Threats Tagged 't1210'
View all threats tagged with 't1210'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1210'
Click on any threat for detailed analysis and mitigation recommendations
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives. Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts. The operation exploited unauthenticated Redis instances using rogue replication techniques to inject cron jobs that deployed XMRig miners. Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities. The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors. A separate February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities, extending the operator's known activity timeline by five months. The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work... Join the discussion | AlienVault OTX General | 09/08/2026, 16:59:09 UTC Added: 09/09/2026, 09:22:16 UTC |
A China-linked cyber espionage infrastructure provider operates a multi-component 'quartermaster' system that offers reconnaissance, proxy orchestration, and traffic routing services to Chinese state-sponsored actors. The infrastructure includes QScan for reconnaissance, Fast Labyrinth for encrypted relay networks using commercial proxy services, QTRouter for proxy access management, and QTProxy for operational node control. It targets research universities, defense networks, government agencies, and critical infrastructure worldwide, with notable focus on the U.S., U.K., and Asia-Pacific regions. The operation leverages commercial proxy services designed to bypass China's Great Firewall, enabling multiple threat actors to maintain anonymity and coordinate operations via shared infrastructure. This represents an advanced evolution in state-enabled cyber espionage capabilities. Join the discussion | AlienVault OTX General | 08/26/2026, 22:00:43 UTC Added: 08/27/2026, 22:07:26 UTC |
An exposed open directory on a Netherlands-hosted server revealed the complete operational toolkit of xlabs_v1, a Mirai-derived IoT botnet operated by an actor using the handle Tadashi. The operation provides DDoS-for-hire services specifically targeting game servers and Minecraft hosts through 21 distinct flood attack variants. The botnet exploits Android Debug Bridge (ADB) on TCP/5555 to compromise over 4 million potentially vulnerable IoT devices including Android TV boxes, smart TVs, and routers. The operation features bandwidth profiling to price-tier infected devices, ChaCha20 string encryption with cryptographic weaknesses, and competitor-eradication routines. Infrastructure analysis consolidated the entire operation within a single bulletproof /24 netblock in the Netherlands, with co-located cryptojacking infrastructure also identified. Join the discussion | AlienVault OTX General | 04/29/2026, 19:42:01 UTC Added: 04/30/2026, 07:51:22 UTC |
0 A critical remote code execution vulnerability (CVE-2025-59287) exists in Microsoft Windows Server Update Services (WSUS) affecting versions from Windows Server 2012 through 2025 with the WSUS role enabled. This flaw allows unauthenticated attackers to execute code with system privileges by targeting exposed WSUS instances on ports 8530 and 8531. Initial patching on October 14, 2025, was incomplete, necessitating an emergency update on October 23. Exploitation has been observed within hours of patch release, with attackers leveraging malicious PowerShell commands for reconnaissance and data exfiltration. Approximately 5,500 WSUS instances are exposed globally, representing a significant attack surface. The vulnerability facilitates initial access and lateral movement within networks. European organizations using WSUS for patch management are at risk of compromise, data theft, and broader network infiltration. Immediate patching and network exposure reduction are critical to mitigate this threat. Join the discussion | AlienVault OTX General | 12/07/2025, 08:53:15 UTC Added: 12/08/2025, 18:23:52 UTC |
0 A new component of PolarEdge's infrastructure, RPX_Client, has been discovered, revealing insights into the threat actor's relay operations. The investigation uncovered 140 VPS nodes acting as RPX Servers and over 25,000 infected devices serving as RPX Clients. The system uses a multi-hop design to conceal attack sources, with compromised IoT devices and VPS servers forming robust barriers. RPX_Client functions as a jumpserver in the Operational Relay Box (ORB) network, providing proxy services and enabling remote command execution. The analysis also revealed connections between previously known PolarEdge infrastructure and the newly discovered components, confirming the attribution to this threat actor. Join the discussion | AlienVault OTX General | 10/29/2025, 18:37:31 UTC Added: 10/04/2025, 10:11:59 UTC |
Forescout honeypot caught hacktivist activity targeting a decoy water treatment plant in Sept.2025. A Russian-aligned group, TwoNet, claimed responsibility for the attack. The group logged into the human-machine interface (HMI) for: defacement, process disruption, manipulation, and evasion. Join the discussion | AlienVault OTX General | 10/10/2025, 16:56:05 UTC Added: 10/10/2025, 17:10:27 UTC |
A significant spike in brute-force traffic targeting Fortinet SSL VPNs was observed on August 3, with over 780 unique IPs triggering the Fortinet SSL VPN Bruteforcer tag. The activity was deliberate and precise, focusing on FortiOS. Two distinct waves of attacks were identified: a long-running set of brute-force activity and a sudden burst beginning August 5. The second wave shifted from targeting FortiOS to FortiManager - FGFM profile. Historical data revealed a potential residential origin or proxy use. The analysis suggests evolving attack patterns and potential reuse of tooling. Research indicates that such spikes often precede new vulnerability disclosures within six weeks. Defenders are advised to use GreyNoise to search for and block malicious IPs associated with this campaign. Join the discussion | AlienVault OTX General | 08/13/2025, 16:59:06 UTC Added: 08/13/2025, 17:17:49 UTC |
AhnLab Security Intelligence Center analyzed attacks on Windows web servers during Q2 2025 using their Smart Defense infrastructure. The study focused on poorly managed servers, categorizing attack types and malware strains. It revealed that multiple threat actors often target vulnerable servers simultaneously, exploiting unpatched systems or misconfigurations. Attackers typically use file upload vulnerabilities to deploy web shells and execute commands, but may also exploit framework or Web Application Server weaknesses. The analysis provides detailed statistics on the number of affected systems and the frequency of attacks, offering insights into the current threat landscape for Windows-based web servers. Join the discussion | AlienVault OTX General | 08/08/2025, 17:08:28 UTC Added: 08/08/2025, 21:02:50 UTC |
Malware campaigns exploiting vulnerabilities in Ivanti Connect Secure devices, specifically CVE-2025-0282, have been active from December 2024 through July 2025. Attackers use MDifyLoader to side-load Cobalt Strike Beacon DLLs, along with vshell RAT and Fscan network scanner, to maintain persistent access. Initial access is gained via brute-force attacks, direct exploitation, and stolen credentials. The threat actors employ advanced lateral movement, persistence mechanisms such as domain account creation and malware service/task registration, and evasion techniques including use of legitimate files and ETW bypasses. European organizations using Ivanti Connect Secure devices are particularly targeted. The threat is assessed as medium severity due to moderate impact and exploitation complexity. No public exploits are currently available. Join the discussion | AlienVault OTX General | 07/18/2025, 07:33:09 UTC Added: 07/18/2025, 09:03:17 UTC |
The report discusses the evolving landscape of vulnerability reporting and management, highlighting concerns about the long-term stability of the CVE system. It notes the emergence of competing projects and the potential fragmentation of vulnerability data sources. The first half of 2025 has seen an increase in CVE publications and Known Exploited Vulnerabilities (KEVs), with a growing proportion affecting network-related equipment. The report emphasizes the importance of continuous tracking and patching of vulnerabilities. It also covers Microsoft's July 2025 security update, addressing 132 vulnerabilities, including critical remote code execution issues. The report stresses the need for prompt application of patches to mitigate potential risks. Join the discussion | AlienVault OTX General | 07/11/2025, 06:42:36 UTC Added: 07/11/2025, 10:46:22 UTC |
Showing 1 to 10 of 10 results