Threats Tagged 't1213'
View all threats tagged with 't1213'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1213'
Click on any threat for detailed analysis and mitigation recommendations
PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft. Join the discussion | AlienVault OTX General | 09/18/2026, 12:51:25 UTC Added: 09/18/2026, 14:16:39 UTC |
Cybercriminals have created numerous fake websites mimicking Bitrefill, a legitimate cryptocurrency-based gift card and eSIM retailer. These fraudulent sites appear in search engine results and use lookalike domains incorporating the Bitrefill brand name with added words or character substitutions, including internationalized domain names using Punycode. Victims are guided through convincing checkout processes that replicate Bitrefill's legitimate payment flow, complete with cryptocurrency options, QR codes, and countdown timers. However, payments are sent directly to attacker-controlled cryptocurrency addresses rather than Bitrefill, with virtually no chance of recovery. The operation demonstrates sophisticated measurement using commercial analytics software to optimize conversion rates, indicating organized criminal activity rather than opportunistic fraud. Join the discussion | AlienVault OTX General | 09/15/2026, 12:44:15 UTC Added: 09/15/2026, 13:47:19 UTC |
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection. Join the discussion | AlienVault OTX General | 09/09/2026, 20:33:03 UTC Added: 09/10/2026, 05:52:16 UTC |
In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments. MediumMalware Join the discussion | AlienVault OTX General | 09/07/2026, 17:14:53 UTC Added: 09/08/2026, 05:07:13 UTC |
Analysis of server infrastructure revealed a complete TukTuk C2 framework (version 2.0) with cross-platform capabilities, including Windows and Linux agents, backend infrastructure, and management panel. The server contained eb.sys matching GentleKiller, along with comprehensive EDR neutralization training materials organized in four progressive lessons covering BYOVD techniques, vulnerable driver hunting, and kernel-level research. DLL sideloading configurations targeting Greenshot, ProcMon, Slack, and Postman were identified. Exfiltrated data included 224 Jira tickets from a global technology company containing information related to U.S. defense organizations and defense contractors, plus credentials from a global healthcare company's Infrastructure-as-Code platform exposing AWS keys, production databases, Azure AD, and Bitbucket access. Join the discussion | AlienVault OTX General | 09/02/2026, 18:24:11 UTC Added: 09/03/2026, 07:52:49 UTC |
0 A suspected Chinese-speaking threat actor conducted targeted intrusions against Philippine nuclear research and defense organizations. On August 13, 2026, an open directory on a VPS exposed custom Python scripts exploiting CVE-2023-49105 in ownCloud and CVE-2024-28000 in WordPress LiteSpeed Cache. The operator exfiltrated approximately 9 GB from a nuclear agency, including reactor core databases, radiation safety documentation, employee PII, BitLocker keys, and strategic planning materials. A second victim, a marine engineering firm serving the Philippine Navy, had its complete WordPress installation compromised. Simplified Chinese language usage throughout scripts, logs, and folder structures indicates operator origin. The methodical targeting of nuclear and naval defense sectors aligns with South China Sea tensions and broader Chinese espionage activities against Philippine government infrastructure. Join the discussion | CVE Database V5 | 08/26/2026, 17:18:25 UTC Added: 04/23/2026, 22:34:35 UTC |
Multiple clusters of North Korean IT workers, designated as PurpleDelta, have been identified applying to over 1,100 companies between late 2024 and early 2025, primarily targeting software, technology, staffing, consulting, and healthcare sectors. The operators maintained at least 22 fabricated personas supported by AI-generated profile photos, custom ChatGPT assistants, and fraudulent identity documents. They demonstrated sophisticated tradecraft, applying to up to 60 positions daily using multi-account management browsers and detailed tracking spreadsheets. During interviews, operators employed screen recording software and AI transcription tools to generate real-time answers, often repeating ChatGPT responses verbatim. Once employed at ten or more organizations, they recorded internal meetings, used personal devices and bank accounts, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware. This activity represents an ongoing insider threat to organizations hirin... Join the discussion | AlienVault OTX General | 08/18/2026, 15:23:41 UTC Added: 08/18/2026, 20:04:25 UTC |
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf... Join the discussion | AlienVault OTX General | 08/14/2026, 10:35:18 UTC Added: 08/13/2026, 13:26:13 UTC |
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise. Join the discussion | AlienVault OTX General | 08/11/2026, 15:03:12 UTC Added: 08/11/2026, 15:26:15 UTC |
Cybercriminals are exploiting API keys used by developers to access AI platforms through a technique called token jacking. Attackers steal these authentication tokens to gain unauthorized access to expensive AI resources, which they either use themselves or resell through gray-market services called transfer stations. These transfer stations act as intermediaries, offering frontier AI model access at discounted rates using stolen credentials. The financial impact can be catastrophic, with victims potentially losing hundreds of thousands to millions of dollars before detection due to unlimited scaling defaults and cyclical billing. Attackers obtain tokens through information stealers, phishing campaigns, compromised code repositories, and poisoned npm packages. Organizations can mitigate risks through spending limits, privileged account reviews, short-term bearer tokens, AI gateways, and tight development environment management. Join the discussion | AlienVault OTX General | 08/06/2026, 12:38:45 UTC Added: 08/06/2026, 16:41:13 UTC |
Showing 1 to 10 of 49 results