08/13/2026, 13:26:13 UTC |
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business 0 Jewelbug is a China-based hackers-for-hire group conducting espionage campaigns against foreign governments and militaries, primarily in the Middle East, Southeast Asia, and South Asia, while simultaneously running a cryptocurrency fraud business. The group uses multiple implants including the Antino backdoor, a malicious browser extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. Between February and May 2026, they recorded over one million implant check-ins, stole more than 580,000 browser cookies, and exfiltrated over 2,300 emails. The financially motivated operations include industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. The group operates with a structured development team and role-based access controls. Join the discussion | AlienVault OTX General | 08/13/2026, 11:13:15 UTC Added: 08/13/2026, 13:26:13 UTC |
Fake Corepack Site Distributes Infostealer and Proxyware to Developers 0 A fraudulent website impersonating Corepack, the Node.js package manager tool, is distributing malware to developers. The attackers exploit timing around Corepack's removal from Node.js bundling, targeting developers searching for installation instructions. The site offers Windows executables that deliver OpenShield infostealer and proxyware, enrolling victim machines in bandwidth-sharing networks without consent. The payload steals browser credentials, SSH keys, establishes persistence, and routes third-party traffic through compromised systems. An alternative download path delivers adware and trojan components disguised as OperaGX installer. The site features AI-generated content with obvious errors, including confusing Yarn package manager with textile crafts. The domain has been reported to registrars for takedown after community members identified the threat. Join the discussion | AlienVault OTX General | 07/25/2026, 07:54:44 UTC Added: 07/27/2026, 08:07:08 UTC |
Upgrades MaaS Ecosystem with Modular Tools 0 Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem. Join the discussion | AlienVault OTX General | 07/23/2026, 16:30:34 UTC Added: 07/23/2026, 23:37:06 UTC |
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT 0 Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib... Join the discussion | AlienVault OTX General | 07/23/2026, 00:27:48 UTC Added: 07/23/2026, 15:22:23 UTC |
ACR Stealer: Two observed intrusion chains amid increased threat activity 0 Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i... Join the discussion | AlienVault OTX General | 07/17/2026, 01:19:38 UTC Added: 07/18/2026, 08:55:18 UTC |
Contagious Interview malware in SVG images: DPRK campaign 0 A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers. Join the discussion | AlienVault OTX General | 07/17/2026, 20:08:00 UTC Added: 07/18/2026, 08:55:18 UTC |
Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk 0 Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:39 UTC Added: 07/16/2026, 10:17:37 UTC |
Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries 0 In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information. Join the discussion | AlienVault OTX General | 07/14/2026, 21:17:46 UTC Added: 07/15/2026, 14:19:07 UTC |
Showing 1 to 9 of 9 results