Threats Tagged 't1192'
View all threats tagged with 't1192'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1192'
Click on any threat for detailed analysis and mitigation recommendations
Cisco Talos observed a spear-phishing attack delivering LucidRook, a newly identified stager that targeted a Taiwanese NGO in October 2025. The metadata in the email suggests that it was delivered via authorized mail infrastructure, which implies potential misuse of legitimate sending capabilities. Join the discussion | AlienVault OTX General | 04/08/2026, 13:48:46 UTC Added: 04/08/2026, 16:35:48 UTC |
Threat actors are exploiting tax season with numerous campaigns leveraging tax themes to deliver malware, remote monitoring tools, fraud attempts, and credential phishing. Over a hundred campaigns have been observed in 2026, with a notable increase in remote monitoring and management (RMM) payloads. Tactics include impersonating tax agencies, claiming expired documents, and requesting tax filing support. While primarily targeting the United States, campaigns have also been observed in Canada, Australia, Switzerland, and Japan. Notable actors include TA4922, a newly designated threat group delivering malware from the Winos4.0 ecosystem, and TA2730, focusing on credential phishing for financial institutions. Business email compromise actors are also using tax form lures to steal financial and personal data. These campaigns demonstrate the ongoing exploitation of timely and topical themes by cybercriminals to deceive users. Join the discussion | AlienVault OTX General | 03/30/2026, 09:16:31 UTC Added: 03/30/2026, 10:08:15 UTC |
Silver Fox, a threat actor, is exploiting Japan's tax filing and organizational change season with a targeted spearphishing campaign against Japanese businesses. The group sends convincing phishing emails related to tax compliance, salary adjustments, and HR matters, tricking recipients into opening malicious links or attachments. The campaign capitalizes on the high volume of legitimate financial and HR communications during this period, increasing the risk of compromise. Silver Fox has expanded its targets from Chinese-speaking entities to Southeast Asia, Japan, and potentially North America. The group uses ValleyRAT, a remote access trojan, to gain control of compromised machines and steal sensitive information. To protect against this threat, organizations should increase vigilance, reinforce awareness about phishing attempts, and verify the authenticity of tax- and HR-themed requests. Join the discussion | AlienVault OTX General | 03/28/2026, 16:12:50 UTC Added: 03/30/2026, 10:08:15 UTC |
A significant joint offensive by the US and Israel has triggered a multi-vector retaliatory campaign from Iran, leading to an escalation in cyberattacks. Iran's limited internet connectivity is likely hindering state-aligned threat actors' ability to coordinate sophisticated attacks. Hacktivist groups are targeting perceived adversaries, while other nation-state actors may exploit the situation. Observed activities include phishing campaigns, DDoS attacks, data exfiltration, and wiper attacks. Multiple Iranian state-aligned personas and collectives have claimed responsibility for various disruptive operations. Pro-Russian hacktivist groups have also been active, targeting Israeli systems and infrastructure. The situation remains fluid, and organizations are advised to implement multi-layered defenses and focus on foundational security hygiene. Join the discussion | AlienVault OTX General | 03/03/2026, 06:39:44 UTC Added: 03/03/2026, 17:02:26 UTC |
Threat actors have discovered a novel method to bypass security controls by abusing the .arpa top-level domain (TLD) in conjunction with IPv6 tunnels. They are exploiting a feature in DNS record management of certain providers to add IP address records for .arpa domains, allowing them to host phishing content on domains that should not resolve to an IP address. The phishing campaigns use spam emails impersonating major brands, with hyperlinked images leading to malicious websites through traffic distribution systems. This technique weaponizes trusted infrastructure essential for network operations, making it challenging for security tools to detect suspicious domains based on reputation, registration information, or policy blocklists. Join the discussion | AlienVault OTX General | 02/27/2026, 09:28:00 UTC Added: 02/27/2026, 09:55:15 UTC |
A sophisticated phishing campaign has been detected that utilizes a multi-stage approach to evade detection. The attack begins with a procurement-themed email containing a PDF attachment. This PDF redirects victims to another PDF hosted on trusted cloud storage, which then leads to a fake Dropbox login page. The attackers exploit trusted platforms and harmless file formats to bypass security measures. The campaign uses social engineering tactics to harvest credentials, which are then exfiltrated to attacker-controlled infrastructure via Telegram. This method proves effective by leveraging legitimate business processes, trusted file types, and reputable cloud services to appear authentic and bypass automated security checks. Join the discussion | AlienVault OTX General | 02/02/2026, 18:31:08 UTC Added: 02/02/2026, 20:15:08 UTC |
CNCERT and Microstep Online jointly detected a cyberattack campaign launched by the "Black Cat" criminal gang. This gang uses search engine SEO (Search Engine Optimization) techniques to push meticulously crafted phishing websites to the top of search engine keyword results. After visiting these high-ranking phishing pages, users are lured by carefully designed download pages, attempting to download software installation packages bundled with malicious programs. Once installed, the program implants a backdoor Trojan without the user's knowledge, leading to the theft of sensitive data from their host computer by attackers. Join the discussion | AlienVault OTX General | 01/09/2026, 10:24:39 UTC Added: 01/09/2026, 10:28:21 UTC |
During the holiday season, threat actors exploit overloaded inboxes and financial stress through two main patterns: Docusign-themed phishing for corporate credential harvesting and loan offer spam for personal data theft. The Docusign campaign uses spoofed emails with authentic-looking branding, redirecting through disposable hosting platforms to a credential harvesting page. The loan scams range from obvious 'Xmas loan' offers to sophisticated marketing-style emails, ultimately leading victims to a detailed identity theft questionnaire on christmasscheercash.com. Both scams utilize seasonal themes and mimic normal end-of-year workflows to increase effectiveness. Defensive measures include verifying sender domains, validating link destinations, and treating unsolicited loan offers as high risk. Join the discussion | AlienVault OTX General | 12/23/2025, 15:09:12 UTC Added: 12/23/2025, 17:31:03 UTC |
Following Hurricane Melissa's devastation in Jamaica in October 2025, cybercriminals launched a series of online scams exploiting the disaster. These scams included phishing campaigns, fake charity websites, and fraudulent financial-relief portals impersonating legitimate aid organizations. Attackers used social engineering tactics to prey on victims' compassion and urgency, often deploying scams within hours of the hurricane. A prominent example involved a cryptocurrency donation site with fabricated transaction data and static images to appear authentic. Numerous fraudulent domains soliciting cryptocurrency donations were identified. While primarily targeting individuals, these scams undermine trust in digital charity platforms and complicate legitimate relief efforts. European organizations involved in disaster relief, financial services, or public awareness campaigns should be vigilant. The threat is medium severity due to social engineering reliance and no direct system exploitation. Mitigation requires enhanced awareness, domain monitoring, and collaboration between cybersecurity entities and relief organizations. Join the discussion | AlienVault OTX General | 11/14/2025, 02:36:40 UTC Added: 11/14/2025, 11:37:02 UTC |
In October 2025, a wave of sophisticated cyber attacks targeted corporate environments, leveraging phishing campaigns exploiting trusted platforms like Google Careers and ClickUp, abusing Figma for credential theft, and deploying the LockBit 5.0 ransomware variant against ESXi and Linux systems. Attackers used legitimate cloud services and multi-stage redirection to evade detection, while a new phishing kit named TyKit emerged. These campaigns threaten corporate credentials, infrastructure integrity, and data confidentiality across multiple sectors. The attacks do not require known exploits in the wild but rely heavily on social engineering and abuse of trusted platforms. Security operations centers (SOCs) must enhance detection capabilities, harden access controls, and employ advanced threat intelligence to mitigate these evolving threats. The overall severity is medium, reflecting the complexity and multi-vector nature of the attacks but without widespread exploitation of zero-day vulnerabilities. European organizations, especially those using affected platforms and cloud services, face significant risks from credential theft and ransomware infection. Join the discussion | AlienVault OTX General | 10/29/2025, 18:37:27 UTC Added: 10/29/2025, 20:13:19 UTC |
Showing 1 to 10 of 17 results