Threats Tagged 't1211'
View all threats tagged with 't1211'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1211'
Click on any threat for detailed analysis and mitigation recommendations
0 The DeadLock ransomware campaign employs a new Bring Your Own Vulnerable Driver (BYOVD) loader exploiting CVE-2024-51324, a vulnerability in Baidu Antivirus driver, to evade endpoint detection and response (EDR) tools. Attackers use PowerShell scripts to bypass User Account Control (UAC), disable Windows Defender, terminate security services, and delete volume shadow copies, facilitating ransomware deployment. DeadLock ransomware targets Windows systems with a custom stream cipher encryption using time-based cryptographic keys, employing advanced techniques such as recursive directory traversal, memory-mapped file I/O, and multi-threaded processing. Initial access is gained through compromised accounts, followed by system registry modifications, remote access establishment, reconnaissance, lateral movement, and defense impairment. Although no known exploits are currently in the wild, the sophisticated use of BYOVD and defense evasion techniques poses a significant threat to organizations. The attack complexity and multi-stage process highlight the need for targeted mitigation strategies. This threat is particularly relevant to European organizations using Baidu Antivirus or similar vulnerable drivers and those with Windows-based infrastructure. The suggested severity is high due to the potential for widespread impact, ease of defense evasion, and the ransomware’s destructive capabilities. Join the discussion | AlienVault OTX General | 12/10/2025, 09:43:19 UTC Added: 12/10/2025, 10:05:28 UTC |
This analysis delves into the HijackLoader malware campaign, which has gained prominence since 2023 for its sophisticated payload delivery and evasion techniques. The campaign initiates with a CAPTCHA-based phishing attack, progressing through multiple stages of obfuscated PowerShell scripts. It employs advanced anti-analysis methods, including anti-VM checks and registry manipulation. The final payload, typically an infostealer like NekoStealer or Lumma, is delivered via a multi-stage process involving packed .NET executables and protected DLLs. The loader's evolution and its role in the broader malware-as-a-service ecosystem underscore the need for organizations to focus on detecting initial access and intermediate stages rather than just final payloads. Join the discussion | AlienVault OTX General | 09/12/2025, 14:56:55 UTC Added: 09/12/2025, 19:29:21 UTC |
A sophisticated backdoor targeting Exchange servers of high-value organizations in Asia has been discovered. The malware, named GhostContainer, is a multi-functional backdoor that can be dynamically extended with additional modules. It leverages several open-source projects and employs various evasion techniques to avoid detection. The backdoor grants attackers full control over the Exchange server and can function as a proxy or tunnel. The malware is believed to be part of an APT campaign targeting government and high-tech companies in Asia. It includes components for C2 parsing, virtual page injection, and web proxy functionality. The attackers demonstrated expertise in exploiting Exchange systems and assembling sophisticated espionage tools. Join the discussion | AlienVault OTX General | 07/17/2025, 14:59:54 UTC Added: 07/17/2025, 19:46:10 UTC |
Showing 1 to 3 of 3 results